What a DSE assessment looks like — a sample excerpt.
A short, synthetic slice of the working documents a DSE cybersecurity risk assessment produces: a finding register and a matching roadmap slice, built with the same bounded-evidence method described on our assessment page.
Findings tied to evidence and an owner.
Each finding states what was observed, why it matters in business terms, the evidence it rests on, who owns the fix, and when it is due. The real deliverable carries more rows and an executive readout.
| Control area | Observation (business context) | Severity | Evidence source | Owner | Target date |
|---|---|---|---|---|---|
| Identity & access | Several privileged accounts lack multi-factor authentication and have no periodic access review, so a single stolen password could reach the most sensitive systems. | High | Admin-role export; access-review policy interview | IT Manager | 30 days |
| Backup & recovery | Backups run nightly but no restore has been tested in the past year, leaving recovery time unproven if ransomware hits. | High | Backup job screenshots; restore-test log (absent) | Infrastructure Lead | 45 days |
| Vulnerability management | No documented patch cadence for internet-facing services; two services are running unsupported versions. | High | Patch-policy interview; external service inventory | IT Manager | 60 days |
| Email security | Sender-authentication records are incomplete, weakening protection against spoofed invoices and payment-diversion fraud. | Moderate | DNS record export; mail-flow policy review | IT Manager | 60 days |
| Logging & monitoring | Security logs are collected but retained for only two weeks, below the stated evidence requirement for incident review. | Moderate | Log-retention configuration screenshot | Infrastructure Lead | 90 days |
| Third-party access | No inventory of vendors with system or data access, so offboarding and incident-notification expectations are unmanaged. | Moderate | Vendor-management interview; contract sample | Operations Lead | 90 days |
Findings sequenced into immediate, near, and next.
The roadmap groups the register by effort and dependency so leadership sees sequencing, not just a list of problems. Every action shown is a synthetic illustration of format — not a recommendation for your environment.
| Horizon | Move | Why now | Owner |
|---|---|---|---|
| Immediate (0–30 days) | Enforce MFA on all privileged accounts and set an access-review cadence. | Highest-likelihood, lowest-cost reduction in account-takeover risk. | IT Manager |
| Near (30–60 days) | Run a timed restore test and record the evidence; document a patch cadence. | Produces restore evidence and addresses this synthetic example's highest-severity finding. | Infrastructure Lead |
| Next (60–90 days) | Complete sender-authentication records, extend log retention, and inventory third-party access. | Reduces fraud exposure and makes incident review possible. | IT / Operations |
Want this built from your evidence?
A free 30-minute Cyber Risk Check scopes what a real assessment would cover for you — the evidence needed, the timebox, and whether a fixed-fee engagement is worth it.
What this is and is not. A synthetic, point-in-time sample of a deliverable. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice, and it makes no statement about any real organization's security. A real engagement rates gaps from your own evidence at a point in time and does not guarantee any security or examination outcome.
Primary sources, verified.