
Blog • August 11, 2026
N-able's 2026 State of the SOC Report, built on data from the Adlumin SOC platform, lands on one finding every firm running endpoint protection should stop and consider: 50% of the attacks observed in 2025 bypassed endpoint controls entirely.
If your security strategy starts and ends with antivirus or EDR, that number means half of last year's attacks would have been invisible to you.
Key Insight
Half of 2025's attacks bypassed endpoint controls entirely — they moved through the network, perimeter, and identity layers that endpoint tools don't watch. — N-able 2026 State of the SOC Report
Here's why. Endpoint tools watch the endpoint — malware execution, suspicious processes, credential theft from memory. They're good at it. But a large share of modern attacks never runs anything on an endpoint until the very end. Network reconnaissance, lateral movement between systems, firewall and VPN exploitation, offline password cracking, identity attacks in the cloud — none of it generates an endpoint alert. By the time something does, the attacker has usually been inside for hours.
The Adlumin data puts numbers on it. Across 2025, the network and perimeter layers caught 137,187 threats that endpoint-only monitoring would have missed. Many weren't minor — they were the opening stages of attacks that would have become full breaches without visibility at those layers.
The same report explains why response speed matters as much as visibility. When a VPN login from an unusual location, internal SMB scanning, and a PowerShell execution show up separately, each looks ambiguous on its own. Correlated across layers, they read as an active compromise.
We watched a version of this play out in one of our own managed environments last Thanksgiving. A client traveled out of state for the holiday, logged in to get some work done, and was immediately flagged for signing in outside their normal area. SentinelOne on the laptop saw nothing wrong — because nothing on the laptop was wrong. The signal only existed in the layers around it. Adlumin correlated the sign-in with what our managed SonicWall appliance was seeing, and the SOAR weighed the context: a company laptop, a clean authentication, the VPN's two-factor prompt answered correctly. No aggravating circumstances, so it stopped at notifying me. Other cases have gone the other way — clients who left the country without telling us were automatically isolated from the network, applications, and resources until we confirmed it was really them. Same detection either way; the response matched the risk.
This is what the Capstone Threat Intelligence Center tracks: daily analysis of active threats — credential campaigns, perimeter exploits, the techniques showing up most often in professional services — and what each one means for the firms we manage.
Brian Sammons has managed IT environments for Ohio professional service firms since 2002. Capstone Technologies Group provides managed security services including firewall management, endpoint protection, backup, and 24/7 threat monitoring for medical practices, law firms, and accounting firms across the Dayton, Columbus, Cincinnati, and Springfield markets.
Questions about what your current tools can and can't see? Schedule 15 minutes and I'll walk you through it.