We are a small London-based team offering B2B software and consulting services. We only have one full-time software developer in our company handling both infrastructure and code development. At the request of an enterprise client, we paid 3,200 pounds last month to have our first comprehensive external penetration test done.
The report we got back listed a total of 28 security vulnerabilities: 3 critical, 7 high, and 18 medium severity. The cybersecurity firm stated that, per standard procedure, all findings must be resolved within 30 days, otherwise the re-test will be marked as a failure.
With just one developer keeping up with daily ops, patching this many issues in 30 days is practically impossible. What are the realistic, industry-standard remediation timelines? Which vulnerabilities should we patch immediately, and which can be pushed to future sprints?