ClearGlass Inc. Clarity Is Power Ontario Security Quick-Audit

Public deliverable example · synthetic data

Sample Security Quick-Audit report.

This demonstration shows how ClearGlass separates observed evidence, unverified controls, risk reasoning and recommended action.

Synthetic demonstration — not a client report

Maple North Fabrication is fictional, maple-north.example is a reserved example domain, and every finding below is illustrative. No real organization, tenant, scan, client evidence or customer result is represented.

OrganizationMaple North Fabrication (fictional)
ScopePublic domain posture + supplied M365 evidence
Assessment dateIllustrative only
Report statusSynthetic sample · v1.0

Executive summary.

In this fictional scenario, the largest avoidable exposure is account takeover: privileged identities do not have consistently verified phishing-resistant controls, and email authentication is not yet enforced. Remediation should begin with administrator identity controls, then DMARC rollout and incident ownership.

High

1 finding

Address before routine improvements.

Medium

2 findings

Plan owners and dates promptly.

Not verified

1 control

Obtain evidence before judging effectiveness.

Decision for leadership: approve a named owner and a 30-day identity-and-email hardening plan. This recommendation is illustrative, not a statement about any real company.

Illustrative findings.

Each finding distinguishes the evidence observed from the inference made. Confidence does not replace severity; it tells the reader how much evidence supports the conclusion.

High · score 16/25

QA-01 · Privileged MFA coverage is not demonstrated

Observation: the fictional evidence package contains an administrator-role export but no authentication-method or Conditional Access evidence.

Risk
A compromised privileged account could enable broad tenant access and material operational impact.
Confidence
Medium — the evidence gap is confirmed; the actual control state is not.
Recommendation
Within seven days, export privileged roles and authentication coverage, remove unnecessary standing access, and require strong MFA for administrators.
Verification
Role export, authentication-method report and applicable access-policy evidence.
Medium · score 12/25

QA-02 · DMARC is monitoring but not enforcing

Observation: the fictional domain maple-north.example is represented as publishing a DMARC policy of p=none. This is sample text, not a live DNS result.

Risk
Without a staged enforcement plan, spoofed mail using the organization’s domain may be more difficult for recipients to reject.
Confidence
High within the fictional dataset.
Recommendation
Inventory legitimate senders, review aggregate reports, correct alignment, then progress deliberately toward quarantine and reject.
Verification
Current DNS records, authorized-sender inventory and DMARC aggregate reporting.
Medium · score 9/25

QA-03 · Incident escalation ownership is unclear

Observation: the fictional policy index lists backup and acceptable-use documents but no named incident coordinator or current contact tree.

Risk
Ambiguous authority can delay containment, communications and evidence preservation during an incident.
Confidence
Medium — the supplied index may be incomplete.
Recommendation
Name a primary and alternate incident lead, document escalation contacts, and run a short tabletop exercise.
Verification
Approved response plan, contact list and exercise record.
Not verified

QA-04 · Restore testing cannot be assessed

Observation: no restore-test record is included. Missing evidence is not treated as proof that backups fail or succeed.

Risk
Recovery capability may differ from documented backup intent.
Confidence
Low — control effectiveness is unknown.
Recommendation
Provide the latest restore-test result or conduct a scoped restore exercise with an owner, date and acceptance criteria.
Verification
Restore log, test record or service-provider evidence.

Evidence and limitations.

  • Read-only and point-in-time; no exploitation or security-control changes.
  • Only authorized assets and supplied evidence are considered.
  • Unseen systems, incomplete exports and later changes remain out of scope.
  • No certification, assurance opinion, legal advice or compliance attestation.

How to interpret this sample.

Real reports vary with scope and available evidence. They do not promise a fixed number of findings or a risk-free environment. Read the published methodology for scoring, confidence and handling rules.