We're a 12-person team based in Boston building cloud-based scheduling and patient management software for the healthcare sector. Ahead of closing an enterprise contract with a hospital network, we were required to pass a security audit, so we hired an outside firm for $6,000 to run a web app and API penetration test. The test wrapped up and we received a massive 75-page PDF report.
The report is packed with CVSS scores, risk matrices, raw HTTP requests, and red-and-yellow color-coded tables. We have a four-person dev team, and looking at the report, they have no idea where to start. With our next product release deadline looming, how can we translate the findings in this PDF into a clear, prioritized remediation task list without completely grinding ongoing work to a halt?