Risk Assessment Remediation
NOTE: ACRA will not discuss remediation unless the client requests it and only after the risk assessment has been delivered.
Remediation process (short, stepwise)
- Review findings: we review the delivered assessment and confirm prioritized items with your team.
- Scope & plan: produce a remediation plan with tasks, owners, and acceptance criteria.
- Schedule work: coordinate windows, vendors, and approvals for changes.
- Implement fixes: apply configuration changes, patches, and controls per the plan.
- Validate: verify remediation with testing and updated scans.
- Handover: deliver final report, checklist, and knowledge transfer to your staff.
Outcomes
- Reduced attack surface through prioritized fixes
- Clear owner assignment and implementation checklist
- Proof of remediation with validation scans and test results
- Updated operational procedures where needed
Estimated timeline
Typical timelines (estimates):
- Small: 1–2 weeks — a handful of low-complexity fixes.
- Medium: 3–6 weeks — multiple systems, configuration changes, vendor coordination.
- Large: 2–3 months — extensive remediation, patches, and process changes across multiple locations.
Suggested price: Flat fee starting at $500 (final price depends on scope and number of prioritized items).