The Detection Debt Report 2026

29.2%

of detection rules are broken

Nearly 3 in 10 deployed, enabled rules cannot produce an alert under any circumstance.

Rules deployedCannot fire

r = 0.08

Bigger rule sets are not better rule sets

Rule count and broken rate are effectively uncorrelated. Fewer rules does not mean a lower broken rate; the worst estate measured was 45.7% broken.

0%25%50%

Vertical axis: share of deployed rules that cannot fire. Horizontal: estate size, smallest to largest.

67%

Rules break because of data, not syntax

Two thirds of broken rules fail on the data they read rather than the logic they contain. Genuine syntax errors account for under 1%.

88%

of environments had an MFA-disabled detection broken

The detections that break are the ones you would bet your job on.

~26,000

alerts a week sat behind a rule that could not fire

Per environment, over a seven-day replay.

The Detection Debt Report 2026

Six SIEM platforms, verified against live customer systems rather than exported rule files. Eight pages.

Download the full report

Want to see this data for your environment? We can scan your SIEMs for free.