2026.08.09 · Methodology

Why We Retest Every Finding Before Closing an Engagement

It’s common for a fix to look complete in a code review or a ticket status but not actually close the underlying issue — a patch applied to the wrong environment, a configuration change that didn’t propagate, or a fix that addressed the symptom but not the root cause.

We include one full round of retesting in every engagement specifically because of this gap. Retesting isn’t a courtesy check — it’s the step that turns ‘we believe this is fixed’ into ‘we confirmed this is fixed,’ which is the only version of that sentence that matters to an attacker, an auditor, or your own leadership.

If a finding doesn’t hold up on retest, it stays open in the report until it does.

← back to insights