-

Horizon3.ai Research Reveals Growing Divide Between Security Leaders and Practitioners

New report shows organizations are measuring activity, not resistance, as AI accelerates real-world attack risk

SAN FRANCISCO--(BUSINESS WIRE)--There is a growing disconnect between how security is reported at the executive level and how risk is experienced by those operating security programs day to day, according to new research from Horizon3.ai, the AI-native proactive security leader.

That gap is reflected in the data: 97% of CISOs say they are confident their endpoint protection would detect attacker behavior, yet only 12% report testing that capability within the last three months. Just 30% of organizations report patching and then testing to confirm that risk has actually been remediated.

Horizon3.ai today announced the findings of its 2026 research report, “The State of Assumed Security: Why Measuring Activity Is Not the Same as Measuring Resistance.” The report surveyed 750 cybersecurity leaders and practitioners across the United States and Europe.

The report highlights how many CISOs believe their organizations would withstand a determined attack, while practitioners report significant exposure, unresolved attack paths, and gaps in validation.

This divide is not theoretical. It shapes how risk is prioritized, how resources are allocated, and how security effectiveness is measured.

“Security programs today are optimized for workflow completion. Scan, patch, rescan, close. That does not mean an attack will fail. As attackers move faster and chain weaknesses across identity, infrastructure, and cloud, the only thing that matters is whether those controls actually stop the attack,” said Snehal Antani, CEO and co-founder of Horizon3.ai.

The report identifies a consistent set of breakdowns across modern security programs:

  • Leadership confidence in “low risk” diverges from practitioner reality
  • Remediation workflows close tickets without closing attack paths
  • Detection is widely trusted but rarely proven under real-world conditions
  • Automation is increasing speed faster than validation
  • Security metrics track progress, not whether exposure has been eliminated

Together, these breakdowns reinforce what the report defines as “assumed security,” a state where organizations measure activity, but do not consistently confirm whether defenses can withstand real attacker behavior.

This gap becomes more consequential as attackers evolve.

Emerging AI capabilities are reducing the effort required to identify, exploit, and connect vulnerabilities into real-world attack paths. As the path from discovery to impact continues to shrink, the difference between assuming security and proving it becomes critical.

“Security teams don’t struggle to find problems. They struggle to prove those problems are actually gone. Most workflows end at patch and rescan, but attackers don’t operate in isolation. They chain weaknesses into real attack paths. If you’re not validating those paths in your environment, you’re not measuring risk,” said Dan Bird, Field CTO EMEA, Horizon3.ai.

The findings point to a clear shift in how security must be measured. Activity alone is no longer a reliable proxy for risk reduction. What matters is whether defenses actually hold under realistic attack conditions.

The full report is available here: https://horizon3.ai/downloads/research/the-state-of-assumed-security/

About HORIZON3.ai

Horizon3.ai is the AI-native proactive security company redefining how organizations validate and strengthen their defenses. It is the company behind NodeZero®, the world’s best and most experienced AI hacker, trusted by four of the Fortune 10, global banks, top pharmaceutical and semiconductor manufacturers, and critical infrastructure operators.

NodeZero enables organizations to proactively hack, fix, verify, and repeat testing on demand across their environment, resulting in stronger defenses and measurable improvements in cyber resilience. Founded by former U.S. Special Operations members and industry experts, Horizon3.ai is trusted by organizations worldwide.

Follow Horizon3.ai on LinkedIn and X.

Contacts

Media Contact
Stephen Gates
press@horizon3.ai

Horizon3.ai


Release Versions

Contacts

Media Contact
Stephen Gates
press@horizon3.ai

Social Media Profiles
More News From Horizon3.ai

Horizon3.ai Accelerates Channel Investment at Global Partner Conference: Americas

SAN FRANCISCO--(BUSINESS WIRE)--Horizon3.ai, the AI-native proactive security leader, today announced expanded investment in its global partner ecosystem at its Global Partner Conference: Americas, signaling a continued shift toward partner-led growth and scaled delivery of offensive security outcomes. Now in its second year, the event brings together more than 100 partners in Orlando, Florida, reflecting strong momentum across the channel. Partners are a key driver of growth, with 32 percent o...

Horizon3.ai Named to Fast Company’s Annual List of the World’s Most Innovative Companies of 2026

SAN FRANCISCO--(BUSINESS WIRE)--Horizon3.ai is proud to have been named to Fast Company’s prestigious list of the World’s Most Innovative Companies of 2026. This year’s list shines a spotlight on businesses that are shaping industry and culture through their innovations. Alongside the World’s 50 Most Innovative Companies, Fast Company recognizes 720 honorees across 59 sectors and regions. “NodeZero® is the most experienced AI hacker in the world. It relentlessly seeks ways to compromise your ne...

Horizon3.ai’s NodeZero®, the World’s Most Experienced AI Hacker, Drives 102% ARR Growth

SAN FRANCISCO--(BUSINESS WIRE)--Horizon3.ai, the AI-native proactive security leader, today announced strong FY2026 growth, with annual recurring revenue (ARR) increasing 102% year over year. This momentum is driven by rapid enterprise and MSSP adoption, as organizations turn to NodeZero to identify and eliminate exploitable attack paths in production environments. More than 5,200 organizations globally, from Fortune 10 enterprises to local school districts, hospitals, manufacturers, financial...
Back to Newsroom