Executive summary
Example Office has an unused staff portal that is still accessible from the internet. The business has not confirmed who maintains it or whether its accounts, software and security alerts are being managed. This is the main exposure requiring management attention.
If old credentials still work or the portal contains an exploitable weakness, an attacker could gain access to the information it holds. Without effective monitoring, that access could go unnoticed. Any route from the portal into other business systems remains unverified.
Public finance instructions and technical documents also provide details that could help someone impersonate a supplier or IT support contact. Successful deception could lead to a diverted payment, disclosure of information or unauthorised access.
Recommended decisions
- Assign an owner to the portal. Have the IT provider establish its dependencies and propose how to restrict or retire it safely.
- Approve replacement of the outdated finance guide and removal of unnecessary technical details. Confirm how staff verify payment changes and support requests.
- Assign responsibility for keeping public services and documents current.
The review records four open findings: one High, two Medium and one Low. It identifies opportunities for misuse; it does not establish that the business has been compromised.
How to read the references
Reference codes connect the report's records so you can trace a conclusion back to its source. The numbers distinguish individual records; priority, confidence and completion status are stated separately.
- Exposure finding EXP-01: An issue identified by the public exposure review. EXP-01 is the unused staff portal; EXP-02 to EXP-04 identify the other findings.
- Evidence EV-01: A supporting record, such as a page capture or owner-validation note. The evidence register explains each record.
- Positive observation OBS-01: Something worth retaining: the general business enquiry page. It is recorded separately from the open findings.
Colour key: Red act promptly · Orange needs attention; plan the fix · Green working, resolved or worth keeping. Each signal also carries its written label.
The report reference in the document details identifies the report as a whole. Client evidence references in these public examples are illustrative; no private evidence files are attached.
Scope and method
The example authorisation covers the public website, three agreed hostnames, two business profiles and six public documents. The owner’s objective is to understand what an outsider could learn without an account, with particular attention to payment fraud and forgotten services.
| Asset group | Coverage | Result / boundary |
|---|---|---|
| www.example.test, portal.example.test, files.example.test | 3 of 3 reviewed | Public landing pages, links and ownership discussion; no login attempts. |
| Website pages | 18 linked pages reviewed | Contact, staff, services, downloads and historic links; not an exhaustive web crawl. |
| Public documents | 6 of 6 agreed files reviewed | Visible content and document properties; two documents support findings. |
| Business profiles | 2 of 2 reviewed | Current business contact details compared with the website. |
| Staff and internal systems | Excluded | No personal profiles, private accounts, internal scanning or mailbox access. |
Work consists of public-page review, a check of the agreed domain records, document inspection, and a factual validation discussion with the office manager. Evidence is timestamped and mapped to the affected asset. Public availability is separated from inferred business risk: a login page alone does not prove weak passwords or a software vulnerability.
Rating method: High means a significant exposure requiring prompt management attention; Medium means a plausible business risk suitable for planned remediation; Low means limited direct impact or an administrative improvement. Confidence describes the strength of the supporting observation, not the likelihood of an attack. Actions are ordered by risk and dependency; implementation timing is agreed by the business and its provider.
Findings register
| Finding or observation / priority | Finding | Confidence | Proposed owner |
|---|---|---|---|
| Exposure finding EXP-01 · High | Unused portal remains publicly accessible | High for exposure; maintenance unknown | IT provider |
| Exposure finding EXP-02 · Medium | Public finance details could aid payment impersonation | High | Office manager |
| Exposure finding EXP-03 · Medium | Technical detail could aid support impersonation | High for publication; current accuracy unknown | IT provider + website editor |
| Exposure finding EXP-04 · Low | Old exposures can persist without scheduled review | Moderate | Business owner |
| Positive observation OBS-01 · Positive | General enquiry contact is appropriate | High | Office manager |
Detailed findings
Exposure finding EXP-01 · High · Open
Unused staff portal remains a potential entry point
Observation and evidence: EV-01 records a publicly accessible sign-in page at portal.example.test on 7 September at 09:20. EV-02 records the office manager's statement on 8 September that staff stopped using the portal in 2024 and that no current support contact could be located. The software version, patch state, remaining accounts, protection against repeated login attempts and monitoring arrangements were not established.
