Skip to content
Reporting

Reports for the people who fix things and the people who sign off.

Two audiences read a penetration test report: engineers who need to reproduce and fix, and security or compliance stakeholders who need to understand risk and demonstrate remediation. Every CyberZ report is written for both.

Standard finding structure

Every finding, the same eleven fields.

Consistency makes reports scannable for stakeholders and actionable for engineers. Nothing is reported without evidence and a remediation path.

  1. 01Finding titleA precise, one-line statement of the weakness.
  2. 02SeverityCritical, High, Medium, Low or Informational — with the reasoning if adjusted from CVSS.
  3. 03CVSSBase score and vector so severity can be compared and re-evaluated.
  4. 04Affected assetExact host, endpoint, parameter or resource.
  5. 05DescriptionWhat is wrong and why it matters, in plain language.
  6. 06Technical impactWhat an attacker can do with it.
  7. 07Business impactWhat that means for customers, contracts and obligations.
  8. 08EvidenceRedacted requests, responses or screenshots proving the finding.
  9. 09Reproduction stepsNumbered steps an engineer can follow to see it themselves.
  10. 10RemediationConcrete fixes, ordered by effectiveness, plus defense-in-depth options.
  11. 11ReferencesPublic standards and guidance for further reading.
Anatomy of a finding

What a finding looks like in practice.

Taken from our fictional sample report. Real reports contain no sample data; sample reports contain no real data.

CYZ-DEMO-002Sample / fictional data
HighCVSS 8.1

Privilege escalation to Admin via invitation role tampering

Affected asset
POST /v1/invitations/accept
Description
The invitation acceptance request included the invited role as a client-supplied field. The server trusted this value instead of the role stored with the invitation.
Technical impact
A user invited as Viewer could accept the invitation with role=admin and obtain Admin privileges in the tenant.
Business impact
Unauthorized administrative access to tenant settings, billing details and member management.
Evidence (redacted, fictional)
POST /v1/invitations/accept HTTP/2{"token":"inv_3f9…","role":"admin"}HTTP/2 200 OK  {"membership":{"role":"admin"}}

Reproduction steps

  1. 1.As tenant Owner, invite a new user with role Viewer.
  2. 2.Intercept the acceptance request from the invited user and change role to admin.
  3. 3.Observe the resulting membership has the Admin role.

Remediation

  • Ignore client-supplied role on acceptance; derive the role from the stored invitation record.
  • Reject requests containing unexpected fields for this endpoint.

Retest result

Remediated

Role is now read from the invitation record only; tampered requests are rejected with 400.

Report contents

What a report may include.

Sections vary with the engagement type; the structure below is typical for application and API tests.

01

Executive Summary

Scope, dates, overall posture, headline findings and remediation status for non-technical readers.

02

Scope

In-scope and out-of-scope targets, accounts, environments and constraints as agreed.

03

Methodology

Which references applied (OWASP WSTG, ASVS, API Top 10, PTES) and how they were adapted.

04

Limitations

Time-boxing, environment differences and anything that constrained coverage.

05

Findings

Every validated finding in the standard structure, ordered by severity.

06

Risk summary

Counts by severity, status after retest and the themes behind the findings.

07

Remediation recommendations

Systemic recommendations beyond individual fixes.

08

Retest results

Per-finding status after remediation: remediated, partially remediated, open or risk accepted.

Delivery and handling

Reports are sensitive documents. They are handled that way.

Reports are delivered through an agreed secure channel, retained only as long as agreed, and never contain more data than needed to prove a finding. Details are on the Security & Trust page.

Next step

Request a security assessment.

Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.