Threat Posture
Threat Posture gives you a plain-language read of where your threat exposure stands right now . It summarises your overall posture and surfaces the most important insights to show what was detected, why it matters, and what to do about it.
What is the Threat Posture
Threat Posture gives you an at-a-glance, plain-language read of your current threat exposure — and the top things driving it — right at the top of Threat Monitoring, above your threat queue.
It's produced by the UpGuard Security Advisor. Where the Threat Analyst works at the individual signal level — triaging each threat, filtering out the noise, and prioritizing the real ones — the Security Advisor works one level up: it looks across all of that triaged activity and distills it into a clear, plain-language view of your overall posture and what's driving it.
It refreshes weekly, and whenever a new Transform is added — not on every incoming threat — and is dated so you can see how current it is (for example, Threat Posture: 7 September). You can collapse the panel at any time if you'd rather focus on the queue.
It's AI-generated. Threat Posture and its recommended actions are produced by the UpGuard Security Advisor (the Threat Analyst is what triages your individual threats in the queue). Treat the recommended actions as guidance to inform your response, not a substitute for your own judgement.
The posture summary
At the top of the panel is a short summary of your overall posture — the headline level and the main factors behind it, written in everyday language. Use it as your quick "where do we stand today" read before you dig into the detail.
Top insights
Below the summary are the Top insights — a list of the most important themes the Security Advisor has found across your threat data, with the most significant first.
Select any insight to expand it. Each one opens into three parts:
-
What was detected — what is it: what the analyst found and what the data is showing.
-
Why it matters — why does it matter: the risk this creates and the potential impact if it isn't addressed.
-
Recommended action — what to do about it: the suggested next step to reduce the risk.
Reading an insight top to bottom takes you from what's happening to why you should care to what to do next, without needing to interpret the raw threat data yourself.
Filter the queue to an insight
Each insight has a Filter threats toggle on the right.
Turn it on and your threat queue filters down to just the threat events behind that insight — so you can jump straight from the insight to the specific threats and start actioning them.
When a filter is active, a filter banner appears at the top of the queue naming the insight you've filtered by.
The tab counts update to show how many of your threats relate to it — for example, Open (87 / 267) means 87 of your 267 open threats belong to that insight.
The filter applies across the Open, Investigating, Remediating and Closed tabs.
To clear it, turn the toggle back off or select the ✕ on the filter banner. You can also combine an insight filter with the standard queue filters (date, transforms, severity, source, and so on) to narrow things down further.
It doesn't change your threats. Filtering by an insight only changes what you're looking at in the queue — it doesn't action, close, or alter any threats
A suggested way to use it
Read the summary for your headline posture.
Expand the top insight to understand what's driving it.
Toggle Filter threats to see the related threats in the queue.
Work through those threats — investigate, remediate, or dismiss.
Move down the list and repeat.
Was this helpful?
Under the insights you'll find a Was this helpful? thumbs up / thumbs down. Your feedback helps us tune the analysis, so let us know if an insight was useful or missed the mark.