Skip to content

SenseOn Insight

SenseOn Insight is a monthly security report written for your organisation. Each report is a narrative brief covering the previous calendar month: what happened across your estate, what SenseOn found, and what you should do next. It is built from the telemetry and cases already in your SenseOn platform, and the SenseOn SOC checks each report before it is released to you.

Insight is written for security leadership as well as analysts, so it suits board updates and periodic posture reviews.

💡 Availability: SenseOn Insight is enabled per tenant on request. If you do not see an Insight report on your Overview, contact your Customer Success Manager to ask for it to be turned on.


When reports are produced

A new report is generated at the start of each month and covers the previous calendar month. For example, the report produced in early October covers September. The SOC reviews it before it appears in your platform, so allow a day or two into the month for the latest report to arrive.

Each report is labelled by the month it covers, for example "Insight Report from September 2026".


Finding your reports

From the Overview

The Reports widget on the Overview shows your latest Insight report alongside the custom report download form. It is headed Insight Report from the report's month, followed by a one-line summary and a View latest insights button. Select the button to open the full report.

If no report has been produced yet, the widget shows "No reports available yet."

On the SenseOn Insight page

The SenseOn Insight page shows a single report in full. Use the Report menu in the top right to switch between months, with the newest first. The breadcrumb at the top of the page takes you back to the Overview.

Each report has its own link, so you can bookmark a particular month or share it with a colleague who has access to your SenseOn platform. The report follows the platform's light or dark mode.


What a report contains

Reports open with a table of contents, so you can jump straight to the section you need. The main sections are:

  • Executive summary. The month at a glance, with the overall posture and the findings that matter most.
  • Security posture score. A single A to E grade, described below.
  • Estate overview. Sensor coverage and the shape of your estate, including an Identity Posture view of multi-factor authentication (MFA) coverage, risky or multi-country sign-ins, and any legacy authentication still in use.
  • Case summary. The month's cases, drawing on analyst notes, closing comments and AI case summaries.
  • Key findings and observations. The significant findings, each with its evidence and how it was detected, followed by smaller observations worth knowing about.
  • Recommendations. Prioritised actions, closing with a Compliance Snapshot that maps the five Cyber Essentials controls to the month's evidence.
  • Security Hardening Posture. Configuration and hardening findings grouped into strengths, weaknesses and areas to review.
  • Vulnerability Management. Installed software whose version matches a known vulnerability, by severity, cross-referenced against the CISA Known Exploited Vulnerabilities catalogue.
  • Threat alerts correlated to your estate. Threat intelligence that matched activity in your environment.
  • Connected data sources. Which of your data sources sent data during the month, and which did not.
  • Appendixes. The methodology, data sources and key IP addresses behind the report, the indicators that threat intelligence flagged as malicious or suspicious, and the Hunt Lab queries that support each finding.

ℹ Vulnerability matches are a starting point. The Vulnerability Management section matches installed software versions against known vulnerabilities. A match does not prove a device is exploitable, because the vendor may have shipped the fix without changing the version number, or the issue may be mitigated by configuration. Confirm with your vulnerability scanner before acting.

Sections only appear when there is data for them. A data source that sent nothing is reported as missing coverage, not as a clean result.

Security posture score

The report gives a single composite score from 0 to 100, graded A to E, so you can track movement month on month:

Grade Score Meaning
A 85 and above Strong
B 70 to 84 Sound
C 55 to 69 Needs attention
D 40 to 54 Weak
E Below 40 Critical exposure

The score combines three weighted areas: coverage and visibility, active threat activity, and security hygiene. Vulnerability matches are reported in their own section but do not affect the grade, because version matching alone is not reliable enough to move a headline score.

The score is calculated by fixed rules from the report's data. It is not written by AI, so the same inputs always produce the same grade, and every deduction is listed. The score is only shown when at least two of the three areas have data for the month.


How a report is produced

  1. Standard Hunt Lab queries run across your estate, covering endpoint posture and hardening, identity and MFA, data source visibility and connector activity.
  2. The month's cases are gathered, with analyst notes, closing comments and AI case summaries.
  3. Indicators are enriched with threat intelligence.
  4. A large language model (Anthropic's Claude) analyses the data and writes the narrative sections. It can run further Hunt Lab queries to support a finding.
  5. The posture score, vulnerability tables, hardening summary and data source inventory are calculated by the platform, not written by the model.
  6. The SenseOn SOC checks the finished report before it is released to your platform.

For how SenseOn handles your data when using generative AI, see AI Case Summaries.


Printing or saving as a PDF

You can print a report, or save it as a PDF, from within the report using your browser's print dialog. To save a PDF, choose Save as PDF as the destination. Reports are laid out for print: the table of contents sits on its own page, and findings and tables are kept together across page breaks where possible.


Insight and the Reporting module

SenseOn Insight Reporting
What you get A written security brief Structured metrics as CSV or JSON
Time range The previous calendar month A range you choose
Who it is for Security leadership and analysts Analysts and external tools
How it is produced Generated monthly and checked by the SenseOn SOC Downloaded on demand or scheduled

Use Insight when you want to understand and explain the month. Use Reporting when you need figures in a stable format for another system or spreadsheet.