All posts

How SE Labs Turns Threat Intelligence into Real-World Security Tests

Anyone can run malware against a security product. Anyone can execute a suspicious file and see if it gets blocked. But this type of basic testing doesn’t determine whether a product can detect and stop the types of attacks that real adversaries are using. That’s where our Threat Series comes into play.

Each series is a structured set of advanced attack techniques and tactics based on real-world threat groups that share a common theme or operational relevance. It’s how we transform our threat intelligence into repeatable, relevant cyber security tests.

Some threat series focus on state-sponsored activity. Others may combine groups because they target similar sectors, use comparable infrastructure, or focus on particular attack techniques like social engineering. In some circumstances, our testing team may also mix Threat Series if it’s an appropriate approach to testing a product.

For example, ransomware testing may use relevant techniques from multiple series, pulling out individual APTs or attack behaviours known to include ransomware or ransomware-like activity. This gives us flexibility because the Threat Series provides structure, but the test remains driven by its goal – in this example, extorting victims.

Dynamic change as threats evolve

The Threat Series are not static. They are not “set and forget” threat menus that remain unchanged year after year. We continually update them as new intelligence emerges, as attackers change their methods, and as defensive technology evolves.

While some techniques used by a group five years ago may still be relevant, they may not be enough by themselves to truly test a cyber security product. Groups adapt their delivery methods, tooling, evasion techniques and post-compromise actions, and our tests need to reflect that evolution to remain relevant.

SE Labs’ Advanced Security Tests are built around full attack chains. We don’t simply drop malware onto an endpoint and wait to see what happens. Our testers behave like real attackers. So real, in fact, the UK police once contacted us because someone in China reported us as a very dangerous, malicious group!

We use relevant routes into a target environment and then attempt to continue the attack through its later stages. That can include phishing, malicious attachments, exploit activity, external remote services, supply chain-style compromise, command execution, reconnaissance, privilege escalation, lateral movement, data collection, data exfiltration and destructive actions.

This allows us to create valid, controlled and repeatable tests that reflects how attackers actually behave today and in the near future. Our Threat Series are central to that process.

Threat Series 11 – State Sponsored Hacking

The latest Fortinet FortiEndpoint Advanced Security Test Report uses Threat Series 11. This series is based on attacks inspired by the behaviour of four Advanced Threat Groups (APTs):

Gamaredon Group
Ember Bear
Evasive Panda
DPRK

These groups were selected because they are associated with state-sponsored hacking, but they don’t all operate in the same way. This allows us to test a product using a diverse set of realistic attack behaviours.

Gamaredon Group is associated with spear phishing attachments and template injection-style delivery. Ember Bear and Evasive Panda bring supply chain and infrastructure-focused behaviours into scope. DPRK activity introduces external remote services and ransomware-relevant techniques, including actions associated with financial motivation and destructive impact.

Across Threat Series 11, the attack chains include a broad range of tactics and techniques mapped to stages such as delivery, execution, action, privilege escalation, post-escalation activity, lateral movement and lateral action.

This structure allows us to measure more than a simple “blocked” or “missed” result. It shows where a product acted.

Did it detect the delivery?
Did it allow execution?
Did the attacker achieve reconnaissance?
Could the attacker escalate privileges?
Was lateral movement possible?
Could data be collected, exfiltrated or destroyed?

These details are important because not all security outcomes are equal.

A product that blocks an attack before execution has performed differently from one that allows the attack to run, notices later, and then attempts to clean up. Both may eventually prevent a breach, but the level of risk, disruption and operational confidence is not the same.

Why Relevance is Key

Security buyers are often presented with bold claims about a product’s ability to stop advanced attacks. Products claim to detect ransomware. They claim to identify nation-state techniques. They claim to provide visibility across the attack chain.

Threat Series testing gives those claims a harder surface to hit.

Instead of relying on marketing language or narrow demonstrations, buyers can look at SE Labs reports to see how a product responded to attacks based on real adversary behaviour. They can see whether attacks were detected, where they were stopped, and whether the product made mistakes with legitimate software.

This matters because real-world testing is not about finding the most exotic way to break a product. It is about testing against attacks that are relevant, credible and operationally meaningful.

SE Labs’ threat intelligence goes much deeper than any single Threat Series. Our research tracks attacker behaviour, emerging techniques and future-facing developments across the threat landscape. But effective public testing has to be selective. It must focus on the techniques that matter to defenders now, while remaining informed by what is likely to matter next.

That is the role of the Threat Series. They provide a structured way to surface the parts of our threat intelligence that are most relevant to a specific test, sector or attacker profile.

Threat Series 11 reflects SE Labs’ broader principle: testing needs to evolve because attackers do. APTs reuse what works, retire what doesn’t, borrow from other groups and adapt to defensive controls.

A credible testing programme has to do the same: observing, updating and emulating attacker behaviour as it develops, while keeping the test grounded in the threats that security teams are most likely to face.

Download the latest Fortinet FortiEndpoint Advanced Security Test Report to see how Threat Series 11 was used in practice.

All posts

The Winners of the SE Labs Security Awards 2026

The SE Labs Awards recognise the organisations that continually deliver outstanding performance in the cyber security industry.

Now in their eighth year, the awards celebrate the technologies and teams helping to keep businesses, consumers and critical systems secure. Covering categories across the Enterprise, Small Business and Consumer markets, the awards highlight the companies setting the standard for protection, detection and resilience in today’s threat landscape.

