Illustrative deliverable

Sample Pen Test report

A fictional, sanitized example showing the format, evidence standards, and decision-useful detail of an authorized CyberClaw engagement.

CyberClaw — authorized security assessment

Northstar Pay
External Web Application Penetration Test

Report date: 9 September 2026
Classification: Confidential — sample

Engagement type
Authorized web application assessment
Testing window
Five business days
Assessment status
Complete — illustrative only
Prepared by
CyberClaw

01

Executive summary

CyberClaw performed an authorized assessment of a fictional customer-payment portal. The objective was to identify material security weaknesses within the approved external web application scope and provide a prioritized remediation plan.

Two findings require attention before the next production release. No critical-risk finding was validated within this sample scope. Results should be interpreted alongside the stated scope, testing window, and limitations—not as a guarantee that no other weaknesses exist.

0Critical
1High
1Medium
1Low
1Informational

02

Scope & rules of engagement

In scope

  • Fictional customer-payment portal and approved API surface
  • Authenticated buyer and administrator roles supplied for the engagement
  • Publicly exposed pages within the documented test window

Out of scope

  • Production disruption, denial-of-service, and load testing
  • Phishing, social engineering, physical security, and third parties
  • Persistence, data exfiltration, or testing outside approved assets

Testing begins only after written authorization, contact escalation paths, approved assets, time windows, and safeguards are confirmed.

03

Methodology & coverage

The approach is adapted to the agreed scope and risk profile. This example follows the planning, execution, analysis, and reporting principles described in NIST SP 800-115 ↗ and uses relevant web-application test areas from the OWASP Web Security Testing Guide ↗.

  1. Plan: confirm authorization, scope, testing windows, contacts, and stop conditions.
  2. Assess: review attack surface, authentication, authorization, session handling, configuration, and input-handling controls appropriate to the scope.
  3. Validate: verify material issues safely and record only the minimum evidence needed to support remediation.
  4. Report: prioritize risk, explain business impact, document limitations, and propose practical next actions.

04

Finding summary

IDFindingSeverityPriorityStatus
NC-01Privileged access lacks a required second factorHighImmediateOpen
NC-02Account recovery controls need stronger verificationMediumNear termOpen
NC-03Security response-header baseline is incompleteLowPlannedOpen
NC-04Asset-owner inventory is incompleteInformationalProgramOpen

05

Detailed finding example

NC-01

Privileged access lacks a required second factor

High
Affected area
Fictional administrator portal
Risk theme
Identity and access management
Validation
Safely confirmed with approved test role

What we observed

Within the authorized sample scope, an administrative access path did not consistently require a second authentication factor. No credentials, user data, or production changes were accessed for validation.

Why it matters

If a privileged credential is compromised, the missing control may increase the likelihood of unauthorized administrative access and changes to customer-facing services.

Recommended remediation

  1. Require phishing-resistant multi-factor authentication for all privileged accounts.
  2. Review administrative role assignments and remove inactive or excessive access.
  3. Alert on unusual privileged authentication events and verify the control in a retest.

Evidence in a real report

A real report would include a minimally sufficient, redacted evidence reference, the affected asset, timestamps, validation notes, and any agreed control mapping. Sensitive details remain restricted to authorized recipients.

06

Remediation roadmap

0–14 days

Contain high-risk exposure

Address privileged access requirements, verify account ownership, and record accountable remediation owners.

15–45 days

Strengthen controls

Improve recovery controls, baseline security headers, and update monitoring or alerting where relevant.

46–90 days

Prove progress

Retest agreed fixes, collect evidence, update risk decisions, and communicate residual risk to leadership.

07

Compliance context

Where requested, a CyberClaw report can identify related control areas for the client’s selected framework. This supports remediation planning; it is not a certification, audit opinion, or legal conclusion.

Example mapping fields

  • Selected framework and control area
  • Validated finding and evidence reference
  • Recommended remediation and owner
  • Target date, retest result, and residual risk

Example frameworks

08

Limitations & next steps

This sample reflects a point-in-time, limited-scope assessment. Security testing cannot identify every issue, and untested systems, time constraints, configuration changes, or new threats can affect results. A real engagement records these limitations explicitly.