Remediation

Track and resolve findings. Mark remediation or request CyberSecurer validation.

Demonstration data — not a real security assessment. The customer portal shows the application experience; live data appears when integrations are connected.

No AI acceptable-use policy

Critical

AI Security · Owner: Security Lead · Due: 2026-10-15

Description

No documented policy governing AI usage.

Business impact

Uncontrolled AI usage may expose sensitive data.

Recommended remediation

Establish an AI acceptable-use policy and inventory AI usage.

MFA not enforced for admins

High

Identity · Owner: IT Admin · Due: 2026-10-22

Description

Administrator accounts lack enforced MFA.

Business impact

Privileged accounts are exposed to credential attacks.

Recommended remediation

Enforce MFA for all administrator accounts.

DMARC not configured

High

Email · Owner: Email Admin · Due: 2026-10-20

Description

No DMARC policy on primary domain.

Business impact

Domain spoofing and phishing risk.

Recommended remediation

Configure DMARC with enforcement policy.

No offline/immutable backups

Critical

Resilience · Owner: Infrastructure · Due: 2026-10-30

Description

Backups are not offline or immutable.

Business impact

Ransomware recovery may fail.

Recommended remediation

Implement offline/immutable backups and test recovery.