Turning Security Findings into a Coordinated Remediation Strategy
Security hardening is not a one-time project. As organizations strengthen their environments, new scan results, updated configurations, and evolving infrastructure create an ongoing cycle of assessment and improvement. Without the right context, teams can spend valuable time reworking completed tasks, assigning issues to the wrong owners, or prioritizing findings that are no longer relevant.
Visus recently partnered with a healthcare-industry client facing exactly this challenge. The organization managed multiple public-facing websites, production and user acceptance testing (UAT) environments, several related domains, an enterprise Sitefinity CMS, cloud-hosted applications, third-party integrations, and shared email and domain infrastructure. While the client maintained an active security-hardening program, new external security scan results introduced another layer of findings that required careful evaluation rather than immediate remediation.
The Challenge
The client's objective extended beyond resolving another list of reported vulnerabilities. The team needed to determine which findings were still valid, which had already been addressed, which required application changes, and which belonged to infrastructure, DNS, or email security.
Several findings crossed technical boundaries, including:
- Content Security Policy (CSP) configuration
- HTTP security headers
- Sitefinity application behavior
- Cloud and web server configuration
- SPF and DMARC records
- Multiple domains and environments
Adding to the complexity, some reported issues reflected earlier scan data rather than the client's current environment. For example, a duplicate Content Security Policy header had already been identified and corrected before the latest review, yet it continued to appear in subsequent findings.
Without historical context, the client risked duplicating remediation efforts, assigning work to the wrong technical teams, and making unnecessary application changes for issues rooted in hosting or domain configuration.
The Visus Approach
Visus applied an AI-assisted security analysis process designed to maintain continuity across the client's ongoing security program rather than treating each scan as an isolated event.
Instead of reviewing only the latest report, the analysis correlated:
- New external security findings
- Previous web application scan reports
- Earlier remediation decisions
- Recently completed improvements
- Current application and infrastructure configurations
This broader perspective allowed each finding to be evaluated within its operational context before recommendations were made.
The analysis organized the remaining work into clearly defined remediation streams, including:
- Domain and email security improvements such as SPF and DMARC configuration
- Hosting and HTTP security header validation
- Sitefinity application updates
- Content Security Policy investigation and refinement
- Validation activities and follow-up security scanning
The review also confirmed completed remediation, including the previously resolved duplicate CSP header, preventing the client from scheduling unnecessary work.
To support implementation, Visus converted the analysis into a structured Jira-based remediation plan that defined ownership boundaries, estimated effort, validation requirements, and acceptance criteria for every workstream.
The Result
The client gained a more reliable and actionable roadmap for continuing its security-hardening program.
Key outcomes included:
- Previously completed fixes were identified and excluded from future remediation work.
- Security findings were assigned to the appropriate technical owners.
- DNS and email security tasks were clearly separated from Sitefinity application changes.
- Findings were prioritized based on technical relevance and current environmental context rather than scanner severity alone.
- The client received structured estimates for investigation, implementation, and validation activities.
- Future external security scans could be measured against a documented remediation baseline.
The engagement also improved traceability between security reports, implemented fixes, remaining risks, and future validation efforts. While final quantitative improvements will be confirmed during the next external security rescan, the client now has a repeatable process for managing security improvements with greater confidence and accuracy.
The Takeaway
Security hardening works best as a continuous program, not as a sequence of disconnected scan reports.
External scanners frequently rediscover previously known conditions, report symptoms originating from different technical layers, or continue displaying findings that have already been corrected after the original scan was completed. Organizations benefit from preserving historical context so new findings can be evaluated alongside prior assessments, completed remediation, application architecture, and technical ownership.
AI delivers the greatest value when it supports continuity, correlation, and planning rather than simply summarizing reports. By connecting new findings with remediation history and current infrastructure, organizations can reduce duplicated effort, avoid unnecessary changes, and make more informed security decisions throughout the lifecycle of their security enhancement program.