Picus Blue Report Reveals Persistent Detection Gaps 

Picus finds that cyber defenses are improving, but detection, post-compromise, and ransomware prevention gaps persist.

Written By
Ken Underhill
Ken Underhill
Aug 12, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

According to Picus’s Blue Report 2026, enterprise cybersecurity defenses improved in 2026. 

However, organizations continue to struggle with detecting stealthy attacker behavior and converting security telemetry into actionable alerts. 

The report analyzed more than 338 million simulated attacks conducted in Picus customer environments between January and June 2026. 

Picus measured how effectively existing security controls prevented attacks and whether simulated malicious activity generated logs and alerts.

Overall prevention scores increased from 62% in 2025 to 69% in 2026, returning to the level recorded in 2024. 

The findings indicate that stronger perimeter defenses do not necessarily translate into equivalent protection once attackers gain access to an environment.

Key takeaways of the Picus Blue Report for 2026

  • Cyberattack prevention improved overall, with Picus reporting that prevention effectiveness increased from 62% in 2025 to 69% in 2026.
  • Post-compromise defenses remain weaker, with organizations preventing only 37% of tested attacker actions after authenticated access was established.
  • Improved security logging is not translating into better alerting, as the log score rose to 58% while the alert score remained at just 14%.
  • Ransomware prevention deteriorated against leading threats, with all 10 of the least-prevented ransomware families scoring 38% or lower.

Picus finds gaps in post-compromise security defenses 

One of the report’s significant findings concerns what happens after an attacker gains authenticated access. 

Picus found a post-compromise prevention rate of only 37%, substantially below the overall 69% prevention score.

The difference was especially pronounced between conspicuous and low-noise attacker behavior. 

Lateral movement techniques using service execution were prevented approximately 90% of the time, while privilege escalation techniques using UAC bypass were blocked approximately 85% of the time. 

In comparison, discovery and collection activity was prevented in only about 10% of attempts.

In Picus’ analysis of MITRE ATT&CK techniques, Impair Command History Logging (T1562.003) was blocked in just 1% of simulations, while Account Access Removal (T1531) was prevented only 2% of the time. 

Data Encoding (T1132) and Signed Script Proxy Execution (T1216) each recorded prevention rates of just 9%.

Advertisement

More security telemetry is not producing more actionable alerts 

Organizations also improved their ability to capture attacker activity without making comparable progress in alerting security teams.

The average log score increased from 54% to 58%, its highest level across editions of the report. 

However, the alert score remained unchanged at just 14%, meaning fewer than one in seven simulated attacks generated a meaningful alert.

Picus identified detection engineering issues as a major contributor to this gap. 

Performance issues accounted for 49% of detection rule failures, compared with 24% the previous year. 

Log collection issues declined from 50% to 41%, suggesting that the challenge is shifting from just collecting telemetry to efficiently processing it and producing useful alerts. 

Remaining gaps in log collection are concerning because activity that goes unrecorded cannot trigger an alert, underscoring the need for organizations to prioritize detection engineering. 

Ransomware prevention declines

The report also found deteriorating protection against several ransomware families. 

All 10 of the least-prevented ransomware families had prevention scores of 38% or lower, while their average prevention score declined from approximately 44% in 2025 to 32% in 2026.

Play ransomware experienced the largest decline, falling from a 50% prevention rate to just 13%.

BlackByte was prevented in 25% of simulations, while LockBit was blocked in only 30% of simulations, down from 45% last year.

Security controls can degrade without continuous validation 

Picus’ findings demonstrate that cybersecurity effectiveness can change as threats, configurations, and infrastructure evolve. 

The company recommends continuously validating controls, strengthening behavioral detection, testing ransomware and advanced persistent threat attack chains, and improving detection engineering. 

Security controls can degrade over time because of configuration drift, broken integrations, operational complexity, and evolving attacker techniques, reinforcing the need for ongoing testing and tuning. 

Advertisement

These findings also reinforce the value of Zero Trust principles, which assume threats may already exist inside the environment and requires continuous verification of users, devices, and access. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.