Winners are selected using a combination of continual public testing, private assessments and feedback from SE Labs’ corporate clients. This means the awards are not based on marketing claims, but on proven performance, consistent results and the ability to stand up to the kinds of attacks organisations and individuals face in the real world.

As threats continue to evolve, the need for rigorous and independent testing has never been more important. The SE Labs Awards recognise those vendors whose products have demonstrated excellence throughout the year, as well as the commitment of the teams behind them.

Hosted in London, the awards ceremony concludes the SE Labs Workshop, which brings together industry peers to explore the latest thinking in cyber security testing, protection and resilience.

And the winners of the 2026 SE Labs Awards are…

ENTERPRISE AWARDS

SE Labs Award for Enterprise Endpoint for Windows

This award recognises the most effective and reliable endpoint protection solutions for enterprise environments running Microsoft Windows. Recipients have demonstrated superior threat detection, operational stability, and resilience against targeted attacks, verified through SE Labs’ independent testing framework.

The winners of this year’s Enterprise Endpoint for Windows Award are:

Broadcom Symantec
CrowdStrike
Kaspersky
Sophos

SE Labs Award for Enterprise Ransomware Protection

Focused specifically on one of the most severe threats facing businesses today, this award recognises the solutions that best protects enterprise environments against ransomware. From prevention and detection to containment and recovery, the winner has proven their ability to neutralise ransomware attacks under rigorous testing conditions.

The winner of this year’s Enterprise Ransomware Award is Palo Alto Networks.

Enterprise Network Detection and Response

Given to the most effective NDR solutions, this award celebrates technologies that excel at identifying and responding to advanced threats moving across enterprise networks. Winners have demonstrated a high level of visibility, threat intelligence integration, and actionable response capabilities under SE Labs’ rigorous testing.

The winner of this year’s Enterprise Network Dection and Response Award is Cisco.

SE Labs Award for Enterprise Security Development

Security is an evolving discipline, and this award recognises the enterprise product or vendor that has shown exceptional progress or innovation in development. Whether through rapid feature evolution, standout engineering practices, or meaningful user-driven enhancements, the winner is helping advance the enterprise security landscape.

The winner of this year’s Enterprise Security Development Awards is Agger.

SE Labs Award for Enterprise E-mail Security Services

This award honours the enterprise email security solution that delivers the strongest protection against phishing, malware, and targeted email threats. Winners provide consistent, effective filtering and threat prevention, validated through SE Labs’ simulation of real-world, enterprise-scale email-based attacks.

The winners of this year’s Enterprise Email Security Service Award are:

Cisco
TrendAI
Zoho

SE Labs Award for Enterprise Next Generation Firewall

This award is presented to the most capable NGFW solutions in an enterprise context. From deep packet inspection and intrusion prevention to threat intelligence and application control, winners combine advanced security capabilities with reliability and performance under stress.

The winners of this year’s Enterprise Next-Generation Firewall Award is Cisco.

SE Labs Award for Enterprise Security Innovator

Reserved for the most forward-thinking companies in the enterprise space, this award recognises innovation that is redefining cyber defence at scale. Whether through groundbreaking technology, strategic integrations, or bold new security architectures, the recipient is pushing the boundaries of what’s possible in enterprise security.

The winner of this year’s Enterprise Security Innovator Award is CrowdStrike.

SE Labs Award for Enterprise Data Protection

This award highlights the solution that best safeguards enterprise data. Whether in motion, at rest, or in use. From preventing data leakage and insider threats to securing cloud environments and compliance, winners provide effective, tested controls to protect valuable information assets.

This winner of this year’s Enterprise Data Protection Awards is Cisco.

SMALL BUSINESS AWARDS

SE Labs Award for Small Business Endpoint for Windows

Tailored for the needs of smaller organisations, this award celebrates endpoint security products that provide strong out-of-the-box protection, ease of management, and robust real-world defence for Windows-based networks, without requiring enterprise-level resources to operate effectively.

The winners of this year’s Small Business Endpoint for Windows Award are:

Kaspersky
Microsoft
Sophos

SE Labs Award for Small Business Security Innovator

Innovation is critical in an evolving threat landscape. This award recognises a standout vendor or service provider pushing the boundaries of small business cyber security. Whether through breakthrough technology, creative service models, or agile threat response strategies, this honour is reserved for those reshaping the future of SME security.

The winner of this year’s Small Business Security Innovator Award is Coro.

SE Labs Award for Small Business Security Development

Recognising growth and evolution, this award goes to the vendor or product that has made significant strides in security development for small businesses. Whether through rapid feature improvement, increased threat coverage, or user-centric enhancements, the recipient is advancing SME-focused security.

The winner of this year’s Small Business Security Development Award is Sophos.

Small Business E-mail Security Service

This award is given to the most effective email protection solution for small organisations. Combining ease of deployment with robust filtering of phishing, malware, and BEC attacks, the winner delivers strong, accessible security without requiring specialist resources.

The winner of this year’s Small Business Email Security Service are:

Microsoft
Mimecast

CONSUMER AWARDS

Home Anti-Malware for Windows

This award acknowledges the home anti-malware products that provide the most reliable, user-friendly protection for Windows PCs. Winners offer strong malware detection, minimal system impact, and an intuitive user experience, as verified through rigerous real-world testing.

