September 22, 2026

How close to 100 per cent can your security team get? 

Chris Harvey
Security Solutions Specialist at Data#3 Limited

What would it genuinely take to achieve 100 per cent detection rates on cyber threats?

It’s a hypothetical question, but an interesting one. Somewhere in your environment right now, a laptop is communicating with a server it doesn’t usually contact, and an account is logging in from a location it’s never used before. There’s probably a process running that looks almost like the one that normally runs at this time, but not quite. None of this looks like an attack on its own, but viewed together, it might be exactly that.

This is the reality every security team lives with. The signal is there, but so is the noise, and the real job is separating them quickly enough to detect the real threats.

Vendors love to make promises about efficacy and detection rates, but if you play the idea of 100 per cent detection out honestly, the answers become more expensive and unreasonable the closer you get. Let’s break down what getting closer to that goal would really require, where the practical limits lie and how platforms like XDR help organisations close the gap.

Playing the 100 per cent game

The easiest way to think about this is as a spectrum, ranging from what’s achievable today through to what’s technically possible but operationally absurd.

Realistic

First up, you’d need to patch every device the moment a fix ships. Then every telemetry source, endpoint, network, cloud, identity and email would feed into a single place instead of five separate consoles. Finally, every alert would be triaged and correlated automatically, rather than queued for a tired analyst at 2am. While this is achievable, most organisations haven’t built it yet because it requires connecting tools that were never designed to talk to each other.

Expensive

This looks like a security team large enough to manually review every alert every hour of every day, with no gaps in coverage and no fatigue. While theoretically possible, the cost would make this prohibitive, outweighing what they’re protecting.

Implausible

Redundant analysts double-checking every decision another analyst makes in real time, forever. Multiple overlapping tools running in parallel, specifically to ensure no single point of failure. However, this creates new problems faster than it solves old ones, because more tools mean more noise, not less.

Ridiculous but guaranteed

Disconnect every system from every network, remove external connectivity and prohibit removable media. Then lock every endpoint in a sealed environment that nobody can use for work. You’d dramatically reduce the attack surface, but you’d also dramatically reduce the organisation’s ability to function. And even then, “unbreachable” would still be a dangerous word to use.

There is, however, a serious principle behind the thought experiment. Industrial and operational technology environments, critical infrastructure, classified systems and other highly sensitive networks often use strong segmentation or physical isolation to limit exposure to corporate networks and the internet. Even in these environments, the objective is risk reduction rather than an assumption that isolation makes a system completely secure.

While this might seem like a silly question, every real security decision is made somewhere between the realistic and the ridiculous ends. The goal we’re chasing is to close as much of the 100 per cent gap as the business can reasonably afford without breaking how the business operates.

Why some platforms can get very close

The realistic end of that list, full telemetry coverage and automatic correlation, is exactly what extended detection and response (XDR) is built to deliver, but not every platform marketed as XDR can come close to 100 per cent.

Several platforms have bolted correlation onto tools that were designed separately, such as an endpoint agent or a network sensor, and stitched them together after the fact. That approach still leaves gaps between the pieces, but in fairness, they are small.

Palo Alto’s Cortex XDR is a good example of a platform built the other way around. Endpoint, network, cloud, identity and email telemetry all feed into a unified data model from day one, rather than correlation being bolted on top of separate tools after the fact. You don’t have to rely on manual cross-referencing to connect a login anomaly to a process execution to a network transfer. That distinction is a big part of why Palo Alto Networks (Palo Alto) has been recognised as a leader in the Gartner Magic Quadrant for four years running.

If you want a real-world example of “close” rather than a hypothetical, MITRE’s independent ATT&CK evaluations are worth a look. In its most recent participation, the 2024 Enterprise Evaluation, Cortex XDR became the first platform to achieve 100 per cent technique-level detection across all the simulated attack steps, without configuration changes or delayed detections. It also achieved 100 per cent detection coverage across the expanded macOS and Linux attack surfaces while preventing eight out of ten attack steps with zero false positives.

A lab result isn’t a guarantee, and real environments are messier than any evaluation. Detecting every technique isn’t the same as preventing every attack either. However, as an independently observed example of what “close to 100 per cent” can look like, it’s a strong result.

None of this makes any platform unbreachable, but it does mean that the realistic end of our list above, connecting the telemetry you already have instead of buying more of it, stops being aspirational and becomes something you can actually move towards. It’s a strong platform capability, but it gets even more interesting once you factor in the cost of acquiring it right now.

What market competition means for your budget

Security vendors are competing hard for share of this market, and that competition works in your favour. When multiple established players are chasing the same customers, enterprise-grade platforms become available at a genuinely significant discount to their usual cost, not because of a time-limited promotion, but because of how competitive this part of the market has become.

That’s worth paying attention to on its own, separate from the technology case. The tools capable of closing the realistic part of the “100 per cent” gap, such as Palo Alto Cortex XDR, cost meaningfully less to acquire right now than they typically would, purely because of vendor competition.

The real barrier isn’t the technology

If the case for XDR is this strong, why hasn’t every organisation already made the switch?

The short answer is swapping out a security platform is disruptive, and the disruption itself can feel riskier than the status quo. Teams worry about downtime during migration, licences going to waste and the operational cost of the change outweighing the savings. That’s normal, yet most vendors talk about what their platform does and skip over how painful it is to get there.

That’s where Data#3 fits into this conversation, with our expertise in architecture, governance and managed services. We can configure a platform to best practice, migrate existing rules and data and ensure that, once it’s live, an organisation gets the outcomes the platform promises, not just the licence. Migration doesn’t have to be a long, disruptive project when it’s planned properly.

See it, don’t just read about it

The best way to understand what fragmented visibility costs a team is to feel it happen.

Through our work with Palo Alto, we’re running an Interactive Simulation that puts your team through a live attack scenario, split across the roles and boundaries that exist in a real security operation, where each group holds only part of the picture.

It’s a valuable way to see the value of Cortex XDR and goes beyond what you can see in a product demo. If you want to know how close your team could get to 100 per cent, this is the way to find out.

Data#3 is a strategic, award-winning Palo Alto Networks partner, recognised with statuses including Diamond Innovator and Growth Partner of the Year. We deliver advanced cybersecurity solutions across Australia, specialising in cloud security, SASE (Prisma Access), and AI-driven threat prevention for enterprises.

Contact us today

To secure your spot for an interactive simulation, contact Data#3 today.

Information provided within this form will be handled in accordance with our privacy statement.