Sample security report

A real report shape, not a vague checklist.

This sample shows the structure a small business can expect: scope, executive summary, evidence, business impact, recommended fixes, owners, and a clean action plan.

Report outputPriority order before detail overload.

The owner sees what to fix first, why it matters, and who should act.

RiskHighMFA first
StructureScope, evidence, impact, fix path.

Readable enough to act on without a meeting marathon.

OpenForge sample report

Website & Email Security Health Check

Prepared for: Example small business
Prepared by: OpenForge
Report type: Sample, non-client demonstration

Overall posture Needs attention 1 High / 3 Medium / 1 Low
DateJuly 2026
ScopeWebsite, email, admin access, recovery
Testing typeAuthorized, non-destructive review
AudienceOwner, provider, technical support
Posture score 62 Needs attention
Reviewed surfaces
IdentityHigh focus
WebsiteMedium
EmailMedium
RecoveryNeeds owner
Owner queue
Business owner

Approve admin recovery model.

Email administrator

Enforce MFA and review forwarding.

Website provider

Apply header and backup improvements.

Executive summary

Functional systems, common gaps, clear priority order.

The sample business has a working website and email platform, but admin protection and recovery ownership need attention. The most important first action is to enforce administrator MFA and remove shared admin use. Website hardening and mailbox rule review should follow.

Scope reviewed
Website

HTTPS, security headers, public admin paths, visible platform exposure, backup ownership.

Email

Microsoft 365 or Google Workspace admin posture, MFA state, forwarding rules, recovery options.

Access

Administrator accounts, stale users, shared credentials, broad permissions.

Recovery

Domain, DNS, hosting, mailbox recovery, emergency owner path.

Risk register
HighAdministrator MFA is not enforcedFix first
MediumWebsite security headers are incompletePlan
MediumMailbox forwarding rules need reviewVerify
MediumRecovery ownership is unclearAssign
LowPublic admin paths should be reducedHarden
Detailed findings
Finding 01Administrator MFA is not enforcedHigh

Administrative access appears to depend on password-only sign-in or inconsistent MFA coverage. A compromised admin account could lead to mailbox access, DNS changes, billing disruption, and data exposure.

Evidence

Admin MFA status is incomplete or not centrally enforced.

Business impact

Account takeover could affect email, website, domain, and recovery channels.

Recommended fix

Enforce MFA for all admins, remove shared admin use, create a documented break-glass account, and review sign-ins.

Owner

Business owner + email administrator

Finding 02Website hardening is incompleteMedium

The website is functional, but baseline hardening is inconsistent. Missing or weak headers increase exposure to browser-side attacks and make the deployment look less mature.

Evidence

Security header baseline requires confirmation and tuning.

Business impact

Weak browser protections may increase risk for customers and staff using the site.

Recommended fix

Confirm HTTPS, add core headers, restrict admin paths where possible, and define update ownership.

Owner

Website provider

Finding 03Mailbox forwarding rules require reviewMedium

Mailbox forwarding and inbox rules should be reviewed for unauthorized forwarding, hidden persistence, or accidental data leakage.

Evidence

Forwarding and mailbox-rule review has not been documented.

Business impact

Sensitive email may leave the business without obvious signs.

Recommended fix

Audit forwarding rules, disable unauthorized external forwarding, and monitor future rule creation.

Owner

Email administrator

Finding 04Recovery ownership is unclearMedium

The business needs a clear recovery path for email, website, domain, DNS, and hosting access before an outage or account lockout happens.

Evidence

Recovery contacts and platform ownership are not written in one place.

Business impact

Recovery delays can turn a small account issue into a business interruption.

Recommended fix

Create a recovery sheet with account owners, providers, emergency contacts, and backup locations.

Owner

Business owner

Action plan
First 48 hoursProtect admin access

Enforce MFA, review admins, remove shared accounts, document break-glass recovery.

Next 7 daysReview mail and website controls

Audit forwarding rules, confirm HTTPS, add security headers, identify website update owner.

Next 30 daysMake recovery boring

Document provider access, domain ownership, backup location, and incident contacts.