Detection Coverage: You Can't Protect What You Don't Know
How to map, score, and close detection coverage gaps before an attacker finds them first
Detection coverage is the measurable map of what your program can actually catch, not the list of tools you have purchased. Most teams can name their SIEM, EDR, and OT monitoring platforms in seconds, but they cannot show which adversary techniques those tools reliably detect today.
That gap between assumed protection and proven coverage is where real incidents survive. According to CardinalOps' State of SIEM Detection Risk Report published in 2024, enterprise SIEM deployments detect only 19% of attacker techniques that organizations claim to prioritize, while 87% could be covered with data already being ingested.
The issue is not usually missing telemetry. The issue is unmapped techniques, untested rules, and unscored gaps. If you cannot map what you detect, you cannot prove what you protect.
The Detection Coverage You Think You Have
Most organizations overestimate detection coverage because they measure activity instead of evidence. Alert volume feels like protection, but alert volume only proves that systems are generating events.
According to CardinalOps in 2024, many security teams run with high log volume and low ATT&CK technique coverage at the same time. In practice, this means teams are busy, dashboards look active, and attackers still move through uninstrumented paths.
Detection coverage means each critical technique is mapped to required telemetry, linked to a specific detection, tested for expected behavior, and tracked for fidelity over time. Without that chain, 'covered' is an assumption, not a security claim.
Start With Who Actually Targets Your Sector
Coverage models fail when they begin with generic threat lists instead of sector-specific adversaries. You should map detections against the threat groups and techniques that repeatedly target your industry, not against a random sample of enterprise playbooks.
According to Dragos Year in Review reporting from 2025, industrial adversary clusters continue to specialize by sector and operational objective. The same year, SANS' ICS/OT survey reported that only 21% of organizations had fully integrated OT threat intelligence into operations.
Your baseline should answer three direct questions: which groups target our sector, which techniques they use most often in initial and lateral stages, and where our current detections are blind to those techniques.
Map Across Every Domain, Not Just the Convenient Ones
Detection coverage must be cross-domain or it will be structurally incomplete. Real attack paths move through identity, endpoint, network, cloud, and OT process environments, so coverage has to follow the same path.
MITRE ATT&CK for ICS documents 12 tactics and 83 techniques that rarely fit a single-tool view. MITRE ATT&CK for Enterprise captures adjacent techniques used before and after OT-impact stages. Mapping one matrix without the other leaves a handoff gap attackers routinely exploit.
Coverage mapping should tie each technique to telemetry source, analytic logic, owner, test status, and known limitations. If one of those fields is missing, that technique is not truly covered yet.
Score the Gaps, Then Build a Backlog
Unscored gaps create unstructured work. A ranked backlog turns detection coverage into an execution program your team can actually run.
Score each uncovered or weakly covered technique by adversary relevance, operational consequence, exploit path frequency, telemetry readiness, and implementation effort. This creates a practical order of operations that avoids 'loud but low-value' engineering cycles.
SANS reported in 2025 that only 17% of organizations had fully implemented ICS-specific tabletop exercises. That execution gap mirrors what most teams face in detection engineering: they know where gaps exist but do not run a repeatable process to close them in priority order.
What to Look For in a Detection Coverage Model
A mature model is measurable, testable, and operationally owned. If your current process cannot produce evidence on demand, the model is still immature.
- Technique-level mapping tied to both ATT&CK Enterprise and ATT&CK ICS
- Clear domain ownership for every detection, including IT-OT handoff points
- Routine validation cycles that test detections against expected adversary behavior
- Gap scoring and ranked backlog execution with measurable close rates
- Board-ready reporting that shows coverage progress, not tool activity
The same coverage blind spots are discussed in this analysis of the OT detection capability gap and in this companion article on the compliance trap in OT cybersecurity. Execution discipline is outlined further in how the CFC builds capability and delivers compliance.
If you cannot answer 'what do we detect' and 'how well does it work' with evidence, start with a scoped detection coverage assessment and turn unknowns into an engineering backlog immediately.
Sources: CardinalOps State of SIEM Detection Risk Report (2024); MITRE ATT&CK for Enterprise and ATT&CK for ICS (accessed 2026); Dragos OT cybersecurity annual reporting (2025 cycle); SANS State of ICS/OT Cybersecurity Survey (2025).
You cannot defend what you cannot map.
Coverage claims require measurable evidence.
Unknown gaps become known attack paths.
If detections are not mapped to prioritized techniques, operators inherit a busy queue instead of a defended surface.
Generic enterprise playbooks miss sector-specific tradecraft, making 'good average coverage' dangerous in high-consequence OT settings.
Coverage models fail when they stop at one domain. Real resilience comes from linked detections across the full kill chain.
Rank gaps by consequence, adversary relevance, and effort so engineering cycles close the highest-risk blind spots first.
A durable coverage model tracks close rates, retest cadence, and ownership so improvements survive staffing and priority shifts.
Start by identifying which adversary behaviors matter most for your sector and environment, then convert them into explicit coverage objectives.
For each technique, document data dependencies, logic ownership, and validation status across IT and OT domains so handoff gaps are visible.
Use a repeatable scoring model and publish close-rate metrics so leadership can track detection coverage improvement as an operational program.
Scope asks if critical techniques are mapped across every relevant domain, including identity and OT process layers.
Quality asks if mapped detections are tested, reliable, and usable by operators under real incident pressure.
Execution asks if prioritized gaps are closing over time through owned backlogs and repeatable validation cycles.
Detection coverage is evidence of capability, not evidence of tooling spend.
Cross-domain technique mapping is the minimum requirement for realistic attack-path visibility.
Gap scoring and backlog discipline are what turn unknown risk into managed engineering work.
