GlobeNewswire by notified

Picus Research Finds Defenses Block Only 37% of Post-Compromise Attacker Actions

11.8.2026 15:04:00 CEST | GlobeNewswire by notified | Press release

Share

Analysis of more than 338 million attack simulations finds prevention improved, but significant gaps remain in post-compromise defense, ransomware protection and data-loss prevention

SAN FRANCISCO, Aug. 11, 2026 (GLOBE NEWSWIRE) -- Picus Security, the leading exposure validation company, today published The Blue Report 2026, which shows a sharp divide between the attacks organizations stop at the perimeter and the actions they prevent after an attacker gets inside. Prevention effectiveness recovered to 69%, returning to its 2024 peak. However, once an attacker gains access, only 37% of their actions get blocked.

Findings are based on analysis of more than 338 million attack simulations run in production environments between January and June 2026. The study showed that security controls perform best against conspicuous activity, including certain lateral movement and privilege escalation techniques. The largest post-compromise gaps involved low-noise activity. Quiet discovery and collection actions were blocked in approximately one in 10 attempts, allowing simulated attackers to enumerate domains, identify file shares, discover active sessions and collect credential material with limited resistance.

“Organizations have become much better at stopping attacker activity that creates obvious signals,” said Dr. Süleyman Ozarslan, co-founder of Picus Security and VP of Picus Labs. “The problem is what happens before those signals appear. Attackers can quietly map an environment, locate valuable systems and gather credentials while many defenses remain inactive. This is why validating defenses across the entire attack path is so critical.”

Detection and prevention gaps persist across the attack chain

The findings also point to a persistent gap between telemetry collection and actionable detection across industries. Organizations logged 58% of simulated attacks but generated alerts for only 14% of them. Fewer than one in seven attacks produced an alert. Performance issues accounted for 49% of identified detection-rule issues, up from 24%.

Other findings include:

  • Evasion techniques were the hardest for controls to block: organizations blocked just 1% of Impair Command History Logging (T1562.003) simulations and 9% of Signed Script Proxy Execution (T1216) simulations, the two lowest technique-level prevention scores in the report. Prevention effectiveness against the Stealth tactic also weakened, from 53% to 47%, one of only two tactics for which controls performed worse than last year.
  • Endpoint security improved as the assume-breach mindset took hold: endpoint prevention reached 83% and Privilege Escalation rose 24 points to 79%, the largest tactic-level gain of the year.
  • Malware prevention fell again as IOC-based detection lost ground: malware-download prevention declined to 50%, down 21 points over two years.
  • Strong performance is rented, not owned: last year’s strongest sectors regressed and last year’s weakest recovered. Transportation gained 29 points to reach 79%, Education lost 30 to land at 40%, South Asia moved from last place to a share of first at 71%, and North America fell to the lowest prevention score of any region at 60%.

Action items for security teams

Based on these findings, Picus recommends that organizations continuously test whether their controls can prevent, detect and contain current attacker behavior. This includes validating complete attack paths, particularly quiet post-compromise discovery, collection and credential-access activity.

Security teams should regularly test detection rules, confirm log-source health and verify that attacks generate actionable alerts. They should also strengthen behavioral detection to reduce reliance on static signatures and known indicators.

Organizations should simulate current ransomware and threat-group behavior across the full attack chain. Vulnerability remediation should prioritize demonstrated exploitability rather than severity scores alone.

About The Blue Report

The Picus Security Blue Report offers empirical evidence of how well security controls perform in real-world conditions. Findings are based on millions of simulated attacks executed by Picus Security customers from January to June 2026. The simulations were conducted safely in live production environments using Picus’ Security Validation Platform and analyzed by the Picus Labs and Picus Data Science teams. The report also includes ecosystem- and industry-specific findings and recommendations to help companies reduce exposure and improve threat readiness.

To read the full findings and recommendations, download the Blue Report 2026.

About Picus Security

Picus Security, the leading exposure validation company, proves what attackers can exploit and what your defenses stop, then closes real gaps with ready-to-deploy fixes and re-validates to confirm, at the machine speed today's AI threats demand. The Picus Platform spans Breach and Attack Simulation, Autonomous Penetration Testing and Exposure Validation, unified by Picus Swarm, a swarm of AI agents that runs the whole validation loop continuously with human oversight. With 75+ integrations, it reaches across on-prem, hybrid cloud, and endpoint environments.

Trusted by many Fortune 500 enterprises, Picus was named a 2025 Gartner Peer Insights Customers' Choice for Adversarial Exposure Validation and is recognized as an Innovation Leader in the Frost Radar for Automated Security Validation.

Follow Picus Security on X and LinkedIn.

