> ## Documentation Index
> Fetch the complete documentation index at: https://docs.leveragecyber.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Remediation Roadmap: Prioritized Steps to Reduce Risk

> Learn how to read and act on your prioritized remediation roadmap — every item includes a priority rank, effort estimate, and dollar impact.

The remediation roadmap turns your Leverage Cyber findings into a structured, ordered action list that any security or engineering team can execute against immediately. Every item in the roadmap carries four data points: the finding, the ALE it represents, the estimated effort required to remediate it, and a priority rank. There is no ambiguity about where to start — the highest-dollar-impact, lowest-effort items appear at the top, and every item below has a documented reason for its position.

## Roadmap Structure

Each entry in your remediation roadmap is presented across four columns designed to support both technical execution and resource planning.

**Finding** identifies the specific exposure — for example, "Leaked executive credentials on dark web forum" or "No DMARC enforcement on primary sending domain." Each finding links back to the full finding detail in your report, including the asset involved, how it was discovered, and the evidence collected.

**ALE Impact** is the Annual Loss Expectancy associated with the finding. This is the annual financial exposure that remediating this item eliminates from your portfolio ALE. Roadmap entries are sorted by ALE descending, ensuring the finding with the greatest financial impact always appears first.

**Effort** is a standardized three-tier estimate of the engineering or operational work required to close the finding: Low (hours), Medium (days to one week), or High (one to four weeks or requires vendor engagement). Effort estimates are based on the specific remediation action required, not a general assessment of the finding type.

**Priority Rank** is the final ordering number assigned to each finding after combining ALE Impact and Effort. A Critical finding with Low effort will outrank a Critical finding with High effort, because the low-effort item produces immediate risk reduction for minimal cost. Priority Rank is the definitive sequence your team should follow.

## Priority Tiers

<Tabs>
  <Tab title="Immediate (Critical)">
    **What qualifies:** Findings with ALE above \$1,000,000/yr, or any finding where active exploitation evidence exists regardless of ALE tier. Also includes any finding involving leaked credentials, exposed authentication systems, or direct access to systems containing regulated data.

    **Typical timeframe:** Remediation or interim mitigation within 30 days of report delivery. For findings with active exploitation evidence, your account team will contact you directly upon discovery — do not wait for the scheduled report.

    **Who owns the action:** CISO or VP of Security owns the remediation plan and timeline. Individual action items are delegated to the appropriate technical owner — identity team for credential findings, infrastructure team for network exposures, and so on. The CISO provides a status update to the board or executive team within 5 business days of the report.
  </Tab>

  <Tab title="Short-Term (High)">
    **What qualifies:** Findings with ALE between $250,000 and $1,000,000/yr, or findings in the Critical ALE band where remediation effort is rated High and an interim mitigation is in place. Short-Term items represent real, material financial exposure but allow slightly more planning time than Immediate items.

    **Typical timeframe:** Remediation complete within 60 days of report delivery. Items requiring vendor engagement or significant infrastructure change should begin scoping immediately so the 60-day target is achievable.

    **Who owns the action:** CISO and CTO share ownership. Engineering leadership scopes the work and assigns it to a team. The CISO tracks progress against the 60-day target and escalates to the executive team if blockers arise that would push remediation beyond the window.
  </Tab>

  <Tab title="Planned (Medium)">
    **What qualifies:** Findings with ALE between $50,000 and $250,000/yr. These findings represent real but manageable risk that can be addressed through normal engineering planning cycles without emergency response. Most organizations will have the majority of their findings in this tier.

    **Typical timeframe:** Remediation complete within 90 days of report delivery. Medium findings should be entered into your standard engineering backlog and assigned to an upcoming sprint or project cycle within the first two weeks after report delivery.

    **Who owns the action:** Engineering or security operations team owns the work. CISO reviews status at the next monthly security review. Medium findings that remain open at the quarterly reassessment are reviewed for re-prioritization — a finding that has aged 90 days without remediation may indicate a resourcing or process issue that needs leadership attention.
  </Tab>

  <Tab title="Accepted Risk (Low/Deferred)">
    **What qualifies:** Findings with ALE below \$50,000/yr, or findings in higher ALE bands where a documented risk acceptance decision has been made by the appropriate authority. Risk acceptance is a formal, documented decision — not inaction. Every finding in this tier must have a named owner, a review date, and a sign-off at the appropriate level.

