Illustrative sample, not a scan of a real customer. These examples use checks available in the current product. They do not assert a score, scan date or verified compliance outcome.
Executive summary
Review the observed web, email and internal service settings with your IT provider. Confirm whether each service is required and whether a compensating control changes the appropriate action. Unassessed devices and checks remain visible in real reports.
Edge example: HSTS header absent
Evidence: the observed HTTPS response did not include Strict-Transport-Security. Action: confirm HTTPS works for the intended scope, configure an appropriate HSTS policy, then rescan. Do not enable subdomain coverage until those subdomains are ready.
Edge example: no DMARC record found
Evidence: no DMARC TXT record was returned for the checked domain. Action: inventory legitimate senders, confirm SPF/DKIM alignment and work with your email administrator on an appropriate DMARC rollout.
Core example: legacy TLS accepted
Evidence: a probed internal service accepted a legacy TLS negotiation. Action: establish which applications depend on that service, test modern protocol support and plan the configuration change. A needed service is not automatically an unnecessary exposure.
Regulatory references and progress
Selected reporting profiles add relevant cited references and applicability questions. One finding can relate to several references. Real reports include available source dates, assessment limits and observed changes between comparable scans. Fixes should be confirmed by follow-up evidence.