The winners of this year’s Home Anti-Malware for Windows Award are:

Gen Digital (Norton)
Kaspersky
McAfee
Microsoft

Home Anti-Malware for Mac

This award acknowledges the home anti-malware products that provide the most reliable, user-friendly protection for macOS devices. Winners offer strong malware detection, minimal system impact, and an intuitive user experience, as verified through rigerous real-world testing.

The winners of this year’s Home Anti-Malware for Windows Award are:

Gen Digital (Norton)
Intego

SE Labs Award for New Home Anti-Malware

This award celebrates a new consumer endpoint solution that has quickly proven its effectiveness. Balancing innovation, simplicity, and real-world protection, the winner stands out as a strong challenger in the competitive consumer security space.

The winner for this year’s New Home-Anti-Malware Award is Protected.net.

SE Labs Award for Consumer Security Development

Presented to the vendor that has shown outstanding development progress, this award reflects continued investment in protection, usability, and customer experience. The recipient is shaping the future of consumer cyber security through meaningful, demonstrable improvement.

The winner for this year’s Consumer Security Development Award is Kaspersky.

SE Labs Award for Consumer E-mail Security Services

With email still a key threat vector for individuals, this award honours the service that most effectively protects consumers from phishing and malicious content. The winner has demonstrated consistently strong filtering and prevention capabilities under SE Labs’ independent testing.

The winner for this year’s Consumer Email Security Services Award is Microsoft.

All posts

How Advanced Cyber Security Products Should Be Tested

When testing advanced cyber security products truthfully, the aim should not be to stage a product demonstration or run an artificially narrow technical exercise. It should be to understand how those products perform under the kinds of attacks organisations actually face. That means testing in a way that reflects how attackers operate in the real world: starting at the beginning of the attack chain, moving through each layer of the target environment, and continuing until the attack is either stopped or the attacker achieves their objective.

This matters because modern security controls do not operate in isolation. A single attack may first be encountered by email security, then by a web gateway, then by network controls, then by endpoint protection, and later by detection and response products – as the attacker moves deeper into the environment.

Credible Entry Points

If a test ignores those earlier opportunities for detection and prevention, and jumps straight to malware execution on an endpoint, the result may appear technical and exact, but it is unlikely to reflect how protection works in practice. A threat that seems to evade one control in isolation may never have reached that stage in a real-world intrusion because another layer would already have blocked it.

For that reason, realistic testing has to begin with a credible entry point. It might start with a spear phishing email, a malicious link, or a file delivered through a convincing social engineering scenario. From there, the attack should be allowed to unfold in the same sequence that a genuine intrusion would follow.

The tester must replicate both sides of the interaction: delivering the lure; opening the message; clicking the link; downloading the file; entering a supplied password where appropriate; and allowing the malicious attack chain to develop naturally. Only then is it possible to judge where prevention occurs, where detection occurs, and how effectively a product supports defenders throughout an attack.

Realistic Environments

The environment matters just as much as the attack path. A meaningful test cannot be carried out against a blank lab machine with no context. The target environment should resemble a real organisation, with users, roles, suppliers, business processes and internal systems. And possibly even third-party partners (that can be impersonated!) That context makes attacks more credible and the results more informative.

A phishing email should look like something the recipient might genuinely receive. A business email compromise scenario should mirror a plausible request, from a plausible source. A compromised endpoint should be capable of serving as a stepping stone for privilege escalation, credential theft, lateral movement, persistence, and possibly access to more valuable assets. Attackers rarely stop at the first machine they compromise. Their aims are usually broader: theft, disruption, espionage, extortion, or preparation for ransomware deployment.

Understand the Nuances of Layered Security

The full-attack-chain approach also provides a more useful view of layered security. In a protection test, one layer may stop the intrusion almost immediately. If that happens, the attack should end there, because in reality the adversary would need to begin again using a different route. In a detection-focused test, some protections may be configured to allow the attack to progress further so that visibility and alerting can be assessed across the intrusion. That makes it possible to evaluate not just whether a product can stop an attack, but whether it can identify and report malicious behaviour throughout the kill chain.

That distinction matters. A protection test asks whether an attack would have been prevented in practice. A detection test asks a different question: if the attacker got further in, how much of their activity would have been seen? Both perspectives are important. One shows whether an organisation would likely have been protected from harm. The other shows how much operational visibility a security team would have had if the attack had developed.

Not every point in an attack chain carries equal significance, and good testing should reflect that. There are multiple opportunities to detect malicious activity: before a message is delivered, when a link is clicked, while a payload is downloading, when a file is written to disk, when execution begins, or later when behaviour such as lateral movement or privilege escalation becomes visible. Recording these stages transparently provides far more value than a simple pass-or-fail verdict. It shows not only whether a product detected something, but when it did, what it saw, and whether that timing was early enough to make a practical difference.

A Focus on Real-World Outcomes

This is also why customer-facing comparative testing should avoid false assumptions. Engineers may quite reasonably isolate a single component to answer a specific internal question, such as whether an endpoint engine can detect particular code once it is already running. That kind of modular testing has value in product development. But it is not the same as realistic comparative testing for buyers. When outer layers are bypassed and a threat is injected directly into a later stage of the attack, the result may overstate weaknesses or strengths that would have little bearing on real-world outcomes. It may be technically interesting, but it is not necessarily representative.

