Skip to content
All notes

Closing VAPT findings before the retest

Short answers to the questions owners ask in the weeks between a VAPT report and the retest.

The VAPT report has arrived with dozens of findings and the retest is already booked. Engineering wants to know which findings matter, and the customer wants to know when they’ll be closed. This note covers the weeks in between.

Which findings matter most?

The ones an attacker could reach in your setup. A medium finding on an internet-facing login can matter more than a high one on a server only staff can reach. Keep the tester’s severity in your tracker and add your own priority beside it, with a line saying why. The tester will compare the two at the retest.

Is the problem only where the tester found it?

Often it isn’t. A missing permission check on the invoice endpoint suggests the same shortcut in the export and the background job, which build the same invoice. Fixing only the reported URL can pass the retest and leave the weakness in place elsewhere. We’d search the code for the pattern before anyone writes a fix.

What if we think a finding is wrong?

Write down exactly why, with evidence, and send it to the tester. They may have tested a different environment, or the feature may have been removed since. If the disagreement is about wording, fix the issue first and settle the wording later.

How do we know a fix worked?

Check it the way it failed. For a permission bug, sign in as someone who should be refused and confirm they are. For a configuration finding, look at the live setting. A merged pull request shows the code changed, so also confirm the fix reached the deployed version.

Then check that normal use still works. A tighter cookie setting can break an embedded login, and a new firewall rule can cut off a partner integration.

What should we send the tester?

Enough that they don’t have to guess which change was meant to fix which finding. Agree the details with them directly, since testers set up retests differently. Leave time in the schedule in case the retest turns up a partial fix.

Who decides a finding is closed?

The original tester, at the retest. Your engineers write the fixes. Anyone else, including us, can help you prepare and check the evidence beforehand.

Which part of your company this is about

An architecture diagram of a typical SaaS product, with the part this note is about lit.

This note is about what a pentest tests: your web app, API and AI features, from outside. Our VAPT report remediation support covers these weeks, up to the retest.

Your pentest report has dozens of findings. Which ones actually matter?

On a free 30-minute scoping call we’ll tell you whether this needs an assessment at all. If it does, you get a fixed fee before any work starts.