News thumbnail
Technology / Fri, 28 Aug 2026 LinkedIn

What 338 Million Attack Simulations Reveal About Enterprise Defenses in 2026

Picus Labs has spent four years putting the same question to enterprise security stacks: when a real attack lands, does the control stop it? The Blue Report 2026 answers it with over 338 million simulations executed across live customer environments between January and June 2026. Breach and Attack Simulation runs known threats against a customer's own controls, their firewalls, email and web gateways, EDR and XDR, and each threat breaks down into individual attacker actions. Different tool, different question: Autonomous Penetration Testing runs full attack chains inside the environment, from foothold to lateral movement to escalation. The log score rose to 58%, a four-year high after two years stuck at 54%.

Picus Labs has spent four years putting the same question to enterprise security stacks: when a real attack lands, does the control stop it? The Blue Report 2026 answers it with over 338 million simulations executed across live customer environments between January and June 2026.

This year's dataset reads like a recovery story, right up until you ask what happens after an attacker is already authenticated.

The good news came first

Average prevention effectiveness rose from 62% to 69%, erasing last year's seven-point decline and returning to the 2024 peak.

Worth knowing what that number counts. Breach and Attack Simulation runs known threats against a customer's own controls, their firewalls, email and web gateways, EDR and XDR, and each threat breaks down into individual attacker actions. 69% is the share of those actions the stack blocked.

That recovery matters because it settles an argument. Controls degrade quietly through configuration drift, broken integrations and unaddressed adversary evolution. Last year's seven-point drop was half that case. This year's rebound is the other half: when teams put those controls back under continuous test, the score climbs back.

Then we measured the inside

For the first time, the report measures what an adversary accomplishes after gaining authenticated access. Different tool, different question: Autonomous Penetration Testing runs full attack chains inside the environment, from foothold to lateral movement to escalation.

The Post-Compromise Prevention Rate was 37%. Barely one attacker action in three was blocked.

The split inside that number is sharper still.

Loud actions get caught: lateral movement through service execution was stopped around 90% of the time, UAC-bypass privilege escalation around 85%. Quiet actions run almost unopposed. Discovery and collection, meaning mapping the domain and enumerating shares and sessions, was the least-prevented category at 10%. Credential access sat at 22%.

The cleanest illustration is one tool, one objective, three procedures.

Mimikatz reading credential material out of LSASS memory was blocked 94% of the time. The same tool pulling RDP credentials from memory: 17%. Reading LSA secrets out of the local registry: 3%. Same tool, same goal, same environments. The only thing that changed was where the credentials were read from, and prevention tracked how heavily that particular path had been signatured rather than the fact that credentials were being stolen at all.

Notice the sequence. Everything defenses catch reliably happens after everything they miss. An attacker maps the domain, finds the shares and reads the credentials, and only then moves laterally.

Defenses catch the second half of the attack.

Detection tells the same story

Here the year produced a second real gain. The log score rose to 58%, a four-year high after two years stuck at 54%. Teams invested in pipelines and log source coverage, and the data shows it.

The alert score did not move. It has been flat at 14% for two years running. Fewer than one in seven simulated attacks produces a meaningful alert.

These two metrics diverged because they are governed by different work. Broader log coverage is pipeline and infrastructure investment, and organizations delivered it. Better alerting is detection engineering: writing rules against current behavior, testing that they fire, tuning them, re-validating them. That second effort is lagging. Telemetry sitting in a SIEM does not correlate itself.

What we'll cover in the webinar

The article covers the headline numbers. The 45-minute session goes into what sits underneath them:

Why IOC-based prevention fell to 50%, down 21 points in two years, and where behavior-based testing has to take over

Ransomware and threat groups: every one of the ten least-prevented families scored 38% or lower, and prevention fell against nine of the ten hardest threat groups, even as the overall score rose

What actually breaks in a detection pipeline, now that rule performance has overtaken log collection as the leading failure category, and why the failures that remain are the silent ones

Industry volatility: Transportation up 29 points to 79%, Education down 30 points to 40%, evidence that strong performance is rented, not owned

The ten least-prevented vulnerabilities, every one blocked under 25% of the time, clustering by weakness class rather than by vendor

What to do about all of it, and where teams should start if they can only fix one thing this quarter

Every finding gets put to Candid for the field read, so the numbers get argued with rather than presented.

Who's speaking

Candid Wüest, Principal Security Advocate at xorlab, brings the field perspective: what these numbers look like from inside real security operations, and why teams end up at the bottom of the distribution without knowing it.

Sıla Özeren Hacıoğlu, Security Research Engineer at Picus Security, presents the research behind the report and what four years of production data reveal about which defensive habits hold and which quietly erode.

© All Rights Reserved.