SAMPLE ASSESSMENT
Example AssessmentWhat a Forensic Horizon assessment tells you
The excerpt below is illustrative output produced for a mid-size enterprise. Figures, sources and findings are examples only and are not drawn from a real customer engagement.
Headline horizons
The three horizons, at a glance
Searchable Horizon
41days
Shortest window across sources that can be queried directly.
Recoverable Horizon
210days
Shortest window across sources that can be restored or exported.
Defensible Horizon
73days
Shortest window that would hold up under scrutiny, end to end.
Target
180days
Agreed with the organization during scoping.
Scenario reconstruction horizons
How far back each scenario can actually be reconstructed
| Scenario | Horizon (days) | Limiting evidence dependency |
|---|---|---|
| Ransomware | 180 | EDR process telemetry, retained 180 days |
| M365 or SaaS compromise | 365 | M365 unified audit log, retained 365 days |
| Data exfiltration | 93 | Firewall / proxy egress logs, retained 93 days |
| Persistent long-dwell compromise | 60 | Endpoint execution history, retained 60 days |
| Privileged account compromise | 88 | Directory service audit logs, retained 88 days |
| Insider threat | 120 | File access and DLP records, retained 120 days |
Horizon limiters
What is holding the horizon back
DHCP history
30 daysLimits historical IP-to-device attribution. Affects lateral movement, ransomware and data exfiltration scenarios.
Endpoint telemetry
90 daysLimits historical execution reconstruction beyond the current EDR window.
SaaS audit
180 daysLimits historical content-access reconstruction in SaaS platforms.
Evidence assurance by source
What was examined, and how confidently
| Source | Retention | Assurance | State |
|---|---|---|---|
| Identity (Active Directory / Entra ID) | 90 days | E3 | Present |
| Endpoint (EDR) | 90 days | E2 | Partial |
| DNS | 30 days | E2 | Partial |
| DHCP | 30 days | E1 | Partial |
| Firewall | 180 days | E3 | Present |
| VPN | 365 days | E3 | Present |
| M365 | 365 days | E4 | Present |
| SIEM archive | 365 days | E1 | Partial |
Assurance scale (E0-E4)
- E0Assertion only
Capability is stated but not examined.
- E1Documentation reviewed
Policy or configuration documentation examined.
- E2Observed
Evidence availability observed in the platform.
- E3Technically tested
Queries executed against historical data.
- E4Demonstrated
Demonstrated during controlled investigation or reconstruction exercise.
Improvement simulation
From 73 days to 180 days
- Current defensible horizon
- 73 days
- Projected defensible horizon
- 180 days
- Extend DHCP history
- Increase EDR retention
- Validate SIEM archive retrieval
Current state
- DNS retention
- 14 days
- Forensic Horizon
- 30 days
- Ransomware reconstruction
- 71%
Recommended change
Increase DNS retention
14 → 90 days
Single-source change; no additional log ingestion into the SIEM required.
Projected impact
- Forensic Horizon
- 30 → 58 days
- Ransomware reconstruction
- 71 → 76%
Projection based on measured dependencies.
What the report contains
Report contents
- Searchable, recoverable and defensible horizons
- Scenario reconstruction horizons
- Evidence assurance scores
- Missing sources
- Collection gaps
- Attribution gaps
- Integrity weaknesses
- Archive validation status
- Horizon limiters
- Prioritized remediation roadmap
- Executive-ready report
How far back could you prove what happened?
The figures above are illustrative. An assessment measures your own environment against the scenarios that matter to it.