The challenge
The programme covers every SharePoint estate under support: a US commercial bank’s platform, and a regulatory case-management system run for several US energy utilities. The worked examples come from the utility side; the totals span both.
Those estates share an awkward property. The software is the supplier’s, but the servers, the scanners, the tickets and the clock belong to the client. Each utility scans on its own schedule with Tenable WAS against the public URLs, and applies its own windows: critical within 15 days, high within 30, medium within 45.
A structural complication sits underneath. The supplier often cannot verify its own work: the platform runs at the client and it holds no login to the scanned URL. A fix is applied blind and confirmed only when the utility re-scans, so the deliverable is the fix plus evidence the client can act on.
Then in February 2026 one utility made remediation part of its cybersecurity scorecard. Overrunning stopped being a debt item carried between status calls, and became a number reported inside the utility about the supplier.
The solution
The backlog was cleared months before it became a metric. Between July and September 2025 a sweep closed 3,152 findings, roughly 70% of the year’s total in one quarter. That sequencing is the whole study: when the scorecard change landed, the programme was working from a clean position rather than digging out under a deadline.
Findings were fixed by class, not one at a time. Sixteen separate findings across one estate closed when HTTP Strict Transport Security was enabled on the web application, a single PowerShell change. A stray archive in the IIS bin folder was deleted and the deployment procedure rewritten so no backup is created there again. Remediations were folded into the build guide, the part that compounds.
A scanner’s recommendation is a recommendation, not an instruction. One finding called for changing IIS anonymous authentication, which would have closed a ticket and broken SharePoint authentication, since that layer needs anonymous access to work at all. Refusing it and carrying a documented exception is slower, and the only defensible answer.
Scope was stated rather than improvised. When a second utility raised .NET Core findings, the SharePoint side said plainly that the application layer was not theirs to answer for, routing it to the owners within a day.
The results
Remediation stopped being an event. Findings arrive continuously against a clock the utility owns, and what makes that survivable is a short queue before the scan lands, one fix closing a class of finding, and evidence arriving with the fix. A rolling 90-day window now shows 550 tracked, 413 remediated, 137 open.
The 137 belong in the record. They are the residue an honest programme carries: fixes that depend on a supplier’s patch, a version bump the client controls, or a maintenance window. Reporting them, with their causes, is what makes the zero next to overdue mean anything.