Skip to content

Security1 publisher3 min readPublished

SE Labs has been running full attack chains against five vendors' products since July

The PIVOT program was announced on September 15 with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos signed up, and the first comparative results are due in January 2027. MITRE's rival test drew 11 vendors in 2025.

The Watch · Security desk

Illustration accompanying SE Labs has been running full attack chains against five vendors' products since July

What happened

  • SE Labs unveiled PIVOT on September 15, a six-month program in which its own ethical hackers attack commercial security products the way intrusion groups do.
  • Broadcom, which owns Symantec and Carbon Black, plus CrowdStrike, Fortinet, Palo Alto Networks and Sophos have confirmed they are taking part.
  • Testing started in July, the test phase closes in October, and SE Labs expects to publish evaluation results in January 2027.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint No buyer can cite a PIVOT score in a 2026 renewal negotiation. The first comparative attack-chain results exist in January 2027, so this year's contracts are argued on the older evidence base.
  • contradiction The record supports vendors signing up, not buyers switching allegiance. Palo Alto Networks is the only company documented as both leaving MITRE's 2025 test and joining PIVOT.
  • decision With 11 vendors in the last MITRE round and five so far in PIVOT, a shortlist question becomes which products have any third-party attack-chain evidence attached to them at all.
  • precedent Participants get their results before publication and use them to close gaps. That sets the terms on which the January 2027 scores should be read, because the tested product may not be the shipped one.

What PIVOT claims over a technique-by-technique matrix is what it records after a detection fires. SE Labs said its testers follow complete attack chains to determine where protection succeeded, where it failed and what happened next [7], and that this "enables buyers to distinguish between a product that identified malicious activity, one that interrupted an attack before significant harm was possible, and one that detected activity but still allowed an attacker to escalate privileges or move further through an environment" [8]. The team impersonates nation-state groups and other threat actors across ransomware, malware and phishing [6]. SE Labs described the actors it emulates as "hacking circles responsible for the most disruptive cyber breaches in recent years" and did not name them [24].

The hands-on window is four months, July to October [5][9][22]. SE Labs calls PIVOT a six-month program [2][23]. The September 15 announcement came about two months after the testers started work at the company's Wimbledon lab [1][4][22].

MITRE's numbers have gone the other way. ATT&CK Evaluations: Enterprise, the US Department of Defense-backed benchmark long treated as the standard in independent testing [19], had 30 participants in 2023, 19 in 2024 and 11 in 2025 [14]. That is a 63% fall in two years [20]. Microsoft, SentinelOne and Palo Alto Networks said publicly they were pulling out of the 2025 round [15]. Charles Clancy, MITRE CTO and SVP of MITRE Labs, told Infosecurity in September 2025 that the team wants a harder test each year and that "sometimes, we don't get the balance quite right" [16]. MITRE set up an advisory council in February 2026 to support the long-term sustainability of the ATT&CK program [17].

Infosecurity Magazine headlined the story as a shift from MITRE to UK testing [25]. The reported facts put one vendor on both sides of that: Palo Alto Networks quit the 2025 MITRE round and is on the PIVOT roster [15][3]. All five PIVOT participants have taken part in the MITRE evaluation at some point [18]. Five is also fewer than half the 11 that sat the 2025 MITRE test [21].

The verification arrangement is what CISOs are being asked to weigh. Gartner and Forrester analysts get the underlying evidence and verify the testing before publication [10]. "We don't ask CISOs to choose between believing SE Labs and believing the vendors. We make the underlying evidence available to Gartner and Forrester, so their analysts can examine it and add their own independent interpretation," SE Labs CEO Simon Edwards said [11]. Participants also see results pre-publication, which SE Labs said helps vendors identify gaps and supports product development against ongoing threat groups and attack types [13].

For a renewal this quarter, none of this is usable. The evaluation results are expected in January 2027 [9]. Edwards said the case for the test is that "the requirements for cybersecurity have completely changed. There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy" [12].

What to watch

  • Whether Microsoft and SentinelOne, the other two public 2025 MITRE dropouts, join the PIVOT roster before the October test cutoff.
  • Whether Gartner and Forrester publish their own written interpretation alongside the January 2027 results or only verify the testing.
  • Whether MITRE's February 2026 advisory council changes participation in the next Enterprise evaluation.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories