Best Practices
Reduce the rate at which the first two tiers refill
Tier 3 covers structural improvements with compounding returns. Nothing here is urgent in isolation, which is exactly why it never gets done without a tier of its own. Tier 3 is the only tier where deferral is a legitimate, recorded outcome — an organization that closes every Tier 3 item is probably under-investing elsewhere.
Does fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?
See the full decision procedure- Remediate within
- 90 days
- Escalation
- Reviewed at quarterly planning; may be formally deferred
- Owned by
- Platform and engineering teams
- Budgeted from
- Planned work — a standing percentage of engineering capacity
Where CVSS fits
Findings in this tier typically score 0.1 – 3.9 — but the score is an input, never the decision. A CVSS 9.8 with no reachability does not belong in Tier 1, and a CVSS 6.5 in the CISA KEV catalog on an internet-facing host does. How Beacon relates to CVSS, EPSS and KEV.
Tier 3 findings by domain
Tier sets the deadline; domain sets the owner. Each entry links to its full definition, detection guidance, and remediation steps.
BCN-T3-NET-00190 daysNon-Critical Service Exposure
Unnecessary services reachable on internal networks, expanding attack surface without immediate risk.
BCN-T3-NET-00290 daysCloud Network Hardening Gaps
Cloud network configuration diverging from CIS Benchmark or provider best practice.
BCN-T3-NET-00390 daysIncomplete Egress Filtering
Unrestricted outbound connectivity, permitting unconstrained command-and-control and exfiltration.
BCN-T3-IAM-00190 daysCoarse-Grained Role Design
Roles that are scoped but still broader than the tasks they support.
BCN-T3-IAM-00290 daysManual Credential Lifecycle
Credential provisioning, rotation, and revocation performed by hand rather than automatically.
BCN-T3-IAM-00390 daysFragmented Identity Federation
Applications with local accounts outside the central identity provider.
BCN-T3-DAT-00190 daysNo Data Loss Prevention Coverage
No technical control detecting or preventing sensitive data leaving approved channels.
BCN-T3-DAT-00290 daysUnverified Backup Restoration
Backups are taken but restoration has never been tested end to end.
BCN-T3-DAT-00390 daysDatabase Configuration Hardening
Database settings diverging from benchmark without creating direct exposure.
BCN-T3-PRC-00190 daysContainer and Image Hardening
Containers running as root, from oversized base images, or without runtime constraints.
BCN-T3-PRC-00290 daysCI/CD Pipeline Hardening
Build pipelines without dependency pinning, artifact signing, or runner isolation.
BCN-T3-PRC-00390 daysInfrastructure-as-Code Security Gaps
Infrastructure defined in code without security scanning, policy enforcement, or drift detection.