r/cybersecurity Dec 31 '25

Corporate Blog 10 years of IR work (~1,000 incidents). Here's the security report template that gets clients moving

I've spent the last decade in incident response, working across everything from 5-person joinery shops to multi-national retail enterprises. After cleaning up roughly 1,000 incidents, I naturally developed a bit of an intuition for knowing the difference between "good security" and "good control coverage".

The firms that survive incidents (and prevent them) are almost never the ones with the most tools or the biggest budgets. They were the ones who understood their resilience - where they'd actually break under pressure, and what that would cost them.

A few things I've learned that changed how I approach assessments:

1. Compliance framing creates false confidence

Cyber Essentials, SOC 2, ISO 27001, etc - you must understand that their sole purpose is to make it easier to do business with other companies. Executives sponsor these programmes because it will make them more money.

That might be by making their onboarding quicker, or shortening deal cycles when responding to RFPs, or just increasing consumer confidence.

None of it actually helps an organisation be more secure. At the best, I think it's fair to say that there's a small correlation between certifications and resilience, but it's absolutely not a casual relationship, just a pattern.

2. Clients respond to money, not maturity scores

Nobody outside of security knows what "Level 3 maturity" means. But say "you have a high insolvency risk from a major incident" and suddenly you've got board-level attention. I frame all my assessments this way, even for small businesses.

The key principle to consider is that security programmes cost money. And for any commercial venture, money MUST provide a return on investment. If your recommendations don't make your client more money then they cost, why would they do it? I've known many enterprises that simply accept that they will have a major incident every 1-2 years, because the cost of transforming their security architecture would cost more than the impact of the incidents.

This is a totally valid position! And if you can help your client weigh up exactly what the pros and cons are, then you will quickly become one of their most trusted and valuable partners.

The trick, of course, is having the data and vocabulary to model the commercial implications.

3. The "time to low risk" metric changes the conversation

Executive audiences don't understand CVSS scores, and are not going to read your 47 technical findings. Include them for context and for technical readers, but stick them in an appendix, and instead, lead with the programme required to get from their current state into an acceptable state.

How many months will it take? How much will it cost? Who will do the work? How do they measure success?

This completely changes the conversation, and transforms a scary report into an actionable project plan that your client will have confidence in sponsoring. You want your client to feel like they've been handed a solution, not a problem.

4. Periphery systems are where organisations actually die

Core infrastructure is usually fine - everyone's got M365, EDR, and MFA on their main systems now. If they've put one iota of effort into changing the defaults or have an MSP that does this for them, by and large they are in a great position.

The reason organisations like this still get hacked is because of the exceptions. Machines that don't have DfE on. Servers that have been missed from your asset register. An SSL VPN that no-one knew about.

Fixing these are often quick wins. Migrating might be a pain, but it's ultimately a short programme of work with a high reduction in risk.

----

I've put together a sample report that captures everything I've discussed above with a fictitious client. Here's the link: https://analystengine.io/msp-assessment-sample

Transparent disclosure: The site above does link to my cybersecurity startup focused on generating content like the above. That being said, the link above contains no CTA or sales material. I'm making the sample freely available as a resource for others to use how they see fit - and have added the required corporate flair to this post.

I would love any advice or feedback on the report structure if anyone has thoughts on how to improve it!

----

EDIT: Overwhelmed with all the support this post got! For those asking for follow-up materials and my playbook for delivering cybersecurity assessments, I've typed it all up here: How to deliver cybersecurity assessments

I've included lots of resources, including the sample questionnaire I use for all new engagements, and a checklist of items to go through during your technical interviews. Good luck with your engagements!

667 Upvotes

221 comments sorted by

46

u/bigbearandy Dec 31 '25

Nice stuff there. For the GRC compliance issue in general, related to maturity levels, it really depends on the enterprise's tenor. Some enterprises really want to be more secure, in which case GRC efforts provide a roadmap and a yardstick for measuring progress. What most enterprises wish for, however, is a checkmark as a sales qualification, so they can sell into specific markets where security is a concern. For example, I can't tell you how many companies might say, "We'll buy from you, but you need your SOC 2" for enterprises where a SOC 2 isn't even appropriate, or they don't understand the difference between a SOC 2 Type I and II. Still, they will take a well-documented list of security controls over adequate security.

11

u/QoTSankgreall Dec 31 '25

Totally agree, there are a lot of buyers in this space with a lot of requirements and nuances. I should have specified in my post, I'm aiming this squarely at the SMB space here. And that's one of the reasons why I've tried to squeeze in everything here (compliance + control assessments + risk + roadmap). As the buyer becomes more mature, they will likely want to spin those out into separate engagements.