Testing that follows an attack from beginning to end is better aligned with how modern threats behave. Real attackers do not engage with one security control at a time in neat isolation. They adapt, retry, pivot, escalate privileges, abuse trust relationships and move towards an objective. Any test that claims to measure advanced defensive capability should account for that reality.

Results That Reflect the Real-World Fight

For purchasers of cyber security products, that realism is the point. They are not trying to buy a laboratory score. They are trying to understand what would happen if a serious attacker targeted their organisation. Would the threat be blocked early? Would it be detected in time for defenders to act? Would there be meaningful visibility as the intrusion unfolded? Would the attack be stopped before significant damage was done?

Effective cyber security testing should answer those questions. It should reproduce realistic attacks, respect the layered nature of modern defence, and show clearly where products detect, prevent and respond. That’s the standard advanced security testing ought to meet. Not the measurement of isolated components in artificial conditions, but the assessment of how security performs in the real-world fight.

All posts

Level:UP Cyber Security Week 2026:

A hands-on opportunity for aspiring cyber security professionals

Are you passionate about cyber security and curious about what a future in the industry could look like?

SE Labs is inviting university students and young adults to apply for Level:UP Cyber Security Week 2026 — a five-day programme designed to give participants practical experience, industry insight, and a clearer view of the skills needed to build a career in cyber security.

Taking place from 6–10 July 2026 at our Wimbledon Village office, the programme offers a chance to learn directly from a company working at the forefront of cyber security testing. At SE Labs, we evaluate next-generation security products using detailed testing and real-world threat intelligence across endpoint, appliance, and cloud security.

A week of practical cyber security experience

Throughout the week, participants will:

  • take part in interactive tutorials
  • experience immersive red and blue team labs
  • build skills in identifying vulnerabilities and defending against cyberattacks
  • develop practical knowledge relevant to real cyber security roles
  • strengthen communication and teamwork skills through group activities
  • put their learning to the test in a Capture the Flag competition

This is designed for students who want more than theory. It is a chance to explore cyber security in a practical, engaging environment and gain experience that could help shape future study and career choices.

Because we want to provide a personalised experience, places are limited. Successful applicants will need to attend in person from 10:00 to 15:00 each day for the duration of the programme. Our office is about a 15-minute walk from Wimbledon Station and can also be reached by local bus routes. Please note that parking is not available.

How to apply

To support the selection process, applicants should submit:

  • a cover letter explaining their interest in cyber security and highlighting any relevant projects, research, or academic achievements
  • ideally, a letter of recommendation from a faculty member who can comment on their potential and skills in IT or a related field

Applications should be sent to levelup@selabs.uk with the subject line:
Level:UP Cyber Security Week Programme

Registration deadline: 03/04/2026

If you are serious about cyber security and want to challenge yourself in a real-world environment, this is an excellent opportunity to take the next step.

All posts

SE Labs Workshop and Annual Awards 2026

A day for candid conversations, practical insights, and a deeper understanding of real-world testing and how it benefits your customers.

On 11 June, we’ll be welcoming some of the world’s leading cyber security organisations to Wimbledon, London for this year’s SE Labs Workshop and Annual Awards.

Those who joined last year will already have a feel for the day. For everyone else, here’s what makes it genuinely useful — and why so many said they’d return.

At its core, this is a one-day event built specifically security developers and product managers. No marketing gloss. No sales pitch. Just a clear and open look at how modern security testing works, where it’s heading, and how that connects directly to the products you build.

What the Day Looks Like

We’ll spend the day working through the areas shaping both our testing and the wider industry. That includes XDR, ransomware, anti-spam, and Mac security, alongside how we are approaching testing zero trust and validating anti-tamper resilience. We will also share what is developing within the PIVOT programme and what that means in practice.

But the real value is not just in the presentations. It’s in the conversations around them. The questions, the challenges, and the chance to sit down with our testing team and talk in-depth.

As Nick Kelly from Trellix said after last year’s event:

“It was a pleasure to attend and meet yourself and the team at SE Labs and learn more about the testing methodology… I thought the presentations were all really well delivered and very informative, and the event very beneficial overall.”

That openness is deliberate. This is a space where you can properly understand how results are produced, what sits behind them, and how they are interpreted by customers.

Why it’s Worth Your Time

The feedback we hear most often is that the day helps developers get a much clearer picture of what good testing actually looks like in modern security products.

Not in theory, but in the context of real-world testing and real customer impact.

Righard Zwienenberg from ESET put it simply:

“The content was interesting and better than expected… We’re already looking forward to the workshop next year!”

When you understand how testing is evolving, it becomes much easier to align product decisions, messaging, and customer conversations with what really matters.

It is also a rare chance to spend time with peers in the same space. Not rushing between meetings, but having insightful conversations with people dealing with the same challenges.

The Awards and the Evening

We will close the day with the SE Labs Annual Awards, followed by drinks and dinner.

The awards recognise cyber security products and organisations that consistently perform at a high level across public testing, private assessments, and enterprise client feedback. It is about sustained performance and real world results.

After that, we slow things down a bit. The evening is a chance to continue the conversations from the day in a more relaxed setting.

As Paul Walker from McAfee shared with us, it was not just the content that stood out, but the warmth, professionalism and genuine enthusiasm of the team and the overall experience.

A Genuinely Useful Day

There is no attendance fee. The only investment is your time and travel.

What you get back is clarity. A better understanding of how your product is tested. And a much closer connection to how those results are seen by customers.

