REM / REM-01
Technical remediation after audits or penetration tests
Implementing identified fixes with testing and rollback preparation to turn audit findings into operational controls.

WHEN IT HELPS
A focused response
to a defined need.
CIO or CISO; a completed report but insufficient capacity, expertise or time to implement fixes.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Revalidate findings
- prepare changes
- staged deployment, technical testing and business acceptance
Deliverables
- Change plan
- implemented settings or fixes
- validation evidence and register of remaining gaps
Acceptance evidence
Each fix is tested and linked to its original finding; unresolved items are explained and approved.
DELIVERY
How the work is structured.
Approach
Validate findings; prioritise and assign; prepare changes and rollback; implement or coach; retest and document closure.
Prerequisites & responsibilities
Customer: approvals, change windows, application owners and business acceptance. Provider: implementation only when included; otherwise advice, coordination and evidence review.
Scope factors
Number and complexity of root causes, environments, dependencies and retests. Time and materials, scoped package or recurring support; effort confirmed after report review.
Questions to clarify
Which report and date? Who authorises changes? What backups, maintenance windows and dependencies exist?
IMPORTANT BOUNDARIES
The original report does not authorise production changes; licensing, redesign and additional scope are separate.
Findings remain explicitly classified as fixed, mitigated, accepted, deferred or unverified. Closure is supported by evidence rather than the administrative status of a ticket.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An SME’s audit finds exposed administration and shared accounts. Project: close unnecessary access, create named accounts and test. Target outcome: evidence-based closure and a retained emergency procedure without improvised outages.
Scenario 02
A web portal has a confirmed access-control flaw. Project: fix it with developers and replay the scenario. Target outcome: validated remediation and regression testing; major rewrites are priced separately.
Technology and reference context
Existing tools and technologies; additional products only after approval.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
