Skip to main content

Study: 37% of Known Cyber Threats Have No Working Detection Coverage

Dallas and Tel Aviv – September 24, 2026 -- Enterprises have working detections for only 63% of the cyber threats they have already identified as relevant, leaving more than a third of known risks operationally uncovered, according to new research from Conifers based on an analysis of 14,652 detections in live enterprise environments.

The report, titled The Detection Blind Spot, found that detection coverage extended to just 64% of the MITRE ATT&CK techniques relevant to each environment studied. Nearly half of all detections examined, 47%, required attention before they could be trusted to function as intended, despite appearing as deployed or healthy in standard inventory-based reporting.

Detection failures span five distinct categories across the security stack

Conifers identified five recurring issues undermining detection reliability: logic errors preventing correct firing, missing telemetry from data sources that stopped flowing or were never onboarded, queries pointed at incorrect data tables, duplicate detections inflating alert volume without adding coverage, and noisy detections so frequent or imprecise that analysts learned to ignore them.

Vendor-owned detections outside the SIEM create unfixable blind spots

Validation efforts have historically concentrated on SIEM rules because they are directly visible and editable by security teams. But endpoint, cloud, identity, email, and network security products each generate their own vendor-authored detections. When these vendor-owned detections misfire, security teams often cannot correct the underlying logic and are left to suppress the alert, tolerate the gap, or let the noise persist until analysts tune it out.

Executives link the gap to accelerating agentic-adversary speed

"The underlying problem with threat detection isn't that detections were poorly written. It's that the telemetry beneath them changes, making detections stale and ineffective without anyone realizing it," said Rutger de Boer, CTO at DTX. Tom Findling, CEO and co-founder of Conifers, said the industry has measured detection strength by counting rules and tools, but "deployed is not the same as protected," adding that threat intelligence, exposure data, hunting, and detection engineering need to operate as one continuous system rather than siloed functions linked by tickets and quarterly reviews.

Report prescribes six operational fixes for security leaders

Conifers recommends measuring coverage through verified working detections mapped to relevant threats rather than raw detection counts; extending detection health management beyond the SIEM to vendor-managed tools; establishing a control point to tune, deduplicate, and suppress detections before they reach analyst queues; tracking the time between identifying a threat and deploying a verified working detection; anchoring threat hunting in exposure data tied to crown-jewel assets; and feeding validated hunt findings back into detection engineering.

Published by
fairsonline_team
Company
Products
News Type