CyberSafe.Now

CONFIDENTIAL

Renewal Evidence Summary for Northwind Creative Co.

Prepared by CyberSafe.Now

Program evidence for Northwind Creative Co.

Generated

Open failures

This section lists required controls whose finding is fail as of this snapshot. The list is empty when no required control is failing.

Failed required controls: 1

Open failures

This section lists required controls whose finding is fail as of this snapshot. The list is empty when no required control is failing.

Internet exposure

This section reports the results of the latest scan of the subscribed public hostname, including open ports and findings.

Target: northwind.example — Pass ·

Open ports: 80, 443

TLS hygiene

Port 443: Pass · TLS 1.3 · expires in 64 days

Identity & SaaS posture

This section reports the latest connector findings for identity and SaaS controls on the subscribed platform.

Platform: Google Workspace · last sync

Control Finding Evidence
Multi-Factor Authentication (MFA) Enforced for All Users Pass Users without MFA: 0
Super Admin Count Within Policy Pass Super admin count: 2
Drive External Sharing Posture Fail Sharing capability: External allowed

Backup posture

This section records the declared backup method, compliance evidence archive status, and data-backup policy review state.

Compliance evidence archive: Enabled

Backup method (declared): Cloud vendor

Last evidence pack:

Data backup policy past due for review: No

Evidence pack contents: Tenant exports, report snapshots, and connector metadata

Endpoint enrollment

Active devices: 8 / 8

Last sync:

Artifact history

This section lists staff reviews and company policy uploads on file, with review-due dates where recorded.

Uploaded company policies

Policy Uploaded by Date File
Data backup policy Dana Ortiz data-backup-policy.docx
Incident response policy Dana Ortiz ir-policy.pdf

Company policies expected for this service tier

Assure Plan expects 11 company policies. 2 are on file.

Policy Required Provided to CyberSafe.Now On file
Dual control for payment changes Yes No —
Acceptable use policy documented Yes No —
Data handling and classification policy documented Yes No —
Password and access control policy documented Yes No —
Information security program policy documented Yes No —
Incident response policy documented Yes Yes ir-policy.pdf (Dana Ortiz, )
Remote work security policy documented Yes No —
Third-party and vendor risk policy documented Yes No —
Data backup policy documented Yes Yes data-backup-policy.docx (Dana Ortiz, )
Backup and business continuity policy documented Yes No —
Security awareness training policy documented Yes No —

Expected policies not provided to CyberSafe.Now

This section lists company policies on the current plan that have no adopted upload. Required policies in this list have no file on record.

Policy Control Required
Dual control for payment changes Dual Control for Payment Changes Yes
Acceptable use policy documented Acceptable Use Policy Documented Yes
Data handling and classification policy documented Data Handling and Classification Policy Documented Yes
Password and access control policy documented Password and Access Control Policy Documented Yes
Information security program policy documented Information Security Program Policy Documented Yes
Remote work security policy documented Remote Work Security Policy Documented Yes
Third-party and vendor risk policy documented Third-Party and Vendor Risk Policy Documented Yes
Backup and business continuity policy documented Backup and Business Continuity Policy Documented Yes
Security awareness training policy documented Security Awareness Training Policy Documented Yes

Adopted policy: Data backup policy

This section reproduces the extracted text of an adopted company policy. CyberSafe.Now retains this extract; original PDF or Word bytes are not stored.

Uploaded by Dana Ortiz as data-backup-policy.docx. Text is the latest extract CyberSafe.Now has on file (original PDF/Word bytes are not retained).

Northwind Creative Co. data backup policy.
Production tenant exports are copied monthly to encrypted object storage.
Dana Ortiz reviews restore tests each quarter and records the result.
Backup media leaving the office require dual custody.

Adopted policy: Incident response policy

This section reproduces the extracted text of an adopted company policy. CyberSafe.Now retains this extract; original PDF or Word bytes are not stored.

Uploaded by Dana Ortiz as ir-policy.pdf. Text is the latest extract CyberSafe.Now has on file (original PDF/Word bytes are not retained).

Northwind Creative Co. incident response policy.
Staff report suspected incidents to Priya Shah within one hour.
Do not wipe devices before insurer approval.
The owner notifies CyberInsure Claims at 1-800-555-0142.