A Running Tool Is Not the Same as Detection
In a Kaspersky study of real incidents, 60% were missed by the organisation for want of high-confidence alerts from tools they already had installed. The oldest incident had been running undetected for four years. And 71% of them happened in the Middle East, Türkiye and Africa.
A 2021 compromise, found in 2025
In July 2026 Kaspersky published the findings from the compromise assessment projects it ran through 2025. The oldest incident the team found had been active since June 2021, on domain controllers, and had gone four years without being detected.
The program was a cryptocurrency miner. It entered through a known vulnerability, EternalBlue (MS17-010), for which a patch had been available since March 2017, four years before the compromise. To avoid notice it kept its files in C:\Windows\Fonts\Mysql, exploiting a quirk of that folder: to an ordinary user, Windows shows only font files there.
None of this required a new technique: an unapplied patch, and an environment in which nothing flagged it for four years.
The tool was installed, and it was running
Of the incidents discovered, 60% had been missed by the organisation for want of high-confidence alerts from the tools already in place. Another 20% were only found by manual analysis. The remaining 20% are not attributed in the report.
In 9.4% of cases, the product itself was misconfigured, out of date or malfunctioning. In one of them, memory inspection was switched off and signatures were stale, so in-memory malware simply stayed invisible.
The report is clear about the mechanism: alerts that could have indicated the compromise were generated, but no incident was declared. They were low-confidence signals, and for those the report is explicit: they require human analysis.
The signal was there. What was missing was somebody to read it.
Without continuous monitoring

Where there was no permanent monitoring and no threat hunting activity, the likelihood that the incidents found were of medium or high severity rose to 84 to 86%. Without monitoring, the incidents that are found are, as a rule, more severe.
Duration confirms it. In 30.8% of the incidents discovered, and in 52% of high-severity compromises, the activity found had more than three months of history behind it.
One further finding deserves attention from anyone buying managed services: roughly half of the MSSP-supported projects had basic Windows audit gaps, such as missing event log collection or disabled audit policies. Having a provider monitoring does not by itself guarantee there is anything to monitor.
This happened in our region
Around 71% of the incidents analysed were at customers in the META region, which in Kaspersky’s definition covers the Middle East, Türkiye and Africa. The remaining 29% were spread across APAC and the CIS.
By sector: government at 29%, education at 19%, financial at 17%. These are the sectors we work in.
What we find in Angola
We wrote here in June that installing Kaspersky is the first step, not the last. Across the assessments our certified team runs for Angolan organisations, about 41% of the protection already being paid for is actually switched on, and no organisation assessed has passed 60%.
Kaspersky’s data describes the next stage of the same problem, at global scale. The assessments in Angola show paid-for protection that was never switched on. The report shows that, even where it was switched on, in some incidents the signal produced was not investigated. And its 9.4% of misconfigured or out-of-date products describes the same kind of gap we find in the consoles we open here.
Protection does not fail for want of a licence, it fails in the space between the licence and the operation.
Measure before you assume
The study points to three checks that can be made before there is an incident: product configuration, alert analysis and log collection.
What is actually switched on?
A configuration read, through console access: six pillars, from basic protection to deployment coverage. Risks ranked by severity, utilisation measured pillar by pillar and prioritised recommendations. About two hours, with nothing changed.
See the assessmentFixing what the assessment finds
Menshen's certified team corrects the gaps the assessment identified: policies, console structure, agent protection, and alerts that reach someone who analyses them. Continuous management of the environment then keeps what was corrected in place, month after month, and a new assessment closes the cycle.
See the Kaspersky services