Yash M.
YM
security analyst
Enterprise (> 1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Centralized Risk Visibility and Asset Insights in UpGuard Breach Risk"
4/5
What do you like best about UpGuard Breach Risk?

One of the most helpful features I found in UpGuard Breach Risk is that it brings different security risks together in a single platform. It provides a centralized risk profile where we can quickly understand the overall security posture and identify the areas that require attention.

Another useful feature is the ability to view the domains and assets associated with a particular risk. This makes it easier to identify exactly which domains are affected and understand the scope of the issue instead of checking each domain separately.

It also helps in prioritizing risks, tracking changes over time, and getting a clearer picture of external security exposure. Overall, having the risks, affected assets, and risk details available in one place makes the assessment and remediation process more organized and efficient. Review collected by and hosted on G2.com.

What do you dislike about UpGuard Breach Risk?

One limitation I noticed with Up Guard Breach Risk is that some findings depend heavily on the platform’s automated detection logic. Because the risks are identified based on specific patterns, keywords, ports, and other indicators, there can be cases where a finding needs to be manually validated before confirming that it is an actual security issue.

For example, with a finding such as “CSP Unimplemented Unsafely,” the detection may rely on specific keywords or CSP directives being present or absent. In some cases, the tool may flag a risk based on the detected configuration without fully understanding the application’s actual implementation or context. This can result in findings that require manual verification.

Similarly, for SSL/TLS-related risks, the platform may identify the issue based on the ports or services it detects. If SSL/TLS is not detected on an expected port, it may raise a finding even when the service is configured differently or SSL/TLS is running on another port. In such cases, we may need to perform a manual scan or additional validation using tools such as Nmap or SSLScan to confirm the actual configuration.

So, while the automated detection is useful for quickly identifying potential risks across a large number of domains, the results should not always be treated as final. Manual validation is still important, particularly for configuration-based findings, to distinguish genuine vulnerabilities from contextual or false-positive findings. Review collected by and hosted on G2.com.

See what 31 reviewers think of UpGuard Breach Risk

4.5 out of 5 · Verified reviews from real users

Read all reviews