Skip to content

Demonstration sample · full scan · 51 passed checks · 12 issues

Sample Company

Demonstration data only. This is not a live scan of EightScope or your domain. The interactive view and PDF both use the same synthetic full-scan fixture. Create a free account to scan your own domains.

sample-company.example

Complete

Full assessment13 July 2026 at 10:51 amDuration 1m 13s

Create free account

Security posture

Grade for this external assessment only. It does not cover internal systems, authenticated apps or penetration testing.

86/100

Grade A

Strong external posture

Assessment confidence: Legacy confidence unavailable

No previous comparable assessment

Finding summary

Critical
0
High
0
Medium
4
Low
8
Passed
51

Assessment details

26 modules in scope: 25 completed, 1 not assessed

Modules in scope
26
Modules completed
25
Modules not assessed
1
Modules failed
0
Assets discovered
13
Assets assessed
11
Scan duration
1m 13s
Scan completeness
complete

Executive summary

sample-company.example received a security score of 86/100. This assessment identified 12 open findings. 51 checks passed.

AI wording does not affect scores or severity. Scores remain determined by EightScope.

View Business Context

Recommended actions

Start with the actions most likely to reduce external risk.

  • 1
    medium

    Clickjacking protection missing (X-Frame-Options / frame-ancestors)

    app.sample-company.example

    Add X-Frame-Options: DENY (or SAMEORIGIN if you embed your own pages).

  • 2
    medium

    Content Security Policy (CSP) missing

    elements.sample-company.example

    Inventory third-party scripts (analytics, chat widgets, payment SDKs).

  • 3
    medium

    Cookie scoped too broadly

    sample-company.example

    Scope the cookie to the most specific host possible (omit Domain, or set it only to the exact application host).

No previous assessment to compare

Run another comparable Standard or Full assessment to begin tracking changes.

Assessment coverage

26 modules in scope: 25 completed, 1 not assessed

Modules in scope
26
Modules completed
25
Modules not assessed
1
Modules failed
0
Assets discovered
13
Fully assessed assets
11

Findings

Review affected assets, evidence and recommended actions.

Showing 12 of 12 findings

Total open
12
Critical
0
High
0
Medium
4
Low
8

Assets

Explore Domain, Hostname, IP, Service and Page targets with assessment status. Large inventories load page by page.

Showing 13 of 13 hostnames

Discovered
13
Reachable
13
Fully assessed
11
Needs attention
2

Discovery only (1)

Subdomains discovered without a full asset assessment record.

Assessment coverage and confidence

This explains how complete the assessment was. Incomplete work lowers confidence; it does not invent security findings.

Completeness
complete
Assessment confidence
Legacy confidence unavailable
Score status
final
Methodology
v2

By scope

ScopeStateCompletionAction
Detailed target coverage unavailable for this legacy assessment.

Modules

ModuleStateAssessed / expectedRetry
Module coverage summary unavailable for this scan.

Evidence

Structured evidence from assessment modules. Select a module for details.

Evidence summary

Review module outcomes across this assessment. Select a module on the left to inspect what was checked, observed values and related findings.

With findings

3

Passed

5

Not assessed

0

Failed / partial

0

Assessment snapshot

Domain
sample-company.example
Modules attempted
26
Module errors
0
Completeness
complete

Modules with findings

Tip: start with modules marked Findings, then review Passed modules for confirmation of what was checked.

No previous assessment to compare

Run another comparable Standard or Full assessment to begin tracking changes.

Run another assessment

Essential Eight external risk indicators

External risk indicators only. This is not an Essential Eight maturity assessment. ACSC assessments require scoped checks of control implementation and effectiveness inside your environment. EightScope can only report what is visible from the public internet.

External concern detected 1Partially assessed 0No negative external indicator detected 3Not assessable externally 4

User Application Hardening

External concern detected

  • No Content Security Policy. The site is more vulnerable to XSS attacks.
  • X-Content-Type-Options not set. Browsers may MIME-sniff responses.
  • No Referrer-Policy header. Behaviour falls back to browser defaults; an explicit header is recommended for consistency.
  • No Permissions-Policy header. Browser features are unrestricted.
  • X-Frame-Options not set. The site may be vulnerable to clickjacking.

Patch Applications

No negative external indicator detected

  • No public CVE matches or disclosed vulnerable application versions detected externally

Patch Operating Systems

No negative external indicator detected

  • No server OS version disclosure detected in banners or headers

Restrict Admin Privileges

No negative external indicator detected

  • No exposed admin panels or critical sensitive files detected

Multi Factor Authentication

Not assessable externally

MFA is enforced inside identity providers and applications. We cannot authenticate as your users or read IdP policy from the outside.

Application Control

Not assessable externally

Whitelisting runs on devices and servers. External scanning has no visibility into installed software policies or execution controls.

Restrict Office Macros

Not assessable externally

Macro settings are configured in Microsoft 365 admin centres and Group Policy. Not on your public website.

Regular Backups

Not assessable externally

Backups run inside your infrastructure. We cannot verify backup jobs, off-site copies, or restore drills from DNS/HTTPS checks alone.