Skip to main content

Fictional sample MSSP report

Northstar Managed SOC (fictional)

Example Manufacturing LtdBuyer / ClientMethod 1.029 September 2026
This worked example is entirely fictional. It is generated from a versioned answer fixture and contains no customer record, report token, or private data.
54/ 100
Developing

Processes exist but are inconsistently evidenced. Monitor closely and close the material gaps.

Raw score: 81 / 150

How this score is calculated →

Decision summary

What this result should change

This fictional example shows how the score is translated into evidence requests and time-bound service actions. It does not describe a real organisation or provider.

Material findings

  1. 1.Detection coverage is described but not demonstrated through a current, environment-specific catalogue and validation record.
  2. 2.Tuning and continuous improvement are reactive, with no agreed review cadence or complete change history.
  3. 3.Reporting shows activity but does not consistently expose coverage gaps, service issues, or outcome trends.

Evidence gaps

  1. 1.Current use-case catalogue mapped to the monitored environment
  2. 2.Detection validation results and known coverage limitations
  3. 3.Tuning register, false-positive trend, and detection change log
  4. 4.Multi-period service report with gaps, issues, decisions, and owners

Priority actions

  1. 1.Ask the provider to produce the current use-case catalogue, validation evidence, and known gaps within 30 days.
  2. 2.Agree a monthly tuning review with false-positive trends, rule changes, decisions, owners, and due dates.
  3. 3.Replace activity-only reporting with a service review pack that records outcomes, material limitations, and remediation commitments.

Dimension breakdown

Read the individual answers and notes alongside each score. A strong average does not cancel a material key-control gap.

01

Onboarding & Discovery Rigour

21/25

Was a formal scope document agreed and signed off before monitoring began?

Yes

Did the MSSP produce a documented asset inventory and data source register for your environment?

Partial

Was a baseline period established before live alerting commenced?

Yes

Were named contacts and escalation paths documented on both sides at onboarding?

Yes
Partial: Did the MSSP produce a documented asset inventory and data source register for your environment?
Was a formal scope document agreed and signed off before monitoring began?
Was a baseline period established before live alerting commenced?
Were named contacts and escalation paths documented on both sides at onboarding?

Assessment notes

The scope is signed, but the asset and data-source register has not been reconciled since two acquisitions were integrated.

02

Detection Quality & Coverage

7/25

Can your MSSP provide a use-case catalogue mapped to MITRE ATT&CK?

Partial

Are detections tuned specifically to your environment beyond vendor-default rules?

No

Is there a documented process for you to request new detection use cases?

Partial

Does your MSSP proactively disclose detection coverage gaps?

No
Red flag: Are detections tuned specifically to your environment beyond vendor-default rules?
Partial: Can your MSSP provide a use-case catalogue mapped to MITRE ATT&CK?

Assessment notes

The provider discusses MITRE coverage but has not supplied an environment-specific use-case catalogue or recent validation results.

03

Triage & Escalation Process

18/25

Are SLAs defined by severity level — and do they cover investigation quality, not just response time?

Partial

Do alert records contain documented analyst reasoning for how each alert was assessed and closed?

Yes

Is there a documented escalation matrix with named contacts and clear escalation criteria?

Partial

Is after-hours and weekend coverage explicitly defined in your contract or SLA?

Yes
Partial: Are SLAs defined by severity level — and do they cover investigation quality, not just response time?
Do alert records contain documented analyst reasoning for how each alert was assessed and closed?
Is after-hours and weekend coverage explicitly defined in your contract or SLA?

Assessment notes

Analyst reasoning is visible, although investigation-quality measures and named customer alternates are incomplete.

04

Tuning & Continuous Improvement

6/25

Is there a formal tuning review process on a defined cadence (monthly or quarterly)?

No

Does your MSSP track and share false positive rate data with you?

Partial

Is a change log maintained for all detection rule modifications?

Partial

Can you point to measurable service improvement compared to the start of your contract?

No
Red flag: Is there a formal tuning review process on a defined cadence (monthly or quarterly)?
Partial: Does your MSSP track and share false positive rate data with you?

Assessment notes

Tuning is reactive. There is no agreed cadence, consolidated change log, or baseline showing improvement since onboarding.

05

Reporting & Client Visibility

10/25

Do operational reports include trend data across multiple periods — not just point-in-time snapshots?

Partial

Do reports proactively disclose coverage gaps, detection limitations, and service issues?

No

Are reports split into executive summary and technical detail?

Yes

Are reports delivered consistently on schedule without requiring you to chase?

Partial
Red flag: Do reports proactively disclose coverage gaps, detection limitations, and service issues?
Partial: Do operational reports include trend data across multiple periods — not just point-in-time snapshots?
Are reports split into executive summary and technical detail?

Assessment notes

Reports are readable but focus on ticket volume. Coverage gaps, service issues, and multi-period outcome trends are not consistently shown.

06

Commercial & Delivery Alignment

19/25

Does the service actually delivered match the scope and commitments in your contract?

Yes

Is there a documented change control process — and is it actually followed?

Partial

Are SLA credits calculated and applied automatically, or do you have to claim them?

Partial

Are exit terms and data return obligations clearly and fairly documented?

Yes
Partial: Is there a documented change control process — and is it actually followed?
Does the service actually delivered match the scope and commitments in your contract?
Are exit terms and data return obligations clearly and fairly documented?

Assessment notes

Core scope is being delivered. Change control and service-credit handling still depend on the customer raising the issue.

This report reflects the answers supplied. Verify material claims against current service evidence before making procurement, assurance, or risk decisions.