Sample deliverables
See the standard of work before you commit.
Every CyberByte engagement ends in evidence a board and a technical team can both act on. These are illustrative examples of the reports we produce — built for a fictional organisation so you can judge the quality and structure. No email required.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide
What you receive
The deliverables, illustrated end to end
A representative set from an Assess → Engineer → Advise engagement. Figures, findings and the organisation are fictional and for illustration only.
Assessment · 01
Executive summary
Meridian Professional Group (fictional · 150 staff)
Meridian Professional Group engaged CyberByte for an independent security assessment ahead of a corporate client's security review. This summary sets out the overall posture, the priorities that matter most, and a costed path to a defensible baseline — in plain business language.
Overall, Meridian's Microsoft 365 environment is functional but under-hardened: identity controls are inconsistent, administrative access is broader than needed, and there is limited evidence to answer third-party questionnaires. None of the gaps are exotic; all are addressable within a focused remediation window.
Assessment · 02
Essential Eight maturity scorecard
Meridian Professional Group (fictional · 150 staff)
Essential Eight maturity
Illustrative scorecard · ML0–ML3
Assessment · 03
Risk register (extract)
Meridian Professional Group (fictional · 150 staff)
| Risk | Likelihood | Impact | Rating | Treatment |
|---|---|---|---|---|
| Account takeover via missing MFA | High | High | Critical | Enforce MFA + Conditional Access |
| Over-privileged Global Admins (7) | Medium | High | High | Reduce to 2; adopt PIM |
| Legacy authentication enabled | High | Medium | High | Block legacy auth |
| Uncontrolled external sharing | Medium | Medium | Medium | Sharing policy + labels |
| No tested restore of backups | Low | High | Medium | Documented restore test |
Assessment · 04
Microsoft 365 findings (extract)
Meridian Professional Group (fictional · 150 staff)
MFA not enforced for all users
High12 of 150 accounts can sign in without MFA, including one with elevated rights.
Recommendation: Enforce MFA via Conditional Access; exclude only break-glass accounts.
Legacy authentication permitted
HighBasic/legacy auth protocols remain enabled tenant-wide, bypassing modern controls.
Recommendation: Block legacy authentication; monitor sign-in logs during rollout.
Excessive Global Administrators
MediumSeven standing Global Admins; no just-in-time elevation.
Recommendation: Reduce to two; adopt Privileged Identity Management.
Anonymous SharePoint links
MediumOrganisation-wide 'anyone' links enabled with no expiry.
Recommendation: Restrict to specific-people links; apply sensitivity labels.
Engineer · 05
Prioritised remediation roadmap
Meridian Professional Group (fictional · 150 staff)
Now · week 1
Highest-leverage, low-effort
- •Enforce MFA everywhere
- •Block legacy authentication
- •Reduce Global Admins to 2
Next · weeks 2–3
Close the priority gaps
- •Conditional Access baseline
- •Defender policy tuning
- •Restrict external sharing
Later · weeks 4+
Sustain and evidence
- •Sensitivity labels + DLP
- •Backup restore test
- •Board-ready evidence pack
Assess · 06
Penetration-test finding (illustrative)
Meridian Professional Group (fictional · 150 staff)
Password spraying against exposed authentication endpoint
HighCVSS 8.1 (illustrative)- Affected
- Externally reachable sign-in endpoint without rate-limiting or MFA on all accounts.
- Evidence
- A small set of common passwords, sprayed slowly, returned one valid credential in a controlled test window.
- Business impact
- A valid credential without MFA could allow mailbox access, data exfiltration, or a foothold for lateral movement.
- Recommendation
- Enforce MFA on every account, enable smart lockout / rate-limiting, and alert on spray patterns.
Engineer · 07
Verification / completion statement
Meridian Professional Group (fictional · 150 staff)
This statement confirms that CyberByte re-tested the agreed findings from the Meridian Professional Group engagement following remediation. Of the 13 prioritised findings, 12 were verified as closed and 1 was accepted as a documented residual risk. Re-testing covered identity, external exposure and the Microsoft 365 configuration in scope.
A completion statement supports client, insurer and tender evidence requirements. It is not an accredited certification and does not guarantee acceptance by any third party.
Advise · 08
Board-ready summary
Meridian Professional Group (fictional · 150 staff)
Security posture
Developing → Defensible
on plan
Priority risks closed
12 of 13
1 residual, documented
Essential Eight
ML1 → ML2 (target)
evidence prepared
Investment to date
Assessment + remediation
fixed price
For the board: the organisation moved from an under-hardened baseline to a defensible one within the agreed window, with the highest-impact identity risks closed first.
One residual risk is accepted and documented with a review date. Evidence is prepared to support the pending client security review. The recommended next step is a light-touch Security Partnership to keep the gains compounding and keep the evidence current.
All content on this page is fictional and for illustration only. It is not an actual client engagement, result, or endorsement.
Request a scoping call
Talk to a senior advisor — not a salesperson.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide