Pillar 06

Re-Test & Proof

A finding is not closed because someone says it is closed. It is closed when it has been tested again and failed to reproduce.

This is the step most engagements skip, and it is the one that converts a report into an asset. Remediation frequently goes wrong quietly — the fix is applied to staging, or to one of four servers, or it is reverted by a later change. Without verification you have a document describing problems you believe are gone.

Re-Test & Proof — Reed Sentinel

What we check

What we check

Finding-by-finding verification

Each item re-tested using the original reproduction steps, not a fresh scan that might miss it.

Regression checking

Whether the remediation introduced anything new, which happens more often than most teams expect.

Reissued report

An updated document showing each finding’s original severity and its verified current state.

Evidence for third parties

The page you hand to an insurer, an auditor, or an enterprise client asking whether you have been tested.

Audit trail

The tamper-evident log covering the re-test as well, so the verification is as provable as the original engagement.

Residual risk statement

An honest account of what was not fixed and why, because an unqualified clean report is rarely a truthful one.

How it works

How it works

01

You remediate

Your team works the prioritised list. We are available for questions but the fixes are yours to apply.

02

We re-test

Every finding re-attempted under the original scope and authorisation.

03

Verify or return

Items that reproduce go back with additional detail. Items that do not are marked verified closed.

04

Reissue

The final report, dated and branded, showing the position before and after.

What we usually find

What we usually find

Re-testing exists because remediation fails quietly far more often than anyone expects. The team believes the finding is closed; the report says it is closed; the system says otherwise. These are the four ways it usually goes wrong.

Fixed on one server of several

The change is applied to the host named in the report, while three identical machines behind the same load balancer keep the original configuration.

Fixed in staging, not production

The remediation is real, tested and correct — and deployed to the wrong environment, where it will sit until somebody checks.

Reverted by a later deployment

A configuration fix applied by hand, then overwritten weeks later when the environment is rebuilt from a template that was never updated.

The instance patched, not the cause

The vulnerable component is updated on the affected system while the image, template or build script that produced it remains unchanged, so the flaw returns with the next deployment.

What you get

What you receive

Verification finding by finding

Each item re-tested with the original reproduction steps, not a fresh scan that may simply miss it.

A before-and-after report

The original severity and the verified current state of every finding, dated and branded.

Evidence for third parties

The document to hand an insurer, an auditor, or an enterprise client asking whether you have been tested.

An honest residual statement

What remains open and why. An unqualified clean report is rarely a truthful one.

You will know the price before you commit.

A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.

Book a free callarrow_forward