SE Labs Launches PIVOT: Independent Testing to Evaluate Cybersecurity Solutions Against Advanced Attacks

SE Labs, a British provider of cybersecurity testing and consulting, has launched the PIVOT program, a new initiative for independent evaluation of enterprise security solutions. The project, announced on September 15, aims to measure the effectiveness of products in countering the most dangerous hacking groups and the most sophisticated attack techniques, providing CISOs with concrete data to assess the performance of solutions in real scenarios.

Quick Answer

PIVOT is an independent testing program that evaluates the effectiveness of enterprise security solutions against advanced attacks. It involves vendors such as Broadcom, CrowdStrike, Fortinet, Palo Alto Networks, and Sophos. Results, expected for January 2027, will be verified by Gartner and Forrester analysts. The program simulates complete attacks, analyzing not only detection but also the evolution of the attack and defense capabilities.

An Innovative Approach to Security Evaluation

PIVOT stands out for its testing method: instead of just checking if a product detects malicious activity, it evaluates the entire cycle of an attack. SE Labs' ethical hackers impersonate state groups and other advanced threats, replicating ransomware attacks, malware, phishing, and other techniques. This approach provides detailed information on where protection worked, where it failed, and what the concrete results were.

The Participating Vendors and the Program Schedule

Confirmed participants include Broadcom (Symantec and Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks, and Sophos. The testing phase, which began in July, will focus on relevant scenarios such as AI-based autonomous attacks, which have targeted platforms like Hugging Face, and large-scale ransomware campaigns, such as the JLR incident that had an economic impact of £19 billion in the UK.

The testing phase will conclude in October, while the results will be published in January 2027. Before disclosure, Gartner and Forrester analysts will examine the data to provide an independent assessment, strengthening the program's credibility.

PIVOT in the Context of Security Testing Evolution

The launch of PIVOT comes at a time of change for independent security testing. The MITRE Engenuity ATT&CK Evaluations, considered the reference standard, have seen a decline in participation in recent years, dropping from 30 vendors in 2023 to just 11 in 2025. Some major players like Microsoft, SentinelOne, and Palo Alto Networks have withdrawn their participation, criticizing the testing approach.

The Differences Between PIVOT and MITRE ATT&CK Evaluations

According to Simon Edwards, CEO of SE Labs, PIVOT offers a different approach compared to MITRE evaluations. While MITRE focuses on the ability of products to detect attacks, PIVOT analyzes the entire lifecycle of an attack, providing information on how far an attacker can progress, what defense teams see, and how results compare between competing products.

Edwards also highlighted that MITRE evaluation results are often unclear, allowing marketing departments to interpret them in a distorted way to promote their products. PIVOT aims to overcome this confusion, providing structured data and third-party verified.

The Regulatory Context and Impact for the UK

The launch of PIVOT coincides with the development of the British Cyber Security and Resilience Bill, which will impose new reporting obligations for essential and digital service providers. The law will require notification of incidents to authorities within 24 hours, with a complete report within 72 hours, also promoting cross-border information sharing with EU authorities under the NIS2 directive.

Edwards emphasized that the program represents a significant moment for British cybersecurity, with major organizations choosing to test their critical solutions in the UK rather than the United States.

The Importance of PIVOT for Cyber Insurance and Compliance

For companies seeking cyber insurance, PIVOT results could significantly influence risk assessments and premiums. With the rise of advanced threats, underwriters may require concrete proof of the effectiveness of security solutions. Similarly, for companies that need to comply with the NIS2 directive or the DORA regulation, PIVOT data could provide a solid basis for demonstrating compliance.

Integration with Other Cybersecurity Services

Companies participating in PIVOT may also consider integrating with other cybersecurity services such as a managed SOC or an MDR service to further strengthen their defenses. Test results could highlight specific areas of weakness that require a more proactive response, such as implementing an advanced SIEM or adopting a Data Loss Prevention to protect sensitive data.

To learn more about how independent tests can influence cybersecurity strategies, explore our penetration testing guide and see also how a SIEM can improve your security posture.

The Impact of PIVOT on the Security Solutions Market

The PIVOT program could redefine the competitive landscape among cybersecurity vendors. With the adoption of more rigorous evaluation criteria, results could influence marketing and product development strategies. For example, companies like Broadcom, which participates with two solutions (Symantec and Carbon Black), may need to make strategic choices about which product to promote based on the results. At the same time, smaller vendors could find in PIVOT an opportunity to compete with industry giants, demonstrating the effectiveness of their solutions in real scenarios.

Implications for Corporate Defense Strategies

For CISOs, PIVOT results will provide concrete data to make informed decisions about security investments. For example, a company that has implemented an MDR service might discover that the tested solution failed in the attack escalation phase, pushing it to consider integrating with a managed Security Operations Center for a more effective response. Similarly, organizations that need to comply with NIS2 compliance could use the results to identify specific areas for improvement in their defenses.

The Evolution of Threats and the Need for Dynamic Testing

The increase in AI-based autonomous attacks, such as those that targeted Hugging Face, underscores the need for dynamic testing that can adapt to rapidly evolving threats. PIVOT, with its approach that replicates complete attacks, could become a model for future security evaluations. This is particularly relevant for companies operating in critical sectors such as energy, critical infrastructure, and healthcare, where digital operational resilience according to the DORA regulation is fundamental.

The Role of the Cybersecurity Community in Validating Results

The participation of Gartner and Forrester analysts in verifying PIVOT results adds an additional level of credibility to the program. These analysts, known for their in-depth research and independent evaluations, could use PIVOT data to update their assessments of cybersecurity vendors. This could influence purchasing decisions by companies that rely on these sources for their security strategies.

Future Challenges for Independent Security Testing

Despite the innovation represented by PIVOT, the sector of independent security testing must face several challenges. One of these is the need to keep up with the evolution of threats. With the emergence of new attack techniques, such as AI-based exploits, testing programs will need to adapt quickly to remain relevant. Moreover, the transparency and objectivity of the results will be crucial to maintaining the trust of the cybersecurity community.

Integration of PIVOT with Other Security Initiatives

PIVOT could be integrated with other security initiatives, such as risk management frameworks and guidelines for ransomware protection. For example, the program's results could be used to improve breach remediation protocols, providing detailed information on how attacks were contained and mitigated. This holistic approach could help organizations strengthen their defenses and respond more effectively to security incidents.

The Future of the PIVOT Program

Looking ahead, PIVOT could expand to include the evaluation of other security solutions, such as identity access management (IAM) platforms and disaster recovery as a service (DRaaS) systems. This expansion could offer a more comprehensive overview of organizations' defensive capabilities, helping CISOs make more informed decisions about security investments. Furthermore, the program could become a reference point for the certification of security solutions, similar to standards like the ISO 27001 certification.

Frequently Asked Questions

What is the main goal of PIVOT?

PIVOT aims to evaluate the effectiveness of enterprise security solutions against advanced attacks, providing concrete data to help CISOs make informed decisions.

How does PIVOT differ from MITRE ATT&CK Evaluations?

PIVOT analyzes the entire lifecycle of an attack, while MITRE evaluations focus primarily on detection capabilities. Additionally, PIVOT provides structured data and third-party verified, reducing the possibility of distorted interpretations.

What are the benefits for companies participating in PIVOT?

Companies can use the results to identify areas for improvement in their defenses, demonstrate compliance with standards such as the NIS2 directive, and positively influence risk assessments for cyber insurance.

When will the PIVOT results be published?

The results of the PIVOT program will be published in January 2027, after being verified by Gartner and Forrester analysts.

How can PIVOT influence the security solutions market?

PIVOT could redefine the competitive landscape among cybersecurity vendors, influencing marketing and product development strategies based on test results.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.