UK-based security testing firm SE Labs has launched a new six-month program to evaluate how well cybersecurity vendors defend against the world's most dangerous hacking groups, attracting major names including Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos. The program, called PIVOT, was unveiled on September 15 and will run until October, with results expected in January 2027. SE Labs said the initiative aims to help buyers distinguish between products that merely detect threats and those that actually stop attacks before serious damage occurs.
The testing takes place in SE Labs' London laboratory in Wimbledon, where trained ethical hackers have been stress testing vendor solutions since July. These "white hat" hackers impersonate nation-state cyber groups and other threat actors, including groups responsible for major recent breaches, to replicate attack types spanning ransomware, malware and phishing. The PIVOT team follows complete attack chains to determine where protection succeeded, where it failed and what happened next. Before publication, independent analysts from Gartner and Forrester will verify the testing results. The pre-release disclosure is also designed to help vendors identify gaps in their security solutions and support product development against ongoing threat groups, SE Labs said.
SE Labs CEO Simon Edwards said in a statement that "the requirements for cybersecurity have completely changed," citing autonomous AI agent attacks and incidents like the JLR breach that influenced the UK economy. Edwards told the outlet he believes businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defenses. The firm said PIVOT is designed to give security leaders meaningful comparisons without asking them to take the lab's conclusions on trust, making underlying evidence available to Gartner and Forrester for independent interpretation.
The launch comes as the MITRE Engenuity ATT&CK Evaluations test—long considered the gold standard of independent cybersecurity testing—faces significant challenges. From 30 participants in 2023, the Enterprise version attracted only 19 vendors in 2024 and 11 in 2025, with Microsoft, SentinelOne and Palo Alto Networks publicly pulling out of the 2025 test. MITRE CTO Charles Clancy told the outlet in September 2025 that the team strives to make the test harder every year and conceded they may have pushed it too far this year. In February 2026, MITRE established an advisory council to support the long-term sustainability of the ATT&CK program. All vendors that have publicly joined PIVOT have participated in the MITRE version, and Clancy told the outlet his team welcomes all security vendors' continued investment in independent testing.
SE Labs said it takes a different approach than MITRE, going beyond evidence of what a product detected to show what happened during an attack, how far an attacker progressed, what defenders could see and understand, and how outcomes compare across competing products. The PIVOT evaluation also examines what the security team would actually see when using the solution, including whether products provide enough context to understand what's happening and to investigate the attempted breach afterwards. Edwards told the outlet he believes that while MITRE's test has become stronger, vendors felt it was more a test of MITRE's own abilities to use the products, and buyers struggled to understand the unstructured data. Edwards also celebrated in a public statement that the world's biggest and best organizations choose to test their critical cyber solutions in the UK rather than in the US, calling it "a landmark moment for British cybersecurity." The program's launch also comes amid development of the British Cyber Security and Resilience Bill, which will mandate designated essential services and digital service providers to report incidents within 24 hours and a full report within 72 hours. The emerging competition between testing regimes may signal a broader shift in how enterprise buyers evaluate security products, particularly as vendors grow more selective about which benchmarks they participate in and what information they're willing to disclose publicly.

