Analysis of more than 338 million attack simulations finds prevention improved, but significant gaps remain in post-compromise defense, ransomware protection and data-loss prevention
SAN FRANCISCO, Aug. 11, 2026 (GLOBE NEWSWIRE) -- Picus Security, the leading exposure validation company, today published The Blue Report 2026, which shows a sharp divide between the attacks organizations stop at the perimeter and the actions they prevent after an attacker gets inside. Prevention effectiveness recovered to 69%, returning to its 2024 peak. However, once an attacker gains access, only 37% of their actions get blocked.
Findings are based on analysis of more than 338 million attack simulations run in production environments between January and June 2026. The study showed that security controls perform best against conspicuous activity, including certain lateral movement and privilege escalation techniques. The largest post-compromise gaps involved low-noise activity. Quiet discovery and collection actions were blocked in approximately one in 10 attempts, allowing simulated attackers to enumerate domains, identify file shares, discover active sessions and collect credential material with limited resistance.

“Organizations have become much better at stopping attacker activity that creates obvious signals,” said Dr. Süleyman Ozarslan, co-founder of Picus Security and VP of Picus Labs. “The problem is what happens before those signals appear. Attackers can quietly map an environment, locate valuable systems and gather credentials while many defenses remain inactive. This is why validating defenses across the entire attack path is so critical.”
Detection and prevention gaps persist across the attack chain
The findings also point to a persistent gap between telemetry collection and actionable detection across industries. Organizations logged 58% of simulated attacks but generated alerts for only 14% of them. Fewer than one in seven attacks produced an alert. Performance issues accounted for 49% of identified detection-rule issues, up from 24%.
Other findings include:
- Evasion techniques were the hardest for controls to block: organizations blocked just 1% of Impair Command History Logging (T1562.003) simulations and 9% of Signed Script Proxy Execution (T1216) simulations, the two lowest technique-level prevention scores in the report. Prevention effectiveness against the Stealth tactic also weakened, from 53% to 47%, one of only two tactics for which controls performed worse than last year.
- Endpoint security improved as the assume-breach mindset took hold: endpoint prevention reached 83% and Privilege Escalation rose 24 points to 79%, the largest tactic-level gain of the year.
- Malware prevention fell again as IOC-based detection lost ground: malware-download prevention declined to 50%, down 21 points over two years.
- Strong performance is rented, not owned: last year’s strongest sectors regressed and last year’s weakest recovered. Transportation gained 29 points to reach 79%, Education lost 30 to land at 40%, South Asia moved from last place to a share of first at 71%, and North America fell to the lowest prevention score of any region at 60%.
Action items for security teams
Based on these findings, Picus recommends that organizations continuously test whether their controls can prevent, detect and contain current attacker behavior. This includes validating complete attack paths, particularly quiet post-compromise discovery, collection and credential-access activity.
Security teams should regularly test detection rules, confirm log-source health and verify that attacks generate actionable alerts. They should also strengthen behavioral detection to reduce reliance on static signatures and known indicators.
Organizations should simulate current ransomware and threat-group behavior across the full attack chain. Vulnerability remediation should prioritize demonstrated exploitability rather than severity scores alone.
About The Blue Report
The Picus Security Blue Report offers empirical evidence of how well security controls perform in real-world conditions. Findings are based on millions of simulated attacks executed by Picus Security customers from January to June 2026. The simulations were conducted safely in live production environments using Picus’ Security Validation Platform and analyzed by the Picus Labs and Picus Data Science teams. The report also includes ecosystem- and industry-specific findings and recommendations to help companies reduce exposure and improve threat readiness.
To read the full findings and recommendations, download the Blue Report 2026.
About Picus Security
Picus Security, the leading exposure validation company, proves what attackers can exploit and what your defenses stop, then closes real gaps with ready-to-deploy fixes and re-validates to confirm, at the machine speed today's AI threats demand. The Picus Platform spans Breach and Attack Simulation, Autonomous Penetration Testing and Exposure Validation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously with human oversight. With 75+ integrations, it reaches across on-prem, hybrid cloud, and endpoint environments.
Trusted by many Fortune 500 enterprises, Picus was named a 2025 Gartner Peer Insights Customers' Choice for Adversarial Exposure Validation and is recognized as an Innovation Leader in the Frost Radar for Automated Security Validation.
Follow Picus Security on X and LinkedIn.
Media Contact
Jennifer Tanner
Look Left Marketing
picus@lookleftmarketing.com
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/bc3718a1-6b01-439f-a14c-0b2040de830d
-
Oticon 推出 Reveal™----全球首款搭载双 AI 的助听器不止听清话语,更能感知丰富的声音世界 丹麦斯莫勒姆2026年8月12日 美通社 -- Oticon 今日正式推出 Oticon Reveal™。这是全球首款搭载双 AI 的助听器,能够让清晰的2026-08-12
-
一切悬念留待最后揭晓,世界冠军即将在伦敦决出最终赢家伦敦2026年8月12日 美通社 -- ABB国际汽联电动方程式世界锦标赛迎来赛季收官时刻,本周末在伦敦ExCel展览馆赛道背靠背双赛,将正式决出202526赛季世界冠军的最终归属2026-08-12
-
AI的“iPhone时刻”已过,但“信息洪灾”才刚刚开始2026年的AI圈,热闹得有些令人眩晕。 短短八周内,阿里Qwen3.8-Max、月之暗面Kimi K3、DeepSeek-V4-Flash、智谱GLM-5.2、字节Seedance 2.5五款重磅模型接连亮相。参2026-08-12
-
战略转型全面落地丨卓特视觉新版官网焕新上线,构建数创协同的 AI 服务新底座近日,“数智时代 创享新篇 —— 卓特视觉战略转型 & Token 业务启动发布会” 于杭州成功举办。会上卓特视觉完成品牌战略跃迁,正式升级为 AI 创意工具与版权数据平2026-08-12
-
奔富 2026 珍藏系列新年份葡萄酒上市 葛兰许 75 周年致敬经典传承杭州2026年8月12日 美通社 -- 2026 年 8 月 11 日,Penfolds 奔富于杭州隆重发布 2026 珍藏系列新年份葡萄酒,悉数呈献由葛兰许领衔的20余款品质佳酿跨越澳大利亚、美2026-08-12
-
AMD股价暴跌17%创近9年之最,苏姿丰紧急回应:AI增速远超想象
-
Ledger 中国销售渠道说明:广州馨潇贸易有限公司官方直营渠道公示
-
江苏省脑机接口产业联盟在宁成立,麦澜德分享前沿成果
-
艾芬达入选国家知识产权强国建设示范创建对象:二十载长期主义,兑现每一份用户价值
-
Esentia宣布成功完成2033年到期的6.125%优先票据和2038年到期的6.500%优先票据的定价
-
中荷人寿北京分公司成功举办中荷创享家品牌发布暨协同发展启航仪式
-
华为系具身智能公司具脑磐石完成新一轮融资:对标JEPA,押注类脑智能的认知世界模型
-
北京暑假补习班有哪些?家长首推一对一权威机构金博升学
-
上海高新技术企业代理机构深度访谈与推荐
-
2026 雷瓦亮相京东 MALL ,匠心筑造专业造型新标杆
