CyberSecurity SEE

Major Cyber Threat Detection Vendors Adopt Innovative UK Testing Program

Major Cyber Threat Detection Vendors Adopt Innovative UK Testing Program

SE Labs Launches Innovative Cybersecurity Testing Program PIVOT

In a significant development within the realm of cybersecurity, the UK-based security testing and advisory company SE Labs has unveiled a new testing initiative aimed at assisting buyers in evaluating cybersecurity vendors. This innovative program, named PIVOT, was officially launched on September 15, 2023, and has already garnered attention from several notable participants in the cybersecurity landscape.

PIVOT is designed to rigorously assess how effectively cybersecurity vendors can defend against highly sophisticated hacking groups and their attack methodologies. Among the preliminary list of participants, prestigious names include Broadcom, the parent company of Symantec and Carbon Black, as well as tier-one cybersecurity firms such as CrowdStrike, Fortinet, Palo Alto Networks, and Sophos. This diverse array of involved companies highlights the program’s relevance and its potential impact on enhancing cybersecurity practices across the industry.

The program is slated to span six months, concluding in January 2027 when results from the independent security testing will be published. A specialized team of trained ethical hackers, operating out of SE Labs’ dedicated testing facility in Wimbledon, London, has been charged with executing the tests. These professionals, often referred to as "white hat" hackers, have been conducting stress tests on the participating vendor solutions since July, focusing on each product’s ability to detect and thwart threats posed by known attack groups.

During these testing scenarios, the PIVOT team impersonates cyber threat actors, replicating the techniques utilized by nation-state hackers and other malicious groups responsible for some of the most significant cyber breaches witnessed in recent years. The tests encompass a range of cyber threats, including ransomware, malware, and phishing attacks. By following complete attack chains, the program aims to identify not only which vendors successfully protect against breaches but also to assess the nature of their solutions and how far attackers could progress once an initial breach occurs.

A central goal of PIVOT is to help buyers differentiate between various products on the market. As SE Labs points out, the program will reveal whether a product merely identifies malicious activity, intervenes to halt an attack before considerable harm occurs, or detects an attack but allows the perpetrator to escalate privileges or navigate deeper into the network. The findings of these evaluations are expected to provide essential insights for cybersecurity leaders, enabling them to make informed decisions regarding their security investments.

Simon Edwards, CEO of SE Labs, underscored the urgency and necessity of the PIVOT initiative in light of changing cybersecurity dynamics. He shared concerns over the evolving landscape characterized by autonomous AI-driven cyberattacks and the recent JLR incident, which had a profound economic impact on the UK. Edwards emphasized the pressing need for businesses to know which cybersecurity solutions genuinely safeguard them against formidable threats from nation-state actors, major ransomware syndicates, and rapid machine-speed attacks.

Additionally, SE Labs has engaged independent analysts from Gartner and Forrester to validate the testing results before publication. Edwards stressed the importance of transparency in the PIVOT program, stating that they do not expect Chief Information Security Officers (CISOs) to take their conclusions on faith. Instead, the underlying evidence will be accessible for external scrutiny, allowing these analysts to incorporate their own perspectives into the evaluation process.

The launch of PIVOT occurs at a pivotal moment in the cybersecurity testing landscape, which has witnessed significant transitions, particularly concerning traditional benchmarks like the MITRE Engenuity ATT&CK Evaluations. Once regarded as the gold standard for independent cybersecurity assessments, recent years have seen challenges for MITRE’s Enterprise version of this evaluation framework. The number of participants has dwindled, prompting notable companies such as Microsoft, SentinelOne, and Palo Alto Networks to withdraw from the 2025 test, indicating a shift in industry sentiment toward the practicality and interpretation of results from such evaluations.

Establishing an advisory council to enhance the long-term sustainability of the MITRE ATT&CK program, which encompasses the ATT&CK Evaluations and framework, reflects MITRE’s acknowledgment of the need for evolution in testing methodology. As organizations continue to navigate an increasingly complex threat environment, the simultaneous existence of multiple independent evaluation options—such as PIVOT and MITRE’s offerings—can serve to bolster the entire industry.

As SE Labs’ Edwards noted, the PIVOT initiative represents a landmark moment for British cybersecurity. The program’s introduction aligns with the UK government’s Cyber Security and Resilience Bill, aimed at mandating swift incident reporting from essential services and digital providers to regulatory bodies. This developing landscape underscores a heightened focus on regulatory compliance and cross-border information sharing, emphasizing the critical part cybersecurity plays in national and economic stability.

In summary, as cybersecurity threats evolve and become more sophisticated, innovative programs like PIVOT provide essential avenues for organizations to assess and improve their defenses. The collaboration between established cybersecurity vendors and independent testing bodies not only paves the way for enhanced security measures but also contributes to a more informed decision-making process for those responsible for safeguarding their organizations from cyber threats.

Source link

Exit mobile version