Skip to content

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Editorial team 2 min read

Most findings are never fixed, and the usual reason is that the report described a vulnerability rather than a decision somebody has to make.

The parts that matter

A title that states the problem, not the tool's name. "Any authenticated user can read other customers' invoices" beats "IDOR in /api/invoices".

Evidence. The request, the response, the screenshot, the account used. Enough for an engineer to reproduce it without guessing and without asking you.

Impact in their terms. Not "could lead to unauthorised access" but "a free-tier user can read every invoice in the system, including names and amounts". Say what an attacker gains, and what it would cost.

Likelihood, honestly. A weakness requiring a chain of unlikely conditions is worth reporting and worth marking as such. Inflating severity trains teams to ignore you.

A fix the team can make. Point at the mechanism, not the principle: which parameter needs an ownership check, which header, which configuration. "Implement defence in depth" is not a fix.

Severity

Use a scale consistently and show your reasoning. CVSS is useful shorthand and a poor standalone answer, because it does not know which host matters to you. Score the technical severity, then adjust for context — exposure, data, compensating controls — and record the adjustment.

What to leave out

Boilerplate, filler, and findings with no path to impact. A report with eight real issues gets acted on; the same report padded to forty does not.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025

Cyber security Guide · 2 min

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Cyber security 2 min read 21 May 2025