Back

Example report. The organisation and all figures are fictitious.

Elmfort Illustrative example

Monthly report

Cyber Resilience
Assurance Report

Harbour & Finch LLP · September 2026

Plan
Assured
Protected staff
85
Reporting period
1–30 Sep 2026
Issued
7 Oct 2026
Good
Your security position improved this month. Three incidents were contained quickly and critical vulnerabilities fell from five to two. Three decisions need your approval, listed on page 5.

Key measures

Security coverage
98% Up 2 points. 2 integrations pending.
Critical vulnerabilities
2 Down from 5. Both scheduled.
Incidents investigated
3 All contained and closed.
Controls with current evidence
46/50 4 awaiting evidence.
Recovery tests
4 3 passed. 1 action raised.
Approved AI services
12 2 awaiting review.
Illustrative example. Not real customer data. Confidential Page 1 of 5
Elmfort Cyber Resilience Assurance Report · September 2026

Section 1

Security operations

Our security operations centre investigated three incidents. Each was contained within the same working day.

Incidents this month

DateWhat happenedSeverityOutcome
4 Sep Sign-in to a finance account from an unfamiliar country Medium Session revoked and password reset within 18 minutes. No data accessed.
12 Sep Phishing email reported by six staff Low Message removed from all mailboxes. Sender blocked.
23 Sep Malicious download blocked on a laptop Medium Device isolated, scanned and returned to the user the same day.

Monitoring coverage

Laptops
83/85
Smartphones
81/85
Identities
100%
Microsoft 365
100%
Azure
100%
SaaS applications
7/9

Open vulnerabilities

Critical
2
High
7
Medium
23
Low
41

38 vulnerabilities fixed and verified this month. Critical fixes took a median of 6 days, against a 7-day target.

Outstanding critical vulnerabilities

FindingOwnerDueStatus
Remote code execution flaw in the VPN appliance IT provider 10 Oct Patch scheduled
Unsupported operating system on the reception PC IT provider 31 Oct Decision needed
Illustrative example. Not real customer data. Confidential Page 2 of 5
Elmfort Cyber Resilience Assurance Report · September 2026

Section 2

Governance and compliance

46 of 50 controls have current evidence, up from 43 last month. The remaining four relate to suppliers, continuity and one legacy device.

Evidence by control area

Access control
12/12
Asset management
6/6
Operations security
10/11
Incident management
7/7
Business continuity
6/7
Supplier relationships
5/7

Coming up

Annual tabletop incident exercise 18 Nov 2026
Acceptable-use policy review 30 Nov 2026
Cyber Essentials renewal 14 Jan 2027

Controls awaiting evidence

ControlOwnerDue
Supplier security review: payroll provider Operations 31 Oct
Supplier security review: document storage Operations 31 Oct
Continuity plan sign-off for the finance system Finance 15 Nov
Removable media log for the reception PC IT provider 31 Oct

Top risks

RiskRatingTrend
Compromise of client data through a third-party supplier High Steady
Ransomware affecting the practice management system Medium Falling
Unapproved AI tools used with client documents Medium Falling
Extended outage of the finance system Medium Rising
Loss or theft of a laptop or phone Low Steady
Illustrative example. Not real customer data. Confidential Page 3 of 5
Elmfort Cyber Resilience Assurance Report · September 2026

Section 3

Resilience and AI

This quarter's recovery tests met their targets for three of four critical services. The finance system restored in time, but its bank feed did not reconnect.

Recovery tests

ServiceTargetAchievedResult
Practice management system 4 hours 2 h 40 m Passed
Document management 4 hours 3 h 10 m Passed
Microsoft 365 mailbox restore 8 hours 1 h 05 m Passed
Finance system 24 hours Restored, bank feed failed Action
Backup assurance. All 9 critical systems completed their scheduled backups this month. We verified a sample restore for each.

AI governance

Approved AI services
12In the AI inventory.
Awaiting review
2Meeting notes, contract review.
Policy acknowledged
92%78 of 85 staff.
  • We detected three new AI tools through sign-in monitoring. Two are now in review. One was blocked because it trains on uploaded data.
  • The client intake assistant, your one custom AI agent, passed its quarterly permission review with no changes needed.
Illustrative example. Not real customer data. Confidential Page 4 of 5
Elmfort Cyber Resilience Assurance Report · September 2026

Section 4

Decisions and next steps

Three decisions need approval from your management team. Our recommendation is shown for each.

Decisions required

DecisionOur recommendationBy
Replace the reception PC, which runs an unsupported operating system Approve replacement before 31 October. Estimated cost: one standard laptop. 17 Oct
Approve the AI meeting-notes tool requested by the advisory team Approve with restrictions: internal meetings only, 30-day retention. 24 Oct
Accept the risk of the payroll provider's missing security evidence until 31 December Accept for a limited time, while the provider completes its assessment. 24 Oct

Improvement roadmap

ImprovementWhenStatus
Integrate the remaining two SaaS applications with monitoring Q4 2026 In progress
Fix the finance system bank feed recovery and retest Q4 2026 Planned
Complete supplier security reviews Q4 2026 In progress
Roll out phishing-resistant MFA for administrators Q1 2027 Planned
Prepare for Cyber Essentials renewal Q1 2027 Planned
Questions about this report? Your service lead will walk you through it at your next monthly review. You can also contact us at any time at hello@elmfort.com.
Illustrative example. Not real customer data. Confidential Page 5 of 5