Remediation roadmap
Sample assessment · generic findings · no client data
Two things SCOUTz refuses to do, and both refusals confuse people at first. It doesn't remediate the problems it finds. And it doesn't show you everything it could find. I want to explain why those two restraints are connected, because together they're the answer to the question every skeptical buyer should be asking about any assessment tool: why should I believe your findings?
Start with the first refusal. SCOUTz diagnoses. The fixing belongs to the MSP, priced and scoped by the MSP, delivered under the MSP's brand. We could have bundled remediation into the platform, plenty of vendors do, and there's obvious revenue in it. But think about what happens to the diagnosis the moment the diagnostician profits from the cure. A lab that also sold surgery would find a remarkable number of tumors. Every finding in a fix-it-yourself tool carries a quiet asterisk: this problem is also a line item for the company that reported it. The client can't tell where the truth ends and the upsell begins, and honestly, over time, neither can the vendor.
Separating the two keeps the scan honest in a way no policy could. The platform has no financial reason to inflate a finding, exaggerate a severity, or discover problems that conveniently match a service catalog. The findings are sized to reality because reality is the only thing they're attached to. The MSP, who does profit from remediation, gets to stand behind numbers produced by something with no stake in the answer. That separation is worth more to a partner's credibility than any feature we could have built in its place.
Now the second refusal, and let me make it concrete, because the abstract version doesn't land.
There are tools in this market that will run a prospect's domain against breach corpuses and produce a slide for the sales meeting: Becky from accounting, her name, sometimes her photo pulled from a profile somewhere, next to a password she used on a Hot Topic account that got breached in 2014. The room goes quiet. The owner is horrified. The deal closes. The vendors who build this feature call it powerful. They're right. It's powerful the way a lot of wrong things are powerful.
Look at what actually happened in that meeting. Becky was humiliated in front of her boss over her personal shopping account from a decade ago, an account that has nothing to do with the company, its tenant, or its security posture. The finding taught the owner nothing actionable, because Becky's old mall password is not a control anyone can remediate. Its entire function was shock. And the MSP presenting the slide is now standing in the worst spot in the room: they've collected, processed, and displayed a private individual's personal breach data to third parties, for commercial gain, in an era when privacy law takes exactly that kind of thing seriously. Do Becky's rights under those laws care that the meeting went well? They do not. The disservice runs three directions at once: to her, to the client whose culture just absorbed a surveillance moment, and to the MSP who may have bought a legal problem to win a deal.
The point is simple. We drew that line not because we can't find it. Breach corpuses are queryable by anyone; building the Becky slide is a weekend of engineering. We drew it because it's not right, and because the ability to do something has never once been an argument for doing it.
That's what connects the two refusals. In both cases we're giving up something real, remediation revenue in one, a proven closing tactic in the other, to protect something more valuable: the ability of a client to trust the report without an asterisk. Restraint is the only vendor signal that can't be faked, because it always costs money, and you can always check whether it was paid. Any tool can show you what it found. Ask what it declined to find, and what it declined to sell you afterward. The one with real answers to both is the one you can trust. # Cluster 5: The Operator Playbook