How this could be used: An attacker could try stolen or reused credentials, repeated password guessing, or a software exploit if a relevant weakness exists. Successful access could expose or alter records retained in the portal. Connections or shared privileges could give access to other systems, but those dependencies have not been checked.
If left unresolved: The login page remains reachable while nobody has demonstrated that the service is being patched, accounts are controlled or suspicious activity is reviewed. If those controls are absent, attempts or successful access could go unnoticed. The portal could become an unintended way into the business, with delayed discovery increasing the work needed to investigate, recover data and restore trust. This is a potential entry point, not evidence of an attacker-installed backdoor.
Recommended action: The IT provider should identify the hosting account, retained data, integrations and remaining users. Restrict access while that review is completed, subject to business dependencies. If redundant, preserve required records through an authorised administrator, retire the service and remove obsolete links and domain records. If it must remain, assign a maintainer, verify patch and account controls, and test that relevant login and administration events reach a named reviewer.
Implementation considerations: Confirm who can administer the hosting account, what business records must be retained and which systems depend on the portal. The business owner should approve any restriction, migration or retirement. Removing only the website link will not close the exposure.
Closure evidence: Repeat the external access check against the original hostname and any replacement route. Record evidence of retirement, or the approved business purpose, access restrictions, maintenance responsibility, patch status, account review and tested monitoring arrangements for continued use. Deleting a website link alone does not stop access to the portal.
Exposure finding EXP-02 · Medium · Open
Outdated finance guide could support payment impersonation
Observation and evidence: EV-03 is an illustrative extract from supplier-guide.pdf, retrieved 7 September at 10:05. It names a former employee and invites suppliers to email payment-detail changes. The office manager confirmed the contact is obsolete in EV-02. No mailbox or payment workflow was tested.
How this could be used: An attacker can reuse the published finance name, supplier wording and payment-change process to make a fraudulent request look familiar. If a supplier or staff member accepts replacement bank details without an independent check, a legitimate payment could be sent to the attacker.
If left unresolved: The obsolete guide continues to lend credibility to payment impersonation and direct people towards an outdated process. The business could lose money, spend time tracing payments and dispute who authorised the change. Whether existing callback and approval controls would stop the attempt was not tested; the owner must verify those controls as well as replace the document.
Recommended action: Replace the guide with a current role-based contact and instructions to verify payment changes using a previously trusted contact channel. Update the download link and ask the website provider to remove the superseded public file. The finance lead should check that the published process matches actual practice.
Verification: Have finance approve the replacement wording, revisit the original file URL and current download page, and retain the approved replacement. Record external copies that cannot be removed. Updating the publication does not, by itself, validate internal payment controls.
Exposure finding EXP-03 · Medium · Open
Published technical details could make a false support request credible
Observation and evidence: EV-04 records a linked project-handover.pdf on 7 September at 11:10. Its appendix includes internal server names, a remote-support product name and an author’s direct email address. These details have no identified customer-facing purpose. Their continued accuracy is unknown; no passwords were observed in the six reviewed files.
How this could be used: An attacker can quote the internal names and remote-support product to impersonate a knowledgeable colleague or IT provider. If that pretext persuades a person to disclose credentials, approve a sign-in or grant remote access, it could open access to business systems.
If left unresolved: The document continues to supply material for tailored support scams and reduces the research an attacker needs to do. A successful deception could expose information or interrupt work while accounts and devices are investigated. The published details do not themselves grant access, and their current accuracy and the effectiveness of staff verification procedures were not established.
Recommended action: The IT provider should decide whether the file needs to remain public. Replace it with a customer-facing version where needed, remove unnecessary metadata, and review related downloads for the same publication mistake. Do not republish the original as part of the remediation ticket.
Verification: The website editor should retain the approved replacement and show that the original URL no longer serves the sensitive version. Review the other scoped documents for similar disclosures. Third-party caches and already-downloaded copies remain a residual exposure.
