The Detection Debt Report 2026
29.2%
of detection rules are broken
Nearly 3 in 10 deployed, enabled rules cannot produce an alert under any circumstance.
r = 0.08
Bigger rule sets are not better rule sets
Rule count and broken rate are effectively uncorrelated. Fewer rules does not mean a lower broken rate; the worst estate measured was 45.7% broken.
Vertical axis: share of deployed rules that cannot fire. Horizontal: estate size, smallest to largest.
67%
Rules break because of data, not syntax
Two thirds of broken rules fail on the data they read rather than the logic they contain. Genuine syntax errors account for under 1%.
- The field moved30%
- The field value changed26%
- Logs never arrived, or went dark22%
The three most common reasons a deployed rule cannot fire.
88%
of environments had an MFA-disabled detection broken
The detections that break are the ones you would bet your job on.
- MFA disabled / login without MFA88%
- Audit logging stopped / logs cleared83%
- Guest or external user invited80%
- Inbox forwarding rule created75%
Share of the environments deploying each detection theme where it was broken.
~26,000
alerts a week sat behind a rule that could not fire
Per environment, over a seven-day replay.
Share of a week's alert volume sitting behind a rule that cannot fire, measured over a seven-day replay.
The Detection Debt Report 2026
Six SIEM platforms, verified against live customer systems rather than exported rule files. Eight pages.
Download the full reportWant to see this data for your environment? We can scan your SIEMs for free.