Join Us in Wimbledon

If you are involved in building, testing, positioning, or supporting security products, this day is designed for you.

We would strongly encourage you to join us on 11 June.

Places are limited, so if you would like to attend, please email: workshop@selabs.uk to secure your spot. If you have colleagues who would benefit from being there, feel free to bring them along too.

We would gratefully value having you in the room.

All posts

Cyber Hygiene: The “Boring” Fix that Breaks Ransomware

Ransomware attacked by cyber hygiene

Ransomware dominates headlines because it’s a concept that is easy to understand. Its impact is felt well beyond the initial victim, and its cost is easily demonstrable. It freezes operations. It halts revenue. It presents a neat number on a ransom note that board members and senior management can understand instantly.

But ransomware isn’t the whole attack. It’s the last step.

And that’s why the most unglamorous topic in cyber security – cyber hygiene – is still the best lever businesses have in reducing the impact of ransomware.

Why Ransomware Keeps Winning

If you’re a cyber attacker, there’s very little incentive to change your behaviour. The fundamentals that worked 10–15 years ago still work today. Find a way in, move around, escalate privileges, deploy the payload and get paid.

That “payload” is the key point. Ransomware is not how an attacker gains access. It’s what gets deployed once access has already been achieved and the attacker has positioned themselves for maximum disruption.

Buying more products is clearly not the primary solution to stopping attacks from reaching their final stage. If it were, the last decade of news headlines on cyber breaches – many involving organisations that should be among the best protected in the world – would look very different.

The uncomfortable truth is that ransomware thrives on basic failures. Attackers do not need zero-day exploits if patching is inconsistent, privileges are excessive or protective controls are mis-configured or poorly maintained. In those conditions, ransomware is not an intrusion problem. It is an inevitability.

In this scenario, it’s probable that many high-profile ransomware incidents weren’t enabled by genius-level exploitation, but by basic mistakes made along the way.

Cyber hygiene is simple – have a plan and execute it

Cyber hygiene sounds like “security 101” because it is. At its core, it’s businesses doing the boring work consistently:

  • knowing what they have
  • setting minimum standards
  • reducing preventable exposure
  • preparing for incidents on the assumption that they will happen

And yet, even in countries like the UK and the US, where you’d expect organisations to be leading the way, over 50% still don’t have a usable cyber security plan.

That’s not a tooling issue. That’s governance, discipline and accountability.

SME Cyber Hygiene Isn’t Just an SME Problem

As our CEO and founder, Simon Edwards, discussed on a recent CyberCube webinar, the issue is compounded for small and mid-sized businesses (SMEs) that often face a triple bind:

  1. They can’t afford “enterprise-grade” security products, and many vendors won’t even sell below minimum seat counts.
  2. They don’t adopt even lightweight standards because they don’t believe they have the budget.
  3. They can’t meaningfully insure themselves out of trouble, either due to cost, eligibility or the reality that insurers require telemetry and controls many SMEs don’t have.

So SMEs remain highly exposed, and that exposure becomes a supply-chain problem for larger organisations.

Why Boards Fund Ransomware (and ignore quieter breaches)

Ransomware is popular with attackers for a simple reason: instant monetisation.

In a strange way, it’s also popular with victims. It’s easy to understand. Boards can quantify the loss in hours of downtime versus the monetary value of the ransom demand.

Compare that to unseen IP theft, data exfiltration or long-term espionage. Those harms are real, but the financial figure is fuzzier, delayed and harder to defend in a budget conversation.

That’s one reason why we believe ransomware will stay in the spotlight for years: it creates an immediate, board-relatable crisis.

The risk is that organisations will optimise spending for the most visible outcome rather than the most probable path and subsequently under-fund the hygiene that prevents attackers getting to the payload stage.

Ransomware Resilience

Ransomware outcomes are shaped long before encryption begins, often by decisions made months or years earlier about patching discipline, privilege control and defensive coverage.

Where cyber hygiene is strong, ransomware struggles to gain a foothold. Not because attackers aren’t capable – but because the path to the payload usually depends on a chain of preventable weaknesses. Which is why when we test a cyber security product against ransomware, such as our most recent report on CrowdStrike Falcon, it’s not about ransomware as a payload alone.

It is about whether security products meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.

All posts

Inside the PIVOT Pilot: Measuring Real-World Cyber Security Protection

As the pilot phase of PIVOT™, our new ground-breaking detection and protection cyber security test, draws to a close, it’s a good moment to explain some of the techniques and the methodology behind the test.

PIVOT isn’t a collection of isolated checks or simulated exercises. Even in pilot form, it was run as a complete test, using real-world attack techniques to answer a single, fundamental question: can a product detect and stop modern cyber attacks across the full attack lifecycle?

The pilot differed from the forthcoming inaugural PIVOT test in one key respect only: participating vendors took part on the understanding that results would not be made public. In every other way, the pilot was executed as the real thing.

Testing Full Attack Chains, Not Individual Threats

PIVOT is designed to emulate complete attack chains rather than individual threats in isolation. During the pilot, products were subjected to realistic attack scenarios that reflected how modern attackers operate in live environments.

This meant evaluating whether products could do more than simply detect malware. We assessed their ability to:

  • Identify suspicious activity early
  • Detect and disrupt reconnaissance
  • Prevent privilege escalation
  • Block lateral movement
  • Stop data theft and system compromise

Real attackers don’t move in straight lines, and neither do our tests. Each scenario was designed to expose how well products perform as attacks evolve and adapt.

