Northstar Pay External Web Application Penetration Test
Report date: 9 September 2026 Classification: Confidential — sample
Engagement type
Authorized web application assessment
Testing window
Five business days
Assessment status
Complete — illustrative only
Prepared by
CyberClaw
01
Executive summary
CyberClaw performed an authorized assessment of a fictional customer-payment portal. The objective was to identify material security weaknesses within the approved external web application scope and provide a prioritized remediation plan.
Two findings require attention before the next production release. No critical-risk finding was validated within this sample scope. Results should be interpreted alongside the stated scope, testing window, and limitations—not as a guarantee that no other weaknesses exist.
0Critical
1High
1Medium
1Low
1Informational
02
Scope & rules of engagement
In scope
Fictional customer-payment portal and approved API surface
Authenticated buyer and administrator roles supplied for the engagement
Publicly exposed pages within the documented test window
Out of scope
Production disruption, denial-of-service, and load testing
Phishing, social engineering, physical security, and third parties
Persistence, data exfiltration, or testing outside approved assets
Testing begins only after written authorization, contact escalation paths, approved assets, time windows, and safeguards are confirmed.
03
Methodology & coverage
The approach is adapted to the agreed scope and risk profile. This example follows the planning, execution, analysis, and reporting principles described in NIST SP 800-115 ↗ and uses relevant web-application test areas from the OWASP Web Security Testing Guide ↗.
Plan: confirm authorization, scope, testing windows, contacts, and stop conditions.
Assess: review attack surface, authentication, authorization, session handling, configuration, and input-handling controls appropriate to the scope.
Validate: verify material issues safely and record only the minimum evidence needed to support remediation.
Report: prioritize risk, explain business impact, document limitations, and propose practical next actions.
04
Finding summary
ID
Finding
Severity
Priority
Status
NC-01
Privileged access lacks a required second factor
High
Immediate
Open
NC-02
Account recovery controls need stronger verification
Medium
Near term
Open
NC-03
Security response-header baseline is incomplete
Low
Planned
Open
NC-04
Asset-owner inventory is incomplete
Informational
Program
Open
05
Detailed finding example
NC-01
Privileged access lacks a required second factor
High
Affected area
Fictional administrator portal
Risk theme
Identity and access management
Validation
Safely confirmed with approved test role
What we observed
Within the authorized sample scope, an administrative access path did not consistently require a second authentication factor. No credentials, user data, or production changes were accessed for validation.
Why it matters
If a privileged credential is compromised, the missing control may increase the likelihood of unauthorized administrative access and changes to customer-facing services.
Recommended remediation
Require phishing-resistant multi-factor authentication for all privileged accounts.
Review administrative role assignments and remove inactive or excessive access.
Alert on unusual privileged authentication events and verify the control in a retest.
Evidence in a real report
A real report would include a minimally sufficient, redacted evidence reference, the affected asset, timestamps, validation notes, and any agreed control mapping. Sensitive details remain restricted to authorized recipients.
06
Remediation roadmap
0–14 days
Contain high-risk exposure
Address privileged access requirements, verify account ownership, and record accountable remediation owners.
15–45 days
Strengthen controls
Improve recovery controls, baseline security headers, and update monitoring or alerting where relevant.
46–90 days
Prove progress
Retest agreed fixes, collect evidence, update risk decisions, and communicate residual risk to leadership.
07
Compliance context
Where requested, a CyberClaw report can identify related control areas for the client’s selected framework. This supports remediation planning; it is not a certification, audit opinion, or legal conclusion.
This sample reflects a point-in-time, limited-scope assessment. Security testing cannot identify every issue, and untested systems, time constraints, configuration changes, or new threats can affect results. A real engagement records these limitations explicitly.