CyberSecurity SEE

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT

On September 15, SE Labs, a prominent UK-based security testing provider, unveiled its new independent testing program called PIVOT. This innovative initiative aims to assess the defenses of cybersecurity vendors against advanced threat actors. The program, which has garnered participation from major players in the cybersecurity landscape—including Broadcom (the parent company of Symantec and Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks, and Sophos—promises to deliver comprehensive evaluations of current market defenses.

The testing phase for PIVOT commenced in July at SE Labs’ specialized facility in Wimbledon, London. With a focus on effective testing methodologies, the results are anticipated to be released in January 2027, setting a significant milestone in understanding the capabilities of cybersecurity solutions.

PIVOT sets itself apart by employing trained ethical hackers who replicate tactics used by nation-state groups and other sophisticated threat actors, infamous for orchestrating major breaches. Rather than merely identifying detection metrics through traditional testing methods, PIVOT meticulously follows complete attack chains. This comprehensive approach allows the program to evaluate not only whether products successfully identified malicious activity but also if they effectively interrupted attacks before substantial damage occurred. Furthermore, it assesses how well vendors can prevent attackers from escalating privileges and moving laterally through environments, a key factor in maintaining organizational security.

In a quest for transparency and credibility, SE Labs will have its findings independently verified by analysts from two highly regarded research firms, Gartner and Forrester, before public dissemination. This verification process enables third-party analysts to dive into the evidence gathered during testing, providing their interpretations and insights. As a result, security leaders can access multiple perspectives on vendor performance, offering a more nuanced understanding of the functionalities and effectiveness of the products being evaluated.

This launch comes at a pivotal moment for independent security testing, particularly as the landscape has shifted dramatically. MITRE’s ATT&CK Evaluations, which have long been regarded as the gold standard in the industry, have witnessed a significant decrease in vendor participation. From 30 vendors in 2023, the numbers dwindled to 19 in 2024, and further collapsed to just 11 in 2025. Several industry giants, including Microsoft, SentinelOne, and Palo Alto Networks, publicly withdrew from the 2025 test. The CTO of MITRE has acknowledged that the organization may have unintentionally made the test too challenging, leading to these withdrawals. In response to this concerning trend, MITRE established an advisory council in February 2026, aiming to facilitate the program’s sustainability moving forward.

Simon Edwards, the CEO of SE Labs, has highlighted how the requirements for effective cybersecurity have evolved significantly. He pointed to the emergence of autonomous AI agent attacks and notable incidents, such as the JLR breach, which adversely affected the UK economy. Edwards remarked that while MITRE’s evaluations have strengthened over time, some vendors expressed concerns that the tests might be more reflective of MITRE’s proficiency in utilizing products, rather than the capabilities of those products themselves. Additionally, many buyers have found it challenging to make sense of unstructured data that emanates from these tests. It is noteworthy that all vendors currently participating in PIVOT have previously engaged with MITRE evaluations, and MITRE has confirmed that organizations can take part in both testing programs concurrently.

As the cybersecurity landscape continues to evolve, SE Labs’ PIVOT program could play a crucial role in addressing the needs of security teams. By offering a robust framework for evaluating vendor defenses in the face of complex cybersecurity threats, this new initiative stands poised to fill a significant gap left by declining participation in existing testing programs. With its innovative testing methods and independent validation from respected analysts, PIVOT aims not only to enhance vendor accountability but also to provide invaluable insights for organizations striving to fortify their cybersecurity postures in an increasingly perilous digital ecosystem. As the industry watches closely, the findings from PIVOT may set new benchmarks for cybersecurity effectiveness and transparency in the coming years.

Source link

Exit mobile version