Monthly report
Cyber Resilience
Assurance Report
Harbour & Finch LLP · September 2026
Key measures
- Security coverage
- 98% Up 2 points. 2 integrations pending.
- Critical vulnerabilities
- 2 Down from 5. Both scheduled.
- Incidents investigated
- 3 All contained and closed.
- Controls with current evidence
- 46/50 4 awaiting evidence.
- Recovery tests
- 4 3 passed. 1 action raised.
- Approved AI services
- 12 2 awaiting review.
Section 1
Security operations
Our security operations centre investigated three incidents. Each was contained within the same working day.
Incidents this month
| Date | What happened | Severity | Outcome |
|---|---|---|---|
| 4 Sep | Sign-in to a finance account from an unfamiliar country | Medium | Session revoked and password reset within 18 minutes. No data accessed. |
| 12 Sep | Phishing email reported by six staff | Low | Message removed from all mailboxes. Sender blocked. |
| 23 Sep | Malicious download blocked on a laptop | Medium | Device isolated, scanned and returned to the user the same day. |
Monitoring coverage
Open vulnerabilities
- Critical
- 2
- High
- 7
- Medium
- 23
- Low
- 41
38 vulnerabilities fixed and verified this month. Critical fixes took a median of 6 days, against a 7-day target.
Outstanding critical vulnerabilities
| Finding | Owner | Due | Status |
|---|---|---|---|
| Remote code execution flaw in the VPN appliance | IT provider | 10 Oct | Patch scheduled |
| Unsupported operating system on the reception PC | IT provider | 31 Oct | Decision needed |
Section 2
Governance and compliance
46 of 50 controls have current evidence, up from 43 last month. The remaining four relate to suppliers, continuity and one legacy device.
Evidence by control area
Coming up
| Annual tabletop incident exercise | 18 Nov 2026 |
| Acceptable-use policy review | 30 Nov 2026 |
| Cyber Essentials renewal | 14 Jan 2027 |
Controls awaiting evidence
| Control | Owner | Due |
|---|---|---|
| Supplier security review: payroll provider | Operations | 31 Oct |
| Supplier security review: document storage | Operations | 31 Oct |
| Continuity plan sign-off for the finance system | Finance | 15 Nov |
| Removable media log for the reception PC | IT provider | 31 Oct |
Top risks
| Risk | Rating | Trend |
|---|---|---|
| Compromise of client data through a third-party supplier | High | Steady |
| Ransomware affecting the practice management system | Medium | Falling |
| Unapproved AI tools used with client documents | Medium | Falling |
| Extended outage of the finance system | Medium | Rising |
| Loss or theft of a laptop or phone | Low | Steady |
Section 3
Resilience and AI
This quarter's recovery tests met their targets for three of four critical services. The finance system restored in time, but its bank feed did not reconnect.
Recovery tests
| Service | Target | Achieved | Result |
|---|---|---|---|
| Practice management system | 4 hours | 2 h 40 m | Passed |
| Document management | 4 hours | 3 h 10 m | Passed |
| Microsoft 365 mailbox restore | 8 hours | 1 h 05 m | Passed |
| Finance system | 24 hours | Restored, bank feed failed | Action |
AI governance
- Approved AI services
- 12In the AI inventory.
- Awaiting review
- 2Meeting notes, contract review.
- Policy acknowledged
- 92%78 of 85 staff.
- We detected three new AI tools through sign-in monitoring. Two are now in review. One was blocked because it trains on uploaded data.
- The client intake assistant, your one custom AI agent, passed its quarterly permission review with no changes needed.
Section 4
Decisions and next steps
Three decisions need approval from your management team. Our recommendation is shown for each.
Decisions required
| Decision | Our recommendation | By |
|---|---|---|
| Replace the reception PC, which runs an unsupported operating system | Approve replacement before 31 October. Estimated cost: one standard laptop. | 17 Oct |
| Approve the AI meeting-notes tool requested by the advisory team | Approve with restrictions: internal meetings only, 30-day retention. | 24 Oct |
| Accept the risk of the payroll provider's missing security evidence until 31 December | Accept for a limited time, while the provider completes its assessment. | 24 Oct |
Improvement roadmap
| Improvement | When | Status |
|---|---|---|
| Integrate the remaining two SaaS applications with monitoring | Q4 2026 | In progress |
| Fix the finance system bank feed recovery and retest | Q4 2026 | Planned |
| Complete supplier security reviews | Q4 2026 | In progress |
| Roll out phishing-resistant MFA for administrators | Q1 2027 | Planned |
| Prepare for Cyber Essentials renewal | Q1 2027 | Planned |