What the customer receives

ShieldCheck example report

The paid deliverable is a structured document the customer keeps, not a chat transcript.

A complete sample document, written the way ShieldCheck writes one. The customer, the numbers and the sources are illustrative.

ShieldCheck Security baseline audit

Security Baseline Audit · USD 89

Better than you expected, with two gaps that matter

Eleven control areas reviewed from supplied evidence. Nine are in reasonable shape for your size. Two are not.

Prepared for
Halliday Works · 19 people, SaaS, first security review
Reference
SC-4418-SBA
Issued
6 October 2026
Settlement
$SHLD · USDC on Base

You came in expecting to be told everything was wrong. It is not. For a 19 person company that has never done this, the baseline is better than most, and this audit is short because there is not much to say about the parts that work. Two findings are genuinely serious and both are fixable this month.

Two critical, nine adequate

Offboarding and backup restore testing are the two real gaps. Nobody has ever tested whether your backups restore, and three former contractors still have active access to production tooling. Everything else is proportionate to your size and stage.

11 Control areas reviewed
2 Critical findings
3 Former contractors with live access
0 Backup restores ever tested
01

Scope

What was reviewed, and what was not

Evidence suppliedReviewedGap
Identity provider user and group export Yes None
Cloud IAM policy export Yes None
Backup configuration screenshots Yes No restore evidence
Device management report Yes None
Vendor list with data categories Yes None
Incident response document Yes None
Secrets management description Yes None
Logging and alerting config Partial Retention period not stated
Network architecture Described only No diagram supplied
02

Summary

Control areas at a glance

Eleven control areas against what is proportionate at 19 people
StatePriority
Multi-factor authentication Enforced everywhereNone
Password and secrets management Managed, adoptedNone
Device encryption All 21 devicesNone
Production access control Role based, sensibleNone
Offboarding No process existsCritical
Backup configuration Configured correctlyNone
Backup restore testing Never performedCritical
Logging and retention Logging on, retention unclearHigh
Vendor review InformalMedium
Incident response Document exists, untestedMedium
Security training NoneLow at this size

Six areas need nothing. That is unusual for a first audit and worth saying plainly: whoever set up your identity and device management did it properly, and you should keep doing whatever that was.

03

Findings

The two that matter

#FindingWhy it mattersSeverity
F1 Three former contractors retain active accounts, two with production database read access. Last active 4, 7 and 11 months ago. Access that nobody is monitoring, held by people with no current relationship and no contractual obligation to you. Critical
F2 Backups are configured and have never been restored. No documented restore procedure and no recorded restore time. An untested backup is an assumption. The failure mode is discovering during an incident that the restore does not work or takes two days. Critical
F3 Log retention period not documented and appears to default to 30 days in two systems Thirty days is shorter than the typical time to discover an incident. You would have no record of how it started. High
F4 No vendor review before adopting tools that process customer data. Eleven such vendors identified. Common at your size and increasingly asked about by enterprise customers during procurement. Medium
F5 Incident response document names a person who left in March The document is otherwise sound. It has simply not been read since it was written. Medium

F1 and F2 together are the whole urgency of this report. Both can be closed in a working day, and neither requires a budget.

04

Remediation

Ninety days, in priority order

  1. This week

    Revoke the three contractor accounts

    Check access logs for the last 12 months on all three before revoking, so you know whether anything was accessed after the engagement ended. Then revoke, and record that you did.

  2. This week

    Write a four line offboarding checklist

    Identity provider, cloud console, code repository, password manager. Four lines in a shared document, triggered by anyone leaving. This is the whole fix for F1 recurring.

  3. Within two weeks

    Restore a backup to a scratch environment

    Actually do it, time it, and write down how long it took and what broke. Until this has been done once, your recovery position is unknown rather than good.

  4. Within a month

    Set and document log retention

    Twelve months where the cost allows, ninety days as a minimum. Write the number down so the next audit has something to check against.

  5. Within 90 days

    One page vendor review, applied to new tools only

    Do not try to retrospectively review eleven vendors. Apply it from now on and pick up the existing ones at renewal.

  6. Within 90 days

    Read the incident document aloud in a meeting

    Thirty minutes, whole team. Fix the names as you go. A tabletop exercise is the grown-up version and this is the version a 19 person company will actually do.

ShieldCheck security baseline · not a penetration test · confidential to the buyer · 6 October 2026 ShieldCheck · $SHLD
The order behind this document
Format

Structured document with tables, checklists and cited evidence.

Back to ShieldCheck →