The finding says “medium”. Everyone exhales. There are already higher-priority issues in the backlog, so this one can wait.
That may be the right decision. It may also miss what the finding makes possible.
Severity is a starting point
Severity scores help teams compare technical characteristics consistently. They are useful. They also have no idea which system holds your customer data, which workflow controls money or how one weakness changes the value of another.
A modest information exposure may reveal an identifier. A separate permissions weakness may let a user act on that identifier. An old supplier account may provide the access needed to join the two.
Each issue can look manageable on its own. Join them together and the path may lead somewhere the business would consider critical.
Attackers do not stop at the first finding
An attacker asks a sequence of questions:
- What can I reach?
- What does this reveal?
- Can I use it to gain more access?
- What other system or privilege becomes available?
- What business outcome can I cause?
A useful penetration test follows those questions. It tests whether findings can be combined and records the evidence behind the path.
Context changes the remediation decision
When teams understand the path, prioritisation becomes easier. They can see which control breaks the chain earliest, which fix reduces the most exposure and which issue only looks minor because it was assessed in isolation.
This does not mean stamping “critical” on everything. That quickly becomes the security version of shouting fire whenever someone makes toast. Explain the conditions, confidence and business impact clearly enough for the team to make a sound decision.
Good reporting shows where the weakness leads and what to fix first. The score can come along for the ride.