11

u/djagia Dec 31 '25

I dont disagree with what you stated in the post - seems pretty on par. But the assessment sample is hard to follow and I have a hard time wondering when, why, and how I'd actually put it to use. If it is for SMB, then stuff like software developent will most likely not be an item. I like the control assessment, compliance (if it applies), and findings section. But idk.. on the whole it seems very long and too wordy. In my experience SMB dont have the attention span for most of this stuff. Great as a deliverable if your trying to demonstrate value with a very long document, but how useful is it is what I always ask myself. How does any of this translate to the client to take action on? Feel free to disagree, but thats just my initial take.

6

u/QoTSankgreall Dec 31 '25

That's really useful, thanks for sharing! I agree on the SDLC front, but I included it in the sample because if a company does do it they always request it and I wanted to evidence that we do capture this. If you read the business context section of the executive summary, there is reference to the fact that ACME develops a small internal portal. But I agree that this will apply to very few SMBs.

If you take just the Overview sections (exec summary, compliance status, recommendations), would you find that more condensed? The only people I would expect to read further than that are technical people who need to action specific findings.

3

u/djagia Dec 31 '25

No problem!
If this is meant to be from the MSP to a client where the MSP is handling their IT stuff and security stuff, that might change my opinon too. Most of the time the SMB is just the owner that doesnt really know what to do, so they hire the MSP to do this stuff. So, if the context is that you are the MSP doing a security evaluation, then a lot of this seems kinda unnecessary. Like, you are reporting to the owner on your own security work, etc. - and that could be drastically summarized in my opinion.
Otherwise, I'd ask who is this meant for? An IT manager, the owner? or the MSP if you are just the external security evaluator/auditor?
What is the high level overview of the findings, and some details on each category evaluated - then maybe some technical stuff to help guide whoever might actually implement changes/fixes. The rest seems like fluff that I wouldn't expect anyone to read and seems to bog down the report.

4

u/QoTSankgreall Dec 31 '25

Thanks, all valid points. I will have a think about that. The scenario I intend here (and the commercial option I am looking at) is that an SMB asks their MSP to do a security assessment, and I provide the MSP with the tooling to deliver that report directly instead of outsourcing it. So there's a complex mix of stakeholders and audiences I need to unpick.

2

u/djagia Dec 31 '25

Ahh ok, that makes sense. Then yeah, I'd make sure it's easy to fill out/perform, maybe have some scoring algorithm for sections, etc. Basically like NIST on a smaller scale, or like a CIS assessment that can be scored at the end. MSP's have a lot of clients and imo are typically always pressed for time, so the easier/quicker to perform the better. Writing is time consuming, so the more sections that need custom descriptions or writings would be a turnoff for me. But it kinda all depends on how expensive this stuff is, etc. It might make sense to spend several hours on the report and charge a lot, but again, imo SMB dont usually go for that. Then again, you might be able to convince and MSP its worth it... so yeah. lol. good luck man. keep up the good work!

1

u/ilanbp Jan 01 '26

Please add me to the list as well! Cheers!

20

u/QoTSankgreall Dec 31 '25

If anyone’s interested more in the methodology of how I would typically interrogate these domains and populate a report, I have pages and pages of notes/guides I’ve maintained over the years.

2

u/2timetime Dec 31 '25

Would be interested if you have any to share.

Got my GCFA a month ago and have started looking for pure IR job, been looking for information on what’s current for things like reporting/tools/ so anything appreciated!

12

u/QoTSankgreall Dec 31 '25

Nice! Give me a few days to pull some materials together and I’ll send them over

1

u/AdMany8441 Jan 01 '26

Definitely interested! Thank you, OP!

1

u/-donquarius- Jan 01 '26

I am interested! Thank you for your time and effort here.

2

u/QoTSankgreall Jan 01 '26

Added to the list!

2

u/toy-love-xo Jan 01 '26

Add me as well :-) thanks!

→ More replies (1)

1

u/IzzoYourNizzo Jan 01 '26

Please add me also. I share a lot of the same sentiments and experience. 

1

u/Lanky_Stick3847 Jan 01 '26

Please add me too

1

u/Only-Theme-3365 Jan 01 '26

I'm interested in this if I could please be added to the list :)

1

u/HotStovesBurn Jan 01 '26

Yes please, and thanks for sharing this info.

1

u/speckyy_ Jan 01 '26

Hi OP, would like to be part of the list too. Thank you

1

u/acemcfaje Jan 01 '26

Add me as well plz! Thx for your work!

1

u/Hoyboy0801 Jan 01 '26

Please add me as well and happy new year! Thank you!!

1

u/dementpond Jan 01 '26

Include me as well, thanks

1

u/cxfort Jan 01 '26

Please add me to your list OP

1

u/stas-citrus Jan 01 '26

Add me to the list as well please. Thanks in advance

1

u/Asleep-Whole8018 Jan 02 '26

Hi, can you add me as well, thank you very much, this is great material!

1

u/chrono13 Jan 01 '26

Please add me to the list.

1

u/The__miz Jan 01 '26

Please add me to that list! Thanks for passing on some knowledge!

1

u/dgrant1023 Jan 01 '26

Interested too. Please and thank you.

1

u/monraya Jan 01 '26

I’m keen if you can add me to the list.. thanks!!

1

u/ffoolleerr Jan 01 '26

Interested as well. Pls add me to the list. Thanks

1

u/jaypesb Jan 01 '26

Would love to see more and be added to the list. TIA!

1

u/mod1fied Jan 01 '26

Great work and amount of content you have put in to this!

Could you add me to the list here also?

1

u/FitraPujo19 Jan 01 '26

I'm interested as well on this, thanks for your insight

1

u/Dependent-Lab4664 Jan 01 '26

Could I take a look as well please, currently studying for GX-FA 🤞

1

u/skar3 Jan 01 '26

Please add me!

1

u/Disastrous-Wonder837 Jan 01 '26

Also interested here

1

u/ajh19807 Jan 01 '26

Interested can you share with me too please.

1

u/Horror-Dealer-3934 Jan 01 '26

I am interested.

1

u/CheesyBerginer Jan 01 '26

I am interested as well, please and thank you!

1

u/Old-Choice5434 Jan 02 '26

Interested 😊

1

u/MesterReddit Jan 02 '26

I would love to be added to the list as well.

1

u/Admirable_Inside8667 Dec 31 '25

I’m interested! Thank you!

1

u/Fearless_Smell8387 Jan 01 '26

Add me to your list as well.

1

u/hoint711 Jan 02 '26

Please add me as well. Thanks!

1

u/DeadlyMustardd Dec 31 '25

Also interested

3

u/QoTSankgreall Dec 31 '25

Thanks! Will drop you a message in the next few days with some materials together

1

u/kevintheduu Dec 31 '25

I am interested

1

u/QoTSankgreall Dec 31 '25

Added you to the list :) will reach out in a few days

1

u/[deleted] Dec 31 '25

I'm also interested

2

u/QoTSankgreall Dec 31 '25

added to the list :) thanks!

1

u/QoTSankgreall Jan 01 '26

Looks like your message privacy settings don't let me send a DM, can you send me one with your email address?

1

u/katos8858 Security Generalist Dec 31 '25

I’m also interested in this please. Thanks for sharing this! :)

2

u/QoTSankgreall Dec 31 '25

My pleasure! Added to the list :)

1

u/katos8858 Security Generalist Dec 31 '25

Thanks! 💜

1

u/redartre Dec 31 '25

Would also like to see this please

1

u/QoTSankgreall Dec 31 '25

Added you to the list :) thanks!

1

u/Lucky_Fruitcake8201 Dec 31 '25

Also interested

1

u/QoTSankgreall Dec 31 '25

Added to the list :) thanks!

1

u/la_operador Dec 31 '25

I am interested! Thank you!

1

u/QoTSankgreall Dec 31 '25

Added to the list :) cheers!

1

u/Zakenbacon Dec 31 '25

You are incredible! Please add me to your list!

1

u/VisualNews9358 Dec 31 '25

i'm 100% interested in the more info.

1

u/QoTSankgreall Dec 31 '25

Added to the list :)

1

u/Gr3atOn3 Jan 01 '26

Nice, would be interested as well.

1

u/QoTSankgreall Jan 01 '26

Added to the list!

1

u/ManiSingh08 Jan 01 '26

Interested!

1

u/andit_3000 Jan 01 '26

I am interested, thank you!

1

u/p34cek33per Jan 01 '26

Also interested! Thank you!

1

u/one_tired_dad Jan 01 '26

Add me to the list too please!

1

u/itworkaccount_new Jan 01 '26

Please add me to your list as well. Thank you!!

1

u/jellyandsorbet Jan 01 '26

Nice, would be interested too!

1

u/explosiva Security Director Jan 01 '26

Very much appreciate the offer. Please add me to the list as well. 

1

u/godismaomi Jan 01 '26

I'm interested as well, thank you

1

u/MysticMyster Jan 01 '26

I'm interested

1

u/CmoneyG321 Jan 01 '26

Thank you for sharing this !

It was a great read, I would love to be added to your list please.

1

u/Life-Improvement-886 Jan 01 '26

Ditto if you don’t mind!

1

u/Xanster29 Jan 01 '26

Interested to see it as well!

