What severity should this finding carry?
A report landed and the severities do not match what your engineers think. Six questions about one finding, then a band, a fix-by date to put in the ticket, and the sentence to send a customer who asks about it.
Severity in a penetration test report is the testing firm's judgement about your system, made by somebody who does not know which of your customers is regulated or which service is load bearing. Sometimes they are right and your engineers are arguing. Sometimes the finding is a high in their template and a medium in your reality, or the other way round.
This works one finding at a time and answers the three questions a triage meeting actually has: what band, by when, and what do we say if a customer asks. The answer appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly.
How the band is worked out
Impact sets the ceiling, because a finding that lets nobody do anything cannot be critical however easy it is to trigger. Exploitability and exposure move it within that ceiling. The data reached and the number of people affected push it up, and honest detection and containment pull it down by at most one band, never to nothing.
This is deliberately a business triage rather than a second opinion on the score. If you want the published numeric version, the CVSS 3.1 calculator produces a base score and a vector string you can paste into a ticket, and CVSS v3 against v4 explains why the two systems disagree with each other on the same finding.
Why a deadline belongs in the ticket
The most common outcome of a penetration test report is that the criticals get fixed, the highs get fixed slowly, and the mediums are still open when next year's test rediscovers them. Writing a fix-by date on each finding at triage is what prevents that, and it is also the thing an auditor asks to see. A remediation policy with dates in it and a ticket trail showing the dates were met is worth more at audit time than the report itself.
Whatever bands you use, apply them consistently and record the reasoning when you downgrade something. The downgrade is defensible. A downgrade nobody wrote down is not. What to do after the fixes ship is on retest and remediation verification, and reading the report as a whole is covered in how to read a penetration test report.
Common questions
Can we overrule the tester's severity?
Yes, and you sometimes should, because you know things the tester does not: which data is regulated, which system is load bearing, what compensating controls actually run. Record the reasoning next to the finding. An adjusted severity with a written rationale reads as governance. A silently downgraded critical reads as something else.
Does detection really lower severity?
By one band at most, and only when the detection is real: an alert that reaches somebody who is awake, and a containment path you have used. It does not lower the severity of anything an attacker completes in a single request, because there is nothing to detect in time.
What about a finding the tester could not demonstrate?
Treat it as a lead rather than a finding. Ask the firm what evidence exists and what stopped them proving it, since the honest answers range from a rate limit that got in the way to a guess from a version number. Then decide whether to fix it cheaply anyway, which is often the right call for a small change.
A customer is asking about a high finding. What do we say?
What was found, what an attacker would have needed, what you changed, and the date you changed it. Enterprise security reviewers are not surprised that a test found something, because a test that finds nothing is the one that worries them. What they are checking is whether you triage on a schedule and can prove the fix shipped.
Do these bands map to CVSS scores?
Roughly, and roughly is the honest word. CVSS scores the vulnerability in the abstract and knows nothing about which of your tenants is a hospital. Use the numeric score for consistency across reports and this kind of triage for deciding what your team does on Monday.