Prioritized Remediation Playbook — worked example
The playbook takes the findings in a paid report and collapses them into a single ordered action plan: Immediate (next 24 hours), Short term (this week) and Strategic (this quarter). Each action carries the steps to fix it, the team that should own it, and an honest effort estimate — so the report leaves your desk as work, not as a list of problems.
Generated from an invented report for acme-logistics.com using the exact same engine that builds a customer playbook. No real organization is described here.
Your ordered action plan — 11 actions
Every finding in this report, de-duplicated and sequenced by urgency, with an owner and an effort estimate. Hand this straight to whoever does the work.
Immediate
next 24 hours · 7Live, exploitable exposure. Treat as an incident — assign an owner today.
- #1criticalDangling CNAME on assets.acme-logistics.com points to an unclaimed host
A DNS record still points at a decommissioned hosting provider bucket that anyone can register. An attacker who claims it serves content from your domain, inheriting cookies, trust and TLS on the name.
- Delete the CNAME record for assets.acme-logistics.com immediately if the asset is retired.
+2 more steps in the full playbookOwner: DNS / platform ownerEffort: mediumCovers 1 finding - #2criticalExposed service on 203.0.113.44:8443 matches a known remote-code-execution CVE
An internet-facing management interface is running a build associated with a high-severity remote code execution vulnerability. It is reachable without a VPN.
- Restrict port 8443 to your corporate ranges or a VPN at the firewall today.
+2 more steps in the full playbookOwner: Infrastructure / cloud teamEffort: mediumCovers 1 finding - #3highDMARC policy is p=none — spoofed mail is delivered, not rejected
Your domain publishes DMARC in monitoring mode only. Anyone can send mail as your domain and it will land in recipients' inboxes, which is the entry point for invoice fraud and recruiting scams.
- Review DMARC aggregate reports for two weeks to confirm all legitimate senders align.
+2 more steps in the full playbookOwner: IT / email administratorEffort: mediumCovers 1 finding - #4highAdministrative login panel indexed by search engines (+1 related finding)
A staff-only console is publicly crawlable, giving attackers a free target list for credential stuffing against your breached-password exposure.
- Place the admin console behind SSO or an IP allowlist.
+4 more steps in the full playbookOwner: Web / application ownerEffort: mediumCovers 2 findings - #5high31 corporate accounts appear in credential breach corpora
Staff addresses on your domain appear alongside cracked or plaintext passwords. Combined with the exposed admin panel above, this is a direct account-takeover path.
- Force a password reset for every affected account.
+3 more steps in the full playbookOwner: Security + HR (account owners) — organization-wide, not just the scanned hostEffort: mediumCovers 1 finding - #6highacme-logistlcs.com resolves and serves a copy of your login page (+1 related finding)
A registered typosquat is actively hosting a cloned sign-in form, which is the classic setup for harvesting employee credentials.
- File an abuse report with the registrar and hosting provider with screenshots as evidence.
+5 more steps in the full playbookOwner: Brand / legal + security — organization-wide, not just the scanned hostEffort: highCovers 2 findings - #7highacmelogistcs.com sells your mis-typed traffic to a rotating set of hostile destinations
This typo domain makes no attempt to copy your brand. Each visit was handed to a different destination — a fake virus alert page, a prize-draw bait page and an adult content site — which is the signature of a traffic broker monetizing people who mis-type your address. Anyone who slips a keystroke reaching for your site can land on a malware prompt while believing they are dealing with you.
- Block and sinkhole the typo domain itself on your DNS firewall, mail gateway and web proxy — the destinations change on every visit, so blocking one landing page achieves nothing.
+3 more steps in the full playbookOwner: Brand / legal + securityEffort: highCovers 1 finding
Short term
this week · 2Real risk that is not yet being exploited. Schedule into this week's change window.
- #8mediumSPF record ends in ~all and includes an unused third-party sender
A soft-fail SPF record combined with a stale include leaves an authorized sending path that your team no longer controls.
- Remove the unused include from the SPF record.
+1 more step in the full playbookOwner: IT / email administratorEffort: lowCovers 1 finding - #9mediumFake recruiter profiles using your brand on two job aggregators
Listings advertise roles that do not exist and route applicants to an off-domain chat channel to collect identity documents.
- Submit brand-impersonation takedowns on each aggregator.
+2 more steps in the full playbookOwner: Brand / legal + security — organization-wide, not just the scanned hostEffort: highCovers 1 finding
Strategic
this quarter · 2Hygiene and monitoring work that stops these findings from coming back.
- #10lowCertificate transparency reveals 14 hosts, 4 of which are undocumented
Hosts issued certificates under your domain that do not appear in your asset inventory. Unowned assets do not get patched.
- Reconcile the certificate transparency list against your asset inventory.
+2 more steps in the full playbookOwner: DNS / platform ownerEffort: mediumCovers 1 finding - #11lowTwo hosts still negotiate TLS 1.0
Legacy protocol support weakens transport security and fails most compliance baselines.
- Disable TLS 1.0 and 1.1 on both hosts and require TLS 1.2 or higher.
+1 more step in the full playbookOwner: Infrastructure / cloud teamEffort: mediumCovers 1 finding
This is a preview: the first step of each action is shown in full, remaining steps are redacted. Purchasing the playbook unlocks every step, owner hand-off and verification check for your own findings.
Want this for your own attack surface?
The playbook is included with either plan — Essential ($3,600/year) or Advanced ($7,200/year) per monitored domain — at no extra cost. Start with a free preview scan to see what is exposed, then add the playbook when you upgrade.