Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Remediation

Knowledge hub

Remediation

The actual work of fixing a finding: the change, the review, the release.

What it means

Remediation is the work of actually fixing a finding. Not logging it, not agreeing that it matters. The code change, the review, the test, the release.

This is the part that eats engineering time and calendar days, and it happens long after the report that started it. Everything before it is paperwork.

Why it matters

Finding a flaw costs little. Fixing one costs real money, so anything that shortens the path from report to fix beats another source of findings.

Most of that time goes on understanding rather than typing. An engineer who has to reproduce the issue first loses half a day before writing a line. A report nobody believes sits untouched while people argue about whether it is real. Priority takes the rest. When everything arrives marked urgent, teams fix the easy things and the hard finding waits. Release cadence decides the rest. A team that ships weekly closes findings weekly, and a team that ships quarterly cannot, whatever the report says.

How it shows up

You can see the difference in what a report hands over. A line saying a parameter is vulnerable sends an engineer looking. The exact request, the response it returned, a screenshot and the source line that allowed it send them straight to the change.

Naming an owner the moment somebody accepts a finding helps too. Work assigned to a team rather than a person moves slowly, whatever its severity says. Cyberlop builds every finding around that handover, with its request, response, screenshot and source line attached. Track the time from report to release as well. Counting findings flatters everybody, while elapsed time tells you whether anything improved.

Questions people ask

Remediation, answered

What is the difference between remediation and mitigation?

Remediation removes the flaw. Mitigation reduces what somebody can do with it while the flaw is still sitting there, for example by restricting who reaches the feature.

Mitigation buys time. A backlog that quietly treats it as finished work is a common way findings stay open for years.

How long should it take to fix a critical vulnerability?

CISA sets deadlines for the vulnerabilities in its known exploited catalogue. Many teams copy that shape internally: days for critical, weeks for high, longer for the rest.

Pick numbers you can actually hit. A target nobody meets teaches people to ignore every target.

Who owns remediation, security or engineering?

Engineering writes the fix. Security decides what counts as done. The usual failure is assigning the work to a team rather than a person, because nothing with a group owner moves quickly.

Do we have to fix every finding?

No. Some findings deserve a written decision to leave them, with a named owner and a review date. That is risk acceptance, and it is a legitimate answer.

What does not work is leaving them undecided, because an untouched ticket and an accepted risk look identical from outside.

Why does remediation always take longer than we planned?

Usually because the report did not carry enough to start from. Reproducing the issue costs half a day before any code gets written, and a finding nobody believes stalls in an argument instead.

Cyberlop attaches the request, the response, a screenshot and the source line for that reason. It does not write the fix for you.

How long do your fixes take?

Every Cyberlop finding carries the request, the response, a screenshot and the source line, so an engineer starts on the fix instead of on reproducing it. Get in touch.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.