Horizon3.ai says organisations are measuring cybersecurity activity, not actual resistance to attacks
Horizon3.ai says many organisations have become proficient at measuring cybersecurity activity, but not whether their systems would actually withstand a real-world cyberattack.
In an exclusive interview with MoveTheNeedle.news, Dan Bird MBE, Field Chief Technology Officer (EMEA) at Horizon3.ai, said the gap between perceived and actual cyber resilience is widening as artificial intelligence accelerates cyberattacks and increases pressure on security teams to validate whether their defences can genuinely withstand attacker behaviour.
The company’s newly released 2026 research report, “The State of Assumed Security: Why Measuring Activity Is Not the Same as Measuring Resistance”, is based on responses from 750 cybersecurity leaders and practitioners across the United States and Europe. According to the research, 97% of chief information security officers (CISOs) said they were confident their endpoint protection systems would detect attacker behaviour. Yet only 12% reported testing those capabilities within the previous three months. Just 30% of organisations said they patched vulnerabilities and then tested to confirm the underlying risk had actually been removed.
The findings point to a growing divide between how cybersecurity is reported at executive level and how exposure is experienced by practitioners operating increasingly complex enterprise environments.
Why Horizon3.ai says organisations are relying on “assumed security”
The report’s central argument is that many organisations still measure cybersecurity through workflows and operational outputs rather than validated resistance to attacks.
“Security programs today are optimized for workflow completion. Scan, patch, rescan, close. That does not mean an attack will fail,” said Snehal Antani in the press release accompanying the report. “As attackers move faster and chain weaknesses across identity, infrastructure, and cloud, the only thing that matters is whether those controls actually stop the attack.”
Bird said the disconnect often begins with the metrics organisations choose to prioritise: “At the executive level, security is measured through process completion such as assets scanned, vulnerabilities found, patches deployed and tickets closed. These metrics are visible and reportable, but they measure effort, not outcome. Closing a ticket confirms work was done. It doesn't confirm an attacker can no longer succeed.”
Bird argues that practitioners working directly with security systems often see a different reality, one shaped by untested assumptions, unresolved attack paths and weaknesses that can still be chained together by attackers.
That distinction is relevant as modern cyberattacks rarely depend on a single vulnerability. Attackers increasingly combine stolen credentials, configuration weaknesses, software flaws and lateral movement techniques to move through environments in ways that traditional vulnerability management systems do not always reflect.
Why patching vulnerabilities no longer guarantees cyber resilience
So many organisations still rely heavily on vulnerability scans, ticket closure rates and compliance reporting as indicators of resilience, but, according to Horizon3.ai, those indicators no longer provide a reliable picture of exposure.
“You can patch every individual finding on your list and still have a fully viable route to domain compromise,” Bird said. “The path runs through the gaps between your findings, not just through the findings themselves.”
That issue becomes more pronounced as security teams face growing volumes of alerts and vulnerabilities. According to Bird, organisations can end up optimising for the speed of remediation workflows rather than focusing on which vulnerabilities genuinely increase breach risk.
This reflects a wider challenge across the cybersecurity industry. Enterprises today operate increasingly fragmented environments spanning cloud platforms, remote endpoints, industrial systems and identity infrastructure. Many security tools remain specialised around individual categories of risk rather than analysing how weaknesses interact across entire systems.
The result is that organisations may appear secure according to internal dashboards while remaining vulnerable to real-world attack paths.
How AI is changing the speed and scale of cyberattacks
The Horizon3.ai report places particular emphasis on the role AI is beginning to play in cyber operations.
AI is not changing attackers’ objectives, Bird said, but “AI can map attack paths faster than most organisations can process their scanner output. It collapses the time between vulnerability discovery and exploitation.”
This compression of time increasingly challenges traditional security workflows that were designed around periodic scanning, scheduled patch cycles and manual validation.
The report argues that as AI lowers the operational cost of reconnaissance and exploitation, organisations will need to place greater emphasis on continuous validation rather than static assessments.
Security vendors have increasingly focused on continuous validation, automated penetration testing and breach simulation as organisations look for ways to test resilience under realistic conditions.
The underlying idea is that organisations should repeatedly test whether attackers could realistically achieve critical objectives inside their own environments, rather than relying solely on vulnerability scans or compliance frameworks.
Horizon3.ai positions its NodeZero platform within that broader transition. The company describes the platform as an autonomous security testing system designed to emulate attacker behaviour across enterprise environments.
Measuring resistance instead of cybersecurity activity
“The most practical way to measure resistance is through a ‘hack, fix, verify’ approach,” Bird advised. “First, you safely emulate real attacker behaviour to identify whether exploitable attack paths actually exist in the environment. Then you remediate the issues you uncover.”
The critical step, he added, is retesting after remediation to verify whether the attack path has genuinely been eliminated.
That emphasis on validation makes sense when looking at regulatory developments. Bird pointed to the European Union’s NIS2 cybersecurity directive, which increases obligations around risk management and incident reporting for operators of essential and important services.
Under frameworks such as NIS2, organisations face growing pressure not only to deploy security controls, but also to demonstrate that those controls are effective.
The challenge is organisational as well as technical. Many companies still separate vulnerability management, detection engineering, compliance and incident response into distinct operational silos. Measuring resistance requires a more integrated understanding of how attackers actually move across systems.
Cybersecurity’s growing gap between perceived and actual resilience
The Horizon3.ai report ultimately presents cybersecurity as a measurement problem as much as a tooling problem.
For years, organisations have accumulated dashboards, alerts and compliance metrics intended to provide visibility into risk. The company’s research suggests those systems can also create a false sense of confidence when they measure operational activity rather than validated resistance.
“Validation is rapidly becoming a standard practice now that practitioners know it is technically possible at scale,” Bird said.
Whether that shift becomes widespread may depend on how quickly organisations adapt to the operational realities created by AI-driven attacks. According to Horizon3.ai, companies that continue relying primarily on procedural metrics could see the gap between perceived and actual security widen further.
“The organisations that close the gap will be the ones that make continuous validation a standard practice rather than a periodic event,” Bird said. “The ones that don't will find that their dashboards look increasingly reassuring while their actual exposure grows.”
Further reading on MoveTheNeedle.news:
Language Is the New Attack Surface: Why AI Security Needs a Fundamental Rethink