"Good advice changes something. Great advice changes the right thing."
Policy Writing and Documentation Standards
Professor Sele: The quality of a consulting engagement's written output is the quality of the engagement as the client experiences it. A brilliant analysis presented in a confusing, poorly structured document loses its value. This module sets the standard for consulting documentation that actually works.
Section 1 — The Consulting Document Hierarchy
Professional consulting engagements produce documents at different levels: Inception report — confirms scope, methodology, and workplan; approved before substantive work begins. Interim report / progress note — updates the client during the engagement; flags emerging findings and any scope adjustments. Draft report — the working document shared with the client for review and factual checking before finalisation. Final report — the definitive deliverable; incorporates client feedback on the draft. Action plan — the implementation document derived from the final report recommendations. Presentation — the verbal delivery of key findings and recommendations to decision-makers.
Section 2 — Report Writing Principles
Audience-appropriate — the executive summary is written for the CEO; the technical annexes are for the security manager. Different sections, different registers. Evidence-based — every finding is supported by specific evidence cited in the report. Structured — consistent use of headings, numbering, and section structure; readers must be able to navigate the document. Actionable — recommendations tell the client what to do, who should do it, by when, and what success looks like. Concise — say what needs to be said, no more; a 60-page report for a 20-page problem serves the consultant's ego, not the client's needs.
Section 3 — The Executive Summary
The executive summary is the most important section of any consulting report — it is the section most decision-makers read. It must: summarise the key findings in plain language (not jargon); state the top 5 priority recommendations in order of urgency; be self-contained (a reader should be able to understand the main message without reading the full report); and be limited to 1–2 pages.
Section 4 — Documentation Security
Consulting documents contain sensitive information about a client's security vulnerabilities. Documentation security requirements: all consulting documents classified at minimum RESTRICTED; transmitted only via secure channels — never unsecured email; version controlled — draft and final versions clearly labelled; stored securely by SafeHaven with access limited to the engagement team; retention period agreed with the client — not indefinitely stored.
- •Document hierarchy: Inception → Interim → Draft → Final → Action Plan → Presentation
- •Write for the audience — executive summary for leadership, technical annexes for specialists
- •The executive summary is the most important section — 1–2 pages, self-contained, top 5 priorities
- •All consulting documents are classified RESTRICTED minimum and transmitted securely
- •Concise is professional — a report longer than the problem it describes serves the consultant, not the client
"I received feedback from a government client that my draft report was 'too negative.' They wanted me to soften the findings. I declined to change the substance — but I did review the language. I had written several findings in language that sounded accusatory rather than analytical. I rewrote those sections in objective, evidence-based language. The substance didn't change. The tone became more professional and less personal. The client accepted the final report without further objection. Facts presented professionally are harder to dismiss than facts presented with an edge. Write analytically, not emotionally."
The purpose of an executive summary in a security consulting report is to: