Picus Security has warned that defensive effectiveness against cyber-threats is slipping, as its latest Blue Report shows a decline in prevention rates and growing attacker success.
Based on more than 160 million real-world attack simulations in live production environments, the Blue Report 2025 found that while cyber-attacks continue to grow in volume and sophistication, the ability of security controls to stop them is deteriorating.
In 46% of environments tested, at least one password hash was successfully cracked – up from 25% in 2024 – while data exfiltration attempts were blocked only 3% of the time, down from 9% last year.
The report noted that infostealer malware has tripled in prevalence, and attackers are increasingly using valid logins to bypass defences. Attacks using valid credentials succeeded 98% of the time, making the technique one of the most reliable ways to evade detection.
“We must operate under the assumption that adversaries already have access,” said Dr. Süleyman Ozarslan, co-founder of Picus Security and VP of Picus Labs.
“An ‘assume breach’ mindset pushes organisations to detect the misuse of valid credentials faster, contain threats quickly, and limit lateral movement — which requires continuous validation of identity controls and stronger behavioural detection.”
The Blue Report also highlighted persistent challenges in stopping ransomware. BlackByte was identified as the hardest strain to prevent, with a prevention effectiveness rate of just 26%. BabLock and Maori followed at 34% and 41% respectively.
Recommended reading
- UK Gov Cyber Breaches Survey 2024 | Key Stats and Data
- Report: Cyber Breaches Are Tanking Share Prices
- Cyber-crime Costs to Hit $1.2tn in 2025, New Report Warns
Detection also remains a weak point.
Discovery techniques such as System Network Configuration Discovery and Process Discovery scored below 12% in prevention effectiveness. Logging coverage held steady at 54%, yet only 14% of attacks generated alerts — a shortfall Picus attributed to gaps in detection rule configuration, logging, and system integration.
Overall prevention effectiveness dropped from 69% in 2024 to 62% in 2025, reversing gains made last year. According to Picus, the findings illustrate how quickly security controls can degrade without ongoing oversight and validation.





