Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Security validation gaps: are your controls proving resistance?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security leaders report 93% confidence they have taken the right steps to prevent a breach, but only 12% validated EDR effectiveness in the last three months and 26% test whether the SOC can detect and interrupt real attack techniques, according to Horizons.ai. The gap shows why verification, not dashboard completion, is becoming the practical measure of resilience.

NHIMG editorial — based on content published by Horizons.ai: The State of Assumed Security

By the numbers:

Questions worth separating out

Q: What breaks when security teams rely on dashboard completion instead of validation?

A: Completion metrics can show that tasks were done without proving that controls stop an attacker.

Q: Why do identity and privilege controls matter in security validation programmes?

A: Because many real attacks turn on credential abuse, over-permissioned access, or reusable sessions.

Q: How can security teams tell whether remediation is reducing attacker opportunity?

A: Look for fewer exploitable external paths, fewer systems with reachable high privilege, and shorter time to close exposures that map to critical assets.

Practitioner guidance

  • Validate controls against live attack techniques Test whether EDR, SOC workflows, and identity controls actually interrupt adversary behaviour rather than only showing administrative completion.
  • Prioritise exploit paths over scan volumes Sort remediation by whether an issue is reachable, chainable, and likely to support privilege escalation or lateral movement.
  • Test identity controls under attack conditions Include privileged accounts, service accounts, and session controls in validation exercises so IAM and PAM assumptions are proven against realistic abuse.

What's in the full report

Horizons.ai's full research covers the operational detail this post intentionally leaves for the source:

  • The survey methodology behind the 750 security leader responses and how the questions were framed
  • The validation criteria used to compare EDR effectiveness, SOC detection, and exploitability testing
  • The report's practical guidance on attack-path elimination and measurable risk reduction
  • The full breakdown of remediation mistakes that can hide exploitable conditions behind closed tickets

👉 Read Horizons.ai's research on assumed security and real-world validation →

Security validation gaps: are your controls proving resistance?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Assumed security is a governance failure, not a tooling failure. Organisations often have dashboards that show tasks completed, yet those same controls may never have been tested against an adversary’s actual route through the environment. That creates a false sense of confidence at board level and a dangerous prioritisation model at operational level. For practitioners, the lesson is that proof of resistance must replace proof of activity.

A question worth separating out:

Q: Should organisations prioritise attack-path testing before expanding more controls?

A: Yes, when they already have broad tooling but weak proof of effectiveness. Attack-path testing reveals which controls actually interrupt adversary movement and which only report coverage. That helps security teams invest in the weakest link first, especially where identity paths or privilege chains remain open.

👉 Read our full editorial: Assumed security is failing: why verification now matters



   
ReplyQuote
Share: