§ Cybersecurity proof & diagnostic assets·synthetic · print-friendly

What a DSE assessment looks like — a sample excerpt.

A short, synthetic slice of the working documents a DSE cybersecurity risk assessment produces: a finding register and a matching roadmap slice, built with the same bounded-evidence method described on our assessment page.

About this asset

Audience
Buyers deciding whether a fixed-fee cybersecurity risk assessment fits, who want to see the deliverable before the call.
Owner service
Cybersecurity Risk Assessment & Roadmap
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The register and roadmap match the bounded-evidence method described on our Cybersecurity Risk Assessment & Roadmap page: a bounded evidence request, a business-context severity rating, and a sequenced roadmap with named owners. Structure follows NIST Cybersecurity Framework 2.0 (NIST CSWP 29) and the CISA Cross-Sector CPGs.
Limitations
Point-in-time, illustrative sample. It is not a DSE assessment, an audit, an attestation, legal advice, or a statement about any real organization. Severity here is a business-context rating, not a vulnerability score.
Verification
The framework structure was checked against the csrc.nist.gov and cisa.gov landing pages linked below. The contents are invented for illustration and cite no real evidence.
Finding register (excerpt)

Findings tied to evidence and an owner.

Each finding states what was observed, why it matters in business terms, the evidence it rests on, who owns the fix, and when it is due. The real deliverable carries more rows and an executive readout.

Synthetic finding register excerpt — not client data
Control area Observation (business context) Severity Evidence source Owner Target date
Identity & access Several privileged accounts lack multi-factor authentication and have no periodic access review, so a single stolen password could reach the most sensitive systems. High Admin-role export; access-review policy interview IT Manager 30 days
Backup & recovery Backups run nightly but no restore has been tested in the past year, leaving recovery time unproven if ransomware hits. High Backup job screenshots; restore-test log (absent) Infrastructure Lead 45 days
Vulnerability management No documented patch cadence for internet-facing services; two services are running unsupported versions. High Patch-policy interview; external service inventory IT Manager 60 days
Email security Sender-authentication records are incomplete, weakening protection against spoofed invoices and payment-diversion fraud. Moderate DNS record export; mail-flow policy review IT Manager 60 days
Logging & monitoring Security logs are collected but retained for only two weeks, below the stated evidence requirement for incident review. Moderate Log-retention configuration screenshot Infrastructure Lead 90 days
Third-party access No inventory of vendors with system or data access, so offboarding and incident-notification expectations are unmanaged. Moderate Vendor-management interview; contract sample Operations Lead 90 days
Roadmap slice

Findings sequenced into immediate, near, and next.

The roadmap groups the register by effort and dependency so leadership sees sequencing, not just a list of problems. Every action shown is a synthetic illustration of format — not a recommendation for your environment.

Synthetic roadmap slice — not client data
Horizon Move Why now Owner
Immediate (0–30 days)Enforce MFA on all privileged accounts and set an access-review cadence.Highest-likelihood, lowest-cost reduction in account-takeover risk.IT Manager
Near (30–60 days)Run a timed restore test and record the evidence; document a patch cadence.Produces restore evidence and addresses this synthetic example's highest-severity finding.Infrastructure Lead
Next (60–90 days)Complete sender-authentication records, extend log retention, and inventory third-party access.Reduces fraud exposure and makes incident review possible.IT / Operations

Want this built from your evidence?

A free 30-minute Cyber Risk Check scopes what a real assessment would cover for you — the evidence needed, the timebox, and whether a fixed-fee engagement is worth it.

What this is and is not. A synthetic, point-in-time sample of a deliverable. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it makes no statement about any real organization's security. A real engagement rates gaps from your own evidence at a point in time and does not guarantee any security or examination outcome.

Primary sources, verified.