We operate a B2B ordering and inventory management portal for corporate clients in the US, with around 45 active enterprise accounts. Ahead of closing a major new enterprise contract, we commissioned an external scan and vulnerability assessment from an independent cybersecurity firm, paying 4,800 USD for the service. The audit wrapped up and we received a highly technical 68-page vulnerability assessment report.
The report lists 6 Critical, 14 High, 27 Medium and a whole bunch of Low findings based on CVSS scores. Our 4-person dev team is already balancing ongoing product roadmap work and has no idea where to even start with this list. The auditing firm just listed the items without prioritizing what's urgent based on actual business risk. How can we turn this report into a realistic remediation schedule and action plan without dumping it on our developers and causing panic?