Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Security assurance
  3. Remediation support and retesting

Security assurance

Remediation support and retesting

We help you close the findings, then retest and update the report so the record shows what was fixed.

Scope a test Call 1300 AURIAN

Who this is for

  • You have a report and no spare capacity to action it

    A test is only worth the fixes it leads to. When the internal team is stretched, findings sit open, and the risk stays.

  • You have no in-house security specialists

    Some findings need security expertise your team does not have day to day. We work alongside them to close the gap.

  • You need evidence that findings were fixed

    Auditors, customers and insurers want proof the issues were closed, not just found. A formal retest and updated report provide it.

What our remediation support covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: CHECKS INCLUDE Retest of perimeter findings, with an updated report Advice on VPN, firewall and TLS changes CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Retest of network findings, with an updated report Segmentation and legacy protocol changes, with your engineers WORKSTATION: CHECKS INCLUDE Retest of endpoint findings, with an updated report Local administrator and endpoint control changes IDENTITY: CHECKS INCLUDE Retest of identity findings, with an updated report Active Directory and AD CS hardening, with your engineers WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: CHECKS INCLUDE Confirmation that the path to customer data is closed The updated report for your auditors and insurer SERVERS: CHECKS INCLUDE Retest of server findings, with an updated report Share, credential and patching changes Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: CHECKS INCLUDE Retest of perimeter findings, with an updated report Advice on VPN, firewall and TLS changes API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Retest of network findings, with an updated report Segmentation and legacy protocol changes, with your engineers WORKSTATION: CHECKS INCLUDE Retest of endpoint findings, with an updated report Local administrator and endpoint control changes WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: CHECKS INCLUDE Retest of identity findings, with an updated report Active Directory and AD CS hardening, with your engineers CROWN JEWELS: CHECKS INCLUDE Confirmation that the path to customer data is closed The updated report for your auditors and insurer SERVERS: CHECKS INCLUDE Retest of server findings, with an updated report Share, credential and patching changes

We pick up from a report, ours or another provider's, and help you close the findings, then formally retest and update the record.

  • A working session to walk through the findings and agree priorities
  • Technical clarification of each finding for your engineers or MSP
  • Hands-on guidance implementing the fixes, at whatever depth you need
  • Coordination with your managed service provider or software vendors
  • A formal retest of the remediated findings
  • An updated report showing what was found and what has been closed
  • An attestation letter for auditors, customers or insurers, on request
  • Advice on the systemic changes that would prevent the findings recurring

How we test it

A penetration test is only worth the fixes it leads to. The most thorough report in the world reduces no risk while it sits in a shared drive, and closing findings is often where organisations stall: the internal team is stretched, some findings need expertise they do not have day to day, and the report’s technical language does not quite translate into a change ticket. Aurian’s remediation support exists to carry findings from discovery to closure, whether the original test was ours or another provider’s.

We start with a working session to make sure every finding is understood and to agree the order of work by risk and effort, because fixing the critical authorisation flaw matters more than clearing a page of informational items. From there we support your engineers or your managed service provider at whatever depth you need, from clarifying a finding to guiding the implementation hands-on, and we coordinate with software vendors where a fix depends on them. The aim throughout is not only to close each finding but to address the cause, so the same class of issue does not return in the next release.

Then we retest. Each remediated finding is tested again to confirm it is genuinely closed rather than reported as done, because fixes are deployed to the wrong environment, applied partially, or reverted by a later change more often than anyone would like. The report is updated to record what was found and what has been closed, and where offered, we provide an attestation letter you can give to an auditor, a customer or an insurer as evidence that the issues were fixed and verified.

Standards PTES, OWASP WSTG, NIST SP 800-115

  1. 01 Review

    We walk through the report with your team, make sure every finding is understood, and agree the order of work by risk and effort.

  2. 02 Support

    We provide clarification and hands-on guidance as your engineers or MSP implement the fixes, at whatever depth you need from us.

  3. 03 Retest

    Once findings are addressed, we retest each one to confirm it is genuinely closed, not merely reported as done.

  4. 04 Attestation

    We update the report to show the closed findings and, where offered, provide an attestation letter for your auditors and customers.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

Informational AUR-2026-014 Sample finding, fictional environment

Retest confirms the invoice authorisation flaw is closed

Affected asset
GET /api/v2/invoices/{id} on app.example.com.au
Rating
Informational Remote 1 × Medium 3 = 3

Description

The high-severity insecure direct object reference from the original web application test has been retested. The endpoint now enforces an ownership check, and an attempt to read another customer's invoice is refused. The finding is confirmed closed and recorded as such in the updated report.

Evidence

GET /api/v2/invoices/1042 HTTP/1.1
Authorization: Bearer eyJhbGciOi...   # a customer who does not own 1042

HTTP/1.1 403 Forbidden
{ "error":"not_authorised" }
# previously returned 200 with another customer's invoice

The same request that previously leaked another customer's invoice is now correctly refused.

Impact

The reportable data-exposure risk from the original finding is removed. The updated report and, where offered, an attestation letter give your auditors, customers and insurer evidence that the issue was not only found but fixed and verified.

Remediation

Keep the ownership check in the shared authorisation layer so new endpoints inherit it, add a regression test that asserts the 403 for cross-customer access, and schedule the next test to cover any new endpoints added since.

References

  • OWASP WSTG, testing for authorisation
  • NIST SP 800-115, technical guide to information security testing
  • A working session on the findings and their priority
  • Hands-on remediation guidance for your engineers or MSP
  • A formal retest of the remediated findings
  • An updated report recording what was found and what has been closed
  • An attestation letter for third parties, on request

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Fixes that address the symptom, not the cause

    A single endpoint patched while the shared component behind a class of findings is left untouched.

  • Findings marked done but not actually closed

    Changes deployed to the wrong environment, or partially, so the issue remains reachable in production.

  • New issues introduced by the fix

    A remediation that closes one finding while opening another, which a retest catches before it ships.

  • Configuration drift after the fix

    A change reverted by a later deployment or a rebuilt server, so the finding quietly returns.

  • No regression test

    A fix with nothing to stop the same mistake being made again in the next release.

  • Systemic gaps behind repeated findings

    The same category of finding across many systems, pointing to a process or standard that needs to change.

Frequently asked questions

Will you fix things directly in our systems?

We work the way you prefer. We can guide your engineers or MSP step by step, or where you want and where access allows, take a hands-on role in implementing fixes. What we do not do is make changes without your knowledge; you stay in control of your environment.

Can you support a report from another provider?

Yes. We can pick up a report from a previous test, ours or another firm's, help you understand and close the findings, and retest them. We do ask to see the original report and evidence so the retest is like for like.

What is an attestation letter?

A short, signed letter you can give to a customer, auditor or insurer stating that the findings were retested and confirmed closed, without disclosing the sensitive detail of the full report. It is available on request at no charge.

Is retesting included in the original test, or separate?

Separate, unless it was quoted with the test. A retest is a short follow-on engagement: each finding rated high or above is tested again once you have remediated, and the report is updated. Remediation support is the broader service for when you want help closing the findings as well as the formal, documented retest.

How long does it take?

It depends on the number of findings and how much hands-on help you want: a retest on its own is typically one to three days, and remediation support is scoped to the findings. We confirm the timeframe after scoping.

Related services

External network penetration testing

External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

Configuration review and benchmarking

Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Vulnerability management

Managed vulnerability management: continuous scanning of external and internal assets, results validated and ranked by a consultant, reported monthly.

Security assurance and compliance services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.