External and internal testing, configuration review, access-control audit and a staff awareness session. Findings were ranked by real business impact rather than raw scanner severity, and delivered with a phased remediation plan sized for the client's own team.
Outcome. A prioritised roadmap closed the highest-risk findings first.