Ethiack Docs

Executive Report

A management-facing report that consolidates all findings from a testing period into a clear picture of security posture and business risk.

The Executive Report is the primary deliverable Ethiack produces at the end of (or during) a security assessment engagement. It can be requested for continuous or on-demand tests, including Agentic Pentests, Expert Pentests, and Continuous AEV. It is a non-technical, management-facing document that consolidates all findings from a defined testing period into a single structured narrative.

Its purpose is to give the customer's leadership team a clear picture of their security posture, the business risk associated with identified vulnerabilities, and a prioritized path to remediation — without requiring them to dig into raw technical findings.

The report is classified TLP:AMBER, meaning it is intended solely for the customer organization and should not be distributed externally.

Report structure

1. Executive Summary

The opening section answers the three questions every stakeholder needs answered immediately: what was tested, what was found, and how bad is it?

1.1 Overview presents the total finding count broken down by severity (Critical, High, Medium, Low, Informative) and by status (open, triaged, informative). Four donut charts give a visual snapshot: all findings by severity, findings by status, open findings by severity, and all-time unfixed findings by severity. This multi-view approach separates noise (informative findings, already-fixed issues) from the residual risk the customer actually carries.

1.2 Business Impact translates technical findings into business language. Rather than listing CVEs, this section describes real-world attack scenarios — for example, how an attacker could chain an SQL Injection with unauthenticated access and a missing DMARC record to execute a full compromise. This is the section to share with a CISO or board.

1.3 Methodology documents the test coverage so the customer can understand what assurance the report provides. It lists the attack categories tested (subdomain enumeration, authentication, input validation, access control, etc.) aligned to OWASP Top 10 and OWASP ASVS. This is important for compliance and audit purposes — it demonstrates the depth of the assessment.

1.4 Timeline records the engagement start date, end date, duration in days, and total finding count. It serves as a factual anchor for the engagement and is useful when tracking security improvement over time across multiple reports.

2. Scope Summary

This section defines the boundaries of the assessment — what Ethiack was authorized to test and what was excluded.

2.1 In-Scope Assets lists every asset that was actively tested (domains, wildcard domains, IPs, etc.).

2.2 Out-of-Scope Assets documents what was excluded, ensuring both parties agree on what was not covered.

2.3 Constraints notes any rules of engagement imposed — rate limits, time windows, authentication restrictions.

2.4 Coverage quantifies tested vs. untested assets. A low coverage ratio means the customer's true attack surface is larger than what this report reflects.

2.5 Limitations captures anything that reduced testing effectiveness — blocked IPs, login-wall barriers, unavailable environments. Customers should read this carefully before treating the report as a complete security clearance.

3. Service Breakdown

A summary of the network services discovered across in-scope assets (e.g., HTTP on port 80, HTTPS on port 443). This gives the customer visibility into their exposed attack surface at the infrastructure level — useful for network hardening and firewall policy reviews.

4. Roadmap

4.1 Mitigations and Improvements is the actionable core of the report. Findings are grouped by severity tier and paired with concrete remediation guidance:

  • Critical findings (e.g., SQL Injection) — immediate code fixes, parameterized queries, WAF deployment
  • High findings (e.g., XSS, SSRF, unauthenticated access) — patch updates, access control review, input validation
  • Medium/Low findings — endpoint hardening, header policy, patch management

Beyond specific fixes, this section recommends systemic improvements: secure development training, least-privilege principles, formal patch management, and continuous penetration testing.

5. Final Remarks

A qualitative narrative that synthesizes the engagement holistically. It calls out patterns — such as recurring input validation failures that suggest a systemic gap in secure development practices — and reinforces urgency on the most critical items.

Appendices

Appendix A — Glossary defines all technical acronyms used in the report, making it accessible to non-technical readers without cluttering the main sections.

Appendix B — Out-of-Scope Assets provides the full list of excluded assets for traceability and audit purposes.

Value this report delivers

The Executive Report bridges the gap between Ethiack's technical assessment output and the business decisions the customer needs to make. It enables customers to:

  • Prioritize remediation investment based on actual business risk, not raw CVSS scores alone
  • Demonstrate due diligence to auditors, regulators, or insurers with a documented, methodology-backed assessment
  • Track security posture improvement over time by comparing reports across engagement periods
  • Communicate security risk to non-technical leadership without translation overhead
  • Identify systemic weaknesses that point to process gaps rather than one-off bugs

On this page