# Deep Purple Report 2025 · AI summary

> AI-generated summary of *Effectiveness of Operational Cybersecurity, Deep Purple Report 2025* (Erium, April 2025, TLP:CLEAR). Refer to the full report for figures and charts.

## Scope
- 500+ simulated attacks and 18,000 technical events in 2024, all mapped to MITRE ATT&CK.
- More than three quarters of campaigns on office IT; industrial environments stable (~6%); cloud and SaaS rising.

## Key figures
- **Average detection score: 38/100**, up from 22 in 2023 (+72%).
- Main detection sources: EDR 65%, SIEM/XDR 42%, firewall 24%, NDR 18%, antivirus 6%.
- Response stays mostly manual: per SANS 2024, 67.8% semi-automated, 22.7% manual, 8% fully automated.

## Findings
- Detection works best in the middle of the kill chain; reconnaissance, discovery and exfiltration remain the weakest stages.
- Living-off-the-Land techniques and PowerShell variants still escape detection; the same EDR can behave differently by PowerShell version.
- Containment targets the compromised machine rather than the attacking source.
- 40,000 CVEs published in 2024 (+38%): vulnerability-centric approaches alone no longer suffice.
- Behavioral detection (UEBA) is gaining ground for cloud and SaaS.
- A clear surge of simulations in H2 2024 for NIS2, DORA and TIBER-EU compliance.

## Recommendations
- Enrich EDR configuration whatever the execution vector.
- Deploy multi-layer detection and response (EDR + SIEM/XDR + NDR).
- Move towards automated or semi-automated remediation, and go back to the source of the attack.
- Train teams on their tools and on coordination between SOC, CSIRT/CERT and IT.