Media Contact
Jennifer Tanner
Look Left Marketing
picus@lookleftmarketing.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/bc3718a1-6b01-439f-a14c-0b2040de830d

Subscribe to releases from GlobeNewswire by notified

Subscribe to all the latest releases from GlobeNewswire by notified by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from GlobeNewswire by notified

Iveco Group signs a 150 million euro term loan facility with Cassa Depositi e Prestiti to support investments in research, development and innovation11.6.2024 12:00:00 CEST | Press release

Turin, 11th June 2024. Iveco Group N.V. (EXM: IVG), a global automotive leader active in the Commercial & Specialty Vehicles, Powertrain and related Financial Services arenas, has successfully signed a term loan facility of 150 million euros with Cassa Depositi e Prestiti (CDP), for the creation of new projects in Italy dedicated to research, development and innovation. In detail, through the resources made available by CDP, Iveco Group will develop innovative technologies and architectures in the field of electric propulsion and further develop solutions for autonomous driving, digitalisation and vehicle connectivity aimed at increasing efficiency, safety, driving comfort and productivity. The financed investments, which will have a 5-year amortising profile, will be made by Iveco Group in Italy by the end of 2025. Iveco Group N.V. (EXM: IVG) is the home of unique people and brands that power your business and mission to advance a more sustainable society. The eight brands are each a

DSV, 1115 - SHARE BUYBACK IN DSV A/S11.6.2024 11:22:17 CEST | Press release

Company Announcement No. 1115 On 24 April 2024, we initiated a share buyback programme, as described in Company Announcement No. 1104. According to the programme, the company will in the period from 24 April 2024 until 23 July 2024 purchase own shares up to a maximum value of DKK 1,000 million, and no more than 1,700,000 shares, corresponding to 0.79% of the share capital at commencement of the programme. The programme has been implemented in accordance with Regulation No. 596/2014 of the European Parliament and Council of 16 April 2014 (“MAR”) (save for the rules on share buyback programmes set out in MAR article 5) and the Commission Delegated Regulation (EU) 2016/1052, also referred to as the Safe Harbour rules. Trading dayNumber of shares bought backAverage transaction priceAmount DKKAccumulated trading for days 1-25478,1001,023.01489,100,86026:3 June 20247,0001,050.597,354,13027:4 June 20245,0001,055.705,278,50028:6 June20243,0001,096.273,288,81029:7 June 20244,0001,106.174,424,68

Landsbankinn hf.: Offering of covered bonds11.6.2024 11:16:36 CEST | Press release

Landsbankinn will offer covered bonds for sale via auction held on Thursday 13 June at 15:00. An inflation-linked series, LBANK CBI 30, will be offered for sale. In connection with the auction, a covered bond exchange offering will take place, where holders of the inflation-linked series LBANK CBI 24 can sell the covered bonds in the series against covered bonds bought in the above-mentioned auction. The clean price of the bonds is predefined at 99,594. Expected settlement date is 20 June 2024. Covered bonds issued by Landsbankinn are rated A+ with stable outlook by S&P Global Ratings. Landsbankinn Capital Markets will manage the auction. For further information, please call +354 410 7330 or email verdbrefamidlun@landsbankinn.is.

Relay42 unlocks customer intelligence with a new insights and reporting module, powered by Amazon QuickSight11.6.2024 11:00:00 CEST | Press release

AMSTERDAM, June 11, 2024 (GLOBE NEWSWIRE) -- Relay42, a leading European Customer Data Platform (CDP), is leveraging Amazon QuickSight to power its new real-time customer intelligence, reporting, and dashboard module. Harnessing the breadth and quality of customer data, the new Insights module empowers marketing teams to dive deep into customer behaviors and gain invaluable insights into the performance of their marketing programs across all online, offline, paid, and owned marketing channels. Preview of the Relay42 Insights module, in pre-beta version Key capabilities of the Relay42 Insights module include: Deep insights into customer behaviors: With the Relay42 Insights module, marketers can ask unlimited questions about their data and gain a deeper understanding of how to serve their customers more effectively. Simplicity with AI-powered querying: Marketers can use artificial intelligence to query their data using natural language search, reducing the reliance on data scientists. Us

Metasphere Labs Announces X Spaces Event on the Topic of Green Bitcoin Mining and Sound Money for Sustainability11.6.2024 10:30:00 CEST | Press release

VANCOUVER, British Columbia, June 11, 2024 (GLOBE NEWSWIRE) -- Metasphere Labs Inc. (formerly Looking Glass Labs Ltd., "Metasphere Labs" or the "Company") (Cboe Canada: LABZ) (OTC: LABZF) (FRA: H1N) is thrilled to announce an engaging Twitter Spaces event on Green Bitcoin mining, energy markets, and sustainability on July 3, 2024 at 2 p.m. ET. Follow us on X at MetasphereLabs for updates and to join the event. What We'll Discuss Bitcoin Mining Basics: Understand the fundamentals of Bitcoin mining.Energy Market Dynamics: Explore how Bitcoin mining interacts with energy markets.Sustainable Innovations: Learn about our efforts to promote sustainability in Bitcoin mining.Sound Money: Discover how tamper-proof currency can enhance stability.Efficient Payment Rails: See how fast, neutral payment systems support humanitarian projects.Carbon Footprint: Compare Bitcoin's environmental impact with traditional banking. "We're excited to host this event and dive into the critical topics of Bitcoin

World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye