Sample Deliverable

See exactly what you'd receive.

Below is a complete sample security assessment — the same report format we deliver to real clients — prepared for a fictional small village so you can judge our methodology, clarity, and thoroughness before you ever pick up the phone.

Why we publish a sample instead of a client's real report

Real assessment findings are confidential — publishing a client's live vulnerabilities would put them at risk, and we'd never do that. So we built a realistic assessment of "the Village of Cedar Hollow," a village that doesn't exist. Every finding, system, and piece of evidence is invented to demonstrate our work without exposing anyone. It's the honest way to show you the goods.

The engagement

Village of Cedar Hollow — at a glance

Client
Village of Cedar Hollow, IL (fictional)
Population
~8,500 residents
Engagement
Vulnerability Assessment + Gap Analysis
Frameworks
NIST CSF 2.0 · CIS Controls v8.1 (IG1)
What we found

Nine findings, prioritized by risk

A realistic spread for a village this size — one urgent item, a couple of high-priority fixes, and a set of achievable improvements. None of them requires a big budget.

1Critical
2High
3Medium
2Low
1Info
CriticalF-01Outdated website CMS with known vulnerabilities

The public website ran software several major versions out of date, with plugins that have publicly documented exploits — one of the most common ways small-government sites get compromised.

CIS Control 7 · Vulnerability ManagementCSF: Protect / Identify
HighF-02No multi-factor authentication on admin & email

Administrative and email accounts were protected by password alone. A single stolen password would grant full access — MFA blocks the vast majority of these attacks.

CIS Control 6 · Access ControlCSF: Protect
HighF-03Email domain can be spoofed (weak DMARC)

With no enforced DMARC policy, attackers could send email appearing to come from the Village — enabling fraud against residents and staff.

CIS Control 9 · Email ProtectionsCSF: Protect
MediumF-04Weak TLS configuration

Legacy TLS protocols and weak ciphers were permitted, with no HSTS — increasingly flagged by auditors and cyber-insurers.

CIS Control 4 · Secure ConfigurationCSF: Protect
MediumF-05No documented incident response plan

No written procedure for who to call or what to do during an incident. The first hours matter most, and improvisation costs time and money.

CIS Control 17 · Incident ResponseCSF: Respond
MediumF-06Backups are not regularly tested

Backups existed but restores were never tested, and isolation was unclear — a serious gap given how aggressively ransomware targets backups.

CIS Control 11 · Data RecoveryCSF: Recover
LowF-07Verbose server headers disclose versions

Server responses revealed specific software versions, making it easier for attackers to match known exploits. Low risk, trivial to fix.

CIS Control 4 · Secure ConfigurationCSF: Protect
LowF-08No security awareness training

Staff hadn't had training in over a year. Most incidents start with a person, and brief regular training measurably reduces successful phishing.

CIS Control 14 · Security AwarenessCSF: Protect
InfoF-09Missing HTTP security headers

Recommended hardening headers weren't set. Not directly exploitable, but a quick defense-in-depth win.

CIS Control 4 / 16CSF: Protect
The big picture

Compliance gap: where the Village stands

We roll every finding up to the six NIST CSF 2.0 functions so leadership can see posture at a glance — no jargon required.

Govern
Developing
Identify
Developing
Protect
Developing
Detect
Early
Respond
Early
Recover
Developing
Cedar Hollow currently meets an estimated 48% of CIS Controls v8.1 essential cyber hygiene (IG1). Its weakest areas are Detect and Respond — the Village would struggle to notice and react to an incident today.
The path forward

A 90-day remediation roadmap

Every report ends with a phased, prioritized plan — highest-impact and lowest-effort fixes first, so progress starts on day one.

First 30 days
  • Enable MFA on admin, email & remote access F-02
  • Deploy DKIM; enforce DMARC F-03
  • Disable legacy TLS; enable HSTS F-04
  • Suppress version headers F-07
30–60 days
  • Update CMS core & plugins F-01
  • Test backup restores; isolate a copy F-06
  • Add HTTP security headers F-09
60–90 days
  • Adopt an incident response plan F-05
  • Launch awareness training F-08
  • Establish a standing patch cadence
Projected outcome: completing all three phases moves the Village from ~48% to roughly 85% of essential cyber hygiene — and we recommend a validation re-test to confirm the fixes and document the improvement.

Read the full report

The complete 9-page PDF includes detailed evidence, recommendations, and effort estimates for every finding — exactly as a real client would receive it.

Download the sample PDF

Get started

Want a report like this for your agency?

The first assessment is free — no cost, no obligation, and results in plain language your team and board can act on.

Request a Free Assessment