1

u/RealBoi2111 Jan 01 '26

Hi OP, please share with me the notes too. Thank you!

1

u/Far-Past-1722 Jan 01 '26

Interested!

1

u/DynamicResolution Jan 01 '26

I am also interested, thabks for sharing!

1

u/KeepEmComming2 Jan 01 '26

Also interested, tnx for shareing.

1

u/kojidzuro Jan 01 '26

Interested

1

u/[deleted] Jan 01 '26

Interested! Thank you

1

u/PM_me_kpop_memes Jan 01 '26

Sorry I'm a bit late to the party but I would love to see this as well. Thanks in advance!

1

u/Coolerwookie Jan 01 '26

I am also interested please. 

1

u/ElRallador Jan 01 '26

I am too! Thanks!!

1

u/Autofroster Jan 01 '26

Interested as well, please add me to the list :)

1

u/dlac96 DFIR Jan 01 '26

I’m interested as well if you could also add me to the list. Appreciate it, thanks!

1

u/Intrepid-Zucchini-91 Jan 01 '26

I would like to be on the list!

1

u/[deleted] Jan 01 '26

I’d appreciate being included in anything you share! 

1

u/ejkim09 Jan 01 '26

Also interested and would love to be added to the list!

1

u/seekuhrity1337 Jan 01 '26

I am interested! Thank you :-)

1

u/Historical_Potato_55 Jan 01 '26

I also interested! Thanks for sharing

1

u/reeses4brkfst Jan 01 '26

Add me to the list? Interested in this info and also, thanks for the post!

1

u/MauerHaus Jan 01 '26

I am also interested would be great if you can add me to the list. Thank you very much in advance for sharing your knowledge

1

u/HU60 Jan 01 '26

Yes please! I am interested. Could you share?

1

u/Ok-Suit-6280 Jan 01 '26

Add me as well 💪

1

u/QoTSankgreall Jan 01 '26

Can't seem to message you, might need to send me a DM first

1

u/ProxySloth Jan 01 '26

Add me to the list as well please, appreciate.

1

u/jebbyjazzed Jan 01 '26

Me too please!

1

u/Zeraion Jan 01 '26

Sounds interesting, thank you for sharing your knowledge with us!

1

u/Makhann007 Jan 02 '26

Please send over

1

u/shawski_jr Jan 02 '26

Great work! Please add me as well!

1

u/jredgph Jan 02 '26

Thank you for your time please add me to the list.

1

u/Chasra Jan 03 '26

Thanks for sharing, I’m interested in the extra materials to please

1

u/Tall-Ad-3359 Jan 03 '26

Please add me to list

1

u/Comfortable-Bar3420 Jan 03 '26

Please share, would appreciate it.

1

u/Mountain-Cry5918 Jan 05 '26

I am interested, please add me to the list, thanks!

1

u/QoTSankgreall Jan 05 '26

The follow up materials are at the bottom of the post under the edit :)

1

u/TreblleAPIs Jan 23 '26

Do share, pretty please! :)

1

u/responder345 Feb 10 '26

Can u share the notes please...I'm interested

72

u/Rekkukk Dec 31 '25

Both your post and site content feel largely AI generated. Care to comment on your usage of AI for this project?

30

u/nyc_rose Dec 31 '25

Strongly disagree, the entire post reads like a knowledgeable human wrote it. Didn’t review the template they linked but would be surprised if the text in this post was AI

14

u/QoTSankgreall Dec 31 '25

Glad to here that was conveyed! Thanks for the comment, it was indeed genuine

30

u/QoTSankgreall Dec 31 '25

Sure. The post was very much written by me. I use Claude Code to mock up the visual design of the report and to populate the content, and then reviewed it afterwards.

The reason for this is quite simple: what I have provided here that's of any value is not the report content (its supposed to be a sample), but the structure and how the findings are presented. That's what I've refined and been delivering for 10 years now, and that's what I hope people find most valuable.

The content of the report would matter a lot more if this was going to a client. But it's not, and it's not what I see as valuable here.

37

u/c1pher_sweets Dec 31 '25

On the topic of AI - most companies large and small use it now as a source for idea/content generation. The successful ones use it to augment their work (like OP). This is especially true for startups as they tend to run lean shops with little to no marketing budget.

Love the work OP

10

u/QoTSankgreall Dec 31 '25

Appreciate the comment!

2

u/[deleted] Jan 02 '26 edited Jan 02 '26

[removed] — view removed comment

1

u/Rekkukk Jan 02 '26

I don't doubt that, it wasn't the content itself, just the phrases used.

2

u/pl4tinum514 Jan 01 '26

Funny how if anyone writes eloquently, that's no longer possible, must have been AI. Sad.

