01
What to include
- Use overall risk as a summary of the run and always show the target, scenarios, and date beside it. A score of 72 does not mean that 72% of the real system is vulnerable.
- For an eligible Starter+ run, include the evidence pack and related controls while stating that the mapping organizes review; it does not certify compliance.
- Compare equivalent runs to show resolved findings, new findings, and score changes. If scope changed, disclose that before presenting a trend.
02
Explain without turning a hypothesis into a fact
- Translate `attack_exposure` as exposure observed in the tested scenarios. Do not turn the score into a percentage of responses, users, or real incidents.
- Describe the asset and plausible consequence conditionally. Quantify customer data or revenue at risk only when a separate analysis supports the number.
- Show the before-and-after comparison and name the cases that were replayed. This communicates progress without claiming that every future variation is covered.