Channel Islands Mortgage
Public Cybersecurity Posture & Verification Assessment
📋 Executive Summary & Status Classification
Verified Active Security Controls
Channel Islands Mortgage holds an active Verified - Managed designation. This organization maintains validated defense controls under The Standard, including multi-factor authentication (MFA), endpoint detection and response (EDR), offsite immutable backups, and continuous monitoring.
Our transparency network monitors whether businesses implement foundational defenses necessary to withstand commodity credential spraying, phishing campaigns, and man-in-the-middle attacks.
🛡️ Observed Technical Controls
HTTP Security Headers A+
HTTP response headers instruct browsers how to handle sensitive user sessions, external scripts, and iframe rendering. Optimal: Strict Transport Security (HSTS) and anti-clickjacking headers are properly enforced.
Email Defense (SPF/DKIM/DMARC) Enforced
Domain-level DNS records prevent unauthorized adversaries from impersonating company staff in outbound phishing attacks. Verified: Active mail routing with SPF and cryptographically aligned DKIM/DMARC enforcement.
Transport Encryption (HTTPS) Active
Valid SSL/TLS certificate configured on cimsloans.com for secure user communications.
All public web traffic is routed over TLS.
The Standard (8 Core Controls) Compliant
Evaluates 8 fundamental protections: Managed EDR, Hardware MFA, Air-gapped Backups, Patch Automation, DNS Filtering, Privilege Separation, Incident Response, and Encryption.
⚖️ Scope Limitations & Assessment Methodology
This transparency report represents an external, non-invasive observation of publicly visible domain settings, DNS records, and HTTP headers as of Feb 2026.
- What this establishes: An objective record of publicly detectable web and mail configurations against standard cyber hygiene benchmarks.
- What this does NOT establish: A public finding does not imply that an internal network breach has occurred, nor does it establish active exploitation. Conversely, lack of a public finding does not guarantee immunity from zero-day threats.