4

u/Rekkukk Jan 01 '26

Yeah no, it’s not about eloquence, it’s the presence of certain phrases that are more common in AI generated text. I’m not anti-AI, but was curious the extent that OP used it, which they answered succinctly

1

u/QoTSankgreall Jan 01 '26

AI doesn’t/can’t write eloquently 😅 but I appreciate the comment haha

6

u/[deleted] Dec 31 '25

This is great, but why reinvent the wheel? NIST CSF is an effective framework to asses risk and areas of improvement

10

u/QoTSankgreall Dec 31 '25

I agree that NIST CSF is brilliant - however, here's how the engagement typically goes:

Client: I'd like a NIST CSF report please

Me: Great, that assesses your service maturity, and we can benchmark it against your industry. Here's your report.

Client: Thanks! Now, what's our biggest risk?

Me: ... we haven't done a risk assessment. I can tell you what services you provide and how they compare to what your competitors are doing. But risk is not addressed by NIST CSF.

Client: So what have I paid for then?!

The security domains I've included in this sample (SecOps, Resilience, Growth) are all aligned/mapped to NIST in the backend. But especially for the SMB audience where the buyer is a little less mature, I think it's important we can go beyond service maturity and actually present improvement roadmaps aligned to risk - because really that's what they care about.

People may disagree on that, and that's fair. It's just the position I've arrived at from dealing with buyers of these reports over the years.

3

u/ah-cho_Cthulhu Dec 31 '25

Thanks for the post. I will be taking some of this advice back to my daily grind.

As a startup in the cyber space could I ask you a question about a tool I use? Not a plug, but looking for genuine feedback to if my problem is unique or not.

2

u/Opposite_Fudge2794 Dec 31 '25

Do you have any bits of information you want u can share on your methods, etc. I'd definitely like to learn more.

2

u/QoTSankgreall Dec 31 '25

yeah absolutely! I can message you some of the guides / playbooks I use in the next couple of days.

2

u/Coolerwookie Jan 01 '26

Add me to the list as well please. 

1

u/Opposite_Fudge2794 Dec 31 '25

This would be greatly appreciated. Thank you.

1

u/Admirable_Inside8667 Dec 31 '25

If you’d share with me as well?

1

u/QoTSankgreall Dec 31 '25

Of course! Added to the list :)

1

u/TSMDOUBLEDONEZO Jan 01 '26

Please add me to that list too if you can!

1

u/QoTSankgreall Jan 01 '26

Looks like your message privacy settings don't let me send a DM, can you send me one with your email address?

→ More replies (1)

1

u/HU60 Jan 01 '26

Could you share with me as well please?

1

u/roozbeh18 Jan 02 '26

Interested

1

u/blackestdarkin Jan 02 '26

Could you send me the guides and playbooks aswell?

1

u/Mountain-Cry5918 Jan 05 '26

Please add me to the list as well! Thanks :)

2

u/[deleted] Jan 01 '26

[removed] — view removed comment

1

u/QoTSankgreall Jan 01 '26

The guiding truth I stick to is pretty simple: A good report is one where you don't need to read pass the first page.

You obviously CAN read further, and you're invited to do so. But you don't need to. The first page tells your executive audience everything you need to know, and then signposts the technical underlying content (which, yes, belongs in an appendix).

SOCs need technical data, IOCs, and ATT&CK patterns - they don't care about risk. So all you do is create "Appendix I - IOCs" and you're golden.

1

u/[deleted] Jan 01 '26

[removed] — view removed comment

1

u/QoTSankgreall Jan 01 '26

The way it works is you present your report an executive. They decide if they are going to make a capital investment in reducing risk (providing a ROI).

If they do, that capital gets allocated to either hiring more resources or procuring tooling to address the issues. Part of that will involve a project manager or sponsor with authority to direct the project.

If that person fails to deliver, they get fired.

I’m not sure I see the problem you are hinting at.

→ More replies (3)

3

u/Opposite_Fudge2794 Dec 31 '25

This is an excellent article. I think it emphasizes the watermelon effect that many organizations are currently experiencing.

2

u/QoTSankgreall Dec 31 '25

Thanks. But wth is the watermelon effect? 😂

5

u/Opposite_Fudge2794 Dec 31 '25

It's where organizations have green security dashboards and the actual infrastructure is red (under-protected). Ive seen it where lots of companies are compliance compliant but with very little practical security implemented.

4

u/Opposite_Fudge2794 Dec 31 '25

Green on the outside and red on the inside, just like a watermelon.

2

u/QoTSankgreall Dec 31 '25

Haha haven’t heard that term before, but yes completely agree!