    **Typical timeframe:** Findings in this tier are addressed in the next annual planning cycle or at the next quarterly reassessment. The review date for accepted risk should never exceed 12 months without a fresh evaluation.

    **Who owns the action:** The CISO maintains the risk register for accepted findings. Each accepted finding is logged with the date of acceptance, the authority who approved it, the rationale, and the next review date. Accepted findings are surfaced in every quarterly reassessment report so leadership maintains visibility into what risks remain open by choice.
  </Tab>
</Tabs>

## Example Roadmap Entries

The table below shows a sample remediation roadmap ordered by Priority Rank. Notice that Priority Rank reflects both ALE and effort — a medium-effort High finding can outrank a high-effort Critical finding when an interim mitigation reduces the active exposure.

| Priority Rank | Finding                                                        | Estimated ALE | Effort | Notes                                                                         |
| ------------- | -------------------------------------------------------------- | ------------- | ------ | ----------------------------------------------------------------------------- |
| 1             | Leaked executive credentials (dark web)                        | \$180,000/yr  | Low    | Force credential rotation and enable MFA immediately                          |
| 2             | No DMARC enforcement on primary domain                         | \$90,000/yr   | Low    | Publish DMARC policy in reporting mode, move to enforcement within 30 days    |
| 3             | Exposed admin panel on legacy subdomain                        | \$75,000/yr   | Medium | Restrict to VPN-only access; decommission if no longer in use                 |
| 4             | Orphaned staging environment with PII                          | \$48,000/yr   | Medium | Audit data contents, remove PII, implement access controls or decommission    |
| 5             | Third-party vendor with breach history accessing internal APIs | \$32,000/yr   | High   | Review vendor access scope, rotate API keys, implement least-privilege policy |

## Tracking Remediation Progress

At each quarterly reassessment, your Leverage Cyber report includes a remediation status section alongside new findings. Every finding from the prior period is reviewed and assigned one of three statuses:

**Resolved** findings have been remediated and are no longer externally visible or exploitable. Resolved findings are removed from the active portfolio ALE calculation, and the ALE reduction is shown in the period-over-period comparison in your executive report.

**Persistent** findings remain open from the prior period. Persistent items are re-evaluated for any changes in threat likelihood or asset exposure that would affect their ALE. A finding that has aged into a higher threat environment — for example, because the underlying CVE now has active exploit code — may see its ALE increase even if the finding itself hasn't changed.

**New** findings have been identified since the prior assessment. New findings are introduced into the roadmap at their calculated priority rank.

The net change in portfolio ALE — the sum of resolved ALE minus new finding ALE — is the primary metric for demonstrating security program progress over time.

## When to Accept Risk

Not every finding warrants immediate remediation. Risk acceptance is a legitimate, documented decision that allows your organization to make an informed choice to carry a known risk when the remediation cost or operational impact is disproportionate to the ALE.

To formally accept a finding, complete the following steps using your organization's risk register or the acceptance workflow in the Leverage Cyber portal.

<Steps>
  <Step title="Document the Finding">
    Record the finding identifier, description, and current ALE from your Leverage Cyber report. Include the date of acceptance and the version of the report the finding appeared in.
  </Step>

  <Step title="State the Rationale">
    Document why remediation is being deferred. Acceptable rationales include: remediation cost exceeds ALE, interim mitigation reduces active exposure, vendor dependency with a committed roadmap date, or business continuity risk from the remediation itself.
  </Step>

  <Step title="Obtain the Appropriate Sign-Off">
    Route the acceptance to the correct authority based on the finding's severity band. Low findings may be accepted by the CISO or Security Lead. Medium findings require CISO sign-off. High and Critical findings require CFO or Board-level acknowledgment — accepting seven-figure annual risk is a business decision, not a security team decision.
  </Step>

  <Step title="Set a Review Date">
    Accepted risk does not mean forgotten risk. Set a review date no more than 12 months from the acceptance date. The finding will surface automatically in your next quarterly reassessment, and the review date reminds the owning team to re-evaluate whether circumstances have changed.
  </Step>
</Steps>

<Tip>
  Use your remediation roadmap directly as input to your annual security budget request. Each roadmap line item maps to a specific ALE reduction and effort estimate, giving you a defensible, dollar-denominated justification for every budget line. A roadmap showing $2.4M in portfolio ALE that can be reduced by 85% for $340,000 in remediation cost is a more compelling budget document than a list of vulnerabilities — it speaks the language finance and the board already use to evaluate capital allocation decisions.
</Tip>
