Internal networks nearly defenseless: reconnaissance stopped only 10% of the time

Corporate defenses posted their best numbers in years, but only at the perimeter. Inside networks, attackers operate almost unopposed, according to Picus Labs' Blue Report 2026, based on more than 338 million real attack simulations across client production environments in the first half of 2026.
Average prevention effectiveness rose from 62% to 69%, matching the 2024 peak, while logging hit a four-year high of 58%. But behind those figures lies a troubling trend: the recovery is happening almost exclusively at the network edge, while internal defenses are growing increasingly fragile.
For the first time, Picus Labs measured post-compromise prevention using autonomous penetration testing: how effectively security controls break the attack chain once an adversary is already inside the network as an authenticated user. The Post-Compromise Prevention Rate stood at just 37%. While the perimeter blocks roughly two attacks out of three, inside the network barely one in three is stopped.
Internal defenses fail unevenly, along a clear line: noisy actions get caught, quiet ones don't. Lateral movement between machines via service execution, using techniques like Sharp-ServiceExec and SMBExec, was blocked about 90% of the time, and UAC-bypass privilege escalation succeeded at around 85%. This reflects EDR doing its job and years of assume-breach investment showing up in the numbers.
But the quiet work of attackers meets almost no resistance. Reconnaissance — mapping the domain, enumerating shares and sessions — was the least-prevented category of all, stopped only 10% of the time. Detection of credentials being quietly read from memory reached about 22%, while one variant pulling secrets straight from the registry was blocked in less than 1% of attempts.