Reconnaissance: Mapping Systems Like an Attacker

Reconnaissance is a fundamental stage of almost every cyber attack. During the pilot, we carried out discovery activities to map systems, users, and access opportunities across the test environment.

Although we built the network ourselves, we deliberately followed attacker workflows. This allowed products to demonstrate whether they could detect suspicious discovery behaviour, flag anomalous activity, or block attackers before an intrusion fully developed.

This approach is central to our Test Like Hackers™ philosophy and provides critical insight into a product’s real-world defensive capability.

Privilege Escalation and Lateral Movement

Successful attacks rarely end with initial access. Attackers aim to escalate privileges, expand control, and move laterally through a network.

During the pilot, we executed realistic escalation and lateral movement attacks based on current criminal techniques. These attacks tested whether products could stop an intrusion from progressing from a single foothold into a full environment compromise.

This stage is not just where security failures can become truly damaging; it’s also where effective products can still prevent a breach from escalating.

Living-Off-the-Land Techniques

Modern attackers increasingly avoid obvious malware in favour of legitimate system tools already present in the environment.

Throughout the pilot, we identified which native utilities could be abused, reviewed recent attacker behaviour from SE Labs’ threat intelligence, and incorporated living-off-the-land techniques directly into our attack scenarios.

This ensured PIVOT measured a product’s ability to detect malicious behaviour, not just known malicious files—an essential distinction in modern cyber security defence.

Email as a Realistic Entry Point

Email remains one of the most common initial access vectors, particularly for Business Email Compromise (BEC) attacks that often contain no malware at all.

Rather than relying on simplistic test cases, the pilot included email-based attacks that reflect how modern attackers actually operate today. These scenarios were informed by SE Labs’ threat intelligence to ensure realism and relevance.

Accuracy Without Sacrificing Protection

False-positive testing plays an important supporting role in PIVOT. A product that blocks legitimate business activity can be almost as disruptive as one that misses real threats.

During the pilot, we verified that detection engines were appropriately balanced—capable of identifying attacks without resorting to overly aggressive blocking. Vendors were not permitted to re-tune their systems during testing beyond standard updates released to all customers, ensuring results reflected real-world deployment rather than test optimisation.

False positives matter, but only insofar as they ensure strong protection doesn’t come at the expense of usability.

From Pilot to the Inaugural PIVOT Test

With the pilot nearing completion, we are analysing not only the results of our tests, but also how clearly and effectively attacks are presented to end users through a product’s reporting and dashboard capabilities.

The inaugural PIVOT test, launching later this year, will follow the same rigorous methodology—with one critical difference: results will be made public, even if they are uncomfortable for individual vendors.

From reconnaissance and initial access through to privilege escalation, lateral movement, and data exfiltration, PIVOT is designed to test security products as attackers encounter them in the real world, and not as laboratory exercises.

All posts

Badges Don’t Stop Hackers: Why Cyber Security Testing Needs a Reality Check

Let’s be honest, cyber security testing has a reputation problem. Between pay-for-badge schemes; incompetent testers; and outright corrupt practices, it’s no wonder security professionals approach test results with healthy scepticism. But there is a better way to test security products. One that actually tells you if your defences will hold up when attackers come knocking.

Test Like a Hacker, Not Like a Script

There is a fundamental principle that separates meaningful testing from superficial product showcases: test like a real hacker would attack. Not with pseudo simulations. Not with automated tools that spit out PCAP binaries. But with actual people conducting full-scale attacks from beginning to end.

This approach started with anti-virus testing in the late 90s, where testers used real threats to see if products actually worked. Today the methodology has evolved to encompass everything from email security to firewalls to full XDR platforms. However, the core concept remains the same: behave like the bad guys do and see what happens.

Why Simulated Testing Falls Short

Automated tools are faster and cheaper. There is no denying that. You can push attacks through systems on a weekly basis without breaking into a sweat. But if a security product doesn’t detect a simulated attack, is it compromised or not? Because, technically, it wasn’t actually an attack.

Real attackers don’t follow scripts. They adapt, pivot, and use tactics specific to the threat group that has their affiliation. Emulating this type of approach, with real people at the helm, takes longer (sometimes eight weeks or more) and costs more money, but the quality of the results actually helps to improve products. More importantly, it gives businesses confidence that their security stack will perform when it matters most.

The Transparency Imperative

The solution to cynicism about testing? Complete transparency. Share everything – the attack methodology; the samples used; the complete chain of events. When everything is documented and repeatable, it’s possible to either prove the test was done correctly or learn from mistakes and improve.

At SE Labs, this means capturing every step of an attack so vendors can replay it. They can understand what went wrong and verify that their fixes actually work. It’s not enough to hand over some binary files and say, “good luck.” That’s not consulting, just expensive confusion.

Real-World Testing Catches What Matters

Something interesting happens while testing systems like an actual attacker. It becomes clear which threats bypass every layer of defence, rather than only a single one. This is critical information for vendors trying to prioritize their engineering efforts.

A threat that bypasses one out of ten defensive layers? Lower priority. A threat that makes it through everything? That goes to the top of the list immediately. This approach aligns vendor investment with what actually protects customers, rather than just chasing perfect scores on artificial benchmarks.

