ESSENTIAL GUIDANCE · POST-TEST · 10 min read
Part of Validate insights →Which penetration-test findings should you fix first?
How to order confirmed penetration-test findings using validated exploitability, credible attack paths and business consequence.
A penetration-test report gives you confirmed findings, but it does not remove the need for a defensible action order. Security leaders and engineering owners should prioritise the attack pathsi that create the greatest practical consequence, then distinguish urgent containment from planned root-cause remediation.
Need an acronym translated?Open the cyber glossary →Start with validated exploitability
Use the evidence produced during the penetration test rather than treating scanner severity as the queue. A reproduced weakness with clear preconditions and demonstrated impact should carry more decision weight than an unverified detection. Confirm what the tester achieved, which access was required and which limitations affected the result.
Look for findings that enable an attack chain
A medium-rated weakness can become urgent when it supplies credentials, access or information needed to exploit another condition. Review findings together and identify which one opens, shortens or strengthens a credible route to sensitive systems, privileged identities or important business processes.
Add asset importance and business consequence
Consider what the affected asset supports, the data or operations at risk and the consequence of loss of confidentiality, integrity or availability. The same technical weakness can justify a different response on an isolated test service than on an internet-facing identity system or revenue-critical application.
Account for exposure, privileges and controls
Priority increases when an attacker can reach the condition easily, exploit it without authentication or use it to gain valuable privileges. Effective segmentation, monitoring, access restrictions or other compensating controls may reduce immediate likelihood, but record their limits and do not treat them as proof that the root cause is resolved.
Fix dependencies and root causes in the right order
Identify findings that share a dependency or stem from the same design, configuration or development weakness. A root-cause fix may close several attack paths, while patching symptoms individually can leave equivalent routes open. Sequence work so prerequisite controls and shared causes are addressed before teams repeat the same change across multiple tickets.
Separate containment from planned remediation
Immediate containment may involve restricting access, disabling a feature, rotating credentials or increasing monitoring while a durable fix is designed and tested. Record the temporary control, its owner and review date. Containment changes urgency; it does not automatically close the confirmed finding.
Define the evidence needed for closure
For each material finding, name the accountable owner, target date, expected remediation evidence and retesti criteria. Preserve the original steps and affected scope so the tester can verify the fix against the demonstrated condition and check that an alternative route has not been introduced.
This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.
Read “Modern penetration testing should create decisions, not just findings” →



