We're a 12-person startup based in Austin offering B2B logistics tracking software. To meet the security requirements of an enterprise client, we hired an independent cybersecurity firm to run our first-ever web app and API penetration test. We budgeted 6,500 dollars for the assessment, and the process wrapped up last Friday.
The final report lists a total of 42 vulnerabilities: 4 critical, 9 high, 18 medium, and 11 low findings. The report runs 80 pages, complete with CVSS scores, theoretical attack vectors, and proof-of-concept exploits for each issue. However, there's zero operational guidance on what needs to be fixed in what order, by whom, or within what timeframe.
Our dev team consists of 4 engineers with ongoing product development sprints. How can we organize these 42 vulnerabilities without stalling our current roadmap, burning out the team, and still presenting a credible remediation schedule to the enterprise client?