Clouds Connected · Case study
Practice studyAcross sectors

4,500 vulnerability findings closed across bank and utility SharePoint estates, with nothing overdue against a 15-day critical SLA.

A standing vulnerability remediation programme across every SharePoint estate under support, covering a US commercial bank and a regulatory platform run for several US energy utilities, where the scanners, the tickets and the clock all belong to the client.

Client
A US commercial bank and multiple US energy utilities
Sector
Across sectors
Engagement
Standing vulnerability remediation programme across every SharePoint estate under support
Period
July 2025 – ongoing
Ongoing programme

This is a standing programme, not a finished project. 137 findings are open as of the last reporting point and are named on this page. The 4,500 figure is the total across every in-scope estate, delivered with the platform vendor’s own team, not a Clouds Connected solo number. Both are stated deliberately: a remediation programme that claims to be finished is not describing remediation.

In brief

SharePoint vulnerability remediation: what this engagement covered

The challenge

The programme covers every SharePoint estate under support: a US commercial bank’s platform, and a regulatory case-management system run for several US energy utilities. The worked examples come from the utility side; the totals span both.

Those estates share an awkward property. The software is the supplier’s, but the servers, the scanners, the tickets and the clock belong to the client. Each utility scans on its own schedule with Tenable WAS against the public URLs, and applies its own windows: critical within 15 days, high within 30, medium within 45.

A structural complication sits underneath. The supplier often cannot verify its own work: the platform runs at the client and it holds no login to the scanned URL. A fix is applied blind and confirmed only when the utility re-scans, so the deliverable is the fix plus evidence the client can act on.

Then in February 2026 one utility made remediation part of its cybersecurity scorecard. Overrunning stopped being a debt item carried between status calls, and became a number reported inside the utility about the supplier.

The solution

The backlog was cleared months before it became a metric. Between July and September 2025 a sweep closed 3,152 findings, roughly 70% of the year’s total in one quarter. That sequencing is the whole study: when the scorecard change landed, the programme was working from a clean position rather than digging out under a deadline.

Findings were fixed by class, not one at a time. Sixteen separate findings across one estate closed when HTTP Strict Transport Security was enabled on the web application, a single PowerShell change. A stray archive in the IIS bin folder was deleted and the deployment procedure rewritten so no backup is created there again. Remediations were folded into the build guide, the part that compounds.

A scanner’s recommendation is a recommendation, not an instruction. One finding called for changing IIS anonymous authentication, which would have closed a ticket and broken SharePoint authentication, since that layer needs anonymous access to work at all. Refusing it and carrying a documented exception is slower, and the only defensible answer.

Scope was stated rather than improvised. When a second utility raised .NET Core findings, the SharePoint side said plainly that the application layer was not theirs to answer for, routing it to the owners within a day.

The results

4,500 vulnerabilitiesclosed since July 2025, across every in-scope estate
Zero overduein every SLA bucket at last reporting
3,152 closedby end of September 2025, roughly 70% of the year’s total
137 openand named: RDS idle sessions, IIS 10 and Symantec Endpoint
DimensionBeforeAfter
Backlog4,000+ active findings across the estates137 open, all long-tail patch dependencies
Overdue itemsWhy remediation became a scorecard metricZero, in every SLA bucket
Remediation unitOne finding at a timeBy class: sixteen closed by a single HSTS change
Where the fix livesIn the environment scannedIn the build guide, so new environments ship hardened

Remediation stopped being an event. Findings arrive continuously against a clock the utility owns, and what makes that survivable is a short queue before the scan lands, one fix closing a class of finding, and evidence arriving with the fix. A rolling 90-day window now shows 550 tracked, 413 remediated, 137 open.

The 137 belong in the record. They are the residue an honest programme carries: fixes that depend on a supplier’s patch, a version bump the client controls, or a maintenance window. Reporting them, with their causes, is what makes the zero next to overdue mean anything.

Technologies

Questions we get asked

SharePoint vulnerability remediation: common questions

How do you meet a client-imposed vulnerability remediation SLA?
By being ahead of it before it matters. The windows on this programme are the utility's, at critical within 15 days, high within 30 and medium within 45, and they are not negotiable. A backlog sweep closed 3,152 findings between July and September 2025, so when remediation became part of the utility's cybersecurity scorecard the following February, the programme was already working from a clean position rather than digging out under a deadline.
What do you do when a scanner's recommended fix would break the application?
Refuse it, document it, and carry it as an exception. One finding on this programme called for changing IIS anonymous authentication; applying it would have closed a ticket and broken SharePoint authentication, which needs anonymous access at that layer to work at all. A scanner produces a recommendation, not an instruction, and closing a ticket by taking a platform down is not remediation.
How do you close a vulnerability you cannot verify yourself?
Ship the evidence with the fix. Where the platform runs in the client's estate and the supplier holds no login to the scanned URL, fixes are applied and confirmed only when the client re-scans. This utility asked for screenshots of each fixed item, because that is what lets their security team close a ticket, so evidence is part of the deliverable rather than an afterthought. Where an item genuinely needs longer, give the client enough detail to request an extension rather than record a breach.
Can one change close multiple vulnerability findings?
Often, and it is the difference between a programme and a treadmill. Sixteen findings on one estate were closed by enabling HTTP Strict Transport Security on the web application through a single PowerShell change. The compounding move is what follows: folding that remediation into the platform build guide, so the next environment ships hardened instead of raising the same sixteen tickets on its first scan.
Related work

Other engagements like this one

Work with us

Two ways this usually starts

For consulting partners

SharePoint delivery under your paper

Nine of the ten engagements in this library were contracted through a systems integrator, an ISV or a managed provider, with Clouds Connected as the named SharePoint delivery lead. Your client relationship, your invoice, our platform depth — white-label delivery, escalation cover, or a fixed-scope block of hours.

Every study here is anonymised by default, which is also how we work inside your accounts.

For direct clients

Upgrades, migrations, recovery, patching

SharePoint Server and Microsoft 365 platform work on estates that cannot simply be rebuilt: version upgrades, tenant and content migrations, disaster recovery design and drills, performance root-cause diagnosis, and scheduled security patching on a standing cycle.

Regulated utilities, financial services, aerospace and healthcare. Based in the Greater Toronto Area, Canada; delivery across North America.

Provenance

Where these facts come from

Reconstructed from project correspondence, September 2021 to September 2026. Every figure on this page traces to a dated message, and the source citation for each sits in the accompanying fact sheet. Nothing has been estimated, rounded up, or written on the client’s behalf.

Clouds ConnectedUtilities · standing vulnerability remediation programme