Sample · two pages · fictional firm
This is what you get
The two-page attestation letter from an External Assessment, for a fictional firm, Hartwell & Bramley LLP. It is written to be forwarded to a client, an insurer or your managing partner. Your real report is specific to your systems.
Northloop Security
Independent External Security Assessment
Hartwell & Bramley LLP
hartwellbramley.co.uk
14 August 2026
This is an independent, point-in-time review of hartwellbramley.co.uk as seen from the public internet - the same starting point an attacker has. It summarises, in plain English, how the firm performs against the questions most commonly raised in client security questionnaires and cyber-insurance renewals. 7 internet-facing systems were reviewed.
Summary: 1 item needs attention.
| Email spoofing protection (SPF & DMARC) | NEEDS ATTENTION | No DMARC record found. Without it, an attacker can send email that looks like it comes from the firm - the mechanism behind wire-transfer ("Friday afternoon") fraud. An SPF record is present, but DMARC is the control that enforces it. |
| Exposed admin & login interfaces | PASS | No admin or login panels were found publicly exposed in the external footprint. The client portal sits behind the provider’s authentication. |
| Remote access exposure (VPN / RDP) | PASS | No exposed VPN/RDP endpoints were identified. Remote working goes through a managed cloud desktop with MFA enforced. |
| Known-vulnerable / outdated software | PASS | No high-severity known vulnerabilities were detected in the external checks. One server discloses its software version, which aids attackers and is worth suppressing. |
| Encrypted web traffic (HTTPS) | PASS | 3 of 3 responding hosts serve over HTTPS with valid certificates. Certificate expiry is monitored. |
| Leaked / breached staff credentials | NOT COVERED | Not covered by the free snapshot. Checked against breach data in the full assessment. |
| Lookalike / spoofed domains | NOT COVERED | Not covered by the free snapshot. Registered-lookalike detection is part of the full assessment. |
| Authenticated & internal testing | NOT COVERED | Out of scope for an external assessment. Available as a separate engagement. |
Prepared by Northloop Security. This report reflects the external, public-facing posture of the named domain at the date shown and is provided for the recipient’s use only. It is an assessment of observed exposure, not a certification, warranty, or guarantee of security, and does not cover internal systems or authenticated access unless separately engaged. Testing was limited to passive and non-intrusive checks of assets the client owns and authorised. Hartwell & Bramley LLP is a fictional firm; no real firm’s findings are shown.
Page two is the technical annex for your IT provider: each finding with the exact location, evidence and fix. See it in the PDF →
See yours.
Start with the one-second spoofing check, then take the full free snapshot from the result. The paid letter above starts from the same place.
Check my domainPrefer to talk it through first? Book 25 minutes