When engineers do not want to re-engineer
When delivering your findings, there will always be a pre-delivery meeting. This meeting exists in order to confirm your findings with the product teams and the management. During these reviews, the engineering teams being on the defensive and/or claiming that something can't be fixed (often for budget reasons or because an early go-to-market is desirable) is a common trope.
Always keep minutes of these meetings and have them validated by the client.
For this meeting to have real value for both the testing team and the client, a few select actors have to be present.
From the client's side:
- The security owner of the device from the client's side (most probably the party that requested the assessment)
- A representative of the client's business side (the risk owner on the client's side)
- A representative of the client's compliance or legal side (that is, the party at the client that is in charge...