Sample deliverable

What a Vranor assessment actually gives you.

This illustrative extract shows how we turn technical evidence into business impact, clear ownership, and remediation that can be tracked to closure.

Vranor · Confidential

Security & AI Risk Assessment

Executive report · Northline Payments Ltd

Illustrative client
12 employees · AWS · Microsoft 365
Assessment window: 7 working days
Overall exposureElevated
Findings1 Critical · 2 High · 1 Medium
Immediate priorityPrivileged identity
Executive assessment

Security fundamentals are present, but three control gaps materially increase the likelihood and impact of an account compromise or data-handling incident.

The most urgent issue is privileged access to Microsoft 365 without enforced multi-factor authentication. Data-governance and AI-use practices also need formal control. These are addressable weaknesses: the recommended 30-day programme focuses first on identity, then data and AI governance, followed by resilience validation.

Priority findings
CriticalVR-01 · Identity
Target · 7 days

Privileged Microsoft 365 access can be compromised with a password alone

Evidence

Two Global Administrator accounts and one billing administrator account were observed without enforced MFA. Conditional Access does not currently protect privileged roles.

Business impact

Compromise of one privileged credential could give an attacker control of email, identity, billing, and security configuration, creating a credible path to business-email compromise and broader tenant takeover.

Required action

Enforce phishing-resistant MFA for all privileged roles, remove standing administrator access where it is not required, and establish two emergency access accounts with monitored use.

Owner · Technology Lead
HighVR-02 · Data protection
Target · 14 days

The organisation cannot demonstrate where all customer personal data is stored or retained

Evidence

Customer information is processed across the application database, support tooling, cloud storage, and exported spreadsheets. No current processing inventory or retention schedule was available.

Business impact

The company may retain personal data longer than necessary, struggle to respond accurately to customer or regulatory requests, and expose more data than intended during an incident.

Required action

Complete a processing and data-flow inventory, assign system owners, define retention periods, and remove unmanaged exports from normal operating workflows.

Owner · Operations Lead
HighVR-03 · AI security
Target · 14 days

Staff can submit company and customer information to unapproved generative-AI tools

Evidence

Interviews identified routine use of public AI assistants for drafting, analysis, and code support. No approved-tool list, input restrictions, or review requirements are defined.

Business impact

Confidential information, credentials, source code, or personal data may be disclosed to third-party AI services without appropriate review or contractual safeguards.

Required action

Publish an interim AI acceptable-use standard, prohibit sensitive inputs to unapproved tools, define approved services, and require human review for material outputs.

Owner · COO
MediumVR-04 · Resilience
Target · 30 days

Backups exist, but recovery has not been proven

Evidence

Automated backups are configured for production data; however, the team could not provide evidence of a recent restoration test or a documented recovery objective.

Business impact

A backup that cannot be restored within business requirements may extend an outage or data-loss event at the point the company most depends on it.

Required action

Run and document a restoration exercise for a critical data set, define recovery objectives, record the result, and schedule recurring restore tests.

Owner · Engineering Lead
30-day remediation plan
Days 1–7

Protect privileged identities, review administrator roles, and establish emergency access.

Days 8–14

Map personal-data flows and deploy interim AI-use controls.

Days 15–30

Test recovery, close evidence gaps, and hold a management review of residual risk.

What leadership receives
Executive risk summaryEvidence-backed finding registerNamed owners and target dates30-day remediation planEvidence checklistClose-out review

Illustrative only. A commissioned report is based on evidence collected from the client's actual environment and is confidential to that organisation.

Request an assessment →