Skip to content

Sample report

Read the report before you run one

This is a complete TrustQuant Resilience Report for a fictional, anonymised profile — annotated line by line so you know exactly what you, and the lenders, insurers and buyers you share it with, would be looking at.

IllustrativeWorked example — no live data, no real organisation.

Assessment subject

Illustrative
Sector
Professional services
Headcount
38 staff
Infrastructure
AWS (eu-west-2) + Microsoft 365
Collection method
Agentless · read-only APIs
Audit cadence
Weekly (Professional plan)
Reference
TQ-RR-2026-0917

A composite profile of a typical UK professional-services SME. Any resemblance to a real organisation is coincidental.

The report, annotated

Four blocks, in the order a reader meets them: scope, the rating, the factor evidence behind it, and the maths that connects them.

TrustQuant Resilience Report

Reference TQ-RR-2026-0917 · Assessment window: rolling, re-scored weekly

Illustrative

Subject

UK professional-services SME, 38 staff

Estate

AWS (eu-west-2) + Microsoft 365

Evidence

Agentless, read-only telemetry

Illustrative

Overall rating

82 / 100 — Resilient band

Strong, well-evidenced posture. Best-positioned for premium insurance and lending terms. The number is a weighted aggregate of six factor scores, each built from verified telemetry rather than self-attestation — so it can be trusted by someone who has never seen your infrastructure.

Shareable as a cryptographically signed Trust Passport.

Factor breakdown

Weights sum to 100

Access & Identity Controls

22% weight
86

MFA enforced on all privileged accounts; two dormant contractor accounts flagged for removal.

Host & Server Hardening

20% weight
82

Patch currency strong; SSH root login disabled; one staging host exposing a non-standard port.

Backup & Recovery Discipline

18% weight
79

Daily off-site backups verified; last restore test 11 weeks ago — recency window drifting.

Cloud Configuration & Exposure

18% weight
80

No public storage buckets; two security-group rules broader than required.

Data Protection & Encryption

12% weight
88

Encryption at rest and in transit across all stores; TLS current on every public endpoint.

Operational & Cost Hygiene

10% weight
74

Three orphaned volumes and one idle host — roughly £85/month reclaimable to fund remediation.

The maths, in the open

Resilience Rating = Σ ( weight_i × FactorScore_i )

= (0.22 × 86) + (0.20 × 82) + (0.18 × 79) + (0.18 × 80) + (0.12 × 88) + (0.10 × 74)

= 81.9 → 82 / 100

Each factor score is itself a priority-weighted roll-up of individual control findings, normalised to 0–100. Read the full methodology.

Downgrade alertIllustrative

Storage bucket set to public — eu-west-2

Detected on the scheduled weekly audit. A configuration change exposed a storage bucket to public access, affecting the Cloud Configuration & Exposure factor.

Factor score

80 → 58

Overall rating

82 → 78

Band

Resilient → Strong

Suggested fix: revoke public access on the bucket and re-apply the account-level block-public-access policy. The 18% factor weight means this single finding moved the overall rating by four points — and fixing it moves it straight back.

What the bands mean

Every reader interprets the same published scale — 82 lands in the Resilient band, the strongest position for insurance and lending terms.

0506580100
Resilient80–100

Strong, well-evidenced posture. Best-positioned for premium insurance and lending terms.

Strong65–79

Solid posture with minor, well-understood gaps to close.

Moderate50–64

Notable exposure. Prioritised remediation will move the score quickly.

At risk0–49

Critical gaps that materially raise financial and operational risk.

Who reads it

Three readers, one report

The same verified evidence, read three different ways. That is the point of a standardised rating — you assemble the proof once.

Commercial lenders

Reads first: Overall band + 90-day trajectory

A forward-looking risk signal that balance sheets miss. A stable rating in the Resilient band evidences low cyber-driven cash-flow risk; a downgrade is an early warning that arrives before the financial damage does.

Cyber-insurance underwriters

Reads first: Backup & recovery + access factors

Verified telemetry in place of a self-attested proposal form. Backup & recovery discipline and access controls carry particular weight — they are the factors that decide whether an incident becomes a claim.

Enterprise buyers & procurement

Reads first: Verification status + factor gaps

A standardised, comparable score instead of a 300-row questionnaire. Because every point traces to collected evidence, one supplier's 82 means the same as another's — the comparison is finally defensible.

The TrustQuant Resilience Rating is a designed, evidence-based model intended to help SMEs measure and improve their posture. It is not a credit score issued by a credit reference agency, and insurance or lending outcomes always rest with the relevant underwriter or lender.

How often it refreshes

A rating is only as trustworthy as its last refresh. Cadence is matched to your plan, and remediation is credited on the next pass — not next quarter.

Compare plans
Monthly scan

Starter

A full re-score every month — the baseline for a small footprint.

Weekly audit

Professional

Weekly re-scoring plus configuration-drift alerts between passes.

Continuous

Enterprise

Real-time monitoring — the rating moves the moment your posture does.

Now see it with your own numbers

The sample above is illustrative. Your report is built from verified telemetry — agentless setup in under 10 minutes.