Skip to content

Security1 publisher3 min readPublished

Fourteen percent of attack actions raised an alert across Picus's 338 million simulations

Picus's Blue Report blames performance issues and log-collection gaps for the misses, both of them configuration work, which is why an AI SOC pointed at that pipeline would only get faster at the one action in seven that already alerts.

The Watch · Security desk

Illustration accompanying Fourteen percent of attack actions raised an alert across Picus's 338 million simulations

What happened

  • The Picus Blue Report 2026 aggregated 338 million attack simulations run by breach and attack simulation tooling inside customer production environments during the first half of 2026.
  • Prevention effectiveness across those runs averaged 69 percent, which left roughly a third of simulated attacks getting past the controls bought to stop them.
  • Logging hit a four-year high at 58 percent of attack actions captured in the SIEM, while the share of actions that produced an alert stayed unchanged at 14 percent.
  • Performance issues now lead detection rule failures at 49 percent, double the 24 percent recorded a year earlier, with log collection gaps accounting for a further 41 percent.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost At four to six hours per CVE, the daily arrival rate is 520 to 780 analyst-hours, so the real decision is which CVEs never get asked about, and headcount rather than exposure decides it.
  • decision Budget aimed at an AI SOC buys speed on the 14 percent of actions that already alert and does nothing for the 86 percent that do not, which puts detection engineering ahead of autonomy in the spending queue.
  • exposure Any programme that validates only critical CVEs is exposed on commodity paths, since the year's least-prevented vulnerabilities sat in a browser, archive utilities, OpenSSL and core OS components at under 25 percent blocked.
  • contradiction The article's own diagnosis is that the failures are configuration and operations work no product purchase resolves, yet the piece is a vendor argument for upgrading the product.

Of every 100 attack actions in the Picus data, 58 reach the SIEM and 14 raise an alert [3]. About three quarters of what has already been collected never fires a rule [3]. That backlog is detection engineering, and in the generation-one BAS design it is priced in engineer hours: someone has to turn a finding into a signature the NGFW will accept or a rule the SIEM will actually fire on [18].

Put the CVE question on the same books. More than 130 new CVEs a day [8], at four to six hours each to answer by hand [10], is 520 to 780 analyst-hours per day [1]. Fit that inside the roughly ten hours the article gives from public disclosure to a weaponized exploit [7] and you need 52 to 78 analysts working in parallel, every day [2]. That is why only the most critical CVEs ever get asked and the rest of the list goes untested [11]. Automated pentesting does not rescue the tail, because it needs a working exploit and day one has none [17].

Average prevention slid seven points in one year and was won back the next, and Picus attributes the difference to who kept testing [13]. A pass proved in March is a claim about March.

The ten-hour figure, the 130-a-day figure and the assertion that fewer than 0.5% of disclosed vulnerabilities are ever patched upstream [9] all appear without a cited measurement [19]. The 338 million simulations are Picus telemetry from Picus customers' production environments [1], and the article, published by Help Net Security, is built around Picus's own autonomous BAS [16]. The timeline numbers, then, are vendor framing rather than independently sourced figures.

The internal numbers survive that discount. Performance issues at 49%, up from 24% the previous year, plus log collection gaps at 41% [4][5] account for 90% of detection rule failures [5], and by the article's own reading both are configuration and operations problems that another purchase does not fix [6]. The log gaps are the worse half because they fail silently: the behavior is never captured, so no rule can fire on it [5].

That is also the case against the reflex purchase. An AI SOC's unit of work is the alert, and autonomy cannot triage an alert that never fires [15]. At a 14% alert score, 86 of every 100 attack actions produce nothing to triage [4].

Human red teams needed about 24 hours to turn a major new threat into working simulation content, and until a few months ago that counted as very fast [14]. The two numbers that carry the argument for continuous validation are the seven-point swing and the four to six hours per CVE [13][10]. Both are measurable inside your own environment, and neither depends on the ten-hour claim being right.

What to watch

  • Whether anyone publishes the measurement behind the ten-hour disclosure-to-exploit figure, or a party other than Picus reproduces it.
  • The next Blue Report's alert score: 14% has not moved, and a rise would be the first sign detection engineering load is actually being automated.
  • Whether performance issues keep doubling as a share of rule failures after going 24% to 49% in a year, which would point at SIEM capacity rather than rule quality.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories