Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do BAS and CART produce different security…
Cyber Security

Why do BAS and CART produce different security answers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Cyber Security

BAS checks whether known techniques are detected or blocked by defensive controls, while CART tries to reach a real objective through an adaptive attack path. One grades the stack against a script, the other tests whether an adversary can actually get to the crown jewels. They are complementary, not interchangeable.

Why BAS and CART answer different questions

BAS and CART look similar because both sit in the validation and assurance space, but they measure different things. BAS is control-centric: it checks whether a scripted technique is detected, blocked, or otherwise handled by the current defensive stack. CART is outcome-centric: it asks whether an adversary can keep adapting and still reach a real objective despite those controls.

The practical difference is that BAS usually starts with a known technique and a predefined expected result, while CART starts with a goal and explores the path needed to achieve it. That means BAS is better for testing specific detections, guardrails, and control coverage, while CART is better for understanding attack resilience, control bypass, and whether layered defenses actually protect high-value assets.

Because they optimise for different evidence, they can legitimately produce different answers from the same environment. A platform may pass a BAS test because it blocks a known pattern, yet still fail a CART scenario if a determined adversary can chain weaker controls, abuse trust boundaries, or pivot around the initial block. Conversely, a control gap exposed by BAS may never become a successful CART outcome if other safeguards interrupt the path before objective completion.

What each approach is really proving

BAS proves how a specific control set behaves against a bounded test. It is useful when the practitioner wants to know, “Did the EDR, SIEM, email filter, or other defensive layer respond the way we expected to this known technique?” In other words, it validates defensive execution against a repeatable script.

CART proves whether the defender has created enough friction, detection, and containment to stop an attacker from completing a meaningful mission. It is useful when the practitioner wants to know whether the environment can resist an adaptive sequence that includes discovery, access, escalation, movement, and objective completion. For that reason, CART tends to surface composition problems that single-step tests miss, including weak segmentation, excessive privilege, and inadequate monitoring of chained actions. MITRE ATT&CK Enterprise Matrix is a useful reference when you want to map those chains to known adversary techniques.

The difference also matters for interpretation. BAS results are usually easier to benchmark over time because the test path is stable. CART results are often more realistic for business risk because they measure whether a defender can stop a living adversary, not just a fixed harness. That is why the two approaches are complementary: one is strong at control verification, the other at adversary outcome validation.

How to use BAS and CART together without confusing the signal

Use BAS when the question is about control performance, coverage gaps, or regression testing after a change. Use CART when the question is about exposure, resilience, or whether an attacker can still reach something valuable even if several controls fire correctly. If you want both confidence and realism, BAS should tell you which defenses fail on contact, and CART should tell you whether the remaining path still matters operationally.

The cleanest way to combine them is to treat BAS as the tactical check and CART as the scenario check. A BAS failure often points to a specific broken detection or block. A CART success often points to a broader architectural weakness, such as a path that remains open even after the obvious control works. For that reason, CART findings are usually more actionable for prioritisation, while BAS findings are often more precise for engineering remediation. NIST Cybersecurity Framework 2.0 is useful here because it separates govern, protect, detect, respond, and recover concerns in a way that helps teams place each test type in the right part of the programme.

When the results differ, do not assume one is wrong. Check what each test was designed to prove, what assumptions it made about attacker behavior, and whether the control failure is local or systemic. A BAS pass with a CART failure usually means the stack can stop a known technique but not an adaptive campaign. A BAS failure with a CART failure usually means the control gap is both real and exploitable. A BAS failure with a CART pass may indicate a noisy but non-fatal weakness that still deserves attention because it expands the attacker's options.

Risk and Threat Considerations

Teams can over-trust BAS because it produces crisp pass/fail output, but that output may only prove one technique under one set of assumptions. CART reduces that blind spot by forcing the question of whether an attacker can route around apparently healthy controls and still reach a business-critical target.

Failure mechanism: A scripted BAS scenario validates isolated control behavior, while an adaptive adversary in CART exploits chaining, privilege, trust, or segmentation weaknesses that were outside the script.

Impact: Defenders may believe they are protected when the environment still allows real compromise paths, delayed detection, or successful objective completion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKEnterprise MatrixBAS and CART both map attack paths to known adversary techniques.
Recommendation — Map test scenarios to ATT&CK techniques and use the matrix to review missing detection or blocking coverage.
NIST CSF 2.0DE.CM-01 — The network is monitored to detect potential cybersecurity eventsBAS evaluates whether controls detect or block a known technique.
ID.RA-01 — Asset vulnerabilities are identified and documentedCART exposes whether weaknesses allow a real attack path to reach an objective.
PR.AA-05 — Network integrity is protected, including by segmentation and boundary protectionCART often shows whether segmentation and boundaries still stop adaptive attack paths.
Recommendation — Use BAS results to validate monitoring coverage against the techniques you expect to detect. Use CART findings to prioritise vulnerabilities that create realistic adversary paths to critical assets. Validate segmentation and boundary controls against realistic multi-step attack paths.

Practitioner Guidance

What to prioritise: Treat BAS as a regression and coverage tool, then reserve CART for paths that would produce material business impact if they succeeded. The highest-value CART scenarios are usually those that test lateral movement, privilege gain, or access to crown-jewel systems rather than generic compromise of low-value assets.

What to verify: Make sure the test design, not the vendor label, matches the question being asked. If you need to know whether a control blocks a known technique, BAS is the better fit. If you need to know whether an attacker can still achieve an objective after defenders react, CART is the better fit.

Practitioner takeaway: The main decision is not which method is “better”, but whether you need control validation or adversary-outcome validation. Mature programmes use BAS to prove individual defenses and CART to prove that the remaining path still fails in practice.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org