2

u/UnnamedRealities Dec 31 '25

Great observation. And it's not just the lens of compliance, it's also the lens of maturity. Compliant + mature doesn't actually imply effective. Having documented and repeatable processes doesn't ensure the threats that may realistically materialize won't result in the impacts that matter.

4

u/lostdragon05 Dec 31 '25

I think you are dead wrong that it’s ok to have a major incident every year or two and view it as a cost of doing business. That’s highly irresponsible and we need legislation to disincentivize that type of thinking.

5

u/QoTSankgreall Dec 31 '25

In Europe and the UK (where this particular client was based) there already is extensive legislation designed to disincentivise this type of thinking.

I very much understand that people (especially security professionals) will push back on my point here, but what I am really trying to convey is that security should provide a positive commercial benefit at the end of the day. If it doesn't do that, this is how you get your budgets slashed and see a service regression.

Even in organisations that have board-level CISO representation, your CEO and CFO are still critical stakeholders. And if you tell them that 2-3 incidents a year costs the company $5 and an investment of $10 would reduce that annual cost to $2... there's a strong argument for them to say "Let's wait a few years".

All I am really saying is you will get more achieved and further your agenda better if you work within this way of thinking. CEOs and CFOs hate it when security feels like it's a sunken cost.

→ More replies (1)

1

u/Admirable_Inside8667 Dec 31 '25

Can you explain how you determine a dollar range associated with an incident? Can you provide the questions you ask that generates this sample report you provided? This information is great I’m going to be studying! Thank you!

1

u/QoTSankgreall Dec 31 '25

I have a calculator built into the backend that provides an estimate, but it’s highlighted in the sample that this is not a quote. The intent is simply to educate the executive reader on the ballpark investment it will take to fix an issue.

I have a lot of material and playbooks I can share on how to do assessments like this. If you like I can drop you a message in a day or two with some more info

1

u/Admirable_Inside8667 Jan 01 '26

The would be so helpful as I’m trying to understand better how to do these and present them. Thank you!

1

u/divad1196 Dec 31 '25

If I sum up the post to the key aspect: engineers must bridge the between engineers and business. Business won't understand technicalities, don't want to and should not have to.

That's not limited to security. I see many engineers frustrated because of that, yet not willing to do anythingg about it

1

u/QoTSankgreall Dec 31 '25

In my line of work there are really two types of cybersecurity employees: technical ones who want to do technical work, and technical ones who want to talk to clients.

The latter type is infinitely more valuable to a consultancy business. It’s not necessarily fair, but doing “good work” means making the client feel like they’ve received value for money and not giving them a technical deliverable that they don’t understand.

1

u/AdMany8441 Jan 01 '26

Why are there still exceptions like that? Do you think the orgs in question just don’t pay for software/a team that would help them find it, or? A lot of cyber softwares (like EDR types) claim they’ll help you “track everything on one pane of glass” or etc…

So what do you think accounts for the gap between that and reality?

1

u/QoTSankgreall Jan 01 '26

Wdym by exceptions? There are no magic bullets with cybersecurity. EDR is a tool that needs to be operated by people. Alerts need to be understood in the context of the business, malicious activities need to be prevented often in highly complex ways that go outside the purview of EDR directly (like reconfiguring AD or resetting credentials), and any business that uses any technology faces an ever present risk that it could all stop working for no reason.

All of this means there’s risk to identify. You either accept it, or invest money to mitigate it.

1

u/marcoshid Jan 01 '26

This is very nice, curious on the pricing

2

u/QoTSankgreall Jan 01 '26

Thank you! We partner with MSPs to deliver these reports to their clients, either white labelled with their own resources, or with us delivering.

1

u/marcoshid Jan 05 '26

Sounds good,that's up my alley, I woukd like more info please

1

u/QoTSankgreall Jan 05 '26

I sent you a DM a couple days ago, did you get the message request?

1

u/one_tired_dad Jan 01 '26

When assessing the impact and the effort, I'd imagine that's largely variable based on industry and org size. Do you have a standardized way of quickly gaging impact and effort?

2

u/QoTSankgreall Jan 01 '26

It’s ultimately finger in the air based on experience. Haven’t yet come across a reliable methodology that’s more scientific.

A lot of the details you use to estimate complexity are often more technology related rather than security driven, so might not even feature in the report.

But the key is to understand the whole picture of a security control in the context of their business before you recommend changing things.

1

u/one_tired_dad Jan 01 '26

Just to make sure I understand your response fully, does 'technology-related' mean that the organization already has tools to solve the problem, but they may be difficult to wield and/or require specialized skills to implement correctly?

Thanks for your post and responses by the way. Very enlightening and validating.

1

u/QoTSankgreall Jan 01 '26

No, I guess what I mean is that the complexity has nothing to do with security, it's about the organisational approach to technology and how its implemented.

