Security Bullish 6 Based on a press release

99.8% Real-World Protection: AV-Comparatives Ranks 16 Endpoint Security Products

Independent testing of 16 business endpoint security products reveals Kaspersky, Bitdefender, and Elastic blocked 99.8% of live attacks, while Elastic scored a perfect 100% in malware detection. The results come amid high-profile breaches at Stryker and Foxconn that exploited weak endpoints.

· 4 min read · Verified by 2 sources ·
Share

Key Takeaways

  • Independent testing of 16 business endpoint security products reveals Kaspersky, Bitdefender, and Elastic blocked 99.8% of live attacks, while Elastic scored a perfect 100% in malware detection.
  • The results come amid high-profile breaches at Stryker and Foxconn that exploited weak endpoints.

Mentioned

AV-Comparatives company Stryker company Foxconn company 2317.TW Nitrogen ransomware company Iranian-linked hackers company Kaspersky company Bitdefender company Elastic company ESTC Avast company Norton company

Key Intelligence

Key Facts

  1. 1AV-Comparatives tested 16 endpoint security products from March to June 2026 under real-world conditions.
  2. 2In the Real-World Protection Test across 400 live attack scenarios, Kaspersky, Bitdefender, and Elastic each blocked 99.8% of threats.
  3. 3Elastic achieved a perfect 100% detection rate in the Malware Protection Test with 1,000 recent samples; Avast and Norton reached 99.8%.
  4. 4The Stryker breach in March 2026 involved Iranian-linked hackers factory-resetting over 200,000 corporate devices across 79 countries.
  5. 5Foxconn confirmed in May 2026 that the Nitrogen ransomware group stole an alleged 8 terabytes of data from North American factories.
  6. 6All tested products maintained low false alarm rates on common business software, according to AV-Comparatives.
Top Real-World Protection Rate
99.8%

Achieved by Kaspersky, Bitdefender, and Elastic against 400 live attack scenarios

Analysis

For cybersecurity teams, the difference between a breach and a block often comes down to the endpoint agent. With Iranian-linked hackers and ransomware groups crippling global manufacturers this year, the latest AV-Comparatives Business Security Test provides a data-driven defense: real-world protection rates, false-alarm behavior, and performance impact across 16 products—so you can choose what actually stops the attack, not just what's marketed.

The first half of 2026 has jolted global enterprises with two stark reminders that endpoint compromise remains the gateway to operational catastrophe. In March, Iranian-linked threat actors breached medical device manufacturer Stryker and executed a mass factory-reset command that wiped more than 200,000 corporate devices across 79 countries, halting production and shipping for days. Two months later, Foxconn confirmed that the Nitrogen ransomware group stole approximately 8 terabytes of sensitive project data from its North American factories. Both incidents exploited weak endpoint security and third-party trust relationships, underscoring the urgent need for independently verified protection capabilities. Against this backdrop, the Austria-based testing institute AV-Comparatives has released the results of its Business Security Test for the March to June 2026 period, providing an authoritative real-world evaluation of 16 leading endpoint security products.

The 16 participants span the industry spectrum: Avast, Bitdefender, Cisco, CrowdStrike, Elastic, ESET, G Data, K7, Kaspersky, ManageEngine, Microsoft, Norton, SenseOn, Sophos, Trellix, and VIPRE.

The test is divided into multiple rigorous components. The Business Main-Test Series subjected each product to 400 real-world attack scenarios collected live from the internet during the testing period, simulating typical user web browsing and file exposure. It also measured each product's ability to detect pre-existing malware introduced via disk or network connections, as well as rates of false alarms on both common business applications and non-business software. A separate Malware Protection Test fed 1,000 recent malware samples to the products to gauge detection accuracy. Crucially, a Performance Test evaluated the system speed impact during everyday tasks such as file copying, archiving, launching applications, and web browsing—an often-overlooked factor that can slow business productivity if the security solution is too heavy.

The 16 participants span the industry spectrum: Avast, Bitdefender, Cisco, CrowdStrike, Elastic, ESET, G Data, K7, Kaspersky, ManageEngine, Microsoft, Norton, SenseOn, Sophos, Trellix, and VIPRE. The headline result is clear: absolutely no room for error against today's threats. In the real-world protection test, three products stood at the top: Kaspersky, Bitdefender, and Elastic each achieved a 99.8% block rate, missing only a fraction of the 400 test cases. That translates to effectively intercepting 399 out of 400 live attacks—a performance that would have prevented the Stryker-style lateral movement in many scenarios. In the dedicated malware detection test, Elastic raised the bar further with a perfect 100% score across all 1,000 samples, demonstrating deep threat intelligence and heuristic engines. Avast and Norton closely followed with 99.8% detection rates, indicating strong signature and behavioral analysis. While the press release highlights these top performers, it is equally noteworthy that some well-resourced enterprise-grade solutions did not achieve such flawless scores, a reminder that brand reputation alone cannot substitute for independent validation.

False positives are another battlefield. The testing confirmed that all products maintained low false alarm rates on business software, meaning IT teams won't be flooded with phantom alerts that waste time and erode trust. Similarly, the performance test revealed varying degrees of system footprint; although the exact rankings were not detailed in the summary, AV-Comparatives has long emphasized that the lightest solutions often surprise against heavyweight contenders. For organizations managing thousands of endpoints, a sluggish security agent can equate to millions in lost productivity, so performance is a critical tiebreaker.

What to Watch

These results arrive at a moment when the attack surface is exploding. Supply chains, remote work, and IoT devices multiply the points of entry, and adversaries are increasingly using 'living off the land' techniques that blend in with legitimate IT operations. The Stryker and Foxconn cases show that once inside, attackers can move laterally with catastrophic speed. Endpoint detection and response (EDR) and next-gen antivirus (NGAV) are no longer optional; they are the last line of defense when perimeter controls fail. The independent testing by AV-Comparatives provides a credible, threat-informed benchmark that CISOs and IT buyers can use to cut through marketing noise.

Looking forward, the security product market will likely see intensified competition around detection efficacy, false positive control, and performance optimization. Elastic's perfect malware detection score may be a harbinger of a data analytics-driven approach outperforming traditional signature-based methods. Meanwhile, the continued participation of established names alongside newer entrants signals a healthy but crowded market. As attackers refine their tactics, continuous, transparent testing will be indispensable. The next reporting period will test how quickly vendors adapt to emerging threats like AI-generated phishing lures and supply chain implants. For now, enterprises that rely on independently verified protection may sleep a little better, knowing their endpoints are less likely to become the next headline.

Timeline

Timeline

  1. Stryker breach

  2. AV-Comparatives test period begins

  3. Foxconn data theft

  4. AV-Comparatives test period ends

  5. Test results published

Sources

Sources

Based on 2 source articles

Cite This Page

"99.8% Real-World Protection: AV-Comparatives Ranks 16 Endpoint Security Products." Cyber Intelligence Brief, August 1, 2026. https://getcyberbrief.com/story/av-comparatives-endpoint-security-test-2026

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.