Example deliverables

See what useful security evidence looks like.

Inspect four non-confidential examples covering investigation, governance, validation and improvement planning. They show the expected structure, decision trail and ownership.

ARTIFACT 01 / SECURITY OPERATIONS

SOC investigation record

A synthetic impossible-travel alert carried from triage rationale through evidence review and a human containment decision.

Case
SYN-IR-2026-014
Severity
Medium, reduced to informational
Owner
Synthetic SOC analyst
Evidence boundary
Test identity and fixture logs only

Alert and hypothesis

  • Two synthetic sign-ins appeared in Auckland and Frankfurt test zones within nine minutes.
  • Initial hypothesis: compromised valid account or pre-approved identity simulation.

Evidence reviewed

  • Identity risk event IR-EVT-0031 showed one denied MFA prompt.
  • Device fingerprint TEST-DEVICE-09 matched the exercise register.
  • Exercise controller record EX-2026-07 confirmed the approved test window.

Decision record

  • Analyst recommended simulated session revocation pending controller confirmation.
  • Human incident lead rejected containment after validating the exercise record.
  • No live session, identity or policy was changed.

Follow-up

  • Add exercise-register context to the triage runbook.
  • Measure time from alert creation to exercise-controller confirmation.

Example status: Closed - benign exercise activity confirmed

ARTIFACT 02 / GOVERNANCE

CISO decision record

A synthetic vendor exception showing the evidence, options, accountable owner, expiry and review conditions behind a risk decision.

Decision
SYN-DEC-2026-008
Risk
Third-party recovery evidence gap
Accountable owner
Synthetic service owner
Authority
Human approval required

Evidence

  • Supplier provided a current security summary but no witnessed restore-test record.
  • Business service has a documented four-hour recovery objective.
  • Replacement within the current quarter would create a higher transition risk.

Options considered

  • Reject the supplier until restore evidence is available.
  • Accept indefinitely without additional controls.
  • Approve a time-limited exception with a witnessed restore test and alternate export path.

Decision

  • Approve the time-limited exception.
  • Service owner must witness a restore test by 31 August 2026.
  • Data owner must validate a documented export path and retain the result.

Review triggers

  • Missed evidence deadline.
  • Material supplier incident or service change.
  • Change to recovery objectives or data classification.

Example status: Approved with conditions - review due 30 September 2026

ARTIFACT 03 / SECURITY VALIDATION

Purple-team coverage report

A benign synthetic validation that separates observed evidence, missing signals and the owned detection work that follows.

Exercise
SYN-PT-2026-005
Technique
T1078 - Valid Accounts
Scope
Dedicated identity in test tenant
Method
Pre-agreed anomalous sign-in

Expected evidence

  • Identity sign-in event with test account and device fingerprint.
  • MFA outcome and session-risk change.
  • SOC alert linked to the exercise identifier.

Observed

  • Sign-in and MFA events arrived within two minutes.
  • Identity alert included source region and device context.
  • Exercise identifier was absent from the SOC case.

Gap and improvement

  • Gap: analysts had to consult the exercise calendar manually.
  • Improvement: enrich cases with active exercise windows and named controller.
  • Owner: detection engineering; target validation: 14 August 2026.

Safety record

  • Written scope and stop conditions confirmed before validation.
  • No production identity, confidential data or disruptive action used.

Example status: Validated with one telemetry improvement open

ARTIFACT 04 / IMPROVEMENT PLANNING

vCISO 30/60/90-day roadmap

A synthetic roadmap that turns an assessment baseline into sequenced work with owners, evidence and review points.

Organisation
Koru Services (synthetic)
Baseline
Moderate risk, 58/100
Top gaps
MFA, restore testing, supplier access
Review cadence
Fortnightly owner check-in

Days 1-30 - reduce immediate exposure

  • Require MFA for email, administrators and the domain registrar.
  • Name incident contacts and publish a hacked-mailbox checklist.
  • Record critical suppliers and current access paths.

Days 31-60 - prove recovery and ownership

  • Run a restore test for one critical business process.
  • Remove dormant supplier and leaver accounts.
  • Assign owners and due dates to the remaining baseline gaps.

Days 61-90 - validate and govern

  • Run a short incident tabletop using the updated contact list.
  • Review DMARC monitoring and decide whether enforcement is ready.
  • Present completed evidence, accepted risks and the next-quarter plan.

Measures

  • MFA coverage for important accounts.
  • Restore-test outcome and recovery time.
  • Percentage of critical suppliers with reviewed access and contacts.

Example status: Draft for accountable-owner review

Need evidence shaped around your environment?

A scoped review can turn your workflows, controls and obligations into an owned decision record and roadmap.

Discuss a review