SectionReports & Notifications

Cindera · Reports & Notifications

Reports & Notifications

Cindera generates audit-ready PDFs, schedules them on a recurring cadence, and alerts you the moment a critical finding lands. This page covers all three plus the trend history you can show internally.

PDF reports

Every completed scan can be exported as a PDF. The report is designed to be the document you hand to an auditor, an insurance broker, or your management team — not a screenshot of the dashboard.

What's in a report

  • Cover page with tenant identifier, scan timestamp, overall score, and score-by-framework (NIS2, GDPR).
  • Executive summary with the count of findings by severity and the top three risks called out in plain language.
  • Findings list grouped by severity. Each finding includes the affected resource, the business impact, the mapped NIS2/GDPR controls, the estimated fix time, and the current status (open, resolved, ignored).
  • Methodology pagedescribing exactly which Microsoft Graph permissions were used and what Cindera did not read. Useful when auditors ask "how do you know this?"
  • Sign-off footerwith the generation date and a checksum so the document can't be silently edited.

How to download

  1. From the dashboard, click Download report (latest completed scan).
  2. From the Reports page, pick any historical scan and click its download icon to export that specific point-in-time view.

Recurring reports

You can configure Cindera to email a fresh PDF report on a schedule, so the people who need it never have to log in to fetch it.

How to configure

  1. Open Settings and find the Recurring reports card.
  2. Pick a cadence — weekly (delivered Monday morning UTC) or monthly (delivered the first business day of each month).
  3. Add one or more recipient email addresses, separated by commas. Internal stakeholders, your MSP, or your insurance broker — whoever should see it.
  4. Save. The next delivery happens on the schedule above.

Each scheduled delivery uses the most recent completed scan as its source. If no scan has run since the last delivery, the email politely says so rather than re-sending the previous report.

Tip for MSPs

For multi-stakeholder reporting, add separate distribution aliases (e.g. cinder-reports@client.com) so the recipient list can change on the client side without you having to update Cindera.

Critical findings email alerts

Cindera sends an immediate email alert the first time a critical finding lands in a scan. These are the findings that genuinely warrant a same-day response — for example, an admin account discovered without MFA, or legacy authentication left unblocked.

When alerts fire

  • A scan finishes and a new critical-severity finding is present that was not on the previous scan.
  • A scan re-detects an existing critical finding that had been marked resolved in Cindera — likely a regression.
  • Alerts do notfire on every scan if the same critical finding is already known and open. We don't want to train you to ignore the email.

Who receives them

Alerts go to every user in your Cindera workspace with the admin role. You can adjust the recipient list from Settings → Notifications.

How to interpret an alert

  • Read the finding linked in the email first. Critical findings are named — e.g. "Admin user alice@contoso.com has no MFA registered".
  • Use the deep link to the Microsoft 365 admin centre to verify before changing anything.
  • Apply the remediation stepsin the finding detail. They're ordered, specific, and written for the person doing the work — not a generic checklist.
  • Re-run a scan after fixing to confirm the finding closes. Cindera marks it resolved automatically when the underlying condition is no longer met.

Last updated · 2026-06-05