Illustrative report · fictional company
See what a professional security checkup delivers.
This sample shows the structure, depth and plain-language guidance included in the $497 Wolex Small Business Network Security Checkup. Northstar Family Dental is fictional, and every domain, IP address and finding below was created for demonstration—not taken from a customer.

Small Business Network Security Checkup
Overall external risk: Elevated
What this means in everyday language: the business has several useful protections, but two internet-facing weaknesses deserve prompt attention. Nothing in this limited review proves that an attacker entered the network. It does show where an attacker could focus and what the business should fix first.
Wolex reviewed one authorized public domain and one authorized public IPv4 address using safe, non-destructive checks. The sample findings below prioritize an exposed remote-administration service and a missing anti-spoofing email policy. The recommended plan begins with containment, then hardening, then validation.
Finding breakdown
Restrict remote administration
Remove public exposure or limit access to an approved VPN and trusted source addresses within seven days.
Exactly what was—and was not—reviewed
Authorized public assets
northstar-dental.example203.0.113.25
The .example domain and 203.0.113.0/24 address range are reserved for documentation.
Test families
- Public DNS and email-domain posture
- HTTPS availability and browser-security headers
- HTTP-to-HTTPS enforcement and security contact
- Connect-only checks of common public TCP services
Included
Public observations of only the listed assets, professional validation, prioritized guidance and one limited retest requested within 30 days.
Not included
Internal scanning, exploitation, password testing, phishing, denial of service or authenticated review of firewalls, cloud accounts, endpoints, Wi-Fi or VPN settings.
Protections already helping the business
Security reports should identify what is working so good controls are preserved during remediation.
HTTPS available
The public website accepted an encrypted connection.
HTTP redirected
Unencrypted root requests were redirected to HTTPS.
HSTS observed
The site instructed supported browsers to prefer encrypted connections.
SPF present
The domain published a policy describing permitted email senders.
Technical evidence with business meaning
Sample excerpt: three representative priority findings are expanded below. A customer report lists every professionally confirmed finding and observation.
Remote Desktop was reachable from the public internet
Why a business owner should care
Remote administration exposed to the internet gives attackers a direct place to try stolen passwords, automated guessing and newly discovered vulnerabilities. The service may be intentional, but broad public access creates avoidable risk.
Evidence
A TCP connection was observed on port 3389 for 203.0.113.25. No login, credential, banner, payload or exploit was attempted.
Recommended action
Remove direct public exposure. Require an approved VPN with multifactor authentication or restrict the service to documented trusted source addresses. Confirm the system owner and business need before changing access.
How to validate the fix
Repeat the external connection check from an approved location and confirm port 3389 is no longer observed from the public internet. Then verify authorized administrators can still connect through the approved path.
DMARC protection was not published
Why a business owner should care
Without DMARC, criminals have fewer technical barriers when pretending to send email from the company domain. That can increase invoice fraud, credential theft and damage to customer trust.
Evidence
No valid DMARC TXT record was observed at _dmarc.northstar-dental.example during the review.
Recommended action
Publish a reviewed monitoring policy, collect aggregate reports, identify every legitimate sender and then move toward quarantine or reject after authorized mail is aligned.
How to validate the fix
Query the DMARC record, confirm one syntactically valid policy is returned and verify aggregate reports are reaching a monitored mailbox or service.
Content Security Policy was not observed
Why a business owner should care
A Content Security Policy gives browsers an additional rule set for limiting where page scripts and other resources may load from. Its absence does not prove compromise, but it removes a useful layer of protection.
Evidence
The root HTTPS response did not include a Content-Security-Policy header.
Recommended action
Inventory required website sources, begin with a report-only policy, resolve violations and then enforce a policy that limits scripts, frames and connections to approved origins.
How to validate the fix
Repeat the HTTPS request, confirm the header is present and review browser developer tools for blocked legitimate resources.
A sequence the business can manage
| When | Action | Owner | Evidence of completion |
|---|---|---|---|
| 0–7 days | Restrict public Remote Desktop exposure | IT provider | External retest plus approved remote-access validation |
| 0–7 days | Start DMARC monitoring and sender inventory | Email administrator | Valid record and received aggregate report |
| 8–30 days | Test and enforce a Content Security Policy | Website provider | Header observed; legitimate site functions verified |
| 31–60 days | Review informational hardening items | Business + IT | Accepted risk or documented completed change |
The owner’s takeaway
Ask the IT provider to show that Remote Desktop is no longer open to everyone, confirm who sends email for the company before enforcing DMARC, and have the website provider add browser protections without breaking the site. Keep screenshots, change tickets or configuration records, then use the included retest to confirm the public result changed.
How to interpret the evidence responsibly
Method
- Validate the customer-authorized external scope.
- Collect public DNS, email and HTTPS evidence.
- Perform connect-only checks of defined common TCP ports.
- Map repeatable observations to draft findings.
- Require professional review before customer delivery.
Limitations
- This is a point-in-time external posture review, not a penetration test or compliance audit.
- An open port identifies exposure, not automatically a vulnerability.
- A non-observed port may be closed, filtered, rate-limited or unreachable from the assessment location.
- No limited review can guarantee every weakness has been found.
Ready for your own evidence?
Turn public exposure into a practical action plan.
Authorize only the assets you want reviewed. No credentials, internal access or software installation required.