Picus Finds Major Gaps in Internal Enterprise Defenses

Picus Labs’ Blue Report 2026 found a sharp divide in enterprise security performance. Across more than 338 million attack simulations in client production environments during the first half of 2026, average prevention effectiveness rose from 62% to 69%, matching the 2024 peak. Yet once an attacker was operating inside the network as an authenticated user, the Post-Compromise Prevention Rate was only 37%.
The results suggest that perimeter controls are recovering faster than internal controls. Picus Labs measured post-compromise resilience through autonomous penetration testing, examining whether security tools could interrupt an attack chain after initial access rather than only block an external entry attempt.
Quiet actions remain the weakest point
Internal defenses performed comparatively well against conspicuous techniques. Lateral movement through service execution, including Sharp-ServiceExec and SMBExec, was blocked about 90% of the time. UAC-bypass privilege escalation was stopped at roughly 85%.
The weakest results involved low-noise activity that can prepare an intruder for later actions. Reconnaissance, including domain mapping and the enumeration of shares and sessions, was prevented only 10% of the time. Credential material read from memory was detected at around 22%, while one registry-based credential-access variant was stopped in less than 1% of attempts.
This distinction reflects the limits of controls focused on known signatures. Picus Labs ran Mimikatz toward the same credential-theft objective through three routes. The familiar LSASS memory-dumping path was blocked almost every time, but retrieving credentials from other memory locations or from the registry was rarely prevented. The tool and goal were unchanged; the detectable route was different.
Detection is not keeping pace with telemetry
Logging reached a four-year high of 58%, but the alert score stayed at 14%. Fewer than one in seven simulated attacks produced an alert, leaving a substantial gap between collected telemetry and operational response. Picus Labs characterises this as a detection-engineering issue rather than a data-collection problem.
Indicator-based malware prevention also weakened. The IOC-Based Prevention Rate for known malicious downloaded files declined to 50%, from 60% in 2025 and 71% in 2024. Repacking can change an indicator without changing the underlying behaviour, limiting tests that assess only previously identified files.
The wider threat landscape has also highlighted the value of testing for changing attacker methods: evolving exploitation chains and attacker techniques shows how incident reporting increasingly tracks evolving exploitation chains and attacker techniques rather than isolated indicators. In the Blue Report dataset, prevention declined against nine of the ten hardest-to-stop threat groups, and every leading ransomware family was blocked less than 38% of the time; Play fell from 50% to 13%.
Continuous validation becomes an operational task
Picus Labs attributes the overall seven-point prevention increase to organisations retesting controls that had drifted and addressing weaknesses exposed by those tests. It recommends validating exploitable exposure rather than theoretical inventory, hardening internal controls against discovery and passive credential access, and treating detection rules as systems that must be tested, tuned and revalidated.
For security teams, the practical implication is to measure controls from an authenticated attacker’s position as well as at the perimeter, prioritising quiet discovery and credential-access behaviours and confirming that relevant logs produce actionable alerts.

