Skip to content

The deliverable

See exactly what you get

The report is the product. This is an interactive, sanitised sample: switch between the executive and technical views to see how findings are scored, evidenced and prioritised. It uses fictional data only.

A GoldAgent report is the product of an authorised assessment. This page shows a sanitised, fictional sample with an executive view, technical findings, severity, evidence, remediation and retest status. Figures in pounds sterling are illustrative scenarios, not forecasts or observed losses. No real customer data appears.

Shape of a GoldAgent assessment reportAn illustrative layout of a GoldAgent report: a header with a scope hash, an overall risk score out of 100, a severity breakdown, an illustrative fraud figure clearly labelled as a scenario, and three sample findings with severity and retest status. Fictional data only.SAMPLE REPORT · ILLUSTRATIVEPBX Security Assessmentscope hash 3f1c…a9e2RISK SCORE62/100SEVERITY3H2M1LILLUSTRATIVE SCENARIO£4,000–£9,000Not a forecast or observed lossHighManagement console reachable externallyRetestHighPermissive international dial planOpenMedProvisioning service unrestrictedOpenFictional sample. Evidence, remediation and retest live in the full report.
What the report looks like. A header with the authorised scope, a risk score out of 100, findings by severity, and an illustrative fraud figure in pounds sterling, labelled as a scenario rather than a forecast. The interactive sample below uses the same fictional data.

Sample report: illustrative

PBX Security Assessment · Sample Organisation Ltd (demonstration)

Authorised window: 2 days · Scope hash sha256:3f1c…a9e2 (illustrative)

Overall risk score

62/100

Findings by severity

3 High3 Medium1 Low

Illustrative fraud exposure

£4,000–£9,000 (illustrative scenario, not a forecast or observed loss)

Change since previous run2 new1 resolved4 unchangedContinuous Assurance tracks findings run to run.

Executive summary

The assessment identified a small number of high-impact weaknesses on an externally reachable PBX estate. The dominant risk is toll fraud: a permissive dial plan combined with an exposed management console and a platform running a vulnerable version would let an attacker place fraudulent calls the business is liable for. Priorities are to restrict the management and provisioning surfaces, patch the platform, and apply least privilege to outbound calling. A retest is recommended once the high-severity items are addressed.

Top priorities

  • HighPBX management console reachable from the public internet
  • HighPermissive dial plan allows international and premium-rate routing
  • HighPlatform running a version with published vulnerabilities

This is a fictional sample using reserved example addresses. It contains no real customer data. Figures are illustrative and are not a forecast or observed loss.

Two audiences, one report

Written for the board and for the engineers

A decision-maker can grasp the risk and a technical team can act on it, from the same document. Machine-readable formats let findings flow into your own tooling.

Currency is pounds sterling (GBP). Any toll-fraud figure is an illustrative scenario, clearly labelled, not a forecast.

  • Executive summary, overall risk score and severity breakdown
  • Authorised scope, gated and stamped with a scope hash in the header
  • Per-finding severity (CVSS where applicable), evidence and remediation
  • Retest status: open, remediated, or retest required
  • Run-to-run change tracking: new, resolved and unchanged findings
  • Exports in HTML, JSON, CSV and SARIF for your pipelines

How the work runs

The assessment sequence behind the report

The GoldAgent assessment lifecycleEight stages in order: scope, authorise, discover, analyse, validate, prioritise, report, then retest. Every engagement follows the same sequence.1Scope2Authorise3Discover4Analyse5Validate6Prioritise7Report8Retest
One repeatable sequence, every engagement. The depth varies with the estate; the order does not: Define scope → Confirm authorisation → Discover exposure → Analyse posture → Validate findings → Prioritise risk → Deliver the report → Retest.

Get a report like this for your estate

Request an authorised assessment. We confirm scope and authorisation first, then deliver a report you can act on.

Testing is only performed against systems you own or are explicitly authorised to test.