According to Picus’s Blue Report 2026, enterprise cybersecurity defenses improved in 2026.
However, organizations continue to struggle with detecting stealthy attacker behavior and converting security telemetry into actionable alerts.
The report analyzed more than 338 million simulated attacks conducted in Picus customer environments between January and June 2026.
Picus measured how effectively existing security controls prevented attacks and whether simulated malicious activity generated logs and alerts.
Overall prevention scores increased from 62% in 2025 to 69% in 2026, returning to the level recorded in 2024.
The findings indicate that stronger perimeter defenses do not necessarily translate into equivalent protection once attackers gain access to an environment.
Key takeaways of the Picus Blue Report for 2026
- Cyberattack prevention improved overall, with Picus reporting that prevention effectiveness increased from 62% in 2025 to 69% in 2026.
- Post-compromise defenses remain weaker, with organizations preventing only 37% of tested attacker actions after authenticated access was established.
- Improved security logging is not translating into better alerting, as the log score rose to 58% while the alert score remained at just 14%.
- Ransomware prevention deteriorated against leading threats, with all 10 of the least-prevented ransomware families scoring 38% or lower.
Picus finds gaps in post-compromise security defenses
One of the report’s significant findings concerns what happens after an attacker gains authenticated access.
Picus found a post-compromise prevention rate of only 37%, substantially below the overall 69% prevention score.
The difference was especially pronounced between conspicuous and low-noise attacker behavior.
Lateral movement techniques using service execution were prevented approximately 90% of the time, while privilege escalation techniques using UAC bypass were blocked approximately 85% of the time.
In comparison, discovery and collection activity was prevented in only about 10% of attempts.
In Picus’ analysis of MITRE ATT&CK techniques, Impair Command History Logging (T1562.003) was blocked in just 1% of simulations, while Account Access Removal (T1531) was prevented only 2% of the time.
Data Encoding (T1132) and Signed Script Proxy Execution (T1216) each recorded prevention rates of just 9%.
More security telemetry is not producing more actionable alerts
Organizations also improved their ability to capture attacker activity without making comparable progress in alerting security teams.
The average log score increased from 54% to 58%, its highest level across editions of the report.
However, the alert score remained unchanged at just 14%, meaning fewer than one in seven simulated attacks generated a meaningful alert.
Picus identified detection engineering issues as a major contributor to this gap.
Performance issues accounted for 49% of detection rule failures, compared with 24% the previous year.
Log collection issues declined from 50% to 41%, suggesting that the challenge is shifting from just collecting telemetry to efficiently processing it and producing useful alerts.
Remaining gaps in log collection are concerning because activity that goes unrecorded cannot trigger an alert, underscoring the need for organizations to prioritize detection engineering.
Ransomware prevention declines
The report also found deteriorating protection against several ransomware families.
All 10 of the least-prevented ransomware families had prevention scores of 38% or lower, while their average prevention score declined from approximately 44% in 2025 to 32% in 2026.
Play ransomware experienced the largest decline, falling from a 50% prevention rate to just 13%.
BlackByte was prevented in 25% of simulations, while LockBit was blocked in only 30% of simulations, down from 45% last year.
Security controls can degrade without continuous validation
Picus’ findings demonstrate that cybersecurity effectiveness can change as threats, configurations, and infrastructure evolve.
The company recommends continuously validating controls, strengthening behavioral detection, testing ransomware and advanced persistent threat attack chains, and improving detection engineering.
Security controls can degrade over time because of configuration drift, broken integrations, operational complexity, and evolving attacker techniques, reinforcing the need for ongoing testing and tuning.
These findings also reinforce the value of Zero Trust principles, which assume threats may already exist inside the environment and requires continuous verification of users, devices, and access.





