The Defensive GapStanding
Where the defensive playbook runs out
Updated 12 August 2026 · Timeframe: Current snapshot
MITRE keeps two facing catalogs: ATT&CK for what attackers do, D3FEND for the defensive techniques that answer them. We laid MITRE's own defense-to-attack mapping over the whole enterprise ATT&CK matrix. Only 44 percent of techniques have a D3FEND countermeasure. Two whole attack stages, reconnaissance and resource development, have none at all, because they happen before an attacker ever touches your systems. Inside the wire the coverage is thinnest at execution (19 percent) and impact (36 percent).
Why it matters
A defensive-technique catalog is a map, not a checklist. Where it is thin you are leaning on detection and response, not on a named preventive technique. And nothing in it watches the two stages before an attacker arrives, so those belong to threat intelligence and exposure management instead.
What to do
- Security leaders. Read D3FEND coverage as a map of where preventive techniques exist. At execution and impact, budget for detection and response, not prevention.
- Lean IT orgs. The best-covered stages, credentials and privilege, are the cheap wins: multi-factor, least privilege, account hygiene.
- MSPs. Nothing in the defensive catalog covers reconnaissance; if you sell attack-surface monitoring, that is the gap it fills, and worth naming.
Our take
Showing exactly where the standard defensive catalog runs out, over the full attack matrix and with the gaps left visible, is the evidence-first framing.