Horizon3.ai Research Reveals Growing Divide Between Security Leaders and Practitioners
嗯,用户让我总结这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”这样的开头。好的,我先快速浏览一下文章。 文章主要讲的是关于网络安全的报告,指出组织在使用AI加速攻击风险时,存在一个很大的问题:他们衡量的是活动,而不是防御能力。比如,CISO们认为他们的端点保护能够检测攻击者行为,但实际测试却很少。只有30%的组织在补丁后测试风险是否真正解决。 报告还提到,领导层对“低风险”的信心与实际操作中的暴露情况不符。检测被广泛信任,但在现实条件下很少被验证。自动化加快了速度,但验证却没有跟上。这些因素导致了“假设安全”的状态,即组织只衡量活动,而没有确认防御是否能真正抵御攻击。 最后,随着攻击者利用AI的能力增强,这种差距变得更加关键。因此,安全必须从衡量活动转向验证防御是否有效。 现在我要把这些要点浓缩到100字以内。首先说明报告的主题和主要发现:组织在AI加速攻击风险时只衡量活动而非防御能力。然后提到CISO的信心与实际测试不足的情况。接着指出检测未被现实验证和自动化的问题。最后强调安全需从活动转向验证防御。 这样应该能准确概括文章内容,并且符合用户的要求。 </think> 新报告指出,随着AI加速现实世界攻击风险,组织衡量的是安全活动而非防御能力。CISO对端点保护信心满满,但仅12%近期测试过能力;30%组织未验证补丁效果。检测被广泛信任却少经实战考验,自动化加快速度但验证不足。安全需从追踪活动转向确认防御有效性。 2026-4-28 12:5:0 Author: horizon3.ai(查看原文) 阅读量:22 收藏

New report shows organizations are measuring activity, not resistance, as AI accelerates real-world attack risk

San Francisco — April 28, 2026 — There is a growing disconnect between how security is reported at the executive level and how risk is experienced by those operating security programs day to day, according to new research from Horizon3.ai, the AI-native proactive security leader.

That gap is reflected in the data: 97% of CISOs say they are confident their endpoint protection would detect attacker behavior, yet only 12% report testing that capability within the last three months. Just 30% of organizations report patching and then testing to confirm that risk has actually been remediated.

Horizon3.ai today announced the findings of its 2026 research report, “The State of Assumed Security: Why Measuring Activity Is Not the Same as Measuring Resistance.” The report surveyed 750 cybersecurity leaders and practitioners across the United States and Europe.

The report highlights how many CISOs believe their organizations would withstand a determined attack, while practitioners report significant exposure, unresolved attack paths, and gaps in validation.

This divide is not theoretical. It shapes how risk is prioritized, how resources are allocated, and how security effectiveness is measured.

“Security programs today are optimized for workflow completion. Scan, patch, rescan, close. That does not mean an attack will fail. As attackers move faster and chain weaknesses across identity, infrastructure, and cloud, the only thing that matters is whether those controls actually stop the attack,” said Snehal Antani, CEO and co-founder of Horizon3.ai.

The report identifies a consistent set of breakdowns across modern security programs:

  • Leadership confidence in “low risk” diverges from practitioner reality
  • Remediation workflows close tickets without closing attack paths
  • Detection is widely trusted but rarely proven under real-world conditions
  • Automation is increasing speed faster than validation
  • Security metrics track progress, not whether exposure has been eliminated

Together, these breakdowns reinforce what the report defines as “assumed security”, a state where organizations measure activity, but do not consistently confirm whether defenses can withstand real attacker behavior.

This gap becomes more consequential as attackers evolve.

Emerging AI capabilities are reducing the effort required to identify, exploit, and connect vulnerabilities into real-world attack paths. As the path from discovery to impact continues to shrink, the difference between assuming security and proving it becomes critical.

“Security teams don’t struggle to find problems. They struggle to prove those problems are actually gone. Most workflows end at patch and rescan, but attackers don’t operate in isolation. They chain weaknesses into real attack paths. If you’re not validating those paths in your environment, you’re not measuring risk,” said Dan Bird, Field CTO EMEA, Horizon3.ai.

The findings point to a clear shift in how security must be measured. Activity alone is no longer a reliable proxy for risk reduction. What matters is whether defenses actually hold under realistic attack conditions.

The full report is available here.

About HORIZON3.ai

Horizon3.ai is the AI-native proactive security company redefining how organizations validate and strengthen their defenses. It is the company behind NodeZero®, the world’s best and most experienced AI hacker, trusted by four of the Fortune 10, global banks, top pharmaceutical and semiconductor manufacturers, and critical infrastructure operators.

NodeZero enables organizations to proactively hack, fix, verify, and repeat testing on demand across their environment, resulting in stronger defenses and measurable improvements in cyber resilience. Founded by former U.S. Special Operations members and industry experts, Horizon3.ai is trusted by organizations worldwide.

Follow HORIZON3.ai on LinkedIn and X.

Media Contact

Stephen Gates
[email protected]


文章来源: https://horizon3.ai/news/press-release/horizon3-research-security-gap/
如有侵权请联系:admin#unsafe.sh