GlossaryCompliance operations

Security posture

Short answer

Security posture is the overall state of an organisation's cybersecurity at a given moment: how well its controls, people and processes protect it, how exposed it is to attack and how prepared it is to detect and respond. It changes constantly as systems, threats and people change.

What makes it up

Posture combines several views: the exposure of the attack surface, the number and severity of open vulnerabilities, the configuration of devices, cloud and SaaS, identity hygiene such as MFA coverage and unused accounts, staff awareness, detection and response capability, and the maturity of policies and compliance.

How it is measured

There is no single score. Common inputs are vulnerability scans, configuration scores from cloud and Microsoft 365 tools, phishing simulation results, pentest findings, audit results and the risk assessment. Posture management tools for cloud (CSPM) and SaaS (SSPM) automate part of this by checking configurations continuously.

Snapshot vs continuous view

An annual audit or pentest shows posture at one point in time. New systems, staff changes and newly disclosed vulnerabilities change it every week, which is why continuous monitoring gives a far more accurate picture.

Why it matters

Management, customers, insurers and regulators increasingly ask companies to show their security posture, through questionnaires, certifications or evidence. Knowing it is the starting point for deciding where to invest first.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub