"The requirements for cybersecurity have completely changed," Simon Edwards, CEO of SE Labs, said on launch. "There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy."
PIVOT: a London-based, adversary-driven test of defenses
SE Labs, a UK security testing and advisory firm, unveiled a six-month testing program called PIVOT on September 15. The program assigns a team of trained ethical hackers, operating from SE Labs’ testing laboratory in Wimbledon, to impersonate nation-state groups and other high-impact cyber threat actors. From July the team has been stress-testing vendor products against full attack chains that include ransomware, malware, phishing and related techniques.
What PIVOT measures and why SE Labs says it matters
Unlike tests that focus on single detections, PIVOT follows complete attack chains to determine how far an attacker can progress and what defenders would actually see. SE Labs says the program is designed to distinguish three outcomes: a product that merely identified malicious activity, a product that interrupted an attack before significant harm, and a product that detected activity but still allowed privilege escalation or lateral movement. The evaluation also examines whether products provide enough contextual telemetry for security teams to investigate and understand what happened after an attempted breach.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWho has signed up — and what that signals
Several major vendors have publicly confirmed participation in PIVOT: Broadcom (the parent company of Symantec and Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. SE Labs noted that all vendors who have publicly joined PIVOT had previously taken part in MITRE’s ATT&CK Evaluations. The presence of these vendors — including names that did not participate in every recent MITRE round — frames PIVOT as an alternative venue where buyers will see how solutions fare against realistic, multi-stage attacks.
How PIVOT positions itself against MITRE ATT&CK Evaluations
SE Labs acknowledges MITRE’s ATT&CK Evaluations as “one of the industry’s most prominent common sources of technical evaluation data,” but says PIVOT takes a different approach. SE Labs argues that MITRE’s outputs can be difficult for buyers to parse and that marketing departments sometimes use the unstructured data to claim victory in ways that confuse purchasers. Charles Clancy, MITRE’s CTO and SVP of MITRE Labs, acknowledged in September 2025 that his team aims to make the test harder each year and conceded they “may have pushed it too far” in 2025.
Concrete evidence of friction: ATT&CK Evaluations: Enterprise drew 30 participants in 2023, 19 in 2024 and 11 in 2025. Microsoft, SentinelOne and Palo Alto Networks publicly announced they were pulling out of the 2025 test. MITRE told Infosecurity it is executing the 2026 Enterprise ATT&CK Evaluation — which examines financially motivated and People’s Republic of China (PRC) espionage tradecraft in a Windows endpoint enterprise scenario — with publication of results planned for December. MITRE also established an advisory council in February 2026 to support the program’s long-term sustainability.
Verification, timeline, and regulatory context
SE Labs said it will make the underlying PIVOT evidence available in advance to independent analysts at Gartner and Forrester so those firms can verify findings and add their own interpretation before results are published. SE Labs framed the pre-result disclosure as a way to help vendors identify gaps and support product development against ongoing threat groups and attack types. The PIVOT test phase is scheduled to end in October, with evaluation results expected in January 2027.
The program’s launch also arrives as the UK considers the British Cyber Security and Resilience Bill, which SE Labs referenced in public statements: the bill will require designated essential services and digital service providers to report incidents within 24 hours to the regulator and the UK’s National Cyber Security Centre (NCSC), provide a full report within 72 hours, widen regulatory scope and promote cross‑border information sharing with EU authorities under NIS2.
How technologists, procurement leaders, and regulators are likely to respond
- Technologists and security teams (CISOs): SE Labs explicitly designed PIVOT to give security leaders "meaningful comparisons" and to show what a security team would actually see during an attack. CISOs will likely use PIVOT output to evaluate how products translate telemetry into actionable context and whether they interrupt attacks before escalation.
- Procurement leaders and buyers: SE Labs framed PIVOT as a tool to avoid choosing based on vendor claims alone; by providing third-party verification from Gartner and Forrester, SE Labs aims to give procurement teams structured evidence to compare products across the same realistic attack scenarios.
- Regulators and policy makers: The timing of PIVOT coincides with prospective regulatory change in the UK. With reporting windows under the British Cyber Security and Resilience Bill set at 24 and 72 hours, regulators and the NCSC will have a heightened interest in products that not only detect incidents but provide clear, timely context to meet reporting requirements.
SE Labs calls PIVOT “a landmark moment for British cybersecurity,” asserting that leading organizations now choose to test critical cyber solutions in the UK. The program’s peer verification and focus on end‑to‑end attack outcomes mark a deliberate effort to reframe vendor testing from detection counts to operational impact — an argument that will be tested itself when PIVOT’s results are published in January 2027.




