Slide Content and Speaker Notes Placeholders in [brackets] should be replaced with your own data. The notes are written to be spoken at a natural pace, about 1,300 words in total. Slide 1: From Findings to Fixes (1 min) On the slide Title: From Findings to Fixes: Closing the Vulnerability Gap Key numbers: [X] open findings | [X]% past SLA | [X] critical/high | [X] days average age Chart: open findings by age bucket (0-30, 31-90, 91-180, 180+ days) Tagline: Scanning finds issues. Value comes only when they are fixed. Speaker notes "Thank you all for being here. We run scans and assessments every [month/quarter], and they work: they find real issues. But finding an issue doesn't reduce risk. Fixing it does. Today we have [X] open findings, [X] percent are past their agreed deadline, and the average age is [X] days. Look at the 180-plus bar: these are issues that have been known to us for six months or longer. This isn't about blame. I want to spend ten minutes on why this is happening, what the expectations are, and how we close the gap together." Slide 2: Why Issues Stay Open (1 min) On the slide No clear owner for the finding or the system Competing priorities, with no capacity in the plan Fear of downtime or breaking applications Legacy systems or vendor dependencies Findings not reaching the right team Prompt: Which of these sounds like your world? Speaker notes "I've spoken to a number of teams, and these are the reasons I hear most. Sometimes nobody is sure who owns the finding. Sometimes the team is busy with project delivery and security fixes lose out. Sometimes there's a real fear that patching will break a critical application. And sometimes the system is old or the vendor is slow. These are real constraints, and I'm not dismissing them. But notice that most of them are solvable with planning, ownership and support. Quick show of hands: who recognizes at least one of these? Good, so we're not alone, and the rest of this session is about removing these blockers." Slide 3: What Policy Requires (1.5 min) On the slide Remediation timelines (per policy): Severity Fix within Critical [X] days High [X] days Medium [X] days Low [X] days System custodians: accountable for remediation IT/project teams: build remediation into delivery Security: report, prioritize, support Can't fix in time? Raise an exception: justification, compensating controls, approval, expiry date Open + no plan + no exception = policy breach Speaker notes "Our policy is clear on timelines: criticals within [X] days, highs within [X], and so on. Custodians are accountable for fixing issues on their systems. IT and project teams are responsible for making sure remediation isn't an afterthought in what we build. Security's role is to give you prioritized, accurate information and help you get unstuck. Now, the policy doesn't say 'fix everything instantly.' If you can't meet a deadline, there's a proper route: raise an exception with a justification, compensating con