What 338 Million Attack Simulations Reveal About Enterprise Defenses in 2026
A new report from Picus Labs analyzes 338 million security simulations to evaluate enterprise defense effectiveness. While overall prevention rates have rebounded to 69%, the study highlights a significant vulnerability in post-compromise scenarios, where only 37% of attacker actions are blocked.
Why it matters
It underscores the critical gap in cybersecurity between initial perimeter defense and the ability to stop lateral movement and data discovery once an attacker has gained access.
Picus Labs has spent four years putting the same question to enterprise security stacks: when a real attack lands, does the control stop it? The Blue Report 2026 answers it with over 338 million simulations executed across live customer environments between January and June 2026.
This year's dataset reads like a recovery story, right up until you ask what happens after an attacker is already authenticated.
Average prevention effectiveness rose from 62% to 69%, erasing last year's seven-point decline and returning to the 2024 peak.
Worth knowing what that number counts. Breach and Attack Simulation runs known threats against a customer's own controls, their firewalls, email and web gateways, EDR and XDR, and each threat breaks down into individual attacker actions. 69% is the share of those actions the stack blocked.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in