Reports
Every report is generated from the same live inventory, agent telemetry and simulation results.
34 pages
Risk Survey Report
Full regulatory risk survey with per-control answers and evidence trail.
12 pages
Gap Analysis Table
Control-by-control gaps with severity, affected assets and evidence source.
18 pages
Work Plan & Budget
Sequenced remediation programme including timelines, CAPEX and OPEX.
22 pages
Attack Simulation Report
Proven attack paths, blocked techniques and control effectiveness.
2 pages
Executive Brief
One-page posture summary for the board and risk committee.
Preview — Gap Analysis Table
| Control | Requirement | Finding | Severity |
|---|---|---|---|
| AC-3 | Enforce least-privilege access to controllers | 12 BMS controllers reachable from corporate VLAN | Critical |
| SI-2 | Timely firmware patching | 34 cameras running firmware with weaponized CVE | Critical |
| AU-6 | Centralized log review | OT segment logs not forwarded to SIEM | High |
| IA-5 | Authenticator management | Default credentials on 7 infusion pumps | High |
| SC-7 | Boundary protection between zones | Flat network between Plant North and IT core | High |
| CM-8 | Complete asset inventory | 18% of IoT devices unclassified | Medium |
| IR-4 | Incident handling playbooks | No OT-specific containment playbook | Medium |