Free tool · Exposure checks

In what order should you fix your Bitsight findings?

Tick what is true of your estate. Get the order to fix it in: attribution, compromise, certificates, ports, email authentication, then vulnerabilities.

Order your fixes

In short
Fix a Bitsight rating in this order: first confirm that the assets rated as yours are yours, then clear active compromise, then the certificate and header layer, then unnecessary open ports, then email authentication, and keep critical vulnerability management running throughout. The order follows how the rating is weighted and how fast each fix registers. It ranks the work and does not forecast points.

Order your fixes

Most teams work a findings list from the top, which is the wrong order: findings are not equally weighted, some are not yours, and a few resolve themselves. Tick what is true of your estate below. The sequence is fixed — that is the point — so ticking only decides which steps drop out.

It opens with every step ticked, so the whole sequence is on the page. Untick what does not apply, or start from the email spoofing check and the SSL estate check, which read two of these from outside in seconds.

Tick what is true of your estate
6steps, in this order.
  1. Step 1 · Before anything else

    Verify the assets are yours

    A rating is calculated against the footprint attributed to you, and attribution is inferred. Findings on a divested subsidiary, a reissued IP range or a shared host sit against your name, and fixing them moves nothing.

    Do: Review the asset list for divested entities, reassigned ranges, shared hosting and acquisitions not yet added, and raise the corrections with Bitsight.

    The rating: Fastest to register: the finding is removed rather than aged out.

  2. Step 2 · Days

    Clear active compromise

    Each one records an incident rather than a weakness, so it hits hardest per event. Compromised Systems carries 26% of the rating.

    Do: Identify the machines, isolate them, clean them, and confirm the traffic has stopped. Look first at forgotten test servers, unpatched appliances and devices on a segment nobody owns.

    The rating: Registers within days to a few weeks once the observed traffic stops.

  3. Step 3 · Days to weeks

    Fix the certificate and header layer

    Visible, unambiguous and usually fixable without touching application logic. Among the most reliably quick wins in the diligence category, which carries 71.5% of the rating.

    Do: Set a TLS 1.2 minimum, reissue expired or weak certificates, and add HSTS and Content-Security-Policy headers.

    The rating: Typically visible within one to two weeks of the next observation. Bitsight lets you request a rescan once it is fixed.

  4. Step 4 · Weeks

    Close unnecessary exposure

    Each open port that serves no current purpose is both a rating drag and a genuine risk, which makes this the least arguable work in the sequence.

    Do: Close legacy management interfaces, databases exposed to the internet and forgotten remote access.

    The rating: Typically visible within one to two weeks of the next observation. Bitsight lets you request a rescan once it is fixed.

  5. Step 5 · Days

    Complete email authentication

    Cheap and fast, and it improves your real resistance to domain spoofing as well as the rating. The common finding is a DMARC record parked at p=none, which tells receiving servers to do nothing.

    Do: Publish SPF and DKIM first, because they break nothing, and move DMARC to enforcement last, once the reports are clean.

    The rating: Typically visible within one to two weeks of the next observation.

  6. Step 6 · Ongoing

    Establish critical vulnerability management

    It decides whether the improvement holds. The vector weights severity, so closing a Material or Severe finding moves the grade more than clearing a backlog of minor ones.

    Do: Triage by severity rather than by count, and make closing the serious findings first a standing practice.

    The rating: Closing a Material or Severe finding registers within weeks; the weighted average takes a quarter or more to reflect a sustained change.

Why this order

Three things set the position of each step: whether the finding records an incident or a weakness, how reliably the fix is quick, and whether it decides that the improvement holds.

  • Attribution first, because everything after it assumes the findings are yours.
  • Compromise before configuration. A compromised system records an incident, so one event hits hard; Bitsight publishes Compromised Systems at 26% of the rating.
  • Configuration next. Diligence, the externally visible configuration hygiene, is 71.5% of the rating. Individually minor findings, collectively the largest share, and among the quickest to clear.
  • Vulnerability management last, and always. It is the step that takes a quarter or more to show, and it is what stops every gain above from eroding.

The full reasoning, with what a realistic quarter looks like, is in how to improve your Bitsight security rating.

Which fixes can be rescanned on request

Ratings are recalculated daily but deliberately carry history, so a fix is not credited instantly. For five risk vectors Bitsight lets you request a rescan once a fix is in, so the repair can earn credit at the next daily update rather than waiting for the ordinary observation: TLS/SSL configurations, TLS/SSL certificates, open ports, server software and web application security. Steps marked above are the ones this applies to. Critical Vulnerability Management states that it is not eligible, so that work moves at observation pace.

What the order does not tell you

One caution applies to the whole list. Every step here is a genuine security improvement, which is why the sequence works. If you find yourself considering a change that raises the number without reducing risk, such as narrowing the monitored footprint, you have stopped managing risk and started managing a metric.

Category weights from Bitsight’s How are Bitsight Security Ratings Calculated?. Rescan eligibility from Bitsight’s knowledge base pages for each risk vector. The order and timescales follow BitScore’s remediation guide and are experience, not Bitsight statements. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

What should we fix first on a Bitsight rating?
Check the asset list before fixing anything. A rating is calculated against the footprint attributed to the organisation, and attribution is inferred, so findings on a divested subsidiary, a reissued IP range or a shared host sit against your name and fixing them moves nothing. After that, clear active compromise, because botnet, malware-server and spam findings record an incident rather than a weakness and hit hardest per event.
How many points will each fix add?
No honest figure exists, and this tool does not offer one. Bitsight weights risk vectors, asset importance, severity and observation age in ways that are not public and not linear, and findings age out on their own schedule. What can be said is direction: compromise hits hardest per event, configuration fixes are the most reliably quick, and vulnerability management decides whether the gains hold.
Which Bitsight fixes can be rescanned on request?
Bitsight lets a fix be rescanned on request for TLS/SSL configurations, TLS/SSL certificates, open ports, server software and web application security, so the repair can earn rating credit at the next daily update. Critical Vulnerability Management states that it is not eligible, and work outside those five vectors registers at the ordinary observation pace.
Why do email authentication fixes come after open ports?
Because the order follows what each fix does for the rating and the risk, not how long it takes. Publishing SPF, DKIM and DMARC is quick and cheap, and worth doing, but an exposed management interface or an active compromise is a larger and more urgent exposure. Where the team is separate, nothing stops the email work running in parallel.

See which of these you can check from outside

  • Free tool · Exposure checksCan anyone send email as your domain?Enter a domain. See what its DNS says about who may send mail as it — and what a receiving server does about mail that fails.
  • Free tool · Exposure checksWhich of your subdomains are failing their SSL checks?Enter a domain. See which of its subdomains serve a certificate or a TLS configuration that a rating would mark down — and which ones nobody has looked at in years.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of remediation-roadmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source →The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating →All free tools