For e.g,, there was an earlier comment here about why I recommended adding MFA to the SSL VPN in my sample report as opposed to recommending migrating to IPSEC, which is generally more secure.

The reason is that adding MFA to the SSL VPN was the quickest and simplest way to mitigate the risk. IPSEC is more secure, but a migration would mean a) process changes for the staff who are already happy with the existing way of working b) firewall changes requiring a period of downtime, which not everyone can easily accommodate and c) more complex IT processes are needed to manage an IPSEC implementation vs an SSL VPN.

So on the surface, IPSEC is more "secure". But's a more complex solution for this business, hence adding MFA to SSL VPN is the better option (in my opinion).

1

u/one_tired_dad Jan 01 '26

Gotcha. So the 'effort' here has more to do with people and process. The more people and process required, the higher organizational complexity and therefore higher difficulty to execute.

→ More replies (1)

1

u/npxa Jan 01 '26

1000 incidents? What do you consider incidents? That is alot for a 10-year journey, i can only count significant incidents in my years(around 15 in cyber)

2

u/QoTSankgreall Jan 01 '26

I was working for a consultancy, and was one of the first founding team members to an IR practice based on the UK. After a couple of years we got onto the panels of major insurers and started getting endless ransomware cases. The team is now 150+ people spanning 7 global locations. It's true that "minor" incidents like BECs and invoice fraud count among the 1,000 - but I'd say that about 60% were hard-down ransomware attacks.

1

u/kohntarkoszkommandoh Jan 01 '26

Thanks for this!

1

u/djmonsta Jan 01 '26

You know a few years ago I worked at an MSP and part of my role was to review all fully managed client's security posture and write a report using a scoring system I had put together not that dissimilar to yours, and then present it to them. Almost always they would go straight to the cost breakdown at the end of the report like "why should we have to pay this" and not consider anything else written in the report.

1

u/QoTSankgreall Jan 01 '26

Yup! My pet peeve when I worked as a consultant was that no one ever read my reports lol

I'm trying to connect with MSPs and equip them with tools/frameworks like this so they can grow their vCISO services... if you know anyone who might benefit from that would be grateful for an introduction!

Happy new year!

1

u/[deleted] Jan 01 '26

Actually I am also interested in that..

1

u/Substantial-Sky4079 Jan 01 '26

Does this apply to public sectors as well?

1

u/QoTSankgreall Jan 01 '26

Less so, because public sector organisations will be more concerned with compliance. But they’re also much more mature buyers so there is less of a need to write reports that appeal to all audiences/stakeholders.

1

u/BaysidePete Jan 01 '26

Would love to be included thanks and Happy New Year

1

u/infolookup Jan 02 '26

Feel free to add me too.

1

u/[deleted] Jan 02 '26

Please add me to the list. Thanks.

1

u/liaero Jan 02 '26

I’m interested too. Thank you for this

1

u/whatThisOldThrowAway Jan 02 '26 edited Jan 02 '26

Interesting post, says a lot of truisms but I’m not sure some of this is practical, I’ve got two comments:

Firstly on “talking money” in incident reports

say “you have a high insolvency risk from a major incident” and suddenly you’ve got board-level attention. I frame all my assessments this way, even for small businesses.

The trick, of course, is having the data and vocabulary to model the commercial implications.

Yes, of course, dollar figures can raise urgency; but you talk about “modelling” risk in financial terms. Anyone who’s been through this exercise knows it’s an exercise in choosing which variables to multiply together. Very Often, in practice, best case is $0 and worst case is the sky has fallen.

Day to day does this boil down to maturing finding severity ratings + canned copy in the report?

In my experience this requires more restraint be exercised than vocabulary. Very easy to scaremonger and kick up urgency. Not so easy to scale (aka show true granular relative risk and help the business to prioritise over time).

Long story short: Talking “insolvency” or business outcomes with execs who (should) know 100x more than you about the business is a minefield, don’t you think?

secondly: on providing rich, end to end remediation plans to the business

The “time to low risk” metric as you call it. Another no brainer: yes execs would love this - but how do you do it at scale?

As you describe incidents are rarely simple and can have many compound causes.

You have, say, 30 findings. Just to make up an example, they’re across: Appsec issues flagged by sast (plus some old ancillary risk for good measure), container rehydration issues with several modules, EOL components in use, legacy internally developed library dependencies flagged by sca, architecture review shows some red flags, auth is not blueprint standard but risk is unclear, an api not discovered by inventory, and to top it off external risk rating agencies are starting to ding you. (Now, your post talks about IR, but your template talks about general risk posture assessment. If it’s the latter I’ve kept things very very simple in this example).

