Action Plans: Risk Remediation

Use the Risk Remediation page in the Security Posture Management application [menu-action-plans.png Action Plans ➔ Risk Remediation] to manage risk remediation plans (RRPs) and generate a Risk Remediation forecast. RRPs list and prioritize findings that can be fixed to improve certain risk vector grades. Plans are designed to identify and remediate high-impact findings with the goal of reaching an A grade.

There are two types of plans available:

Base Plan: The default, system-generated plan that represents the most efficient path to an A grade based on Bitsight's proprietary methodology.

Custom Plans: User-defined plans that scope the base plan to the findings you intend to work on. You can exclude specific findings and include or exclude findings by filter criteria. Custom plans keep Bitsight's prioritization order and grading methodology — customization changes which findings appear in the plan, not how they are weighted.

A Risk Remediation forecast generates a projection based on your selected plan (base or custom) and its associated inputs.

Risk Remediation is available with some SPM packages for My Companies and MySubsidiary subscriptions.

RRPs are available for the following risk vectors:

  • TLS/SSL Certificates
  • TLS/SSL Configurations
  • Web Application Security
  • Desktop Software
  • Mobile Software
  • Critical Vulnerability Management
  • DMARC

This article covers RRP calculation, capabilities, and interpretation. To learn more, refer to the following articles:

Base Plan vs. Custom Plan

The Base Plan is the benchmark for remediation. It represents the most efficient path to an A grade with no constraints applied. Bitsight always generates the Base Plan first, then applies your customizations on top of it, so a baseline is always available for comparison.

Custom Plans let you adjust which findings the plan covers:

  • Exclude findings you cannot address right now, such as work that is blocked, out of scope, or accepted as risk
  • Scope the plan by filter criteria, so it reflects a specific team, threat group, severity, or issue tracking status
  • Create multiple custom plans and compare them to evaluate different remediation strategies

Within any plan, base or custom, findings remain ordered by rating impact.

You can compare a custom plan against the Base Plan at any time to:

  • Understand the tradeoffs between the ideal path and a practical one
  • See how exclusions change your projected grade
  • Confirm alignment with Bitsight's recommended approach

Excluding a finding does not change your grade. Exclusions apply to the plan only. Excluded findings continue to affect your risk vector grade, and excluding a large number of findings may make an A grade unreachable within that plan.

Building a Custom Plan

Excluding Findings

Select individual findings to exclude from the plan. You can record an optional reason for each exclusion.

Scoping by Filter Criteria

Custom plans use the same findings filters as the Findings Table, including any saved filters you have already built.

Risk vector is applied automatically, since each plan covers a single risk vector.

You can combine filter-based scoping with individual finding exclusions in the same plan.

Sharing Custom Plans

Custom plans can be Shared or Private, the same way Benchmark Groups work. Because Risk Remediation Plans are visible to all users in your organization, marking a plan Private lets you run a plan just for yourself. Plans created before custom plans were released are treated as base plans and are shared.

Custom Plans on a Schedule

When a plan runs on a recurring cadence, Bitsight applies the rules from your most recent custom plan to the next run. Your exclusions and filter criteria carry forward, so the custom plan stays current instead of reverting to the base plan.

How It Works: Calculation and Capabilities

RRPs are point-in-time, so outside factors like new findings, infrastructure changes, and changes in our inventory of companies can shift the outcome of the report.

Critical Vulnerability Management Risk Vector

This RRP projects your future risk vector grade based on different remediation scenarios, prioritizing the most severe findings to prevent your grade from deteriorating.

All Other Risk Vectors

These RRPs show the most efficient path to improve a risk vector grade to an A based on grade-impacting findings at the time of calculation. RRPs are point-in-time, so outside factors like new findings, infrastructure changes, and changes in our inventory of companies can shift the outcome of the report.

RRPs are calculated with the assumption that fixed findings become or are replaced by Good findings. Good findings have the highest impact on your risk vector grades. There are many valid ways to remediate, mitigate, or improve findings, but not all result in a Good finding.

In addition to findings that need to be fixed, RRPs contain findings that need to be maintained. When a plan is calculated, the weight of finding grades that need to be maintained plus the anticipated weight of findings you fix along the way is enough to improve your grade to an A.

Remediating findings in the Maintain for an A group helps pad your ratio of positive to negative findings and can potentially protect your A grade from dropping as new findings occur.

An RRP calculates the most efficient remediation path to an A–no more, no less. It does not take into account what happens if you don’t follow the plan. If you skip or ignore a finding that the plan has identified as part of your path, it remains on your RRP. Remediated findings remain on your RRP until they've completed their lifetime.

Reading a Plan

The RRP supports multiple risk vectors. The data in each plan is laid out differently, but the overall structure remains the same: findings are listed from most to least impactful and separated into groups.

Critical Vulnerability Management Risk Vector

The Critical Vulnerability Management RRP models multiple remediation scenarios and projects your future risk vector grade based on the number, severity, and age of vulnerabilities addressed.

It helps answer key questions such as:

  • How soon and by how much will the letter grade drop if current findings are not fixed?

  • How many findings must be remediated now to maintain the current grade?

  • What would the future grade be if additional findings were fixed today?

The report estimates hypothetical 90-day scenarios, assuming a subset of current unremediated findings is remediated as of the report date. Each scenario includes the findings in that row and all rows above it, and displays the expected grade at different points in time. Previously remediated findings may continue to impact the grade for a period of time.

All Other Risk Vectors

Groups contain the findings that need to be fixed to improve your letter grade from the current grade to the next in sequence. This improvement is usually from one grade to the next, such as CB, but in rare cases you may see skip-level groups such as CA.

Findings in each group are ordered from most to least impactful. In cases where findings have the same weight, they are listed alphabetically. Findings don’t have to be fixed in order, but all findings in a group must be fixed to improve the grade as seen in the RRP.

Finding Details

The RRP includes information to help you remediate findings. Select an individual finding from the RRP to open a details sheet like the one on the Findings Table page. To open a group of findings in the Findings Table page, select View in Findings. In the Critical Vulnerability Management RRP, select a group of findings in the Findings column to open them in the Findings Table page.

Issue tracking fields, including status and assignee, appear directly in the plan. You can update status and assign a finding without leaving the Risk Remediation page.

RRPs can be scheduled. If your plan is older, findings in it may no longer exist or may not impact your grade. Scheduling your plan keeps it up to date and prevents you from working with old information. Scheduled runs of a custom plan reuse the rules from your most recent custom plan.

Downloading a Plan

Downloading plans allows you to track your progress over time using comparative reporting. We recommend scheduling and downloading plans weekly or monthly for this purpose.

Active Plan

Select Download CSV in the top right of the plan page.

Historical Plan

Select See Historical Plans, then select Download CSV next to the historical plan you wish to download.

Publish Date or Recent Edits
  • September 1, 2026: Custom Plans: exclude findings, scope plans by findings filters, share or keep plans private, and update issue tracking status and assignee from the plan. Critical Vulnerability Management plans can now be scheduled.
  • March 24, 2026: Security Posture Management rebrand.
  • April 8, 2025: Risk Remediation Plan is available for Web Application Security.
  • October 29, 2024: Reordered plan types to match the platform. Linked to the new Risk Remediation Forecast article.
  • October 23, 2024: Added navigation instructions.
Was this article helpful?
5 out of 7 found this helpful

Comments

0 comments

Please sign in to leave a comment.