Cyber Resilience

The Defensive GapStanding

Where the defensive playbook runs out

Updated 12 August 2026 · Timeframe: Current snapshot

Privilege escalation80Credential access73Persistence64Defense evasion41Execution19Reconnaissance0
D3FEND coverage by attack stage (% of techniques with a countermeasure) · security-resilience.ai

MITRE keeps two facing catalogs: ATT&CK for what attackers do, D3FEND for the defensive techniques that answer them. We laid MITRE's own defense-to-attack mapping over the whole enterprise ATT&CK matrix. Only 44 percent of techniques have a D3FEND countermeasure. Two whole attack stages, reconnaissance and resource development, have none at all, because they happen before an attacker ever touches your systems. Inside the wire the coverage is thinnest at execution (19 percent) and impact (36 percent).

Why it matters

A defensive-technique catalog is a map, not a checklist. Where it is thin you are leaning on detection and response, not on a named preventive technique. And nothing in it watches the two stages before an attacker arrives, so those belong to threat intelligence and exposure management instead.

What to do

Our take

Showing exactly where the standard defensive catalog runs out, over the full attack matrix and with the gaps left visible, is the evidence-first framing.