Skip to content
CyberByteSecurity

Sample deliverables

See the standard of work before you commit.

Every CyberByte engagement ends in evidence a board and a technical team can both act on. These are illustrative examples of the reports we produce — built for a fictional organisation so you can judge the quality and structure. No email required.

ILLUSTRATIVE SAMPLE — NOT AN ACTUAL CLIENT RESULT
  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide

What you receive

The deliverables, illustrated end to end

A representative set from an Assess → Engineer → Advise engagement. Figures, findings and the organisation are fictional and for illustration only.

Assessment · 01

Executive summary

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

Meridian Professional Group engaged CyberByte for an independent security assessment ahead of a corporate client's security review. This summary sets out the overall posture, the priorities that matter most, and a costed path to a defensible baseline — in plain business language.

Overall, Meridian's Microsoft 365 environment is functional but under-hardened: identity controls are inconsistent, administrative access is broader than needed, and there is limited evidence to answer third-party questionnaires. None of the gaps are exotic; all are addressable within a focused remediation window.

Overall postureDeveloping
Priority findings5 high · 8 medium
Target baselineEssential Eight ML2
Est. remediation≈ 3–4 weeks

Assessment · 02

Essential Eight maturity scorecard

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

Assessment · 03

Risk register (extract)

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

RiskLikelihoodImpactRatingTreatment
Account takeover via missing MFAHighHighCriticalEnforce MFA + Conditional Access
Over-privileged Global Admins (7)MediumHighHighReduce to 2; adopt PIM
Legacy authentication enabledHighMediumHighBlock legacy auth
Uncontrolled external sharingMediumMediumMediumSharing policy + labels
No tested restore of backupsLowHighMediumDocumented restore test

Assessment · 04

Microsoft 365 findings (extract)

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

  • MFA not enforced for all users

    High

    12 of 150 accounts can sign in without MFA, including one with elevated rights.

    Recommendation: Enforce MFA via Conditional Access; exclude only break-glass accounts.

  • Legacy authentication permitted

    High

    Basic/legacy auth protocols remain enabled tenant-wide, bypassing modern controls.

    Recommendation: Block legacy authentication; monitor sign-in logs during rollout.

  • Excessive Global Administrators

    Medium

    Seven standing Global Admins; no just-in-time elevation.

    Recommendation: Reduce to two; adopt Privileged Identity Management.

  • Anonymous SharePoint links

    Medium

    Organisation-wide 'anyone' links enabled with no expiry.

    Recommendation: Restrict to specific-people links; apply sensitivity labels.

Engineer · 05

Prioritised remediation roadmap

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

Now · week 1

Highest-leverage, low-effort

  • Enforce MFA everywhere
  • Block legacy authentication
  • Reduce Global Admins to 2

Next · weeks 2–3

Close the priority gaps

  • Conditional Access baseline
  • Defender policy tuning
  • Restrict external sharing

Later · weeks 4+

Sustain and evidence

  • Sensitivity labels + DLP
  • Backup restore test
  • Board-ready evidence pack

Assess · 06

Penetration-test finding (illustrative)

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

Password spraying against exposed authentication endpoint

HighCVSS 8.1 (illustrative)
Affected
Externally reachable sign-in endpoint without rate-limiting or MFA on all accounts.
Evidence
A small set of common passwords, sprayed slowly, returned one valid credential in a controlled test window.
Business impact
A valid credential without MFA could allow mailbox access, data exfiltration, or a foothold for lateral movement.
Recommendation
Enforce MFA on every account, enable smart lockout / rate-limiting, and alert on spray patterns.

Engineer · 07

Verification / completion statement

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

This statement confirms that CyberByte re-tested the agreed findings from the Meridian Professional Group engagement following remediation. Of the 13 prioritised findings, 12 were verified as closed and 1 was accepted as a documented residual risk. Re-testing covered identity, external exposure and the Microsoft 365 configuration in scope.

A completion statement supports client, insurer and tender evidence requirements. It is not an accredited certification and does not guarantee acceptance by any third party.

Ref: CB-SAMPLE-0000Prepared by: Principal Security ConsultantScope + dates: per Statement of Work

Advise · 08

Board-ready summary

Illustrative sample

Meridian Professional Group (fictional · 150 staff)

Security posture

Developing → Defensible

on plan

Priority risks closed

12 of 13

1 residual, documented

Essential Eight

ML1 → ML2 (target)

evidence prepared

Investment to date

Assessment + remediation

fixed price

For the board: the organisation moved from an under-hardened baseline to a defensible one within the agreed window, with the highest-impact identity risks closed first.

One residual risk is accepted and documented with a review date. Evidence is prepared to support the pending client security review. The recommended next step is a light-touch Security Partnership to keep the gains compounding and keep the evidence current.

All content on this page is fictional and for illustration only. It is not an actual client engagement, result, or endorsement.

Request a scoping call

Talk to a senior advisor — not a salesperson.

A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide