Insights from Compromise Assessment projects: missed incidents and hidden threats

Analytics2026-07-03, 16:19
Kaspersky researchers analyzed the results of Compromise Assessment projects conducted in 2025 and identified key reasons why attackers can remain undetected in corporate infrastructures for months. Below are the main findings — the full report is available at this link.
60% of incidents were not detected by existing security tools before the Compromise Assessment began. About 20% of threats were identified only through manual analysis by specialists.
More than half (52%) of high‑severity incidents showed traces of compromise for over 90 days. In one case, attackers remained in the infrastructure for about four years, using compromised domain controllers for covert cryptomining.
40% of detected web shells were found in backups, creating a risk of re‑compromise after infrastructure restoration.
86% of organizations that claimed to have a vulnerability management process still had exploitable misconfigurations. The authors attribute this to a lack of formalized vulnerability management processes and incomplete asset inventory: in 25% of cases individual servers were not monitored at all.
In every project that revealed an incident, attackers used remote‑administration tools and Living off the Land (LoLBins) techniques to disguise their activity as legitimate OS processes.
The researchers also note that organizations conducting Compromise Assessments regularly are far less likely to face high‑severity incidents than those turning to such audits only after an attack.
The study demonstrates that the absence of detections should not be taken as proof of security. In practice, what matters most is not just having monitoring tools but overall operational maturity: proper configuration of defenses, continuous monitoring, proactive threat hunting, accurate asset inventory, and analysts' readiness to investigate even low‑priority events. Equally important are well‑defined communication processes and regularly updated incident response plans — these factors enable timely detection of hidden compromises and help reduce the risk of critical incidents.
Vendors
Kaspersky
Products
Compromise Assessment