Exposure finding EXP-04 · Low · Open
Unreviewed public information lets old exposures persist
Observation and evidence: In EV-02, the office manager described ad hoc website updates; no review register was supplied. Confidence is Moderate because this is based on the interview and documents provided, not a review of every business procedure.
How this could be used: After staff departures, supplier changes or service retirement, old contact details and exposed systems may stay published because nobody is scheduled to review them. Those stale details can continue supporting the payment and support impersonation scenarios above, while redundant services remain discoverable.
If left unresolved: Individual fixes may become outdated again and similar exposures can accumulate. The business may repeatedly pay to rediscover and remove the same classes of problem, with a longer period in which an attacker can use the information. This is a maintenance gap that prolongs other risks, rather than a demonstrated route into a system on its own.
Action and closure: Assign an owner to each domain, profile and download area. Establish a review process and trigger checks when key staff leave, suppliers change or a service is retired. Record what each review covers, have the owner approve the register, and retain evidence that the agreed checks were completed.
Positive observation OBS-01 · Positive observation
Keep the general business enquiry page
EV-05 records a current role-based enquiry address and business telephone number on the contact page. The reviewed page does not publish private residential details. Keep these useful contact routes and include them in the ownership review. Hiding ordinary business contact information would impede customers without resolving the findings above.
Action plan and dependencies
- Establish control of the portal: The business owner appoints an accountable owner. The IT provider confirms hosting access, remaining accounts, retained data and integrations, then proposes an access restriction or retirement approach. Escalate missing access or unclear dependencies to the business owner.
- Replace the misleading public documents: The office manager, finance lead and website editor agree the correct payment-change wording and remove unnecessary technical detail. Coordinate the publication changes and verify the original URLs so obsolete copies are not still being served.
- Complete the portal decision: Retire the service with approved records preserved, or document why it must remain and verify its access, patching and monitoring controls. A temporary restriction is a safeguard while that decision is completed, not the final outcome.
- Maintain and verify the changes: Create the public-content register, assign review ownership and agree the business events that trigger a check. Retain closure evidence and record any remaining risk for an authorised business decision.
The business and its provider agree implementation arrangements around access, approvals and operational dependencies.
Evidence register and limitations
| Evidence reference | Record / collected AEST | Supports |
|---|---|---|
| Evidence EV-01 | Portal landing-page capture · 7 Sep, 09:20 | Public accessibility only |
| Evidence EV-02 | Owner validation notes · 8 Sep, 14:00 | Service ownership, contact currency, review practice |
| Evidence EV-03 | Supplier guide extract · 7 Sep, 10:05 | Published finance contact and wording |
| Evidence EV-04 | Project document extract and properties · 7 Sep, 11:10 | Technical and author details |
| Evidence EV-05 | Contact-page capture · 7 Sep, 09:35 | Appropriate general contact details |
A client delivery would include an access-controlled evidence pack with original locations, collection times, file integrity records where appropriate, and a redaction record. This public example uses reserved .test names and deliberately omits original files. Evidence references here demonstrate traceability rather than linking to real captures.
The review is a point-in-time sample of agreed public information. Unlinked pages, private content, personal accounts, leaked credentials and archived third-party copies were not exhaustively searched. No exploitation, authenticated testing or compromise investigation was performed. An absence of findings in those areas must not be read as an assurance that they are safe.
Handover and closure
The proposed walkthrough covers the portal decision first, then document changes and ownership. The business owner confirms priorities; the IT provider and office manager confirm named action owners and achievable dates. Unresolved factual disagreements are added to the finding rather than silently removed.
Each action remains Open until the agreed verification evidence is reviewed. If a risk is accepted instead of fixed, record the approving business owner, reason, compensating measures and expiry date. Remediation work and any subsequent retest must be agreed separately; this example does not imply an ongoing monitoring service.
Delivery checklist: report and findings register; controlled evidence pack; action tracker; walkthrough notes; and a documented list of remaining questions. Version 1.0 is the initial illustrative issue, with no remediation or retest claimed.