Built from a demonstration environment, not client work
This is what you get when the work is done.
Every engagement ends with a written report. Rather than describe one, here is a full specimen: a Security & Compliance Snapshot for a fictional 18-person dental practice, built from a demonstration environment so you can judge the format and the depth before you spend anything.
Security & Compliance Snapshot
Regional dental practice · 18 staff · Specimen
Prepared by
Jordan Beck, CISSP-ISSEP
1 · Executive summary
The practice is subject to the HIPAA Security Rule and currently lacks a documented Security Risk Analysis, which is a mandatory annual requirement and the most common OCR audit finding. The review identified three high, two medium, and one low priority item. None indicate an active breach, and all are addressable within 30 to 60 days. A documented SRA plus the prioritized remediation below would move the practice from undocumented to defensible.
Plain-language takeaway: you are not in trouble today. If OCR or a breach knocked tomorrow, the missing risk analysis is the gap that hurts, and it is the highest-value first fix.
2 · Compliance mandate status
| Framework | Applies | Status | Required artifact |
|---|---|---|---|
| HIPAA Security Rule | Yes | No documented SRA on file | Annual Security Risk Analysis + remediation plan |
| HIPAA Privacy Rule | Yes | Partial; policies outdated | Updated policies + workforce training records |
| PCI-DSS | Conditional | Not assessed | Correct SAQ + attestation |
3 · Prioritized findings
Business risk: The most common OCR audit finding; direct penalty exposure
Recommendation: Conduct and document the SRA
Business risk: No accountability; easy lateral movement
Recommendation: Unique accounts, least privilege, MFA
Business risk: Ransomware could be unrecoverable
Recommendation: Implement and test offline or immutable backups
Business risk: Phishing is the top small-business breach vector
Recommendation: Quarterly micro-trainings
Business risk: Exposure to known, already-fixed vulnerabilities
Recommendation: A defined patch cadence
Business risk: Larger attack surface than the practice needs
Recommendation: Segment the networks
4 · Method and data handling
- Non-intrusive review of configuration, policy, and posture against the applicable framework. No exploitation, no disruption.
- Analysis performed on JBeck Cyber equipment for the duration of the engagement; nothing sent to third-party cloud services, and nothing retained after close.
- Conducted under signed, scoped authorization. Findings reflect point-in-time observations.
This specimen is a professional starting framework, not legal advice, and every figure in it is illustrative. A real engagement populates findings from your environment.