Sample
VELDTECH
Cybersecurity Evaluation Report
Business Onsite Assessment & Findings
- Prepared For
- Northgate Facilities Group
- Lead Assessor
- Stephen Veldhuizen, Founder
- Engagement
- Business Cybersecurity Evaluation (Onsite)
- Environment
- 38 employees, 41 endpoints, 2 servers
- Classification
- Confidential, For Client Use Only
Executive Summary
This report documents an onsite cybersecurity evaluation of the Northgate Facilities Group environment. Fourteen findings were identified across system configuration, network administration, security controls, and operational documentation. Three are rated Critical and should be addressed within 30 days.
The most significant exposure is that multi-factor authentication is available but not enforced on the Microsoft 365 tenant. Twenty-two of 38 accounts can currently be accessed with a password alone. Combined with the absence of endpoint detection and the flat network described in Finding 4, a single successful phishing email would give an attacker broad, largely unmonitored access.
Summary of Findings
| Area | Finding | Risk |
| Cybersecurity | MFA not enforced on 22 of 38 M365 accounts | Critical |
| Cybersecurity | No endpoint detection and response; built-in antivirus only | Critical |
| Network | Guest wireless shares a subnet with accounting systems | Critical |
| System Config | 9 workstations running Windows Home; cannot be centrally managed | High |
| Cybersecurity | All users hold local administrator rights | High |
| Cybersecurity | Microsoft 365 data not backed up; retention relies on Microsoft defaults | High |
| Cybersecurity | Third-party patching unmanaged; 6 systems more than 90 days behind | High |
| Network | Consumer-grade access points with no central management | Moderate |
| Help Desk | No documented vendor contacts or escalation path | Moderate |
Finding 4: Flat Network, No Segmentation
Observation
The guest wireless network issues addresses on the same subnet as the production network. A visitor device joining guest wireless can reach the file server and the accounting workstation without crossing any filtering boundary.
Analysis
Guest wireless is, by design, a network you allow strangers onto. Where no segmentation exists, the practical security of the accounting system becomes equal to the security of the least trustworthy device that has ever connected to guest wireless. This also affects the two networked printers, which are running firmware from 2021 and are reachable from every device in the building.
Recommendation
Implement VLAN segmentation separating guest, staff, server, and device traffic, with firewall rules permitting only required flows between segments. The existing firewall supports this; the work is configuration rather than hardware replacement.