EmberKat
Problems/Findings with no owners

An audit or penetration test returned findings nobody owns.

The report lists symptoms in the order the tooling produced them. Nothing indicates which findings share a cause, which are already satisfied, and which do not apply. Meanwhile the list is treated as a backlog of equal items, and it does not move.

Indicative range
Typically €6,000–12,000, fixed scope
Shape
Usually ten business days, remote.

What you are already seeing

  • A severity label from a scanner is being used as an implementation priority.
  • The same class of finding returns after being marked closed.
  • Policy owners and engineering owners disagree about who acts.
  • Evidence collection starts the week before the retest.

What gets examined

  1. 01

    Which findings are the same underlying cause seen from different angles.

  2. 02

    Which require a system change rather than a document.

  3. 03

    Which do not apply, and what rationale would close them defensibly.

  4. 04

    Who can implement, approve and verify each remaining item.

What you are left holding

  1. 01

    Findings grouped by cause, with the count that actually matters.

  2. 02

    An owned backlog with acceptance criteria per item.

  3. 03

    Documented rationale for anything closed without a change.

  4. 04

    An evidence plan agreed before the work starts, not after.

Before you send anything

Plain language is enough — the system, who owns the outcome, and the date that matters. Keep confidential reports, credentials and production data out of a first message; a secure exchange route is agreed before any of it moves. Indicative ranges are exactly that: the scope, exclusions and price are confirmed in a written proposal before work starts.

Next step

Describe the situation

A short reply confirms whether this is the right shape of work, what inputs are needed, and what it would cost.

Send the context