Making sense of the report.
WHAT A REPORT SHOULD CONTAIN
Executive summary Scope and methodology Findings, each with severity Evidence Remediation guidance What was not tested
WHY WHAT WAS NOT TESTED
It establishes the limits of the assurance.
WHAT EACH FINDING SHOULD INCLUDE
What it is Where it was found How it was verified What an attacker could achieve How to fix it
WHY THE IMPACT STATEMENT
Severity without context does not support prioritisation.
WHAT TO ASSESS FOR EACH FINDING
Whether it is genuine Whether it applies in your context What it would actually allow How difficult it would be to exploit What it would cost to fix
WHY YOUR CONTEXT
A finding rated critical generically may be low risk behind other controls, and the reverse is also true.
WHAT TO QUESTION
Findings you do not understand Severity ratings that seem wrong Remediation advice that is impractical
WHY
The tester should be able to explain and justify each one.
WHAT TO ESTABLISH
A discussion of the report with the tester.
WHY
Reports delivered without discussion are frequently misread.
WHAT TO PRIORITISE
Issues that are externally exploitable Issues affecting sensitive data Issues that are easy to exploit Issues that are cheap to fix
WHY THAT LAST ONE
Quick fixes reduce exposure immediately.
WHAT TO AVOID
Treating the report as a list to be completed in order Fixing only what is easy Disputing findings to avoid work
WHAT TO PRODUCE
A remediation plan with owners and dates.