We do not wait until the final report to inform you about critical vulnerabilities. When our pentesters discover a critical finding, it is communicated immediately so you can take action to protect your organization without delay.
Our workflow for critical findings
- Direct publication to Security Reporter. The finding is published to our Security Reporter platform within hours. You see the reproduction steps, exploitability and risk classification immediately.
- Phone call to your contact person. Our pentester calls your designated contact person directly to explain the finding and answer questions.
- Support with immediate mitigation. Where possible, we advise on temporary mitigation (for example, temporarily disabling a feature) to address acute risks directly.
- Verification after remediation. When you have resolved the vulnerability, we verify the fix directly without waiting for the final report.
What qualifies as critical
We classify a vulnerability as critical when it meets one or more of these conditions:
- Unauthorized access to sensitive data (personal, financial or medical information)
- Complete compromise of authentication or authorization
- Remote code execution on production systems
- Active exploitation known in the wild (0-day or recently published)
- CVSS score of 9.0 or higher
Why this direct workflow matters
During the average pentest duration of 2 to 4 weeks, an attacker could exploit a critical vulnerability before the final report reaches you. Direct communication gives you the time advantage to respond before a vulnerability escalates into an incident. This is standard on all DongIT pentests, regardless of the package.
Preparation on your side
For optimal handling of critical findings we ask you in advance to:
- Designate a contact person available by phone during the pentest period
- Indicate who has authority to decide on immediate mitigation (for example, temporarily taking a service offline)
- Have your incident response plan ready in case immediate action is needed
More about preparation? See the FAQ on how you prepare for a pentest. Contact us for a complimentary scoping conversation.
Nederlands