Rosemary Bookkeeping (Goska Dabrowski)
Public Cybersecurity Posture & Verification Assessment
📋 Executive Summary & Status Classification
Public Assessment Finding
Feb 2026
Observation Category: Vulnerable | Headers Evaluation: C
Our transparency network monitors whether businesses implement foundational defenses necessary to withstand commodity credential spraying, phishing campaigns, and man-in-the-middle attacks.
🛡️ Observed Technical Controls
HTTP Security Headers C
HTTP response headers instruct browsers how to handle sensitive user sessions, external scripts, and iframe rendering. Moderate: Basic transport encryption is configured, but granular CSP or permission policies are incomplete.
Email Defense (SPF/DKIM/DMARC) Public Check
Domain-level DNS records prevent unauthorized adversaries from impersonating company staff in outbound phishing attacks. Public Record: Outbound domains without strict DMARC rejection policies remain susceptible to spoofed email delivery.
Transport Encryption (HTTPS) Active
Valid SSL/TLS certificate configured on rosemarybookkeeping.com for secure user communications.
All public web traffic is routed over TLS.
The Standard (8 Core Controls) Unconfirmed
Evaluates 8 fundamental protections: Managed EDR, Hardware MFA, Air-gapped Backups, Patch Automation, DNS Filtering, Privilege Separation, Incident Response, and Encryption.
⚖️ Scope Limitations & Assessment Methodology
This transparency report represents an external, non-invasive observation of publicly visible domain settings, DNS records, and HTTP headers as of Feb 2026.
- What this establishes: An objective record of publicly detectable web and mail configurations against standard cyber hygiene benchmarks.
- What this does NOT establish: A public finding does not imply that an internal network breach has occurred, nor does it establish active exploitation. Conversely, lack of a public finding does not guarantee immunity from zero-day threats.