# BlackNoise reports 2022 to 2026 · AI synthesis

> AI-generated synthesis of four BlackNoise editions (2022 barometer, 2023 annual report, Deep Purple 2025, Deep Purple IV 2026). Figures come from the reports; metrics evolved between editions, so compare trends rather than absolute values.

## Four years in numbers
| Edition | Scope | Headline detection figure | Top detection source |
|---|---|---|---|
| 2022 barometer | 85 simulations, 5,270 events | 8% average detection rate | EDR (75%) |
| 2023 annual report | 300+ simulations, 13k events | score 22/100 | EDR (68%) |
| Deep Purple 2025 (2024 data) | 500+ simulations, 18k events | score 38/100 (+72%) | EDR (65%), SIEM/XDR 42% |
| Deep Purple IV (2025 data) | 2,000+ simulations | score 42/100 (+11%) | EDR (69%), SIEM/XDR 49%, NDR 21% |

## What changed
- **Detection matured, then plateaued** on mastered scopes, while cloud, OT/ICS and supply chain opened new blind spots.
- **Blind spots are stable:** discovery, lateral movement and exfiltration have been the weakest stages every year.
- **From one tool to a chain:** EDR remains the cornerstone, now paired with SIEM/XDR and complemented by NDR.
- **From measuring to validating:** BAS became Adversarial Exposure Validation; response (MTTR) and automated blocking are now tested, not assumed.
- **Compliance became a driver:** NIS2, DORA and TIBER-EU turned simulation results into evidence.

## Constant lesson
Regularity outweighs exhaustiveness: the organizations that progress most are those that test most often, whatever their SOC model.
