One report, read two ways.
Every assessment produces a single document, layered so a board and an engineering team can both work from it without a second version and without a translator between them.
Risk register, ranked
The number, and how it was reached.
The register is the spine of the report. Each row is ranked by residual score and carries an owner, so a finding is something a named person can close rather than a line nobody holds.
What the document contains.
Executive summary
The risk picture and the decisions it points to, in plain language a board reads without a translator.
Ranked risk register
Every finding with its inherent and residual score, its owner and the reasoning behind the rating.
Threat model
The threats mapped with STRIDE and MITRE ATT&CK across each system in scope.
Control recommendations
Specific mitigations matched to the tools you already run, with new spend named only where it is genuinely required.
Remediation roadmap
A sequenced plan ordered by risk reduction per unit of effort, so the first item moves the number most.
Method and traceability
How each score was reached, so any rating can be challenged and answered with evidence.
See the standard applied in full.
Our satellite threat model is published with the same structure, so you can read the method before you commission it.