An audit or penetration test returned findings nobody owns.
The report lists symptoms in the order the tooling produced them. Nothing indicates which findings share a cause, which are already satisfied, and which do not apply. Meanwhile the list is treated as a backlog of equal items, and it does not move.
- Indicative range
- Typically €6,000–12,000, fixed scope
- Shape
- Usually ten business days, remote.
What you are already seeing
- A severity label from a scanner is being used as an implementation priority.
- The same class of finding returns after being marked closed.
- Policy owners and engineering owners disagree about who acts.
- Evidence collection starts the week before the retest.
What gets examined
- 01
Which findings are the same underlying cause seen from different angles.
- 02
Which require a system change rather than a document.
- 03
Which do not apply, and what rationale would close them defensibly.
- 04
Who can implement, approve and verify each remaining item.
What you are left holding
- 01
Findings grouped by cause, with the count that actually matters.
- 02
An owned backlog with acceptance criteria per item.
- 03
Documented rationale for anything closed without a change.
- 04
An evidence plan agreed before the work starts, not after.
Before you send anything
Plain language is enough — the system, who owns the outcome, and the date that matters. Keep confidential reports, credentials and production data out of a first message; a secure exchange route is agreed before any of it moves. Indicative ranges are exactly that: the scope, exclusions and price are confirmed in a written proposal before work starts.