We are a 14-person software company operating in the fintech space. An independent third-party cybersecurity firm just wrapped up a two-week penetration test on our web application and API services. Last night, they delivered an 85-page comprehensive pen test report. The report lists a total of 24 different vulnerabilities across critical, high, and medium severity levels.
When I shared the report as-is with our 5-person dev team, chaos ensued. The devs complained that the language in the report is far too theoretical, that there are no concrete instructions on how to patch the findings at the code level, and that their current sprint plan is completely blown. They have no idea which vulnerability to start with.
What is the most efficient way to hand off pen test findings to a dev team? In what format should we deliver these vulnerabilities, and how can we establish a priority order without derailing their workflow?