HomeCyber BalkansSE Labs Introduces PIVOT Testing Program

SE Labs Introduces PIVOT Testing Program

Published on

spot_img

SE Labs Introduces PIVOT Program to Enhance Cybersecurity Testing for Major Vendors

On September 15, SE Labs, a leading UK-based security testing provider, announced the launch of its innovative program known as PIVOT. Designed to run over a six-month period, PIVOT aims to rigorously evaluate the defenses of cybersecurity vendors against advanced threat actors. Major industry players such as Broadcom—parent company of Symantec and Carbon Black—CrowdStrike, Fortinet, Palo Alto Networks, and Sophos have signed on to participate in this groundbreaking initiative, with results set to be released in January 2027, following the conclusion of the testing phase in October.

The program is built upon a unique methodology that employs trained ethical hackers based at SE Labs’ Wimbledon facility. These hackers will simulate attacks from various source entities, including nation-state groups, allowing them to replicate complete attack chains across various scenarios. These situations encompass a range of threats, including ransomware, malware, and phishing attacks. The focus of the program is to track where protection measures succeed or fail, diving deep into each stage of the attack to understand what security teams actually witness during incidents. This approach marks a significant departure from more conventional, detection-focused testing; it seeks to provide insights into how far attackers can infiltrate an environment.

The oversight of the testing results will include independent verification by analysts from respected research firms Gartner and Forrester, adding another layer of credibility to the outcomes produced by the PIVOT program. The CEO of SE Labs, Simon Edwards, emphasized that the program addresses evolving cybersecurity challenges. These include emerging threats such as attacks involving autonomous AI agents and large-scale incidents exemplified by the significant data breach affecting the UK-based Jaguar Land Rover (JLR). Edwards noted that the aim of disclosing results prior to publication is to assist vendors in identifying security gaps that can inform product development against ongoing threats.

The announcement of the PIVOT program comes at a time of considerable transformation in the landscape of independent security testing. Notably, MITRE’s ATT&CK Evaluations, which have long been viewed as the gold standard in cybersecurity testing, recently experienced a marked decline in participation. Attendance dropped from 30 vendors in 2023 to 19 in 2024, with only 11 committing to the program in 2025. High-profile withdrawals from the 2025 evaluations included companies like Microsoft, SentinelOne, and even Palo Alto Networks. MITRE’s Chief Technology Officer, Charles Clancy, acknowledged that the difficulty of the test may have dissuaded participation, though he remains optimistic about the ongoing investment in independent security testing through various programs.

In contrast to MITRE’s approach, SE Labs intends to distinguish PIVOT by scrutinizing the entire progression of attacks and providing contextual insights relevant to security teams engaged in real-world incident response. Edwards pointed out that confusion surrounding MITRE’s testing methodology may have led vendors to interpret results ambiguously, sometimes allowing marketing departments to misrepresent the data to claim unwarranted victories. All vendors currently involved in PIVOT had previously participated in MITRE evaluations, highlighting a shared history in the evolving realm of cybersecurity benchmarks.

As MITRE prepares to execute its 2026 Enterprise test—focusing on tradecraft related to financially motivated attackers and Chinese espionage—the anticipation for its results builds. Although these results are slated for release in December, specifics regarding participant numbers have not been disclosed.

In conclusion, SE Labs’ PIVOT program represents a significant step forward in the field of cybersecurity testing. By prioritizing the understanding of attack progression and collaborative vulnerability identification, it seeks to empower vendors and enhance the resilience of their products against an ever-evolving threat landscape. As industry dynamics shift and older testing paradigms face scrutiny, programs like PIVOT could redefine how cybersecurity effectiveness is measured in the future.

Source: Infosecurity Magazine

Source link

Latest articles

How Security Leaders Strengthen Protection and Accelerate Response in a Webinar

In the realm of cybersecurity, where the stakes are high and threats continue to...

Two in Five Organizations Experience AI-Related Compliance Failures in the Past Year, Research Reveals

Recent research from Camunda reveals that a staggering 40% of organizations have encountered issues...

Cyber Essentials Achieves Record Year Despite Low Takeup

The United Kingdom's flagship cyber certification initiative, Cyber Essentials, has achieved a notable milestone,...

Ransomware Targets Your Last Line of Defense Webinar

Registration Now Open: ISMG Welcomes New Members In a notable move to enhance networking and...

More like this

How Security Leaders Strengthen Protection and Accelerate Response in a Webinar

In the realm of cybersecurity, where the stakes are high and threats continue to...

Two in Five Organizations Experience AI-Related Compliance Failures in the Past Year, Research Reveals

Recent research from Camunda reveals that a staggering 40% of organizations have encountered issues...

Cyber Essentials Achieves Record Year Despite Low Takeup

The United Kingdom's flagship cyber certification initiative, Cyber Essentials, has achieved a notable milestone,...