Regulatory
Maintain the license to operate
Tier 2 covers conditions that threaten certification, contract, or regulatory standing. The consequence is not a breach but a finding in someone else's report: a qualified SOC 2 opinion, a failed PCI DSS assessment, a GDPR Article 32 exposure. These are deadline-driven rather than threat-driven, and the deadline belongs to the auditor.
Would a named auditor, regulator, or contractual counterparty record this as a deficiency?
See the full decision procedure- Remediate within
- 30 days
- Escalation
- Security manager review at 14 days
- Owned by
- Compliance, with engineering executing the remediation
- Budgeted from
- Planned work — scheduled against the audit calendar
Where CVSS fits
Findings in this tier typically score 4.0 – 6.9, or any score where a control is mandated — but the score is an input, never the decision. A CVSS 9.8 with no reachability does not belong in Tier 1, and a CVSS 6.5 in the CISA KEV catalog on an internet-facing host does. How Beacon relates to CVSS, EPSS and KEV.
Tier 2 findings by domain
Tier sets the deadline; domain sets the owner. Each entry links to its full definition, detection guidance, and remediation steps.
BCN-T2-NET-00130 daysRegulated Environment Segmentation Gaps
Insufficient isolation around a cardholder, health, or otherwise regulated data environment.
BCN-T2-NET-00230 daysInsufficient Logging and Retention
Security-relevant events are not captured, not centralized, or not retained for the required period.
BCN-T2-NET-00330 daysMissing Intrusion Detection Coverage
No detection capability at network boundaries or across critical segments.
BCN-T2-IAM-00130 daysNon-Compliant Authentication Policy
Password and authentication settings that do not meet the applicable regulatory standard.
BCN-T2-IAM-00230 daysMissing Periodic Access Reviews
No recurring, evidenced certification that granted access remains appropriate.
BCN-T2-IAM-00330 daysUngoverned Service Accounts
Non-human identities without owners, documented purpose, or lifecycle management.
BCN-T2-DAT-00130 daysEncryption Below Regulatory Standard
Data is encrypted, but with algorithms, key lengths, or key management that fail the applicable requirement.
BCN-T2-DAT-00230 daysData Retention and Deletion Non-Compliance
Personal or regulated data kept beyond its lawful basis, or deletion requests not honored throughout.
BCN-T2-DAT-00330 daysAbsent Data Classification
No scheme identifying which data is sensitive, where it lives, and which controls apply.
BCN-T2-PRC-00130 daysVulnerability Management Process Gaps
No defined scanning cadence, remediation SLA, or exception process — or incomplete asset coverage.
BCN-T2-PRC-00230 daysChange Management Control Gaps
Production changes without review, approval, testing, or a recorded rollback path.
BCN-T2-PRC-00330 daysUntested Incident Response Capability
No incident response plan, or a plan that has never been exercised.