Included in Guardian Core

Turn every material finding into an owned, dated and auditable piece of work.

Guardian connects findings from supported sources to governed risks and one All Actions queue so owners, due dates, remediation, evidence and closure review remain visible.

Australian data residency

Guardian for Australian customers is built, operated and hosted in Australia. All Guardian customer and platform data, including backups and recovery copies, is maintained and stored within Australia.

Guardian CoreRisk RegisterAll ActionsImmutable history and evidence
Why it matters

Security issues remain open when responsibility is unclear or closure is accepted without evidence.

A scanner, analyst, penetration tester or training system can identify the problem, but another team usually owns the change required to reduce the risk.

Guardian keeps the source context with the risk and required action so the organisation can see who owns the work, when it is due, what outcome is expected and what evidence supports closure.

01

Separate risk from raw findings

Record the business concern, affected scope, treatment decision and current risk state.

02

Put every required change in one queue

Bring finding, risk and remediation actions together with source, severity, owner, due date and status.

03

Review closure instead of assuming it

Retain evidence and history so a completed task can be checked against the required security outcome.

What you receive

The controls needed to keep remediation accountable.

Risk and action records remain linked to their source context while using consistent ownership and workflow.

RR

Risk Register

Record material risk, status, treatment, owner, review dates and supporting context.

AA

All Actions

One prioritised work queue across supported findings, risks and remediation sources.

OW

Owners and due dates

Make responsibility, timing and overdue work visible to the people completing and reviewing it.

WS

Workflow state

Track open, in progress, waiting, review, completed and closed work using controlled lifecycle states.

EV

Evidence and history

Retain approved evidence, updates and immutable history supporting review and reporting.

SC

Source context

Keep the originating module, finding, investigation or engagement linked to the remediation work.

How the work moves

A consistent path from finding to reviewed closure.

The exact risk aggregation and closure policy is defined by the customer or provider operating model.

01

Receive

A supported Guardian source creates or contributes a finding or required action.

02

Assess

Decide whether the issue is a business risk, direct remediation action or informational record.

03

Assign

Set the owner, priority, due date, treatment and required outcome.

04

Work

Complete the technical, operational, policy or learning remediation.

05

Evidence

Attach or reference the evidence needed to support the claimed outcome.

06

Review and close

Confirm the outcome, retain history and close or return the work for further action.

How teams use it

A common remediation process across very different security sources.

A business can use the same queue for a critical vulnerability, a dark web exposure, a failed patch, an investigation follow-up, a website finding or overdue training.

Providers can review authorised customer work through customer-scoped views while the customer retains clear ownership and evidence of the required outcome.

Scope and boundaries

Risk aggregation and acceptance remain governed decisions.

Guardian does not automatically combine unrelated findings into one risk or make legal, compliance or certification determinations from the presence of a finding.

Risk acceptance, treatment, closure and review authority are defined by the customer policy and applicable service responsibilities.

Take the next practical step

Review where security findings currently lose ownership or evidence.

We will map the source workflows, risk policy, action states, roles and closure evidence required for a practical Guardian remediation process.