Executive decision view
Business exposure, attack narrative, priorities, accountable owners, and the decisions required now.
REPORT—STD
Not a vulnerability list, but a decision record connecting boundaries, attack narrative, evidence, priority, remediation, and verification.
Five layers connect leadership, engineering, and assurance in a shared, traceable record.
Business exposure, attack narrative, priorities, accountable owners, and the decisions required now.
Exact assets, roles, dates, access, exclusions, blocked work, assumptions, and point-in-time limitations.
Named method and version, stable test and control identifiers, applicability, execution state, result, evidence, and limitation.
Affected asset, sanitized evidence, reproduction steps, CVSS v4.0 vector, separate business priority, root cause, and validation criteria.
Tactical fix, strategic control improvement, accountable owner, due date, retest evidence, and residual risk.
Every finding includes the affected asset, prerequisites, reproduction steps, sanitized evidence, impact, CVSS score and vector, separate business priority, root cause, remediation, and validation criteria.
The CVSS v4.0 score and vector do not replace business-risk assessment.
A reasoned treatment decision based on exposure, asset, evidence, and impact.
The report distinguishes automated discovery, manual validation, and professional inference.
The closure record compares original and current status, shows verification evidence and residual risk, and states exactly what was not retested.
NEXT DECISION
The PDF is fully fictional, uses .invalid domains, and contains no client data. It demonstrates decision framing, coverage, evidence, findings, and closure.
Download sample report (PDF)