Skip to content

The deliverable

See exactly what you get

The report is the product. This is an interactive, sanitised sample: switch between the executive and technical views to see how findings are scored, evidenced and prioritised. It uses fictional data only.

Sample report: illustrative

PBX Security Assessment · Sample Organisation Ltd (demonstration)

Authorised window: 2 days · Scope hash sha256:3f1c…a9e2 (illustrative)

Overall risk score

62/100

Findings by severity

3 High3 Medium1 Low

Illustrative fraud exposure

£4,000–£9,000 (illustrative scenario, not a forecast or observed loss)

Change since previous run2 new1 resolved4 unchangedContinuous Assurance tracks findings run to run.

Executive summary

The assessment identified a small number of high-impact weaknesses on an externally reachable PBX estate. The dominant risk is toll fraud: a permissive dial plan combined with an exposed management console and a platform running a vulnerable version would let an attacker place fraudulent calls the business is liable for. Priorities are to restrict the management and provisioning surfaces, patch the platform, and apply least privilege to outbound calling. A retest is recommended once the high-severity items are addressed.

Top priorities

  • HighPBX management console reachable from the public internet
  • HighPermissive dial plan allows international and premium-rate routing
  • HighPlatform running a version with published vulnerabilities

This is a fictional sample using reserved example addresses. It contains no real customer data. Figures are illustrative and are not a forecast or observed loss.

Two audiences, one report

Written for the board and for the engineers

A decision-maker can grasp the risk and a technical team can act on it, from the same document. Machine-readable formats let findings flow into your own tooling.

  • Executive summary, overall risk score and severity breakdown
  • Authorised scope, gated and stamped with a scope hash in the header
  • Per-finding severity (CVSS where applicable), evidence and remediation
  • Retest status: open, remediated, or retest required
  • Run-to-run change tracking: new, resolved and unchanged findings
  • Exports in HTML, JSON, CSV and SARIF for your pipelines

Get a report like this for your estate

Request an authorised assessment. We confirm scope and authorisation first, then deliver a report you can act on.

Testing is only performed against systems you own or are explicitly authorised to test.