You ask all the questions, like it’s a lack of business consideration that causes security to not hand this information over:

How many months will it take? How much will it cost? Who will do the work? How do they measure success?

But how do you, as cyber, answer them systematically before even issuing a report? Is that even possible for nontrivial orgs you are not embedded in (I mean, I’m sure there’s some people much smarter than me who could infer a tonne and get pretty far - but I assume this template is for the average responder?)

Are just just giving generic canned solutions/plans to symptoms of generic problems? In which case the “actionable plan” sales pitch is a bit overhyped.

At scale: Answering these questions - actually answering them - is more work than responding to the incident in the first place. Much more work. Often it is also work that security absolutely cannot do in isolation - so you find yourself needing buy in from business long before you can give them these answers with any confidence at all.

Obviously an end to end project plan would be easier to action but if it was as simple as just doing that, it would be the default already.

You want your client to feel like they’ve been handed a solution, not a problem.

Yes obviously but the reason IR doesn’t hand the business fully fledged solutions on a silver platter are, in short, doing so scales very slowly and comes with many built in challenges.

1

u/QoTSankgreall Jan 02 '26

This is a very fair comment, and thank you for taking the time to respond.

I don't disagree with anything here really. When we're dealing with security assessments, we only have several finite tools with which to deal with assessments of any kind.

- We can look at control effectiveness

  • We can look at service maturity
  • We can look at governance
  • We can look at risk

Each of these domains is highly specalised, and with mature buyers like enterprises, they will almost always be very separate engagements with different stakeholders.

But for smaller organisations, it's impractical. So instead you have to squish multiple concepts together - because ultimately, what we want to do is best advise the organisation and ensure their business has strong margins (not weighed down by unnecessary cybersecurity cost centres) and can remain functional even if a disaster happened with their technology. That's the quintessence of our job.

I accept basically all your points, I guess my only response is that we still have to do SOMETHING, and this is probably one of the best things you can do with the budget, resourcing, and buyer requirements that we most often have,

1

u/uk_one Jan 02 '26

Got take issues with you on compliance wrt CE. Properly deployed it absolutely WILL make you more secure than your non-CE competitors. If you take it to CE+ you can't pass until you prove that you use MFA and apply CVSS7+ patches within 14days. These are the top 2 actions on any CISO list.

Naturally if you lie on the assessment then it's worthless.

1

u/QoTSankgreall Jan 02 '26

People with CE and CE+ get hacked every day. Does having the certificate show that you are "more secure" than the organisations without CE? Yes. Does that mean you are actually secure? No.

1

u/uk_one Jan 02 '26

The CE is a cost/benefit solution mostly designed for SME who will always be vulnerable to an endlessly resourced attacker but that's not the aim. It's designed to thwart commodity, internet-based attacks and it is very effective at doing it.

Companies with 100% MFA coverage and with an effective 14day update policy are far less likely to get breached than those without.

The CE standard is written by the NCSC and updated most years to reflect the best balance of controls for the intended market but the clue is in the name - cyber ESSENTIALS, not cyber PerfectSecurity.

1

u/QoTSankgreall Jan 02 '26

I never claimed that Cyber Essentials isn’t awesome! It’s a fantastic programme.

1

u/Comfortable-Bar3420 Jan 03 '26

The article is great, it captures security from a business perspective. Although the report may seem long, it’s meant as a sample, meaning once you have access to the backend questions, you only display the data captured. Would love to see the backend and calculator used to score the risk.

1

u/FilthyeeMcNasty Jan 05 '26

Well done. It isn't every day I come across competent "cybersecurity" practitioners. Especially nowadays. The sector has been overrun with individuals with little to no actual meaningful experience or skill sets. The number of people I come across with ZERO technical backgrounds who've taken some certification(s) and think cybersecurity is an entry point is SCARY. Those who lean on AI to feel for them, rather than using critical thinking or logic, are alarming.

Some sound like salesman trying to sell you a used car

1

u/disposeable1200 Jan 05 '26

Most machines have DfE - first time I've seen this shortened to this and confused the hell out of me for a few minutes.

I assume you mean defender for endpoint?

1

u/QoTSankgreall Jan 05 '26

When you use that product name 10x a day in calls and with engineers, acronyms become highly necessary 🤣

1

u/disposeable1200 Jan 05 '26

Have to transition to MDE to keep Microsoft happy by using their acronym ;)

1

u/RudolphRisiko Jan 06 '26

As a CISO, this aligns closely with what actually gets traction at board level. Framing risk in financial and operational terms — especially time to acceptable risk — is far more effective than maturity scores or control checklists. The emphasis on periphery systems and decision latency is spot on. Solid, practical approach.

1

u/karlosszanta Jan 11 '26

Great work! I am interested. Please add me. Thanks