Will the report just contain technical scanner output?
No. The specification explicitly requires a plain-English executive explanation, supported by technical evidence and practical recommendations.
Understand / Explain / Recommend
The initial AI Defence security report is designed to explain what was examined, what was found and what should happen next. It combines a plain-English executive explanation with technical evidence, prioritised recommendations and the information a customer needs before authorising changes.
The report must state what was examined, which evidence was available and where inspection was incomplete. Secure configurations and insecure findings both belong in the account, but a check that could not run must not be represented as a pass.
Findings are organised into critical, high, medium and low priority with context. The report should explain why an issue matters, what an attacker could potentially gain and how strong the supporting evidence is. An inferred weakness, a confirmed exposure and a verified compromise require different language.
A material finding needs a clear affected asset, evidence, explanation, recommended action and expected outcome. The customer also needs the likely impact, possible downtime and recommended order of work. Dependency and access concerns should be visible before a change is approved.
For example, an exposed database may justify restricting network access. The recommendation should identify legitimate application, replication and backup connections that must survive. The executive explanation can describe the business consequence while the technical record preserves the exact rule or configuration evidence.
The intended workflow records authorised actions and retests after remediation. Findings should therefore retain a distinction between recommended, authorised, attempted and verified. An unsuccessful or inconclusive check must remain visible.
After the agreed work, the accepted environment state becomes a baseline for future monitoring. Approved exceptions should carry enough context for future reviewers to understand why a remaining risk was accepted. This approach supports operational decisions; it does not imply an accredited certification, independent attestation or a guarantee of compliance.
No. The specification explicitly requires a plain-English executive explanation, supported by technical evidence and practical recommendations.
No. Examples on this website illustrate the workflow. They are not customer scans, measured detection results or evidence that an environment has been assessed.
Start with understanding
Discuss the assessment scope, current capabilities and the control you need with Altari Systems.