The cybersecurity landscape is witnessing a significant shift as major firms move away from the US Department of Defense-backed MITRE Engenuity ATT&CK Evaluations.
Participation has dwindled to just 11 companies, down from 30 the previous year. In contrast, the UK-based PIVOT programme by SE Labs has garnered attention, with CrowdStrike, Palo Alto Networks, and Broadcom confirming their participation.
This six-month rigorous testing regime examines the potency of cybersecurity solutions against some of the world’s most formidable hacking groups and attack methods.
Testing critical cyber solutions
According to Simon Edwards, CEO of SE Labs, the decision by leading organisations to participate in the UK’s PIVOT marks a significant milestone in cybersecurity testing outside the US. He noted, “There are now very few tier-one vendors that aren’t testing within PIVOT.”
Edwards highlighted the growing complexity of cyber threats, citing examples such as autonomous AI agent attacks and economically impactful incidents like the JLR attack. The programme aims to rigorously test security solutions against various high-profile threats, including nation-state attacks and ransomware.
PIVOT testing methodology
PIVOT uses trained ethical hackers to simulate nation-state and high-profile cyberattacksUnder PIVOT, SE Labs deploys trained ethical hackers to simulate attacks by nation-state groups and notorious hackers. This approach includes replicating incidents involving ransomware, malware, and phishing to assess vendor solutions’ effectiveness in detecting and preventing threats from known sources.
It provides a comprehensive evaluation framework for testing the resilience of cybersecurity defences.
Authority insights
Adam Bromwich, Vice President of Engineering and CTO of Broadcom’s Enterprise Security Group, stressed the importance of transparency within PIVOT testing. He remarked, “CISOs today need clarity and proof, not just promises. PIVOT emphasises full transparency and inclusion of major analyst firms to set a new standard for trust.“
This sentiment was echoed by Simon Reed, Chief Research and Scientific Officer at Sophos, who stated that PIVOT “brings clarity to endpoint testing” by focusing on genuine threat detection and prevention.
Independent scrutiny on test results
The test results from the PIVOT programme are independently scrutinised by analyst firms before publication. This process aids vendors in identifying weaknesses in their cybersecurity solutions and facilitates product development to address emerging threats. The testing phase runs from July to October, with a comprehensive report expected in January 2027.
This development coincides with preparations for the Cyber Security & Resilience Bill, which will require essential services and digital service providers to report incidents swiftly. The legislation aims to enhance regulatory scope and encourage cross-border information-sharing with EU authorities, aligning with the NIS2 directive.
A wave of cybersecurity firms have abandoned the Department of Defense-backed MITRE test as major companies join independent cyber testing programme PIVOT, run by British company SE Labs.
Participants in MITRE Engenuity ATT&CK Evaluations plummeted from 30 to just 11 last year.
Meanwhile, CrowdStrike, Palo Alto Networks and Broadcom are among the participants confirmed for PIVOT, a 6-month testing programme by SE Labs evaluating how effectively vendors can defend against the world’s most dangerous hacking groups and attack techniques.
Testing critical cyber solutions
“It’s a landmark moment for British cyber security, as the world’s biggest and best organisations choose to test their critical cyber solutions in the UK rather than in the US,” said Simon Edwards, CEO of SE Labs. “There are now very few tier-one vendors that aren’t testing within PIVOT.”
“The requirements for cyber security have completely changed. There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy. Businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defences.”
PIVOT testing
The PIVOT testing will see teams of trained ethical hackers from SE Labs impersonate nation-state cyber groups and other hacking circles responsible for the most disruptive cyber breaches in recent years, replicating attack types across ransomware, malware, phishing and beyond to stress test vendor solutions on their ability to detect threats from known attack groups and protect against them.
Authority insights
Adam Bromwich, Vice President of Engineering and CTO, Enterprise Security Group at Broadcom, said: “CISOs today need clarity and proof, not just promises. PIVOT emphasises full transparency and inclusion of major analyst firms to set a new standard for trust. For us isn’t just about a score; it’s about demonstrating Symantec and Carbon Blacks’ real-world efficacy in an open, verifiable way that empowers customers to make confident security investments.“
Simon Reed, Chief Research and Scientific Officer (CRSO) at Sophos, said: “SE Labs’ PIVOT brings clarity to endpoint testing. It highlights who’s genuinely preventing and detecting threats, not just tuning for test conditions. As cybersecurity focuses increasingly on prevention and resilience for real-world protection, this independent assessment is critical to retain trust.”
Independent scrutiny on test results
The data from testing is shared with analyst firms for independent scrutiny ahead of publication to help vendors identify gaps in their security solutions and support product development against ongoing threat groups and attack types. The test portion of the programme runs from July to October, with the final report released in January 2027.
It comes amid the development of the Cyber Security & Resilience Bill, which will mandate designated essential services and digital service providers to report incidents within 24 hours to the regulator and NCSC and a full report within 72 hours, widen regulatory scope, and promote cross-border information sharing with EU authorities under NIS2.
Leave a comment