A group had acquired a subsidiary that manufactures medical devices. An assessment had produced a report nobody at the subsidiary could act on. Security there was not a department — it was one long-serving employee carrying it alongside another job, with no additional headcount.
Every finding traced back to four kinds of exposure, each generating dozens of separate entries. Remediation then ran on four different clocks: email authentication took hours, while separating production equipment from the internet was a planned change with downtime, agreed around a manufacturing schedule. Treating those as one backlog is what had kept the list frozen.
Everything in scope closed. What was deliberately accepted was written down with a reason rather than left open, so the next assessment starts from a decision instead of a gap.