What MITRE ATT&CK Coverage Percentages Really Measure

The article argues that a coverage percentage is meaningless without knowing the denominator and proof method. Validated coverage counts techniques where a deployed rule fires against required data sources. It highlights that the metric can hide gaps in the threat model and framework version.
Coverage percentages only carry meaning when the denominator is explicitly defined—the prioritized technique set from an organization's threat model—and when the proof method is validated, meaning a deployed rule actually fires against the required data source. Without these constraints, a number on a slide can obscure more than it reveals.
The article also flags that framework version matters: ATT&CK v19 released April 2026 changes what techniques exist to measure. Gaps also emerge from uncollected logs, making certain techniques undetectable regardless of rule availability. Organizations must audit log sources, track framework updates, and distinguish vendor-claimed coverage from what is genuinely deployed and validated in their environment.
This reporting could reshape how security teams evaluate their detection posture, pushing them to demand transparency about denominators and validation methods rather than accepting headline percentages. Boards and executives may begin asking harder questions about what coverage numbers actually prove, potentially shifting vendor accountability. Smaller organizations without dedicated detection engineering staff could struggle to perform the audits the article recommends, widening the gap between well-resourced enterprises and those with limited capacity.