top of page

Picus Blue Report 2026: Multi-million dollar defenses still miss quiet attacks

According to the annual Blue Report 2026 recently published by Picus Labs, the cybersecurity defense capabilities of enterprises are showing signs of recovery, but the truth behind these positive numbers hides many concerning vulnerabilities.

The Blue Report is an annual research report conducted by Picus Security (Picus Labs), with the purpose of evaluating the real-world effectiveness of enterprise defense and malware, ransomware detection solutions. Based on the analysis of over 338 million real attack simulations in the first half of 2026, Picus Labs has painted a comprehensive picture of how current security systems operate.

A solid exterior, an empty interior

The most notable bright spot is that the average prevention effectiveness has increased from 62% to 69%, matching its 2024 peak. This shows that the outer protection solutions (perimeter) are doing their job of blocking hackers quite well.

the-average-prevention-effectiveness-has-increased-picus-blue-report-2026
The average prevention effectiveness has increased.

However, complacency will quickly disappear if we look at what happens at the "core". For the first time, Picus Labs conducted a measurement of post-compromise defense effectiveness (via autonomous attack simulation - autonomous pentest). The results show: the successful prevention rate inside the internal network plummeted drastically, to only 37%.

Simply put, at the gateway, the system can block 2/3 of attacks. But when bad actors have gotten inside and operate under the guise of a valid user, the system only stops 1/3 of destructive actions, leaving the remaining 2/3 of behaviors free to run rampant. Enterprises are pouring a lot of money into building a towering wall, but forgetting to protect the courtyard inside.

Technological barriers: Catching the loud, missing the quiet

The failure of the internal network does not happen randomly. It diverges clearly based on how the attacker acts: loudly or quietly.

With easily detectable behaviors such as running malicious code, moving between servers (lateral movement), or attempting to gain administrative privileges (privilege escalation), Endpoint Detection and Response (EDR) systems operate very effectively, blocking 85% to 90% of these efforts.

autonomus-pentesting-effectiveness
Autonomus Pentesting effectiveness

But on the flip side, "quiet" actions are almost invisible to the monitoring layers. Techniques like system reconnaissance and network scanning are only blocked at a paltry rate of 10%. The stealthy extraction of login credentials from memory is also only detected at about 22%. Most alarmingly, when malicious actors deliberately steal passwords from the Registry, the prevention rate plunges to under 1%.

This shows that hackers can freely map the network, harvest passwords, and prepare everything without facing any resistance, before they decide to launch the decisive blow.

The blind spot from signature-based detection methods

The root cause of this weakness lies in how security tools operate: they rely too heavily on "signatures" (signature) – meaning previously known recognition signs.

The report provides a valuable example from Mimikatz, a popular password theft tool. If hackers use Mimikatz to extract data the "traditional" way from LSASS memory, the system easily catches them with a 94% rate. Why? Because this behavior is so famous that security vendors have long put it on the blacklist.

But if it is the same Mimikatz, with the same goal of stealing passwords, but the malicious actor shifts direction to read from the Registry, the prevention rate immediately freefalls to 3%. The security system is completely "blind" to this behavior because it looks exactly like a normal operation of a system administrator.


evaluation-of-the-mimikatz-tool
Evaluation of the Mimikatz tool

Similarly, the prevention effectiveness against malware infections through downloads is also sliding down, from 71% (in 2024) to 60% (in 2025) and currently to only 50%. As attackers continuously repackage malware into new shells, chasing old detection patterns (IOC) becomes a lopsided race for antivirus software.

the-prevention-effectiveness-against-malware-is-sliding-down
The prevention effectiveness against malware infections through downloads is sliding down.

The monitoring paradox: Overflowing data but absent alerts

When proactive defense layers fail, the last hope is placed on the alerting system (alert) for humans to intervene in time. Sadly, this checkpoint is also facing a serious problem.

This year, the system logging rate (logging) reached the highest level in the past 4 years at 58%. But the alert generation rate stagnated at the figure of 14%. This means less than 1/7 of simulated attacks triggered an alarm.

Enterprises are collecting more monitoring data than ever, but cannot turn that data into practical action. The gap between what is recorded and what is alerted is no longer a data collection problem, but a daunting challenge in alert configuration techniques (detection engineering).

Security effectiveness is not a permanent asset

The report also points out that, even against notorious and well-studied threat groups, the defense capabilities of enterprises are still losing ground. The prevention level has declined against 9/10 of the most complex attack groups. Top extortion malware (ransomware) families all have block rates below 38%, in which the Play malware family recorded a severe drop from 50% to only 13%.

enterprise-defenses-effectiveness
Enterprise Defenses effectiveness

From the data presented in the Blue Report 2026, Picus Labs offers practical recommendations for enterprises to strengthen their security shields:

  • Validate real risks instead of counting theoretical flaws: Do not just tally vulnerabilities on paper. Use simulation and testing methods (like autonomous pentest) to see which vulnerabilities can actually be exploited in your network.

  • Harden the system against reconnaissance behaviors: It is necessary to rigorously test monitoring systems against quiet moves like network scanning and account information harvesting, and shift the focus from "signature"-based detection to "behavioral" analysis.

  • Fine-tune the alerting system: The building of alert rules must be seen as a continuous engineering process. Rely on the latest attack behaviors to write rules, ensure they operate effectively, filter out spam notifications, and continuously update them according to the actual situation.

In summary, information security is not a box bought to be used forever. It is like a subscription service, and its value only truly exists if the enterprise continuously tests, updates, and validates the resilience of the system against the increasingly sophisticated tactics of cybercriminals.

References: Blue Report 2026, Help Net Security

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page