Below is a complete sample security assessment — the same report format we deliver to real clients — prepared for a fictional small village so you can judge our methodology, clarity, and thoroughness before you ever pick up the phone.
Real assessment findings are confidential — publishing a client's live vulnerabilities would put them at risk, and we'd never do that. So we built a realistic assessment of "the Village of Cedar Hollow," a village that doesn't exist. Every finding, system, and piece of evidence is invented to demonstrate our work without exposing anyone. It's the honest way to show you the goods.
A realistic spread for a village this size — one urgent item, a couple of high-priority fixes, and a set of achievable improvements. None of them requires a big budget.
The public website ran software several major versions out of date, with plugins that have publicly documented exploits — one of the most common ways small-government sites get compromised.
Administrative and email accounts were protected by password alone. A single stolen password would grant full access — MFA blocks the vast majority of these attacks.
With no enforced DMARC policy, attackers could send email appearing to come from the Village — enabling fraud against residents and staff.
Legacy TLS protocols and weak ciphers were permitted, with no HSTS — increasingly flagged by auditors and cyber-insurers.
No written procedure for who to call or what to do during an incident. The first hours matter most, and improvisation costs time and money.
Backups existed but restores were never tested, and isolation was unclear — a serious gap given how aggressively ransomware targets backups.
Server responses revealed specific software versions, making it easier for attackers to match known exploits. Low risk, trivial to fix.
Staff hadn't had training in over a year. Most incidents start with a person, and brief regular training measurably reduces successful phishing.
Recommended hardening headers weren't set. Not directly exploitable, but a quick defense-in-depth win.
We roll every finding up to the six NIST CSF 2.0 functions so leadership can see posture at a glance — no jargon required.
Every report ends with a phased, prioritized plan — highest-impact and lowest-effort fixes first, so progress starts on day one.
The complete 9-page PDF includes detailed evidence, recommendations, and effort estimates for every finding — exactly as a real client would receive it.
Get started
The first assessment is free — no cost, no obligation, and results in plain language your team and board can act on.
Request a Free Assessment