Skip to content

Writing

Nobody buys a list of vulnerabilities

The security industry sells detection because detection is what it can measure. The thing customers are actually asked for is proof that something was fixed — and almost nothing produces it.

Every security product in this category sells the same thing: it finds more, faster, with fewer false positives. The demos are all a list. The pricing is all per-thing-scanned. And the number that goes in the board pack is all findings produced.

Now go and read a customer security questionnaire. It does not ask how many vulnerabilities you found. It asks whether you remediate them, how quickly, and how you know. It asks for evidence.

The gap between finding and fixing is where the value is

A finding is a claim about the past: at some point, this code had this problem. It has no expiry and no resolution. Six months later it is in a spreadsheet with a status column somebody filled in from memory.

A fix is an event: a change went in. But "we fixed it" is an assertion, and an assertion from the party with an interest in it being true. Your customer has no reason to accept it and you have nothing to offer them except your word.

What closes that is a chain: this finding existed, this change addressed it, this test failed before the change and passed after, and this re-scan no longer finds it. Four facts, each verifiable, linked. That is a different kind of object from a finding, and it is the one people are actually asking for.

Why a signature matters more than it sounds like it should

A PDF from a vendor is worth what the vendor is worth. If the evidence is only as good as our continued existence and goodwill, then we have not solved the trust problem, we have inserted ourselves into it.

So the record is signed with a key whose public half is published, and the verifier is public and takes nothing from us. If this company is acquired, pivots, or closes, every proof we ever issued still checks. That is the difference between evidence and a marketing artefact, and it is an uncomfortable thing for a vendor to build because it removes our leverage on purpose.

The honest limits

A proof says one finding was fixed and re-checked on one date. It does not say your product is secure, it is not a certification, and our documents say that on their face.

It is also not free of judgement: somebody decided the test was the right test. What it removes is not judgement but the need to take our word for the mechanical parts — that the change went in, that the test behaved as described, that the re-scan happened, and that the record has not been edited since.

That is a smaller claim than the industry usually makes. It is also one we can keep.