The “100% Problem” Isn’t Really a Problem

Even when a product scores 100% in testing, there’s still value in the results. Smart engineering teams use perfect scores to analyse how their product responded and whether it could be more efficient. They’re not just popping champagne. They’re asking whether blocks could happen earlier in the chain or with less overhead.

This only works when the testing methodology provides enough detail to support that kind of analysis. “You blocked everything, congrats” doesn’t help anyone improve.

Prevention AND Detection Both Matter

The debate between prevention and detection is kind of missing the point. In a world where attackers live off the land and use legitimate admin tools, pure prevention isn’t always possible. What matters is the end result: did you get breached or not? And if something did happen, can your Security Operations Centre (SOC) get in the way before serious damage occurs?

Real-world testing captures this full picture to give organisations confidence in their product choices. It’s like crash test dummies versus measuring individual component strength – you need to see what happens when everything comes together under realistic conditions.

Making It Repeatable and Useful

Good testing isn’t just about finding problems—it’s about creating a feedback loop that makes products better. This means:

  • Complete documentation of every attack step
  • Repeatable procedures so vendors can verify and fix issues
  • Forensic evidence that proves what actually happened, not just what alerts claimed
  • Long-term consistency so you can evaluate products over time, not just in one snapshot

The XDR Reality Check

Testing complex, layered security setups (like XDR platforms with multiple integrated products) is legitimately hard. It can take months just to get everything configured and working together. But the methodology doesn’t need to change. The test should still be conducting full attack chains from start to finish. What changes is the technical effort required to set up the environment.

In contrast, simulated testing doesn’t account for how threats actually move through integrated systems. Sure, it might be cheaper and easier, but it won’t tell a CISO if their million-dollar security investment actually works.

Beyond the Badge Collectors

Some companies come to SE Labs and think they can just pay money and get a badge to slap on their website. They’re surprised when we insist on running actual tests that involve real threats and measuring actual results. Because, after all, real attackers don’t care about badges. However, it reveals a fundamental misunderstanding of what security testing should be.

Real testing means you might discover your product doesn’t detect anything. That’s valuable information—both for the vendor who needs to improve and for potential customers who need to know the truth.

What This Means for Security Teams

If you’re evaluating security products, look for tests that are:

  • Transparent about methodology and results
  • Conducted by real people, not just automated tools
  • Repeatable and documented in detail
  • Consistent over time across multiple test cycles
  • Focused on full attack chains, not isolated components

Don’t rely on vendors who avoid testing or only participate in tests they can game. Don’t trust results from testers who won’t share their methodology or samples. And definitely don’t make decisions based on pay-for-badge certifications.

The Bottom Line

Testing cyber security products shouldn’t be complicated in concept, even if it’s complex in execution. Test like hackers. Be transparent about methods and results. Focus on whether threats actually get through or not. Make everything repeatable so your security and the vendors’ product can improve.

Behaving like a hacker is more expensive and time-consuming than automated alternatives, but it’s the only way to know if your security products will perform when facing actual adversaries. In an industry with too many exaggerated claims and not enough honest evaluation, that’s worth the investment.

After all, you’re not defending against automated test scripts. You’re defending against real people who are highly motivated to break into your systems. Your testing should reflect that reality.

All posts

The Mac Myth: Why Your CEO’s Laptop Might Be the Weakest Link

For years, the mantra has been the same. Macs don’t get viruses. It’s a belief so deeply ingrained that many organisations have relaxed their security posture for Apple devices, particularly when C-suite executives insist on using their preferred MacBooks and iMacs.

But this complacency is creating a critical vulnerability in enterprise security—one that sophisticated attackers are increasingly exploiting.

Why Mac Users Have Become Prime Targets

While Macs still represent a little under 10% of the computer market, they’re no longer being ignored by attackers. Why? Because that 10% represents some of the most valuable targets in any organisation.

Mac users tend to fall into two categories: individuals who have spent premium money on their devices, and executives at large enterprises who have demanded Mac access. Both groups typically have elevated privileges, access to sensitive information, and the authority to approve significant transactions.

From an attacker’s perspective, why cast a wide net targeting thousands of Windows users when you can focus your efforts on a smaller number of high-value Mac users who likely have access to financial systems, strategic plans, customer data, and intellectual property?

The Compliance Gap

There’s another factor driving the need for Mac security: regulatory compliance. Many organisations have security policies requiring protection on all devices. “All endpoints must have anti-virus” is a common mandate, regardless of operating system.

This creates a situation where organisations need Mac security products not just for technical protection, but to satisfy legal and compliance obligations. The question becomes: do these products actually work, or are they just checkbox solutions?

When Built-In Protection Isn’t Enough

Our latest testing reveals a concerning reality about macOS security. While Apple has built several anti-malware technologies into macOS including Gatekeeper, XProtect, and the Malware Removal Tool (MRT), these defences proved inadequate against targeted attacks designed to mimic real-world threat actor behaviour.

In comprehensive testing conducted in May 2025, we created targeted attacks using common tools available to and frequently used by real attackers. We then tested macOS with default security settings (including the firewall) against these threats.

The results were stark. MacOS failed to protect against a single attack. Across 11 different attack scenarios, each stage of the attack chain succeeded, including escalating system privileges. This meant attackers could snoop on Wifi networks, clear logs to hide their activity, exfiltrate personal and corporate data, and encrypt files on disk—essentially achieving complete compromise of the target systems.

