1. Estimate investigation time
Enter the time needed to confirm scope, affected resources, and the unsafe configuration path.
2. Add containment time
Include temporary access restrictions, isolation, credential changes, or service controls used to stop further exposure.
3. Estimate correction work
Enter the time to create and review a safe configuration change, including infrastructure-as-code updates.
4. Add deployment and propagation
Include pipeline execution, cloud control-plane propagation, and waiting for approved change windows.
5. Estimate validation
Include security checks, functional testing, monitoring review, and confirmation that the exposure is closed.
6. Apply dependency overhead
Use a percentage for approvals, handoffs, vendors, and teams that cannot work continuously.