1 finding
Address before routine improvements.
Public deliverable example · synthetic data
This demonstration shows how ClearGlass separates observed evidence, unverified controls, risk reasoning and recommended action.
In this fictional scenario, the largest avoidable exposure is account takeover: privileged identities do not have consistently verified phishing-resistant controls, and email authentication is not yet enforced. Remediation should begin with administrator identity controls, then DMARC rollout and incident ownership.
Address before routine improvements.
Plan owners and dates promptly.
Obtain evidence before judging effectiveness.
Decision for leadership: approve a named owner and a 30-day identity-and-email hardening plan. This recommendation is illustrative, not a statement about any real company.
Each finding distinguishes the evidence observed from the inference made. Confidence does not replace severity; it tells the reader how much evidence supports the conclusion.
Observation: the fictional evidence package contains an administrator-role export but no authentication-method or Conditional Access evidence.
Observation: the fictional domain maple-north.example is represented as publishing a DMARC policy of p=none. This is sample text, not a live DNS result.
Observation: the fictional policy index lists backup and acceptable-use documents but no named incident coordinator or current contact tree.
Observation: no restore-test record is included. Missing evidence is not treated as proof that backups fail or succeed.
Real reports vary with scope and available evidence. They do not promise a fixed number of findings or a risk-free environment. Read the published methodology for scoring, confidence and handling rules.