MITRE ATT&CK Coverage Has No Clock
A detection mapped to a technique is not resistance strength unless containment can finish before the attacker reaches the objective.
The Coverage Number Hides The Race
Many detection programmes still summarize MITRE ATT&CK coverage as a percentage: how many techniques have at least one mapped detection. The number is tidy, defensible in a steering pack, and easy to improve quarter by quarter. It is also dangerously incomplete.
MITRE ATT&CK Enterprise is an open knowledge base of adversary tactics and techniques built from observed intrusions. MITRE’s Enterprise collection version 19.1, released on 12 May 2026, catalogs 697 techniques and profiles 174 tracked threat groups. MITRE publishes it as STIX 2.1. That is a substantial body of structured knowledge, but it records what adversaries do, not how fast they do it.
That distinction used to be a tolerable approximation. When a programme had detections mapped across the matrix, it was tempting to read broad coverage as evidence that resistance strength was rising. The recent Unit 42 machine-speed case makes that shortcut harder to defend.
Palo Alto Networks Unit 42, as reported by Dark Reading on 3 September 2026, responded to an intrusion in which a human operator used coordinated frontier AI agents to run a multi-stage ransomware attack end to end in under 10 hours, compared with roughly two weeks for a comparable attack carried out by hand. Dark Reading reported that the agents ran reconnaissance, harvested hardcoded credentials and tokens from source code repositories, retrieved master administrative credentials from the secrets management system, hijacked the CI/CD pipeline, and exfiltrated cloud access keys. No novel zero-day and no elite tradecraft were involved. The distinguishing feature was AI-assisted operational efficiency.
That is precisely the scenario in which a static coverage percentage becomes misleading. The detection can exist. The alert can fire. The technique can be mapped correctly. The programme can still lose the race.
Detection Is Not Resistance Until It Changes Outcome
A quantitative cyber risk management methodology frames this more precisely. Its standard reference text, by Freund and Jones, defines loss event frequency as threat event frequency multiplied by vulnerability. Vulnerability is the probability that threat capability exceeds resistance strength. Resistance strength is the aggregate effect of every control standing between a threat actor and a loss event, and it is meaningful only relative to a specific threat actor and a specific asset. Threat capability includes skills, knowledge, experience, resources, time and materials.
That last component, time, is where the ATT&CK coverage percentage breaks. A mapped detection is not automatically resistance strength. It is, at best, a control input. It may become resistance strength if it starts a response sequence that completes before the attacker reaches the objective. If containment completes after exfiltration, encryption, credential abuse, or another material objective, the mapped detection did not reduce vulnerability for that event path. It produced awareness after the loss condition had occurred.
This is not a criticism of ATT&CK, but of how programmes often operationalize it. ATT&CK is excellent for describing behaviors, structuring detection engineering, and finding blind spots in telemetry. But a technique mapping does not contain a clock. It does not say whether the detection fires in time, whether triage consumes the available margin, whether approval gates delay containment, or whether automation is trusted enough to act without a human.
The Unit 42 Incident Response Report 2026 sharpens this. Palo Alto Networks Unit 42 investigated more than 750 incidents in 2025 and reported a fastest observed exfiltration time of 72 minutes, down from 285 minutes the prior year. Unit 42 presents this as a fastest-case figure, not a median. The same report says more than 90 percent of cases involved preventable gaps, and its first recommendation is to align security operations to attacker speed with integrated detection and automated containment. It also describes AI as reducing the skill and time requirements of existing attacks rather than inventing new ones, and notes that scanning for newly disclosed vulnerabilities begins within minutes of disclosure.
So the risk question is not, “Do we have a detection for this technique?” It is, “Given this technique fires in this environment, what is the probability that containment completes before the attacker objective?” That is a different metric. It turns coverage from a cataloging exercise into a probability statement about loss outcomes.
Replace Matrix Coverage With Time-Bound Coverage
A more useful ATT&CK-based metric starts with the same mapping, but refuses to stop there. For each material event path, the programme needs three distributions built from observed evidence.
The first is attack tempo: how long a relevant threat actor takes to move from the detected technique to the objective. External intelligence provides a starting view. Unit 42’s fastest observed exfiltration time of 72 minutes, and the Dark Reading account of an AI-assisted intrusion completing end to end in under 10 hours, are not universal parameters. They are warnings that the left tail of attacker time has moved. IBM’s Cost of a Data Breach 2025 still reports a global mean time to identify of 181 days and a mean time to contain of 60 days, both a nine-year low, down from the 2021 peak of 212 days to identify and 75 days to contain. Mandiant M-Trends 2026 reports global median attacker dwell time of 14 days, up from 11 days, pulled up by long-running espionage and DPRK IT-worker operations. These measures describe different populations and phases of compromise. A mature model does not average them into comfort; it separates fast operational paths from slow dwell-time populations.
The second is detection timing: when the alert fires relative to the intrusion path. A detection that fires after credential extraction has a different risk effect from one that fires at repository access, even if both map to the same ATT&CK area. The matrix records behavior. The detection engineering owner and the analyst building the quantitative risk analysis need the local telemetry timing.
The third is response timing: how long triage, decision, containment, validation, and escalation actually take. This must come from the organization’s own case data, exercises, and control telemetry. Incident response owners know where time is consumed. Detection engineering owners know which alerts are reliable enough to automate. An outside analyst can help structure the uncertainty and run the Monte Carlo simulation, but the credible distributions have to be grounded in the operating team’s evidence.
A short illustrative example shows the difference. Suppose, using illustrative round numbers only, a programme reports 80 percent ATT&CK coverage for a technique cluster associated with credential access and deployment activity. For one scenario, the observed attacker time from first relevant alert to objective is represented as a range from 30 minutes to 10 hours. The organization’s measured containment time, from alert firing to confirmed containment, is represented as a range from 15 minutes to 12 hours. A Monte Carlo simulation samples both ranges repeatedly and counts the cases where containment finishes first. If containment wins in 45 percent of the simulated cases, then the relevant coverage metric is not 80 percent. For this event path, the time-bound coverage is 45 percent.
Those numbers are illustrative, not source claims. The point is the structure. The mapped detection is only valuable to the quantitative risk model to the extent that it changes vulnerability. It changes vulnerability when the control sequence beats the attack sequence. Otherwise, it changes reporting, not loss exposure.
The Better Board Metric
This reframing also changes how Return on Control is argued. Adding another detection to an already mapped technique may have little effect if response remains slower than the attacker path. Tuning an existing detection to fire earlier, automating a containment action, removing an approval delay, or narrowing the asset scope may reduce vulnerability more than increasing the raw percentage of mapped techniques.
That is why the better executive metric is not “percentage of techniques covered.” It is “probability of containment before objective, given that the technique fires,” segmented by material scenario, asset, and threat actor. From there, annualized loss exposure can be estimated with a more defensible connection between control performance and loss outcome.
ATT&CK remains a strong organizing frame. MITRE’s model gives programmes a common language for adversary behavior. But the current machine-speed cases mean the control question has moved from coverage existence to coverage timing. A detection programme that cannot attach time to its ATT&CK map is measuring catalog completeness while the loss event is being decided somewhere else.