There are two types of plans available:
Base Plan: The default, system-generated plan that represents the most efficient path to an A grade based on Bitsight's proprietary methodology.
Custom Plans: User-defined plans that scope the base plan to the findings you intend to work on. You can exclude specific findings and include or exclude findings by filter criteria. Custom plans keep Bitsight's prioritization order and grading methodology — customization changes which findings appear in the plan, not how they are weighted.
A Risk Remediation forecast generates a projection based on your selected plan (base or custom) and its associated inputs.
Risk Remediation is available with some SPM packages for My Companies and MySubsidiary subscriptions.
RRPs are available for the following risk vectors:
- TLS/SSL Certificates
- TLS/SSL Configurations
- Web Application Security
- Desktop Software
- Mobile Software
- Critical Vulnerability Management
- DMARC
This article covers RRP calculation, capabilities, and interpretation. To learn more, refer to the following articles:
- Running a Risk Remediation Plan
- Scheduling a Risk Remediation Plan
- Risk Remediation Plan Details by Risk Vector
- Risk Remediation Forecast
Base Plan vs. Custom Plan
The Base Plan is the benchmark for remediation. It represents the most efficient path to an A grade with no constraints applied. Bitsight always generates the Base Plan first, then applies your customizations on top of it, so a baseline is always available for comparison.
Custom Plans let you adjust which findings the plan covers:
- Exclude findings you cannot address right now, such as work that is blocked, out of scope, or accepted as risk
- Scope the plan by filter criteria, so it reflects a specific team, threat group, severity, or issue tracking status
- Create multiple custom plans and compare them to evaluate different remediation strategies
Within any plan, base or custom, findings remain ordered by rating impact.
You can compare a custom plan against the Base Plan at any time to:
- Understand the tradeoffs between the ideal path and a practical one
- See how exclusions change your projected grade
- Confirm alignment with Bitsight's recommended approach
Excluding a finding does not change your grade. Exclusions apply to the plan only. Excluded findings continue to affect your risk vector grade, and excluding a large number of findings may make an A grade unreachable within that plan.
Building a Custom Plan
Excluding Findings
Select individual findings to exclude from the plan. You can record an optional reason for each exclusion.
Scoping by Filter Criteria
Custom plans use the same findings filters as the Findings Table, including any saved filters you have already built.
Risk vector is applied automatically, since each plan covers a single risk vector.
You can combine filter-based scoping with individual finding exclusions in the same plan.
Sharing Custom Plans
Custom plans can be Shared or Private, the same way Benchmark Groups work. Because Risk Remediation Plans are visible to all users in your organization, marking a plan Private lets you run a plan just for yourself. Plans created before custom plans were released are treated as base plans and are shared.
Custom Plans on a Schedule
When a plan runs on a recurring cadence, Bitsight applies the rules from your most recent custom plan to the next run. Your exclusions and filter criteria carry forward, so the custom plan stays current instead of reverting to the base plan.
How It Works: Calculation and Capabilities
RRPs are point-in-time, so outside factors like new findings, infrastructure changes, and changes in our inventory of companies can shift the outcome of the report.
Critical Vulnerability Management Risk Vector
This RRP projects your future risk vector grade based on different remediation scenarios, prioritizing the most severe findings to prevent your grade from deteriorating.
All Other Risk Vectors
These RRPs show the most efficient path to improve a risk vector grade to an A based on grade-impacting findings at the time of calculation. RRPs are point-in-time, so outside factors like new findings, infrastructure changes, and changes in our inventory of companies can shift the outcome of the report.
RRPs are calculated with the assumption that fixed findings become or are replaced by Good findings. Good findings have the highest impact on your risk vector grades. There are many valid ways to remediate, mitigate, or improve findings, but not all result in a Good finding.
In addition to findings that need to be fixed, RRPs contain findings that need to be maintained. When a plan is calculated, the weight of finding grades that need to be maintained plus the anticipated weight of findings you fix along the way is enough to improve your grade to an A.
Remediating findings in the Maintain for an A group helps pad your ratio of positive to negative findings and can potentially protect your A grade from dropping as new findings occur.
An RRP calculates the most efficient remediation path to an A–no more, no less. It does not take into account what happens if you don’t follow the plan. If you skip or ignore a finding that the plan has identified as part of your path, it remains on your RRP. Remediated findings remain on your RRP until they've completed their lifetime.
Reading a Plan
The RRP supports multiple risk vectors. The data in each plan is laid out differently, but the overall structure remains the same: findings are listed from most to least impactful and separated into groups.
Critical Vulnerability Management Risk Vector
The Critical Vulnerability Management RRP models multiple remediation scenarios and projects your future risk vector grade based on the number, severity, and age of vulnerabilities addressed.
It helps answer key questions such as:
How soon and by how much will the letter grade drop if current findings are not fixed?
How many findings must be remediated now to maintain the current grade?
What would the future grade be if additional findings were fixed today?
The report estimates hypothetical 90-day scenarios, assuming a subset of current unremediated findings is remediated as of the report date. Each scenario includes the findings in that row and all rows above it, and displays the expected grade at different points in time. Previously remediated findings may continue to impact the grade for a period of time.
All Other Risk Vectors
Groups contain the findings that need to be fixed to improve your letter grade from the current grade to the next in sequence. This improvement is usually from one grade to the next, such as C → B, but in rare cases you may see skip-level groups such as C → A.
Findings in each group are ordered from most to least impactful. In cases where findings have the same weight, they are listed alphabetically. Findings don’t have to be fixed in order, but all findings in a group must be fixed to improve the grade as seen in the RRP.
Finding Details
The RRP includes information to help you remediate findings. Select an individual finding from the RRP to open a details sheet like the one on the Findings Table page. To open a group of findings in the Findings Table page, select View in Findings. In the Critical Vulnerability Management RRP, select a group of findings in the Findings column to open them in the Findings Table page.
Issue tracking fields, including status and assignee, appear directly in the plan. You can update status and assign a finding without leaving the Risk Remediation page.
RRPs can be scheduled. If your plan is older, findings in it may no longer exist or may not impact your grade. Scheduling your plan keeps it up to date and prevents you from working with old information. Scheduled runs of a custom plan reuse the rules from your most recent custom plan.
Downloading a Plan
Downloading plans allows you to track your progress over time using comparative reporting. We recommend scheduling and downloading plans weekly or monthly for this purpose.
Active Plan
Select Download CSV in the top right of the plan page.
Historical Plan
Select See Historical Plans, then select Download CSV next to the historical plan you wish to download.
- September 1, 2026: Custom Plans: exclude findings, scope plans by findings filters, share or keep plans private, and update issue tracking status and assignee from the plan. Critical Vulnerability Management plans can now be scheduled.
- March 24, 2026: Security Posture Management rebrand.
- April 8, 2025: Risk Remediation Plan is available for Web Application Security.
- October 29, 2024: Reordered plan types to match the platform. Linked to the new Risk Remediation Forecast article.
- October 23, 2024: Added navigation instructions.
Comments
Please sign in to leave a comment.