UK security testing provider SE Labs has launched a six-month programme, called PIVOT, to assess how effectively cybersecurity products defend against major hacking groups and attack techniques. Announced on 15 September 2026, the programme includes Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos.
Ethical hackers at SE Labs’ Wimbledon laboratory have been testing products since July by impersonating nation-state groups and other threat actors across attack types including ransomware, malware and phishing. The testing follows complete attack chains, examining not only whether activity was detected but whether an attack was stopped, or whether the attacker could escalate privileges and move through the environment. Testing is due to finish in October, with results expected in January 2027.
SE Labs said independent analysts from Gartner and Forrester will review the evidence before publication. The company described PIVOT as a response to concerns about the usefulness and interpretation of MITRE Engenuity’s ATT&CK Evaluations, whose Enterprise participation fell from 30 vendors in 2023 to 19 in 2024 and 11 in 2025. Microsoft, SentinelOne and Palo Alto Networks withdrew from the 2025 test.
However, MITRE CTO Charles Clancy said the organisation welcomed continued investment in independent testing and that PIVOT and ATT&CK Evaluations provide different forms of evidence. MITRE is conducting its 2026 Enterprise evaluation, covering financially motivated and People’s Republic of China espionage techniques in a Windows endpoint environment, with results due in December; participants had not been disclosed at publication.