
Technology Access Resilience Check
A municipal police department with solid administrator coverage and MFA, but a shared login on its most critical system, no periodic access review, and undocumented account recovery.
This is a fictional sample report. Main Street Fire Department and Main Street Police Department are illustrative examples and do not represent any real agency. Figures, names and details are invented to show what this tool produces.
By category
Top findings
- Access review: 0/100
- Authentication & accounts: 50/100
- Recovery & offboarding: 50/100
Recommendations
Require MFA and end shared logins
Turn on multi-factor authentication for critical systems and give each administrator their own account. Shared logins make it impossible to trace actions or cleanly remove one person’s access.
Document recovery and offboarding
Write down how to recover each critical account and how access is removed when someone leaves. Do it before you need it, not during a crisis.
Put ownership under the department
Move account ownership to a department-controlled email, and keep vendor support and renewal details somewhere the department can always find them. Accounts tied to a personal email leave with that person.
Review access on a schedule
Set a simple recurring review of who has access to what. Access tends to accumulate quietly until a review surfaces it.
Re-check after any staff change
Access resilience changes whenever an administrator joins or leaves. Re-run this check after leadership or IT-role changes.
How this was made. This report is generated from a structured public-safety framework and the information you provided. Treat it as informed guidance, not a final answer, and confirm the specifics against your department’s own facts and judgment before you act.