Security1 publisher2 min readPublished
Unit 42 counts four or more attack surfaces in 43% of its investigations
The figure is Palo Alto Networks' own, drawn from investigations where a single endpoint alert turned out to be one leg of an intrusion running through cloud, identity and SaaS at the same time.
The Watch · Security desk

What happened
- The figure is attributed to the 2026 Unit 42 Global Incident Response Report, and the post citing it gives no case count.
- The early legs Unit 42 lists look routine on their own: an endpoint alert, a cloud administrator provisioning a resource outside normal activity, an unfamiliar app asking for elevated permissions.
- The remedy the post prescribes is platform-level correlation into unified incident storylines, delivered by Palo Alto's Cortex SecOps, Unit 42 MDR analysts and Managed XSIAM.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint An analyst holding one leg of a four-surface intrusion has nothing to correlate it against, so the ceiling this sets is on triage quality.
- decision SOC owners have to decide where correlation lives: in a platform that joins identity, cloud and endpoint telemetry, or in an analyst moving between consoles by hand.
- precedent Vendor incident response counts increasingly set architecture expectations, and buyers will be quoted this one in procurement.
- cost A consolidation budget justified only by the four-surface share is being justified by the minority of these cases. The case for correlating across tools supports more than that.
A pivot across four surfaces leaves four separate records, and each one looks ordinary by itself. As the intrusion progresses, Unit 42 says permissions change inside a SaaS application, cloud resources get provisioned or reconfigured, data is staged for exfiltration, and new network connections appear between systems that rarely talk to each other [5]. Investigated separately, the post says, teams can miss the connection between those signals and the larger attack [6].
"Because attackers don't operate within the boundaries monitored by individual security tools, security operations can't either," Unit 42 wrote [7].
If 43% of the cases involved four or more surfaces, 57% involved three or fewer [1]. A stack rebuilt on the strength of the 43% is being rebuilt for the smaller share of what these responders worked. Two domains already cross a console boundary, so the case for cross-domain correlation does not stand or fall on the four-surface count.
The post names five environments that attacks move across: cloud, endpoint, network, identity and SaaS [3]. It also reports cases spanning as many as eight attack surfaces, three more than that list holds [2][2]. Nothing in the post defines what counts as a surface, so 43% is not a number a buyer can reproduce against another responder's count, or against their own.
That matters for how the figure gets used. Consolidation pitches lean on counts like this one, and a count whose unit is undefined cannot be compared across vendors. The post's argument about correlation stands on its own: an analyst who can see one leg of a pivot has nothing to correlate it against. Correlation across identity, cloud and endpoint telemetry is a property of the platform or of the analyst's memory, not of the individual alert.
The cheapest recommendation in the post is the after-action one. Review each investigation for where analysts lost context, where detections or correlation rules could be improved, and which response steps created delays, then refine the detection logic, correlation rules, automation and playbooks from what the review found [10].
What to watch
- The 2026 Unit 42 Global Incident Response Report itself: how many cases, and what counts as an attack surface behind the 43%.
- Whether another incident response shop publishes a comparable multi-surface count for 2026 that can be set against 43%.
- Any measured figure for containment or detection time in cross-domain correlated investigations versus per-tool ones.