Phase 5 · The Handoff

The one-page handoff

This is what the job actually produces — not clever attacks, but clear documentation someone can act on. One page, for a non-technical director who does not know what a VLAN is.

Fill in the three sections. Draft with your tutor bot, then edit hard until a busy director could read it in two minutes and know what to do Monday.

What we set up

In plain language — no jargon. What does the network do now that protects them?

Example shape

"We separated your network into four walled-off sections so that a problem in one — say, a visitor's laptop on the guest wifi — can't spread to your staff computers, your cameras, or your phones. Guest wifi is now completely isolated from everything staff use."

What we found

The exposure. What did the recon turn up, and what did the network's own monitoring catch? Specific but not alarming — you're informing, not scaring.

Example shape

"A lot of detail about your technology is public — a job posting lists your exact systems, and a conference talk mentions a shared password for your network gear. Separately, our monitoring detected and flagged a simulated scan of the network — the system is watching, and it works."

What we recommend

Concrete, prioritized, jargon-free. Three items maximum. Each one is something a small nonprofit could actually do.

1.

2.

3.

The test before you submit

Hand this to someone who wasn't in the room. If they can tell you what Marrowfield should do first, and why, without asking a question — it's done. If they say "what's a VLAN?" — edit again.

Why only three recommendations

You'll want to list everything you found. Don't. Picking the top three is the skill — a director will act on three items and ignore ten. The segmentation you describe under "What we set up" is the exact thing you built in Phase 1: you configured it, watched it, tested it, and now you explain it. This report closes the loop on the whole day.