The deliverable
See exactly what you get
The report is the product. This is an interactive, sanitised sample: switch between the executive and technical views to see how findings are scored, evidenced and prioritised. It uses fictional data only.
Sample report: illustrative
PBX Security Assessment · Sample Organisation Ltd (demonstration)
Authorised window: 2 days · Scope hash sha256:3f1c…a9e2 (illustrative)
Overall risk score
62/100
Findings by severity
Illustrative fraud exposure
£4,000–£9,000 (illustrative scenario, not a forecast or observed loss)
Executive summary
The assessment identified a small number of high-impact weaknesses on an externally reachable PBX estate. The dominant risk is toll fraud: a permissive dial plan combined with an exposed management console and a platform running a vulnerable version would let an attacker place fraudulent calls the business is liable for. Priorities are to restrict the management and provisioning surfaces, patch the platform, and apply least privilege to outbound calling. A retest is recommended once the high-severity items are addressed.
Top priorities
- HighPBX management console reachable from the public internet
- HighPermissive dial plan allows international and premium-rate routing
- HighPlatform running a version with published vulnerabilities
This is a fictional sample using reserved example addresses. It contains no real customer data. Figures are illustrative and are not a forecast or observed loss.
Two audiences, one report
Written for the board and for the engineers
A decision-maker can grasp the risk and a technical team can act on it, from the same document. Machine-readable formats let findings flow into your own tooling.
- Executive summary, overall risk score and severity breakdown
- Authorised scope, gated and stamped with a scope hash in the header
- Per-finding severity (CVSS where applicable), evidence and remediation
- Retest status: open, remediated, or retest required
- Run-to-run change tracking: new, resolved and unchanged findings
- Exports in HTML, JSON, CSV and SARIF for your pipelines
Get a report like this for your estate
Request an authorised assessment. We confirm scope and authorisation first, then deliver a report you can act on.
Testing is only performed against systems you own or are explicitly authorised to test.