Skip to content
YSYarra Secure

Illustrative sample · not a client report

Quick Cyber Risk Reviewsample report

This fictional, redacted example shows how Yarra Secure presents evidence, priorities, limitations, and next steps. It does not describe a real organisation, engagement, or security incident.

Sample organisation
Example Allied Health (fictional)
Sample domain
allied-health.example
Review basis
Passive signals + questionnaire

Executive summary

Three practical priorities, with the limits stated up front

In this fictional example, the strongest positive signal is current website transport encryption. The main opportunities are consistent MFA, a separate call-back step for payment-detail changes, and a staged move toward stronger email-domain impersonation controls. These observations support prioritised follow-up; they do not prove that systems are secure or compromised.

3

prioritised actions

4

sample evidence items

0

systems accessed

Sample evidence register

Every conclusion points back to an observable signal or stated process

The entries below are invented examples. A real report records the relevant dates, evidence references, and any uncertainty.

Fictional sample evidence for a Quick Cyber Risk Review
RefSignalSample observationWhy it mattersSource
E-01Email-domain impersonation controlsIllustrative DNS evidence shows SPF present and a DMARC policy set to monitoring only.Monitoring can provide visibility, but it may not yet direct receiving mail systems to reject impersonated messages.Passive public DNS review
E-02Multi-factor authentication coverageThe fictional questionnaire records MFA on the owner account but not every staff mailbox.Uneven coverage leaves some accounts relying on a password as the main access control.Client questionnaire
E-03Payment-change verificationThe fictional process accepts supplier bank-detail changes after an email reply, without a call to a known number.A separate verification channel would make an intercepted or impersonated email less useful.Client questionnaire
E-04Website transport securityThe illustrative website presents a current TLS certificate and redirects HTTP traffic to HTTPS.This is a positive baseline signal, but it does not establish that the application or its accounts are secure.Passive website check

Prioritised action plan

Sequence controls by business value and implementation effort

Timing is illustrative and would be agreed against the real organisation’s systems, responsibilities, and change windows.

1

Apply MFA to every business mailbox and administrative account

Closes the clearest account-access gap described in the questionnaire.

Suggested owner

Business owner + IT provider

Indicative timing

First 7 days

2

Introduce a known-number call-back for bank-detail changes

Adds a separate verification channel before money moves.

Suggested owner

Office manager

Indicative timing

First 7 days

3

Plan a staged DMARC move from monitoring toward enforcement

Reduces domain impersonation risk after legitimate senders are checked.

Suggested owner

IT provider

Indicative timing

Within 30 days

What happens next

The report is designed to travel with you

Use your existing IT provider

Share the evidence and action list with the people who already manage your systems.

Implement internally

Assign each action to an owner and record when the change has been verified.

Scope hands-on help

Ask Yarra Secure to quote only the remediation work you want assistance with.

The Quick Cyber Risk Review is $1,500 + GST. Read the full scope and methodology or email contact@yarrasecure.com.au.