TL;DR: Security leaders report 93% confidence they have taken the right steps to prevent a breach, but only 12% validated EDR effectiveness in the last three months and 26% test whether the SOC can detect and interrupt real attack techniques, according to Horizons.ai. The gap shows why verification, not dashboard completion, is becoming the practical measure of resilience.
At a glance
What this is: This research argues that security programmes relying on completion metrics are mistaking activity for proof of resistance.
Why it matters: It matters to IAM practitioners because identity, privilege, and lateral movement controls only reduce risk when they are validated against real attack paths, not assumed from checklist completion.
By the numbers:
- 93% of CISOs believe they’ve taken the right steps to prevent a breach
- 12% have validated EDR effectiveness in the last 3 months
- 26% test whether their SOC detects and interrupts real attack techniques
- 11% confirm or remediate known exploited vulnerabilities within 24 hours
👉 Read Horizons.ai's research on assumed security and real-world validation
Context
Security validation is the difference between believing a control works and proving it under attack. This report focuses on that gap across defensive programmes, where teams often track patches, tickets, and scan counts while missing whether real adversary techniques can still move through the environment. The primary keyword here is security validation, because that is the standard the report says is replacing assumed security.
The identity angle is indirect but real. When attackers can move laterally, reuse credentials, or bypass weak detection, the underlying failure is often not a missing policy but an unproven control across access, privilege, and response. That makes the findings relevant to IAM, PAM, and NHI governance teams as well as broader SOC and resilience owners.
Key questions
Q: What breaks when security teams rely on dashboard completion instead of validation?
A: Completion metrics can show that tasks were done without proving that controls stop an attacker. The result is a false sense of security, especially when identity abuse, lateral movement, or privilege escalation can still succeed. Practitioners need proof that controls interrupt real techniques, not just evidence that tickets were closed.
Q: Why do identity and privilege controls matter in security validation programmes?
A: Because many real attacks turn on credential abuse, over-permissioned access, or reusable sessions. If IAM and PAM controls are not tested under realistic conditions, organisations may assume they reduce risk while attackers still have a workable path. Validation shows whether those controls actually constrain movement and access.
Q: How can security teams tell whether remediation is reducing attacker opportunity?
A: Look for fewer exploitable external paths, fewer systems with reachable high privilege, and shorter time to close exposures that map to critical assets. If the programme only reduces ticket counts, it may be improving reporting without lowering real risk.
Q: Should organisations prioritise attack-path testing before expanding more controls?
A: Yes, when they already have broad tooling but weak proof of effectiveness. Attack-path testing reveals which controls actually interrupt adversary movement and which only report coverage. That helps security teams invest in the weakest link first, especially where identity paths or privilege chains remain open.
Technical breakdown
Why completion metrics fail as proof of security
Dashboard-centric security programmes often measure outputs rather than resistance. A closed ticket, a completed scan, or a patched endpoint says little about whether an attacker can still authenticate, escalate, or move laterally after initial access. Validation changes the question from did we finish the task to does the control hold when tested against real techniques. That matters because modern attack paths are chained, adaptive, and identity-aware. If controls are only checked in isolation, the programme can look healthy while the adversary still has a viable route through privilege, authentication, or exposed services.
Practical implication: replace completion reporting with control validation tied to live attack paths.
How real-world exploitability testing changes prioritisation
Exploitability testing asks whether a vulnerability, misconfiguration, or access path can actually be used in context. That is different from simply confirming a fix exists. In practice, validation can show that two issues with the same severity score have very different operational risk because one is reachable, chainable, and likely to support lateral movement. For identity teams, this includes testing whether standing privileges, stale credentials, and weak detection paths still allow meaningful abuse even when hygiene metrics look acceptable. The control problem is not existence of policy, but proof that policy blocks abuse under realistic conditions.
Practical implication: prioritise remediation by exploit path, not by scan count alone.
Attack-path elimination and lateral movement testing
Attack-path elimination focuses on removing the sequence an adversary would use, not just individual weaknesses. Lateral movement testing is especially important because identity compromise often becomes the bridge from an initial foothold to broader environment control. This means validating whether privileged accounts, service identities, and over-permissioned sessions still enable traversal between systems, clouds, or workloads. In security terms, the programme is moving from static control assurance to dynamic resistance testing. That aligns closely with zero trust principles, where access is continuously challenged and assumed trust is replaced by observable verification.
Practical implication: test for chained movement from initial access to privileged reach, then remove the weakest link.
Threat narrative
Attacker objective: The attacker aims to turn presumed control coverage into actual access, then expand that access through paths defenders have not validated.
- Entry begins when an attacker gains a foothold through a reachable weakness, exposed service, or identity weakness that was assumed to be controlled.
- Escalation occurs when the attacker uses that foothold to test whether credentials, permissions, or lateral movement paths remain viable in practice.
- Impact follows when the adversary reaches systems, data, or privileged workflows that the programme believed were protected by completion metrics rather than verified resistance.
NHI Mgmt Group analysis
Assumed security is a governance failure, not a tooling failure. Organisations often have dashboards that show tasks completed, yet those same controls may never have been tested against an adversary’s actual route through the environment. That creates a false sense of confidence at board level and a dangerous prioritisation model at operational level. For practitioners, the lesson is that proof of resistance must replace proof of activity.
Security validation is the right named concept for this market shift. It describes the move from counting remediation work to demonstrating that controls interrupt exploitation, lateral movement, and privilege abuse. That matters because identity-driven attacks rarely fail at the first barrier. They fail only when access, detection, and response are tested as a chain. For IAM and PAM teams, this means control efficacy must be measurable under attack conditions, not inferred from policy coverage.
Identity governance becomes more important when the environment is harder to trust. If attackers can move by abusing credentials, service identities, or excessive privileges, then the control question shifts toward whether access paths are observable and interruptible. This is where NHI governance, PAM, and zero-standing-privilege practices intersect with broader security validation. For practitioners, the implication is to validate identity controls in the same way you validate detection and endpoint resilience.
Completion metrics create remediation theatre when exploitability is still open. A vulnerability can be scanned, a ticket can be closed, and a patch can be recorded while the attack path remains available through adjacent conditions. That is why real-world exploitability matters more than backlog reduction alone. For security leaders, the practical conclusion is to make remediation meaningful by tying it to verified loss of attacker reach.
The market is moving toward measurable resistance as the default security language. Security programmes will increasingly be judged by whether they can prove interruption, not merely report coverage. That will pressure vendors, SOCs, and identity teams to show evidence of control performance across detection, privilege, and attack-path elimination. For practitioners, the direction of travel is clear: validation becomes the operating model, not an occasional exercise.
What this signals
Security validation will become a board-level language for proving control effectiveness. For identity and security programmes, that means dashboards will matter less than evidence that attackers cannot reuse credentials, traverse privilege chains, or bypass detection. Teams should expect pressure to tie IAM, PAM, and SOC metrics to observable interruption rather than activity volume.
Attack-path reduction is the practical bridge between zero trust and operational resilience. The next maturity step is not simply adding more controls, but proving that existing controls break adversary sequences at the point of identity, access, or response. For practitioners, that means prioritising testable reductions in attacker reach over incremental reporting gains.
Validation debt is the new governance gap. If an organisation cannot show that key controls were tested against real techniques, its security posture rests on assumption, not evidence. That gap will increasingly affect IAM, NHI governance, and PAM programmes because identity remains a common route into broader systems.
For practitioners
- Validate controls against live attack techniques Test whether EDR, SOC workflows, and identity controls actually interrupt adversary behaviour rather than only showing administrative completion. Use attack simulations that chain initial access, privilege abuse, and lateral movement so the result is measurable resistance, not a checklist outcome.
- Prioritise exploit paths over scan volumes Sort remediation by whether an issue is reachable, chainable, and likely to support privilege escalation or lateral movement. This keeps teams from optimising ticket closure while leaving active paths open.
- Test identity controls under attack conditions Include privileged accounts, service accounts, and session controls in validation exercises so IAM and PAM assumptions are proven against realistic abuse. Use the 52 NHI Breaches Analysis as a reference point for common identity failure patterns.
- Measure response interruption, not activity counts Track whether the SOC can detect and stop real attacker techniques, then compare that result with scan closure and patch completion metrics. The goal is to align operational reporting with actual reduction in attacker reach.
Key takeaways
- The report shows that many security programmes are still measuring activity rather than proving resistance to attack.
- The gap between executive confidence and validated control effectiveness is wide enough to distort prioritisation and leave attack paths open.
- Identity, privilege, and response controls now need to be tested as a chain, because that is how attackers actually move.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement | The report focuses on proving resistance to attacker techniques and movement. |
| NIST CSF 2.0 | DE.CM-8 | The article centres on validation of monitoring and response effectiveness. |
| NIST SP 800-53 Rev 5 | SI-4 | System monitoring and analysis align with proving defensive effectiveness. |
Map validation exercises to credential access and lateral movement tactics, then test whether controls interrupt them.
Key terms
- Security Validation: Security validation is the practice of testing whether controls actually stop or disrupt attacker behaviour in a real environment. It goes beyond compliance checking and focuses on observable resistance, including whether detection, privilege, and response controls still hold when challenged.
- Attack path: A sequence of identities, permissions, systems, and data stores that an attacker can traverse after obtaining trusted access. In practice, attack paths matter more than single accounts because they show how a low-risk identity can become a route to high-value exposure.
- Exploitability context: Exploitability context is the evidence used to decide whether a vulnerability matters in a specific environment. It includes reachability, code path exposure, compensating controls, and product-specific advisories, and it turns raw scan data into a decision that can be defended.
- Lateral Movement: A post-compromise technique where an attacker uses a compromised NHI to move through a network, accessing additional systems and escalating impact without triggering detection.
What's in the full report
Horizons.ai's full research covers the operational detail this post intentionally leaves for the source:
- The survey methodology behind the 750 security leader responses and how the questions were framed
- The validation criteria used to compare EDR effectiveness, SOC detection, and exploitability testing
- The report's practical guidance on attack-path elimination and measurable risk reduction
- The full breakdown of remediation mistakes that can hide exploitable conditions behind closed tickets
Deepen your knowledge
NHI Mgmt Group's NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives practitioners a structured way to connect identity control design to operational risk and validation.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org