What makes it up
Posture combines several views: the exposure of the attack surface, the number and severity of open vulnerabilities, the configuration of devices, cloud and SaaS, identity hygiene such as MFA coverage and unused accounts, staff awareness, detection and response capability, and the maturity of policies and compliance.
How it is measured
There is no single score. Common inputs are vulnerability scans, configuration scores from cloud and Microsoft 365 tools, phishing simulation results, pentest findings, audit results and the risk assessment. Posture management tools for cloud (CSPM) and SaaS (SSPM) automate part of this by checking configurations continuously.
Snapshot vs continuous view
An annual audit or pentest shows posture at one point in time. New systems, staff changes and newly disclosed vulnerabilities change it every week, which is why continuous monitoring gives a far more accurate picture.
Why it matters
Management, customers, insurers and regulators increasingly ask companies to show their security posture, through questionnaires, certifications or evidence. Knowing it is the starting point for deciding where to invest first.




