Remediation Support
73% of companies don't fix critical vulnerabilities within 90 days. We bridge the gap between pentest findings and actual fixes. Our engineers work alongside your IT team to remediate vulnerabilities, harden systems, and verify the fixes.

What is Remediation Support?
Remediation Support bridges the gap between a completed penetration test and actually fixed vulnerabilities — nFlo's security engineers work hands-on alongside your IT team to prioritize, remediate, and verify each finding, including a retest to confirm closures. The service covers Active Directory hardening, web application fixes, network segmentation, and cloud configuration; 73% of companies fail to fix critical vulnerabilities within 90 days of receiving a pentest report (Verizon DBIR).
Pentest done, report delivered, nothing fixed
Closed loop: pentest → fix → verify
Prioritization
Which vulnerabilities to fix first
Remediation
Hands-on fixing with your team
Verification
Retest to confirm fixes
“We have a pentest report. 47 vulnerabilities. Now what?”
Sound familiar? A company commissioned a penetration test, received a detailed report with vulnerabilities and recommendations. The report went to the IT team and… sat there for months. A year later, the next pentest found the same vulnerabilities.
Why does this happen?
-
IT is overloaded - helpdesk, infrastructure, projects, fires. Pentest report is at the end of the queue.
-
Competency gap - “Kerberoasting vulnerability” sounds scary, but the admin doesn’t know how to fix it.
-
Fear of breaking things - “If I change the firewall config, email might stop working.”
-
No ownership - 47 vulnerabilities across 15 systems. Who’s responsible for what?
-
No prioritization - Everything is critical = nothing is prioritized.
The result: 73% of companies don’t fix critical vulnerabilities within 90 days. The pentest was a wasted investment.
Pentest + Fix = Closed Loop
We don’t leave you with a report and good wishes. We bridge the gap between finding and fixing. Our security engineers work alongside your IT team to actually remediate vulnerabilities.
What you get:
- Prioritization session (2h) - business risk ranking, not just CVSS. What to fix first based on real impact.
- Remediation hours package - our engineers + your IT. Hands-on fixing together.
- Hardening - configuration improvements beyond the pentest scope.
- Knowledge transfer - your team learns, not just watches.
- Verification retest - we confirm vulnerabilities are actually fixed.
- Documentation - evidence for auditors that the cycle is closed.
How it Works
Step 1: Prioritization Session (2 hours)
We review the pentest report together:
- Business context for each finding
- Real-world exploitation risk
- Fix complexity vs impact
- Quick wins identification
- Remediation roadmap with owners and deadlines
Output: Prioritized action plan, not just a report.
Step 2: Remediation (Hours Package)
Our engineers work with your IT:
- Active Directory hardening - fixing Kerberos, NTLM, password policies
- Web application fixes - SQL injection, XSS, CSRF remediation
- Network security - firewall rules, segmentation, TLS configuration
- Cloud configuration - AWS/Azure/GCP security hardening
- System patching - coordinated patching of critical systems
Model: We don’t take over - we work together. Your team learns the “why” and “how.”
Step 3: Hardening (Beyond the Report)
Pentests find specific vulnerabilities. We go further:
- Security baseline configuration
- Logging and monitoring improvements
- Backup verification
- Incident response preparation
Step 4: Verification Retest
After remediation, we verify:
- Are vulnerabilities actually fixed?
- Did the fix introduce new issues?
- Is coverage complete (all variants)?
Only after successful retest is the vulnerability marked as closed.
Remediation Packages
Quick Fix (20 hours)
For focused remediation after a targeted pentest:
- Prioritization session (2h)
- 15 hours of hands-on remediation
- 3 hours of documentation
- Basic retest (fixed vulnerabilities only)
Best for: Small scope pentests (external only, single application) Price from: $4,000
Standard Fix (40 hours)
For comprehensive remediation after a full pentest:
- Prioritization session (2h)
- 30 hours of hands-on remediation
- 5 hours of hardening beyond report
- 3 hours of documentation
- Full retest
Best for: Combined internal + external pentest Price from: $7,500
Enterprise Fix (80+ hours)
For large-scale remediation programs:
- Extended prioritization (half-day workshop)
- 60+ hours of remediation
- Extensive hardening program
- Weekly status meetings
- Full retest + remediation verification
- Board-ready documentation
Best for: Multi-system pentests, compliance programs Price: Custom quote
Who is this for?
This service is for you if:
- You have a pentest report and don’t know where to start
- Your IT team is too busy to address security findings
- Previous pentests found the same issues (remediation gap)
- You need to prove closed loop to auditors (ISO 27001, NIS2)
- You want your team to learn while vulnerabilities get fixed
Related Glossary Terms
Learn more about key concepts related to this service:
Contact your account manager
Discuss Remediation Support with your dedicated account manager.

How we work
Our proven service delivery process.
Prioritization
2h session: business risk ranking of findings
Remediation
Our engineers + your IT = fixed vulnerabilities
Hardening
Configuration improvements beyond the report
Verification
Retest to confirm vulnerabilities are closed
Benefits for your business
What you gain by choosing this service.
Actually fixed
Not just documented - truly remediated
Team upskilling
Your IT learns while we fix together
Audit evidence
Closed cycle for auditors
Better ROI
Pentest investment pays off
Related Articles
Expand your knowledge with our resources.
CVE-2026-56782: Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api...
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_k...
Read more →CVE-2025-55017: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users...
Read more →CVE-2025-64152: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users...
Read more →Frequently Asked Questions
Common questions about Remediation Support.
How much does post-pentest remediation support cost?
Quick Fix 20h (small scope, 10-20 vulnerabilities): from $4,000. Standard Fix 40h (medium scope, 30-50 vulnerabilities): from $7,500. Enterprise Fix 80h+ (large scope, complex environment): custom quote. Retest is included in Pentest + Fix bundle.
Do you fix vulnerabilities for us?
We don't make changes alone - it's your infrastructure. We work alongside your IT: show how to fix, help with configuration, verify correctness. Your admin makes changes, we guide and support. Knowledge transfer included.
Can you help with a report from another pentest firm?
Yes - we accept reports from any reputable pentest firm. Only requirement: report must be detailed enough (PoC, affected URLs, reproduction steps). During prioritization session (2h) we'll analyze the report and establish action plan.
How many support hours do I need?
Depends on number and complexity of vulnerabilities: 10-20 vulnerabilities (mostly configuration) = 20h, 30-50 vulnerabilities (mix) = 40h, 50+ vulnerabilities or complex environment (AD, cloud, OT) = 80h+. We'll estimate precisely during prioritization session.
Is retest included in the price?
In Pentest + Fix bundle (when nFlo did the pentest) - yes, retest is included. For standalone remediation support (external report) - retest is an additional option (from $2,000).