Business Impact Report
Report version: v0.2.1
The Business Impact Report turns a technical scan, compliance or exposure, into a clear, non-technical story for leadership. Instead of a wall of findings, it explains what your security posture means for the business: what the risk score represents, how it changed since last time, what it could cost, which business units are most exposed, and which fixes to prioritize first. It is generated by AI and available in 24 languages.
Every report is grounded only in your own scan results. The narrative is written by AI from the findings of your scan and nothing else; all figures (trend, exposure ranges, projection, benchmark) are calculated deterministically from your data, never invented.
What the report contains
| Section | What it tells leadership |
|---|---|
| Executive scorecard | The score at a glance: pass rate, score ring, and the change versus the last scan. |
| Executive summary | A board-ready overview of your posture in plain language, no jargon required. |
| What your score means | A plain-language reading of your compliance percentage and the real-world exposure behind it. |
| Progress since the last scan | The change in score, with how many checks were fixed and how many regressed. |
| How you compare | An anonymized benchmark: your percentile versus the typical average for the same scan type. No individual tenant is identified. |
| What this could cost | Illustrative breach-exposure and regulatory fine ranges, with a clear disclaimer. |
| Business units at risk | The parts of your organization most exposed by the current findings. |
| Prioritized roadmap | The highest-impact fixes first, each with a suggested owner, effort, and a 30/60/90-day horizon. |
| What-if projection | The score you could reach by resolving the high-severity findings first. |
| Regulatory alignment | How findings map to GDPR, NIS2 and ISO 27001 obligations. Curated by our team, not generated. |
| Evidence | The check IDs the narrative is based on, so every claim is traceable. |
| Technical appendix | The full list of findings with severity and remediation, for the people who will do the work. |
Not every section appears on every report. Progress since the last scan needs a previous scan of the same type to compare against, and How you compare appears once enough comparable scans exist to form an anonymized benchmark.
Audiences
The same scan can be presented for three audiences; pick one in the report's preview header:
- Board (default): plain business language, outcomes over configuration.
- CISO: more technical, organized around control areas and attack paths.
- Auditor: compliance and evidence focused, aligned to GDPR, NIS2 and ISO 27001.
Switching audience regenerates the narrative in that lens. The figures stay the same; the framing changes.
Generating and viewing a report
Reports are generated on demand from the dedicated Business Impact Report page in the sidebar: nothing is produced automatically when a scan finishes. On that page, pick a completed scan from the Generate for scan list and click Generate report. Generating a report uses one credit (see Report credits below). A scan reported before v0.2.1 re-renders once into the new format on first view.
Once the report exists it appears in the report list on the same page. Use Download to save the PDF. The audience (Board, CISO, Auditor) is chosen when the report is generated; generating again for a different audience produces a fresh PDF.
The report language comes from your account Settings (the reports and email language), so every report uses one consistent language; there is no per-report language picker. A report is generated once per scan, language and audience, then cached. A scan whose results are unchanged from the previous scan reuses the existing narrative. A report cannot be deleted on its own; it is removed only when its scan is deleted, which also clears the underlying PDF.
Delivery
Scans run on your plan's schedule. When a scan completes you get a completion email. Reports are not produced automatically: open the Business Impact Report page, pick the scan you want, and click Generate report, whenever you need it.
Languages
The report is generated directly in your account language, set in Settings (the reports and email language), not machine-translated after the fact. All 24 languages are supported; to change the language of future reports, update it in Settings. Technical terms (CIS, EIDSCA, MFA, and similar) stay in English so they remain precise; the surrounding prose is written naturally in the chosen language.
Report credits
Business Impact Reports use a simple credit system. Generating one report uses one credit, and you can see your balance, buy credits, and review your usage on the Business Impact Report page.
- With an included allowance: your subscription may include a monthly BIR credit allowance. Generating a report draws from this allowance, which resets at the start of each billing month; unused monthly credits do not roll over. Need more in a given month? Buy additional credits, which never expire.
- Without an included allowance: buy credits first from the Buy credits section, then generate. Purchased credits never expire.
Credit pricing depends on your subscription and is arranged with your MSP or MSSP partner. Credit purchases appear on your Billing page.
Data protection and AI
The report is generated by AI that runs entirely within EU data boundaries, in the data region you chose at sign-up. Your data is never used to train, fine-tune or improve any AI model. The AI is invoked only to generate your report, in the moment, for you. This use of AI is transparent, kept under human oversight, and aligned with the EU AI Act. See Data Protection for the full picture.