Illustrative report · fictional company

See what a professional security checkup delivers.

This sample shows the structure, depth and plain-language guidance included in the $497 Wolex Small Business Network Security Checkup. Northstar Family Dental is fictional, and every domain, IP address and finding below was created for demonstration—not taken from a customer.

Wolex Technologies

Small Business Network Security Checkup

Prepared forNorthstar Family DentalAssessment typeExternal posture reviewReport statusProfessionally reviewed

Overall external risk: Elevated

What this means in everyday language: the business has several useful protections, but two internet-facing weaknesses deserve prompt attention. Nothing in this limited review proves that an attacker entered the network. It does show where an attacker could focus and what the business should fix first.

Wolex reviewed one authorized public domain and one authorized public IPv4 address using safe, non-destructive checks. The sample findings below prioritize an exposed remote-administration service and a missing anti-spoofing email policy. The recommended plan begins with containment, then hardening, then validation.

1Domain reviewed
1Public IP reviewed
11TCP ports checked
4Positive controls

Finding breakdown

First action

Restrict remote administration

Remove public exposure or limit access to an approved VPN and trusted source addresses within seven days.

Exactly what was—and was not—reviewed

Authorized public assets

  • northstar-dental.example
  • 203.0.113.25

The .example domain and 203.0.113.0/24 address range are reserved for documentation.

Test families

  • Public DNS and email-domain posture
  • HTTPS availability and browser-security headers
  • HTTP-to-HTTPS enforcement and security contact
  • Connect-only checks of common public TCP services

Included

Public observations of only the listed assets, professional validation, prioritized guidance and one limited retest requested within 30 days.

Not included

Internal scanning, exploitation, password testing, phishing, denial of service or authenticated review of firewalls, cloud accounts, endpoints, Wi-Fi or VPN settings.

Protections already helping the business

Security reports should identify what is working so good controls are preserved during remediation.

HTTPS available

The public website accepted an encrypted connection.

HTTP redirected

Unencrypted root requests were redirected to HTTPS.

HSTS observed

The site instructed supported browsers to prefer encrypted connections.

SPF present

The domain published a policy describing permitted email senders.

Technical evidence with business meaning

Sample excerpt: three representative priority findings are expanded below. A customer report lists every professionally confirmed finding and observation.

High priority · High confidence

Remote Desktop was reachable from the public internet

Why a business owner should care

Remote administration exposed to the internet gives attackers a direct place to try stolen passwords, automated guessing and newly discovered vulnerabilities. The service may be intentional, but broad public access creates avoidable risk.

Evidence

A TCP connection was observed on port 3389 for 203.0.113.25. No login, credential, banner, payload or exploit was attempted.

Recommended action

Remove direct public exposure. Require an approved VPN with multifactor authentication or restrict the service to documented trusted source addresses. Confirm the system owner and business need before changing access.

How to validate the fix

Repeat the external connection check from an approved location and confirm port 3389 is no longer observed from the public internet. Then verify authorized administrators can still connect through the approved path.

Target: Contain within 7 days
High priority · High confidence

DMARC protection was not published

Why a business owner should care

Without DMARC, criminals have fewer technical barriers when pretending to send email from the company domain. That can increase invoice fraud, credential theft and damage to customer trust.

Evidence

No valid DMARC TXT record was observed at _dmarc.northstar-dental.example during the review.

Recommended action

Publish a reviewed monitoring policy, collect aggregate reports, identify every legitimate sender and then move toward quarantine or reject after authorized mail is aligned.

How to validate the fix

Query the DMARC record, confirm one syntactically valid policy is returned and verify aggregate reports are reaching a monitored mailbox or service.

Target: Begin within 7 days; enforce after sender validation
Medium priority · High confidence

Content Security Policy was not observed

Why a business owner should care

A Content Security Policy gives browsers an additional rule set for limiting where page scripts and other resources may load from. Its absence does not prove compromise, but it removes a useful layer of protection.

Evidence

The root HTTPS response did not include a Content-Security-Policy header.

Recommended action

Inventory required website sources, begin with a report-only policy, resolve violations and then enforce a policy that limits scripts, frames and connections to approved origins.

How to validate the fix

Repeat the HTTPS request, confirm the header is present and review browser developer tools for blocked legitimate resources.

Target: Harden within 30 days

A sequence the business can manage

WhenActionOwnerEvidence of completion
0–7 daysRestrict public Remote Desktop exposureIT providerExternal retest plus approved remote-access validation
0–7 daysStart DMARC monitoring and sender inventoryEmail administratorValid record and received aggregate report
8–30 daysTest and enforce a Content Security PolicyWebsite providerHeader observed; legitimate site functions verified
31–60 daysReview informational hardening itemsBusiness + ITAccepted risk or documented completed change

The owner’s takeaway

Ask the IT provider to show that Remote Desktop is no longer open to everyone, confirm who sends email for the company before enforcing DMARC, and have the website provider add browser protections without breaking the site. Keep screenshots, change tickets or configuration records, then use the included retest to confirm the public result changed.

How to interpret the evidence responsibly

Method

  1. Validate the customer-authorized external scope.
  2. Collect public DNS, email and HTTPS evidence.
  3. Perform connect-only checks of defined common TCP ports.
  4. Map repeatable observations to draft findings.
  5. Require professional review before customer delivery.

Limitations

  • This is a point-in-time external posture review, not a penetration test or compliance audit.
  • An open port identifies exposure, not automatically a vulnerability.
  • A non-observed port may be closed, filtered, rate-limited or unreachable from the assessment location.
  • No limited review can guarantee every weakness has been found.
Wolex TechnologiesVeteran-owned · CISSP-led · Beaverton, Oregon

Illustrative sample · No customer data · Not an actual security assessment

Ready for your own evidence?

Turn public exposure into a practical action plan.

Authorize only the assets you want reviewed. No credentials, internal access or software installation required.

Purchase the $497 checkup