Get vulnerability remediation support

Support for prioritizing and resolving pentest findings by OSCP and OSWE-certified ethical hackers

Vulnerability remediation by DongIT

Have you had a pentest performed and does the report contain vulnerabilities that your own development team cannot or will not resolve? Our ethical hackers support development teams with prioritizing, analyzing and resolving findings. We ensure your application actually becomes more secure, not only on paper.

This service is especially suitable for organizations without their own application security team, for complex pentest reports with many findings, or for situations where external validation of remediation is desired.

Remediation support is delivered by OSCP and OSWE-certified ethical hackers who know the attack techniques themselves. We know exactly why a vulnerability is problematic and how to resolve it structurally, not just mask it. On time and materials or via a fixed-scope project.

When do you engage our remediation support?

Vulnerability remediation is not always trivial. For some teams it is a daily routine, for others a frustrating blocker. Our support fits different situations.

  • Pentest report with many findings. Your team does not know where to start. We help prioritize based on impact and exploitability, so critical issues are addressed first.
  • Complex vulnerabilities. Business logic flaws, authorization issues, cryptographic problems or race conditions require in-depth expertise your team may not have in-house.
  • No internal application security team. We temporarily fill the role until your team is built, or deliver ongoing support for smaller organizations.
  • Compliance deadline. For NIS2, ISO 27001, DigiD or GDPR audits where certain findings must be resolved before the auditor review takes place.
  • External validation. Your team has implemented the fixes and you want independent confirmation that everything is correctly resolved before the formal retest.

Our approach: from report to secure code

We follow a structured approach aligned with how development teams work. No document dumping, but concrete steps that lead to demonstrably more secure code.

  1. Prioritization of findings

    We go through your pentest report and help prioritize based on impact, exploitability and existing mitigations. Critical findings first, cosmetic issues later. This way your team knows where the most value can be gained.

  2. Root cause analysis per finding

    Behind one visible vulnerability often lies a structural problem in the codebase that causes multiple related issues. We analyze the underlying cause so one fix resolves multiple findings.

  3. Advice or implementation

    Depending on your preference: we advise your own development team with concrete code suggestions, or our specialists implement the fixes themselves via a separate branch that your team can review.

  4. Code review and validation

    When your team or our specialists have applied the fix, we verify that the vulnerability is actually resolved and that no new issues have been introduced. Regression checks prevent a fix from breaking something elsewhere.

  5. Formal retest

    Based on the original pentest we perform a targeted retest that demonstrably confirms the findings are resolved. Delivery via Security Reporter, directly usable for your auditor or supervisory authority.

What we help development teams with

Our specialists have experience with the most common vulnerability categories from pentest reports. A few examples:

  • Injection vulnerabilities. SQL injection, XSS, command injection and related findings.
  • Authorization issues. IDOR patterns, privilege escalation and broken access control.
  • Authentication flaws. Session management, SSO integration (SAML, OIDC) and MFA implementation.
  • Cryptographic issues. Key management, TLS configuration and secure storage of sensitive data.
  • Business logic flaws. Complex workflow issues that scanners systematically miss.
  • Configuration issues. Security headers, CORS settings and framework hardening.

We work with most modern tech stacks: Node.js, .NET, Java (Spring), Python, PHP, Ruby and Go. For frontend: React, Vue, Angular and Svelte. For niche stacks such as Elixir, Rust or specific ERP implementations, we assess per engagement whether we have the right expertise in-house. Transparent, also when another party fits better.

Two engagement models

Advisory and review

We analyze your report, prioritize the findings and provide concrete remediation advice per issue. Your own development team implements the fixes. On hourly basis or as a fixed-scope project.

When in doubt during implementation, you can ask our specialists questions via direct communication lines.

Implementation support

Our specialists implement the fixes themselves, via a separate feature branch that your own team can review and merge after their own QA. You retain full control over your codebase.

On time and materials, with transparent hour accountability per finding.

For both models: no long-running development contracts, no retainer commitments. You engage us when you need us.

Frequently asked questions

Do you only work with findings from DongIT pentests?

No. We support remediation of findings from pentests performed by other parties. Your report is your property and we work with what you provide. We do recommend that the report contains sufficient detail (CVSS scoring, reproduction steps, affected endpoints) so we can prioritize efficiently.

Are there conflicts of interest if you implement fixes yourselves and later also test?

For formal pentest retests after implementation of our fixes, we deploy a different team than the remediation team. This safeguards the independence of the retest and is transparently documented in the reporting. This prevents the same person from both writing and validating the fix.

How do you guarantee our code stays secure?

We do not commit directly to your main branch. Our fixes are delivered via a separate feature branch that your team can review and merge after their own QA. You retain full control. Access to your repository takes place via temporary, limited credentials that are revoked after completion.

Which programming languages and frameworks do you support?

Node.js, .NET, Java (Spring), Python, PHP, Ruby and Go for backend. React, Vue, Angular and Svelte for frontend. For niche stacks (Elixir, Rust, ERP implementations) we assess per engagement whether we have the right expertise in-house. At mismatch we refer you to a partner agency.

Do you offer long-running development support?

No. Our focus is remediation support tied to specific pentest findings. For complete web development projects or ongoing development capacity we refer you to partner agencies with whom we structurally cooperate.

What about shorter engagements or small issues?

For small engagements (for example one or two critical findings) we apply a minimum of four hours. For larger engagements we prepare an estimate upfront with a range per finding, so you know what to expect.

Is your pentest report ready for action?

Contact us with a brief description of your situation: number of findings, tech stack and any deadline. We schedule a complimentary intake conversation in which we jointly determine the approach. Response within one business day.