There is a story the security industry tells itself about progress. Each year, organizations invest more. Each year, new tools arrive to cover new attack surfaces. Each year, security teams add capabilities: EDR, SIEM, SOAR, CSPM, XDR, CTEM. The stack grows. The controls multiply. The coverage expands.

And each year, the breaches continue.

Pentera's AI Security and Exposure Benchmark 2026, surveying 300 US CISOs and security executives, puts a number on this gap in a way that is difficult to dismiss. In the past 12 months, 68% of enterprises reported a net increase in security tools. Over the same period — the past 24 months — at least 75% of those same enterprises dealt with an attacker gaining unauthorized access to their environment. Most of the 16% who declined to disclose are likely in the same category.

More tools. Same breaches. The math does not work.

What the Stack Actually Looks Like

The average enterprise in the survey manages 47 security solutions across their IT environment. 40% operate with 51 or more. These are not small or poorly resourced organizations — they represent enterprises with 3,000 or more employees, spending an average of $2.48 million annually on cybersecurity, not including personnel costs.

These are organizations that take security seriously. They have budgets, teams, and tooling that most companies would consider mature. And 75% of them got breached anyway.

47
average security solutions managed by enterprise security teams
68%
of enterprises added net new security tools in the past 12 months
75%
of enterprises dealt with an attacker inside their environment in the past 24 months

Why More Tools Doesn't Mean More Protection

The instinct to add tools is rational. A new threat surface appears — cloud misconfiguration, AI system exposure, supply chain risk — and a tool exists to address it. The CISO adds it. The board sees a response. The compliance checkbox gets filled. The stack grows.

What the stack does not automatically generate is coverage. A tool deployed is not a threat detected. A control installed is not a vulnerability closed. The gap between having a security solution and having that solution actually prevent a breach is where most security programs are weakest — and it is precisely the gap that is invisible without continuous adversarial validation.

Splunk's 2025 State of Security report found that 46% of security teams admit they spend more time maintaining security tools than actively defending their organizations. This is the operational weight of stack sprawl: more time on integration, configuration, and alert management, less time on actual defense. As Pentera's data shows, the challenge shifts from coverage to coordination as stacks grow. Security teams must manage an increasing number of technologies, configurations, integrations, and data sources — adding overhead to day-to-day operations without necessarily improving outcomes.

The Validation Gap

The missing piece is proof. Not proof that the tools exist. Not proof that the controls are configured. Proof that the controls actually work against a realistic adversary operating in your specific environment, today.

This distinction matters because environments change constantly. A control that was effective six months ago may be ineffective today because the configuration drifted, a new integration introduced a gap, or a new attack technique bypassed the detection logic. The only way to know is to test — actively, continuously, against real attack scenarios.

Pentera's data makes the validation argument empirically. Among enterprises that conduct quarterly penetration testing, 80% report being confident in their security posture. Among those testing annually, that figure drops to 71%. The cadence of validation directly correlates with the confidence of the outcome — and confidence grounded in tested reality is a fundamentally different thing than confidence grounded in the assumption that installed tools are working.

The uncomfortable question: Of the 47 tools your security team manages, how many have been tested against a realistic attack scenario in the past 90 days? Not configured, not deployed — tested. Proven to detect or prevent what they're supposed to detect or prevent in your actual environment?

What Consolidation Actually Requires

The survey data shows something interesting about the consolidation conversation that dominates security industry discussions. 85% of CISOs say AI is influencing their consolidation strategy. Only 3% are actively consolidating due to AI capabilities. 11% are consolidating for reasons entirely unrelated to AI — cost, vendor overlap, operational efficiency.

The gap between consolidation intent and consolidation action reflects something real: CISOs are reluctant to remove controls where the perceived impact could weaken their security posture. That reluctance is rational. Removing a tool you haven't validated means removing something that might be the thing standing between your environment and an attacker. If you don't know whether it's working, you don't know whether you can afford to remove it.

Validation breaks this paralysis. When you know what's actually working — proven against real attack scenarios — you can make rational decisions about what to keep, what to replace, and what to remove. Consolidation without validation is guessing. Consolidation with validation is strategy.

The Reframe

The security industry has optimized for coverage: more tools, more surfaces monitored, more alerts generated. The data suggests that coverage without validation produces the outcome we're seeing — heavily tooled environments that are still routinely breached.

The organizations that break this pattern are not the ones with the largest stacks. They are the ones that know what their stack is actually doing — that have tested their controls against realistic adversaries and can answer, with evidence rather than assumption, whether their environment would hold up under a real attack.

More tools is not the answer. Knowing whether your tools work is. And the only way to know is to test.

Source: Pentera AI Security & Exposure Benchmark 2026. Survey of 300 US CISOs and senior security executives, conducted December 2025 by Global Surveyz Research. Splunk State of Security 2025.

See what continuous testing finds in your environment.

Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.

Request early access →