Security Assessment Snapshot
Warden Assessment Report
This is an example of the deliverable a $299 Security Assessment Snapshot produces. Company, names, findings, and all details are entirely fictional and illustrative.
Company Profile & Assessment ScopeRef: WRD-SAMPLE-001
Sector
B2B SaaS / FinTech-adjacent
Infrastructure
AWS + managed Kubernetes
Assessment date
2026-08-15
Assessment Scope
External attack surface (public IPs + domains)Identity & access management postureCloud storage configurationPublic dependency hygieneMFA enrollment coverageTransport securityLogging & secrets hygiene
◈ All analysis conducted under agreed scope and explicit authorization from the named company. Warden does not access, scan, or investigate any environment without written authorization.
Prioritized Findings
Findings are ranked by composite priority score (Reachability + Exploitability + Business Impact, each scored 1–10). Scores reflect environment-specific context — a finding reachable from the public internet scores higher than the identical vulnerability behind 3 authentication layers.
#
Finding
Reachability
Exploitability
Business Impact
Priority
F-001
Unauthenticated Admin Panel Reachable from Public Internet
Exposed Admin Interface
Panel is indexed by Shodan, returns HTTP 200 without credentials, and exposes user management and billing controls — direct path to account takeover or data exfiltration.
CRITICALScore: 26
F-002
Long-lived IAM Access Keys Assigned to Production Service Account
Stale IAM Credentials
Keys are 14 months old with no rotation policy, carry S3 full-access and EC2 describe permissions, and have no associated MFA or usage monitoring — stolen keys enable persistent lateral movement.
HIGHScore: 22
F-003
Public S3-Compatible Storage Bucket Exposes Internal Build Artifacts
Misconfigured Storage
Bucket ACL is set to public-read; directory listing reveals build logs containing environment variable fragments and internal service hostnames useful for reconnaissance.
HIGHScore: 21
F-004
Critical Node.js Dependency with Known RCE (CVE-2024-XXXX) in Production
Unpatched Public Dependency
Package version in package-lock.json is two minor releases behind the patched version; the affected code path is exercised by the customer-facing file-upload endpoint.
HIGHScore: 21
F-005
MFA Not Enforced for 60% of Privileged Identity Provider Accounts
Weak MFA Coverage
IdP audit log shows 18 of 30 accounts with admin or billing roles have not enrolled MFA; password-spray or credential-stuffing attacks against these accounts have no second factor to defeat.
MEDIUMScore: 18
F-006
Outbound TLS Certificate Pinning Absent on Mobile API Client
Transport Security Gap
API calls from the mobile app use system root store without pinning; a network-positioned attacker (e.g. corporate proxy or rogue Wi-Fi) can perform an undetected MitM on PII-bearing endpoints.
MEDIUMScore: 15
F-007
Internal Logging Pipeline Captures and Stores Raw Authorization Headers
Sensitive Data in Logs
Structured-log middleware passes full HTTP headers to the log aggregator; bearer tokens visible in plaintext in log retention store create a secondary exfiltration surface if the logging service is compromised.
MEDIUMScore: 13
Recommended Actions — Top 2 Findings
Evidence-backed recommendations for the two highest-priority findings. Warden separates the recommendation from the authority to act — every action requires explicit authorization and agreed scope before execution.
F-001Unauthenticated Admin Panel Reachable from Public Internet
CRITICAL · 26/30Evidence basis
Panel is indexed by Shodan, returns HTTP 200 without credentials, and exposes user management and billing controls — direct path to account takeover or data exfiltration.
Recommended action
Immediately place the admin panel behind a VPN or allowlisted IP range and enable authentication on all admin routes. Short-term: rotate all admin credentials assuming exposure. Medium-term: introduce a dedicated admin subdomain with enforced MFA and no public DNS record — any public access to admin routes should return 404, not a login page.
◎Governance note: Warden provides recommendations and evidence — not execution. Acting on this finding requires your team to authorize, scope, and control the remediation. Warden does not take autonomous action in your environment without explicit written authorization.
F-002Long-lived IAM Access Keys Assigned to Production Service Account
HIGH · 22/30Evidence basis
Keys are 14 months old with no rotation policy, carry S3 full-access and EC2 describe permissions, and have no associated MFA or usage monitoring — stolen keys enable persistent lateral movement.
Recommended action
Rotate the access keys immediately and issue replacement keys with least-privilege scoping (read-only S3, no EC2 describe permissions unless operationally required). Implement a 90-day key rotation policy enforced via IAM policy, and attach usage monitoring alerts (CloudTrail or equivalent) to trigger on anomalous call patterns from service accounts.
◎Governance note: Warden provides recommendations and evidence — not execution. Acting on this finding requires your team to authorize, scope, and control the remediation. Warden does not take autonomous action in your environment without explicit written authorization.
What you get for $299
A Security Assessment Snapshot — delivered.
What you just read above is exactly what a real $299 assessment produces — scoped to your environment, grounded in evidence, ranked by what actually matters to your business.
◈
Company profile + agreed scope
Documented scope so you know exactly what was and wasn't included.
▲
5–7 prioritized findings
Each finding ranked by reachability, exploitability, and business impact — not just CVSS severity.
⊘
Evidence-backed rationale
Every finding links to the observable evidence that surfaced it.
◎
Recommended actions for top findings
Clear, actionable guidance — with governance separation between the recommendation and authority to act.
✓One-time $299 — no subscription✓Delivered within agreed timeline✓No autonomous access without authorization✓Fully scoped & governed