Security
What a security assessment should actually give you
A list of 200 findings is not a report. A prioritized plan with owners and dates is.
LB
Laura Bermúdez18 Jun 2026 · 6 min read

Most assessment reports are scanner output with a cover page. They are long, technically correct and impossible to act on, because everything is labelled important and nothing is sequenced.
A useful assessment answers three questions: what can an attacker reach today, what would it cost us, and what do we fix first.
What to require from the deliverable
Before you sign an assessment, ask that the report contain the following.
A finding without an owner and a date is a note, not a plan.
Findings ranked by real exposure, not by generic CVSS score alone.
A named owner and a target date for each item in the top tier.
Reproduction steps a developer can follow without the tester present.
A retest included, so closing an item is verified and not assumed.
/ Security // Assessment // Process /