- Job title
- Administrative manager
- Sector
- Plastic
- Organization type
- two-branch business
- Joined
- Jan 2023
- Message
- 181
We're a US-based B2B software company with a team of 14. Last month we ran our first comprehensive pen test and paid roughly $4,800 for it. The report just came in, listing 40 vulnerabilities across critical, medium, and low severity tiers.
The consulting firm that ran the test suggested we adopt a dedicated remediation platform—priced at $6,000 annually—to manage the fix cycle, track SLAs, assign tasks to developers, and log verification results. Our engineering team consists of four developers and one sysadmin.
For a team of our size, are these kinds of remediation tools genuinely necessary, or can we handle the process effectively through our existing project management and ticketing setup? Would love to hear from anyone who has navigated a similar workflow.