The DDactic Report Format: Built for the CISO's Question List

June 5, 2026 | 8 min read | For CISOs

Most security assessment reports answer the questions the vendor wanted to ask. The DDactic report format was designed from the questions CISOs actually ask after an assessment: What is our overall posture? What is the single most important thing to fix? How do we compare to our sector? What does "fix" look like in practice? Each section of the report maps to one of these questions.

The format was developed through iteration with CISOs at financial institutions, insurance companies, and SaaS platforms. The consistent feedback from early versions was that technical appendices with raw finding dumps were read by one engineer and ignored by everyone else in the room. The current format puts the decision-relevant summary at the top and the technical detail in appendices that are optional reading.

Section 1: OPI Score and Sub-Scores

The first page of every DDactic report is the OPI (Open Protection Index) score: a single 0-100 number representing overall DDoS resilience posture. Below it are five sub-scores covering the dimensions measured: edge protection configuration, API layer hardening, TLS and connection settings, authentication surface hardening, and breach exposure risk. The sub-scores show where the overall score is dragged down, enabling immediate prioritization without reading the full report.

Section 2: Top 3 Findings

The second section surfaces the three findings with the highest impact on the OPI score. Each finding is presented in a fixed format: the affected endpoint or service, the observed behavior, the expected behavior, the OPI impact if remediated, and the remediation action (specific configuration command, not a generic recommendation). A CISO can read this section in under 5 minutes and leave with a concrete action for the next sprint.

Section 3: Full Finding List with Engineering Detail

The complete finding list is ordered by OPI impact, not by severity label. Each finding includes: the finding type, the affected endpoint, evidence (request/response pair, screenshot, or log extract), the vendor-specific remediation command, the estimated remediation effort in engineering hours, and a verification procedure to confirm the fix worked. This section is the input to the engineering sprint, not the CISO briefing.

Section 4: Sector Comparison

Where DDactic has sufficient data from comparable organizations in the same sector, the report includes a percentile ranking. A financial institution with an OPI of 58 knowing they are in the 40th percentile for their sector has a materially different conversation with their board than a company that received the same score without context. Sector comparison data is aggregated and anonymized; no individual organization's data is shared.

Section 5: Remediation Roadmap

The final section groups the full finding list into three categories by effort and impact: quick wins (under 2 hours, high OPI impact -- typically misconfigured rate limits and missing timeout settings), sprint items (2-40 hours, medium OPI impact -- typically WAF rule additions and API gateway configuration), and architectural items (requiring design changes, lower immediate OPI impact but necessary for long-term resilience). This categorization lets engineering teams plan remediation across time horizons without re-analyzing the findings themselves.

Get a DDactic Assessment Report

Start with a free scan to see your OPI score and the top-impact findings for your environment.

Run a Free Scan
CISOReport FormatOPIFindingsDDoS Assessment