The Free Solution That Isn’t

Given macOS’s vulnerability to targeted attacks, third-party anti-malware becomes essential. But not all solutions deliver what they promise.

We tested two popular Mac anti-malware products, Intego Mac Internet Security (paid) and TotalAV Antivirus Free. The contrast was dramatic.

Intego detected most threats upon arrival and neutralised the remainder during execution. It prevented us from gaining meaningful control of any target system, achieving a 98% protection rating.

TotalAV’s free version, however, performed no better than macOS alone. It failed to prevent a single attack across all 11 scenarios, earning the same -125% protection rating as the unprotected operating system.

One particularly troubling aspect we found, was that TotalAV’s marketing clearly states that the free product includes “Real-Time Antivirus” protection. The website emphasises, “TotalAV Antivirus is a free to use Antivirus packed with all the essential features to keep you safe.”

Yet in our testing, TotalAV Free only detected threats when we ran manual scans, after attacks concluded. By that point, attackers had already achieved remote access, escalated privileges, stolen data, and covered their tracks. Detection after compromise offers little value.

This suggests strongly that real-time protection is not actually enabled in the free version, despite marketing claims to the contrary.

What Organisations Should Do

The results of our Advanced Security macOS Home Anti-Malware test make several points clear:

  1. Don’t rely on macOS built-in security alone for protection against targeted attacks. While Apple’s defences may catch some commodity malware, they proved ineffective against the types of targeted campaigns that threaten enterprises.
  2. Verify real-time protection is actually enabled in any anti-malware solution deployed. Marketing claims and actual functionality don’t always align, particularly in free versions of commercial products.
  3. Invest in tested, proven solutions for Mac endpoint security. The price difference between free and paid solutions is negligible compared to the cost of a successful compromise.
  4. Rely on reviews that test against realistic attack scenarios. Simple malware detection tests don’t reveal whether products can stop multi-stage targeted attacks that use living-off-the-land techniques and legitimate system tools.
  5. Apply the same level of security controls to Mac devices as Windows endpoints. The smaller market share doesn’t translate to lower risk. In fact, the high-value nature of Mac users may make them more at-risk targets.

Ensure All Endpoints are Protected

The myth that Macs are inherently secure has created a dangerous blind spot in enterprise security. As attackers increasingly focus on high-value targets in the executive suite, organisations need to reassess their Mac security posture.

This doesn’t mean abandoning Mac. But it does mean treating Mac endpoints with the same security discipline applied to other systems, such as requiring proven protection, verifying it works as claimed, and maintaining appropriate controls regardless of user seniority.

Don’t assume built-in protection and free tools are sufficient, or you risk leaving your most sensitive data in the hands of your most vulnerable devices.

For complete details on our testing methodology and results, download the full Security Evaluation Test Report for macOS Home Anti-Malware.

All posts

6 Things You Didn’t Know About SE Labs

You might be surprised by what we test, how and for whom. 

SE Labs Infographic depicting types of cyber security testing.

SE Labs supports a diverse client base, including security vendors and large enterprises, with independent testing services. While some results are public, most engagements remain confidential due to their strategic nature. 

1. Core Areas of Expertise 

Our testing spans a broad section of the cyber security technology stack, with established methodologies in: 

  • Endpoint security 
  • Network security appliances (e.g. firewalls) 
  • Cloud-based security services (e.g. email) 
  • Incident response integrations (e.g. XDR) 

We continuously refine our processes to address evolving threats and technologies. 

2. Validation for Investment and Stakeholder Confidence 

Start-ups seeking investment benefit from independent validation of their security technologies. SE Labs supports both vendors and investors by evaluating security efficacy under realistic conditions. Our infrastructure, comprising physical and cloud-based environments, enables deployments that mirror operational use. 

3. Product Comparison Testing for Enterprises 

Enterprises often require third-party testing to inform procurement decisions. SE Labs facilitates structured product comparison testing under real-world conditions. Our flexible lab infrastructure replicates operational environments, reducing the need for custom internal testbeds and minimizing disruption to business activities. 

4. Product Development Support 

Many vendors engage SE Labs during the product development lifecycle. Our facilities and experts simulate attacker and defender scenarios, assisting in the refinement of detection and response capabilities. These tests may support internal R&D, incident response training or readiness for third-party evaluations like MITRE Engenuity. 

5. Industry-Leading Test Logging 

SE Labs provides comprehensive reporting, including: 

  • Full threat artifacts 
  • Terminal recordings of attacker command inputs 
  • Detailed logs for each test case 

Clients benefit from continuous, actionable feedback, often updated daily, with data volumes reaching gigabytes per scenario. 

“When you ask for the sample your product missed, expect more than a file hash value or a PE file!” – Nikki Albesa, Test Lead for Endpoint Security. 

6. Emerging and Custom Testing Services 

We actively pursue the development of new testing areas, including: 

  • macOS threats and APT simulations 
  • Internet of Things (IoT) device security 
  • DNS filtering technologies 

For organisations with novel technologies, SE Labs offers bespoke test design and execution. 

A Trusted Authority in Cyber Security Testing 

SE Labs delivers rigorous, independent cyber security testing, supporting product validation, investment decisions, and technology comparisons. With detailed reporting, flexible infrastructure and expertise in emerging threats, we provide trusted insights for vendors and enterprises alike. Engage with us to ensure your solutions perform under real-world conditions. 

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us