SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Picus report finds gaps in post-compromise defence

Picus report finds gaps in post-compromise defence

Wed, 12th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Picus Security has published its 2026 Blue Report, which found that organisations blocked 37% of attacker actions after authenticated access was established.

The findings are based on more than 338 million attack simulations conducted in production environments during the first half of the year. Overall prevention recovered to 69%, returning to its previous peak. But the data also showed a clear gap between blocking activity at the perimeter and stopping behaviour after an attacker had moved inside a network.

Security controls were more effective against activity that created clearer signals, including some forms of lateral movement and privilege escalation. By contrast, lower-noise actions performed after compromise were far less likely to be stopped.

Quiet discovery and collection activity was blocked in about one in 10 attempts. Simulated attackers were often able to enumerate domains, identify file shares, discover active sessions and collect credential material with limited resistance.

Dr. Süleyman Ozarslan, Co-Founder of Picus Security and VP of Picus Labs, said the results showed an important distinction in how defensive tools respond to different forms of attacker behaviour.

"Organisations have become much better at stopping attacker activity that creates obvious signals. The problem is what happens before those signals appear. Attackers can quietly map an environment, locate valuable systems and gather credentials while many defenses remain inactive. This is why validating defenses across the entire attack path is so critical," said Dr. Süleyman Ozarslan, Co-Founder of Picus Security and VP of Picus Labs.

Detection gap

The study also highlighted a gap between collecting telemetry and producing actionable alerts. Organisations logged 58% of simulated attacks but generated alerts for only 14%, meaning fewer than one in seven attacks prompted a warning.

Performance issues were the largest source of detection-rule problems, accounting for 49% of identified issues, up from 24% in the prior report period.

The weakest prevention scores at the technique level appeared in evasion-related activity. Controls blocked just 1% of simulations involving Impair Command History Logging and 9% involving Signed Script Proxy Execution, making them the two lowest-scoring techniques in the report.

Prevention effectiveness against the Stealth tactic also declined, falling from 53% to 47%. It was one of only two tactics where control performance weakened from the previous year.

Endpoint shifts

Not all measures deteriorated. Endpoint prevention rose to 83%, while prevention against Privilege Escalation increased by 24 percentage points to 79%, the largest tactic-level gain recorded this year.

Malware-related measures moved in the opposite direction. Prevention of malware downloads fell to 50%, down 21 percentage points over two years, suggesting weaker results for detection methods that depend heavily on indicators of compromise.

The report also pointed to uneven performance across sectors and regions. Transportation improved by 29 points to 79%, while Education dropped by 30 points to 40%.

Regional shifts were similarly pronounced. South Asia moved from last place to a share of first at 71%, while North America posted the lowest prevention score of any region at 60%.

Ransomware and exfiltration

Two of the starkest findings concerned ransomware and data loss. Data exfiltration prevention stood at 7%, while all 10 of the least-prevented ransomware families scored 38% or lower.

These results suggest that even as organisations recover some effectiveness in broader prevention metrics, they remain exposed in areas linked to information theft and disruptive follow-on attacks. The post-compromise figures also indicate that security teams must do more than stop initial access. They also need to identify quieter, less conspicuous behaviour after a foothold has been gained.

Picus recommended that organisations test whether their controls can prevent, detect and contain current attacker behaviour across the full attack path. It also urged security teams to verify detection rules, check the health of log sources and confirm that simulated attacks generate actionable alerts.

The company also recommended placing more weight on behavioural detection rather than relying mainly on static signatures and known indicators. It advised prioritising vulnerability remediation according to demonstrated exploitability rather than severity scores alone.

The report was compiled from simulated attacks run by Picus customers in live production environments and analysed by the company's research and data science teams. It found that while perimeter and endpoint measures had improved in several areas, post-compromise defence, data exfiltration controls and alerting remained weak points.

Data exfiltration prevention remained at 7%, and organisations generated alerts for only 14% of simulated attacks.