# Deep Purple Report IV (2026) · AI summary

> AI-generated summary of *Operational Security Effectiveness, Deep Purple Report IV* (Erium, updated August 2026). Refer to the full report for figures, charts and methodology.

## Scope
- More than 2,000 attack simulations run in 2025 and H1 2026 on production infrastructures.
- Mid-caps and large groups: public sector, finance and insurance, industry, telecoms, aerospace, transport, retail, healthcare.
- OT/ICS environments doubled their share (12% of campaigns in 2025); cloud and SaaS coverage accelerated.

## Key message
Vulnerabilities grow faster than they can be patched, accelerated by AI-assisted offense. Alongside **Patch First**, a second principle emerges: **Response First**. The most exploitable vulnerabilities must trigger a rapid, automated, proportionate response, and that response must be verified under real conditions.

## Four findings
1. **Detection keeps improving:** 42/100 in 2025 (+11% vs 2024), but cloud, OT/ICS and supply chain shift the blind spots.
2. **Weakest areas:** Discovery, Exfiltration and Lateral Movement, especially against Living-off-the-Land techniques.
3. **Response validation takes hold:** MTTR is timed and automated countermeasures are tested before activation.
4. **Regularity beats SOC model:** simulation frequency explains progress far better than in-house, MSSP or hybrid set-ups.

## Detection sources (2025)
- EDR 69% · SIEM/XDR 49% · NDR 21%.
- Best detected: OS Credential Dumping, Kerberos ticket theft, Impair Defenses, Abuse Elevation Control, Default Accounts.
- Least detected: Network Service Discovery, Account Discovery, Exfiltration over alternative protocols and web services, Remote Services.

## How organizations use validation
- Detection validation 90% · Response (MTTR) validation 60% · NIS2/DORA compliance 60% · Crisis exercise preparation 50%+ · Pentest targeting, supply chain and rule forging 20%.

## Five recommendations for 2026/27
1. Qualify open vulnerabilities through attack paths.
2. Validate automated response before broad activation, then after every major change.
3. Train for taking back control on high-impact scenarios, end to end.
4. Turn every gap into training: replay, learning paths, quizzes, role-play.
5. Reuse the same evidence across SOC, CIRT, GRC, executive committee, compliance and providers.
