UK Launches New Cyber Testing Program for Major Vendors

▼ Summary
– SE Labs launched the PIVOT program to stress-test cybersecurity vendors against nation-state threats and major attack groups.
– Participating vendors include Broadcom, CrowdStrike, Fortinet, Palo Alto Networks, and Sophos, with testing running from July to October.
– The program simulates complete attack chains involving ransomware, malware, and phishing to evaluate defense effectiveness.
– Results will be verified by independent analysts from Gartner and Forrester before publication in January 2027.
– CEO Simon Edwards emphasizes that rigorous testing is essential for buyers to distinguish between detection and actual protection.
A New Standard for Vendor Verification
Starting this July, a specialized team of ethical hackers has been conducting rigorous stress tests on major cybersecurity solutions. These white hat specialists, employed by SE Labs, are operating from their testing laboratory in Wimbledon, London, under the banner of a new initiative called PIVOT. The program aims to provide organizations with clear data on how well vendor products can identify and neutralize threats posed by known attack groups. Several industry heavyweights have already committed to the trial, including Broadcom, which owns both Symantec and Carbon Black, as well as CrowdStrike, Fortinet, Palo Alto Networks, and Sophos.
SE Labs unveiled the six-month PIVOT program on September 15, positioning it as a critical tool for buyers who need to evaluate the efficacy of cybersecurity vendors. The core objective is to assess how effectively these tools defend against the world’s most dangerous hacking groups and sophisticated attack techniques. By simulating real-world scenarios, the program seeks to bridge the gap between marketing claims and actual defensive capabilities.
Simulating Real-World Threats
The methodology behind PIVOT involves replicating the tactics of nation-state cyber groups and other significant threat actors. According to SE Labs, the team impersonates “hacking circles responsible for the most disruptive cyber breaches in recent years.” This approach allows them to test defenses across a wide spectrum of threats, including ransomware, malware, and phishing campaigns.
Rather than looking at isolated incidents, the PIVOT team traces complete attack chains. This holistic view determines exactly where protection mechanisms succeeded, where they failed, and what occurred immediately after a breach attempt. The goal is to provide granular insights into product performance. As SE Labs stated, “This enables buyers to distinguish between a product that identified malicious activity, one that interrupted an attack before significant harm was possible, and one that detected activity but still allowed an attacker to escalate privileges or move further through an environment.”
The initial testing phase is scheduled to conclude in October, with comprehensive evaluation results expected to be published in January 2027. This timeline provides vendors with ample time to address any identified vulnerabilities while giving security leaders timely data to inform procurement decisions.
Addressing the Evolving Threat Landscape
Simon Edwards, CEO of SE Labs, emphasized the urgency of such rigorous testing in today’s digital environment. He noted that the requirements for cybersecurity have completely changed. With the rise of autonomous AI agent attacks, such as those that affected Hugging Face, and the massive economic impact of incidents like the JLR breach, businesses face unprecedented challenges. Edwards argued that “Businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defenses.”
To ensure the credibility of the findings, the SE Labs testing process will be verified by independent analysts from Gartner and Forrester before the results are made public. This collaboration aims to remove bias and provide multiple layers of validation. Edwards explained the strategy: “We don’t ask CISOs to choose between believing SE Labs and believing the vendors. We make the underlying evidence available to Gartner and Forrester, so their analysts can examine it and add their own independent interpretation.”
He added that PIVOT is designed to give security leaders meaningful comparisons without asking them to take conclusions on trust. Furthermore, the pre-result disclosure phase is intended to help vendors identify gaps in their security solutions and support product development against ongoing threat groups and attack types.
Challenges Facing Independent Testing Benchmarks
The launch of PIVOT occurs during a period of significant shift in the landscape of independent enterprise security testing. Historically, the MITRE Engenuity ATT&CK Evaluations were regarded as the gold standard for such assessments. However, the Enterprise version of this US Department of Defense-backed benchmark has encountered notable difficulties in recent years.
Participation in the ATT&CK Evaluations has declined sharply. In 2023, the test attracted 30 participants, but that number dropped to 19 vendors in 2024 and further fell to just 11 in 2025. Major players such as Microsoft, SentinelOne, and Palo Alto Networks publicly announced their withdrawal from the 2025 test cycle. This exodus suggests growing concerns about the feasibility or fairness of the testing criteria.
Charles Clancy, MITRE CTO and SVP of MITRE Labs, acknowledged these challenges in September 2025. He admitted that the team strives to increase the difficulty of the test annually to drive industry progress, but conceded they may have pushed too far in the most recent iteration. “Each year, we want to design a test that’s harder than the year before in order to drive the whole industry forward, since the test can offer an opportunity for vendors to upgrade their products in preparation for the test and once they get the results. And sometimes, we don’t get the balance quite right,” he explained.
In response to these sustainability issues, MITRE established an advisory council in February 2026. This body is tasked with supporting the long-term viability of the MITRE ATT&CK program, which includes both the evaluations and the widely used framework for mapping adversary techniques. As the industry navigates these changes, programs like PIVOT offer a fresh perspective on how to validate cybersecurity effectiveness in an increasingly complex threat environment.
(Source: Infosecurity Magazine)

