Vulnerability remediation plan template: turn audit findings into fixes that finish
An audit report ends with a findings list. A remediation plan is what makes that list shrink. Most small teams fail here in one of two ways: the findings live in a PDF nobody reopens, or they become a 40-row spreadsheet so heavy that week two abandons it. This template keeps one table, four clocks, and one weekly meeting — built to be finished, not filed. Score your starting point in the 45-check security audit scorecard; whatever it flags becomes rows in this plan.
1. The plan is a table, not a policy
A remediation policy says criticals are fixed within 48 hours. A remediation plan says V-07, no MFA on the billing console, Dana, by Thursday, evidenced by a screenshot. One is a sentence; the other is a Tuesday. Write the policy one-pager if you must (the audit preparation checklist includes one), but the working artifact is a single table with nine columns and rows you can count on one screen.
2. The nine columns that make a fix finish
- ID — V-01, V-02… The ID is how the report, the ticket, and the evidence folder refer to the same finding without re-describing it.
- Finding, in one line — written so a new hire understands it: “Shared admin login on the file server,” not “identity hygiene gap.”
- Zone — identity, endpoint, network, backups, vendors. Zones keep the plan balanced; without them, four weeks of endpoint work hides an untouched backup problem.
- Risk rank (1–4) — 1 = money or data can leave tonight; 4 = hygiene. Rank with the severity definitions in the severity matrix, not with mood.
- Owner (one name) — never “IT,” never “both of us.” If two names go in the column, zero owners went in.
- Fix, in a verb — “Enable MFA on…,” “Rotate…,” “Restore-test….” A finding restated as a worry is not a fix.
- Effort (S/M/L) — S = under an hour, M = under a day, L = needs a purchase or a project.
- Due date — a real calendar date from the severity clocks below. “ASAP” is not a date.
- Status + evidence link — Open / In progress / Verified. Verified means the evidence link points at a dated screenshot or export — the same standard as the evidence folder.
3. Rank by risk ÷ effort, not by fear
The order of work is not the order of scariness. Take each row and sort by rank first, effort second. A rank-1 finding with an S effort goes before a rank-1 finding that needs procurement — not because it matters more, but because it costs less to stop being true. The classic first week: four or five S-effort rows (MFA, departed accounts, registrar mailbox, stale keys) that collapse the top of the findings list before the L-effort rows even start. This is the same fix-first logic the preparation checklist applies before an audit, applied continuously afterward.
Tie-break with exposure: internet-facing before internal, money-path before convenience. A rank-2 on the public website outranks a rank-2 on a laptop nobody takes home.
4. The four severity clocks
Pick clocks you can actually keep, then let the clocks pick the due dates:
- Rank 1 — 48 hours to contained or fixed. If containment is all you can do (disable the account, block the IP), containment counts, and the full fix gets its own row.
- Rank 2 — one week. The quiet killers: stale API keys, unpatched CMS plugins, the backup job nobody has ever tested — see the patch management checklist for the cadence that keeps rank-2 from reappearing.
- Rank 3 — within the month. Hygiene with a receipt: documentation, labeling, rotation schedules from the secrets rotation checklist.
- Rank 4 — backlog, reviewed monthly. Anything rank 4 is allowed to wait visibly. The risk is in pretending the backlog does not exist.
Write the clocks down once. When an auditor or a customer questionnaire asks “what is your remediation SLA,” the answer is the four numbers, not a shrug.
5. The weekly remediation sprint (45 minutes, one meeting)
- Monday, 15 minutes, the stand-up: read the table top-down. Every In-progress row gets one sentence: on track, blocked (say what), or slipped (new date, said out loud). No status theater — dates move only in this meeting.
- Same day, 10 minutes of closes: anything done since last week gets its evidence attached and flips to Verified. An unverified close stays open; that rule is the whole difference between a plan and a wish list.
- 10 minutes of new rows: new findings from the week (a phishing report, a scanner hit, a departed employee) enter with ID, rank, owner, date — before the meeting ends.
- 10 minutes of the one thing: pick the single largest blocked item and give it a decision or a date for a decision. Most L-effort rows are not stuck on work; they are stuck on someone saying yes.
Forty-five minutes a week is the entire meeting burden of this template. If remediation needs more meetings than that, the table has too many owners per row.
6. What “done” means (closure needs evidence)
A finding closes when three things exist: the fix was applied by the named owner, the evidence is dated and attached to the row, and someone other than the fixer looked at it for ten seconds. That third part catches the honest failure mode — MFA enabled on the test tenant instead of production — before the audit retest catches it instead. Use the security audit report template to mark findings remediated with the evidence reference, so the report stays the single source of truth.
7. The one-page report upward
Whoever signs the audit invoice also signs off on the cleanup. Once a month, one page: the counts (open by rank), the closed this month (with IDs), the two oldest open rows and why, and the one decision being asked for. Ten minutes to write, and it converts security spending from a cost into a visible shrinking list — which is what keeps the budget for the L-effort rows.
8. Worked example: 14 findings, three weeks, five people
The eleven-person logistics firm from the preparation checklist finished its audit with fourteen findings — seven already marked remediated during preparation. The remaining fourteen rows (they logged the mediums too) went into this table on the Monday after the report. Week one, risk÷effort put four S-rows first: the two forgotten SaaS tools from the critical findings were disabled and their data exported, the billing console got MFA, and the restore test got its screenshot — four closes, one afternoon of actual work. Week two was the M rows: the CMS plugin patch (rank 2, one week clock, held), the password-manager rollout replacing the last two shared logins, and the registrar move. Week three held the one L row — a proper backup appliance quote — which became a decision in the monthly one-pager rather than a silent stall. Twelve of fourteen rows verified in three weeks; the two open rows had dates, owners, and a one-line reason each. The customer questionnaire that started the whole audit was answered with the plan attached.
The counterfactual is the norm, not the exception: the same fourteen findings emailed as a PDF, re-discovered by the next audit a year later, nine of them unchanged, two of them worse — and the remediation conversation starting from zero credibility.
9. Five remediation numbers
- Verified closure rate (verified closes / total closes — target: 100%; anything lower means evidence is being skipped, and skipped evidence becomes re-opened findings).
- Rank-1 clock compliance (rank-1 rows contained within 48h — target: 100%; this is the number an auditor tests first).
- Median age of open rank-2 (target: under 14 days; a rank-2 aging past a month means the clocks are decorative).
- New rows per week vs closes per week (if new exceeds closes for a month, the estate is growing faster than the fixes — that is a staffing or scope conversation, and the table is how you prove it).
- Days from audit report to first verified close (target: under 7; momentum in week one predicts the fate of the whole list).
Where this fits
The findings come from the 45-point small-business security audit, scored live in the interactive scorecard, delivered in the report template, and prepared for with the preparation checklist. If you would rather hand the whole loop — findings, ranked plan, weekly sprint — to an outside pair, that is the Small-Team Ops Audit; and when any row says “if this fires, we lose the week,” the Custom Incident Runbook turns it into a procedure your team can run without you. The Ops Starter Kit covers the incident half of the plan; Vol. 2 covers the on-call rotation that inherits it.