Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Article

Coverage is not a percentage

What ATT&CK mapping tells you, what it does not, and how a coverage number becomes misleading.

Updated August 2026 · 6 minute read

The number everyone wants

Boards ask for it, insurers like it and vendors are happy to supply it: a single percentage describing how much of MITRE ATT&CK you cover.

It is a reasonable thing to want. It is also, taken at face value, close to meaningless, and understanding why is the difference between a coverage programme that improves security and one that improves reporting.

Problem one: every technique counts the same

A raw percentage treats a technique used by three state actors against your exact sector identically to one that has never been observed outside a research paper.

Adversaries do not distribute their effort evenly across the matrix, so a defender who does is optimising for the wrong thing. Two organisations with the same percentage can have completely different real exposure, and the one with the lower number is frequently better defended.

Problem two: claimed coverage is not demonstrated coverage

Most coverage maps are assembled from what products say they can detect. That is a statement about a product in a lab, not about your deployment, your log sources, your tuning or your exclusions.

The gap between the two is where incidents live. A detection that exists but was disabled during a noisy migration, or that depends on a log source that stopped shipping three months ago, appears on the map exactly like one that works.

What a useful map looks like

Three changes make the difference.

Weight it. Overlay the actors, campaigns and tooling actually active against your sector, geography and technology, and let that reorder the map. The gaps at the top should be the ones that matter to you.

Separate claimed from proven. A technique should only be marked covered when something has demonstrated it. Everything else is a hypothesis, and displaying hypotheses as facts is how boards end up surprised.

Show drift. Coverage decays. Log sources break, rules get disabled, estates change. A map that only ever goes up is not measuring anything.

The question worth asking instead

Not "what percentage do we cover" but "against the techniques an adversary would actually use on us, where are we covered, where are we blind, and how do we know".

That question is harder to answer and considerably more useful. It also has the pleasant property that answering it honestly tends to produce work worth doing, whereas optimising a percentage tends to produce detections for techniques nobody is using.

FAQ

Questions, answered

Is ATT&CK mapping worth doing at all?
Yes, emphatically. The problem is not the framework, it is the reduction to a single number. ATT&CK is the closest the industry has to a shared vocabulary for describing what a security programme covers, and used properly it turns an argument about tooling into a conversation about specific, testable gaps.
How do you prove coverage rather than claim it?
By executing the technique against your environment under controlled conditions and observing whether your detection fires. Where it does, coverage is evidenced. Where it does not, you have found a gap that a datasheet would have hidden.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.