A municipal pentest that became a closed ticket list, not a PDF
Council had asked for a pentest. The last one sat unread. We scoped the systems residents actually use, ranked the paths, and retested the highs before the next council packet.
0 open
High findings at retest
11
Weeks from kickoff to retest
None
Resident-facing outage
The challenge
A public-facing portal, an internal file estate and a VPN that still allowed password-only access. A prior report from two years earlier listed 90 findings with no owners. Staff were nervous that a test would take the website down during tax season.
What we did
We wrote rules of engagement that excluded denial of service and set a maintenance window for anything invasive. External testing ran first, then an assumed-breach internal test. Findings were ranked by path to resident data or payment, not by raw CVSS. Each high had an owner and a date. The retest was booked in the same quarter.
The outcome
Nine high findings, all closed or accepted in writing before the retest. VPN moved to MFA. The portal's privileged function was no longer reachable from a low-privilege account. Council received a two-page brief, not a 90-page appendix.
Let's talk about what you are running
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
