Skip to main content
The remediation roadmap turns your Leverage Cyber findings into a structured, ordered action list that any security or engineering team can execute against immediately. Every item in the roadmap carries four data points: the finding, the ALE it represents, the estimated effort required to remediate it, and a priority rank. There is no ambiguity about where to start — the highest-dollar-impact, lowest-effort items appear at the top, and every item below has a documented reason for its position.

Roadmap Structure

Each entry in your remediation roadmap is presented across four columns designed to support both technical execution and resource planning. Finding identifies the specific exposure — for example, “Leaked executive credentials on dark web forum” or “No DMARC enforcement on primary sending domain.” Each finding links back to the full finding detail in your report, including the asset involved, how it was discovered, and the evidence collected. ALE Impact is the Annual Loss Expectancy associated with the finding. This is the annual financial exposure that remediating this item eliminates from your portfolio ALE. Roadmap entries are sorted by ALE descending, ensuring the finding with the greatest financial impact always appears first. Effort is a standardized three-tier estimate of the engineering or operational work required to close the finding: Low (hours), Medium (days to one week), or High (one to four weeks or requires vendor engagement). Effort estimates are based on the specific remediation action required, not a general assessment of the finding type. Priority Rank is the final ordering number assigned to each finding after combining ALE Impact and Effort. A Critical finding with Low effort will outrank a Critical finding with High effort, because the low-effort item produces immediate risk reduction for minimal cost. Priority Rank is the definitive sequence your team should follow.

Priority Tiers

What qualifies: Findings with ALE above $1,000,000/yr, or any finding where active exploitation evidence exists regardless of ALE tier. Also includes any finding involving leaked credentials, exposed authentication systems, or direct access to systems containing regulated data.Typical timeframe: Remediation or interim mitigation within 30 days of report delivery. For findings with active exploitation evidence, your account team will contact you directly upon discovery — do not wait for the scheduled report.Who owns the action: CISO or VP of Security owns the remediation plan and timeline. Individual action items are delegated to the appropriate technical owner — identity team for credential findings, infrastructure team for network exposures, and so on. The CISO provides a status update to the board or executive team within 5 business days of the report.

Example Roadmap Entries

The table below shows a sample remediation roadmap ordered by Priority Rank. Notice that Priority Rank reflects both ALE and effort — a medium-effort High finding can outrank a high-effort Critical finding when an interim mitigation reduces the active exposure.

Tracking Remediation Progress

At each quarterly reassessment, your Leverage Cyber report includes a remediation status section alongside new findings. Every finding from the prior period is reviewed and assigned one of three statuses: Resolved findings have been remediated and are no longer externally visible or exploitable. Resolved findings are removed from the active portfolio ALE calculation, and the ALE reduction is shown in the period-over-period comparison in your executive report. Persistent findings remain open from the prior period. Persistent items are re-evaluated for any changes in threat likelihood or asset exposure that would affect their ALE. A finding that has aged into a higher threat environment — for example, because the underlying CVE now has active exploit code — may see its ALE increase even if the finding itself hasn’t changed. New findings have been identified since the prior assessment. New findings are introduced into the roadmap at their calculated priority rank. The net change in portfolio ALE — the sum of resolved ALE minus new finding ALE — is the primary metric for demonstrating security program progress over time.

When to Accept Risk

Not every finding warrants immediate remediation. Risk acceptance is a legitimate, documented decision that allows your organization to make an informed choice to carry a known risk when the remediation cost or operational impact is disproportionate to the ALE. To formally accept a finding, complete the following steps using your organization’s risk register or the acceptance workflow in the Leverage Cyber portal.
1

Document the Finding

Record the finding identifier, description, and current ALE from your Leverage Cyber report. Include the date of acceptance and the version of the report the finding appeared in.
2

State the Rationale

Document why remediation is being deferred. Acceptable rationales include: remediation cost exceeds ALE, interim mitigation reduces active exposure, vendor dependency with a committed roadmap date, or business continuity risk from the remediation itself.
3

Obtain the Appropriate Sign-Off

Route the acceptance to the correct authority based on the finding’s severity band. Low findings may be accepted by the CISO or Security Lead. Medium findings require CISO sign-off. High and Critical findings require CFO or Board-level acknowledgment — accepting seven-figure annual risk is a business decision, not a security team decision.
4

Set a Review Date

Accepted risk does not mean forgotten risk. Set a review date no more than 12 months from the acceptance date. The finding will surface automatically in your next quarterly reassessment, and the review date reminds the owning team to re-evaluate whether circumstances have changed.
Use your remediation roadmap directly as input to your annual security budget request. Each roadmap line item maps to a specific ALE reduction and effort estimate, giving you a defensible, dollar-denominated justification for every budget line. A roadmap showing 2.4MinportfolioALEthatcanbereducedby852.4M in portfolio ALE that can be reduced by 85% for 340,000 in remediation cost is a more compelling budget document than a list of vulnerabilities — it speaks the language finance and the board already use to evaluate capital allocation decisions.