All posts

Inside the PIVOT Pilot: Measuring Real-World Cyber Security Protection

As the pilot phase of PIVOT™, our new ground-breaking detection and protection cyber security test, draws to a close, it’s a good moment to explain some of the techniques and the methodology behind the test.

PIVOT isn’t a collection of isolated checks or simulated exercises. Even in pilot form, it was run as a complete test, using real-world attack techniques to answer a single, fundamental question: can a product detect and stop modern cyber attacks across the full attack lifecycle?

The pilot differed from the forthcoming inaugural PIVOT test in one key respect only: participating vendors took part on the understanding that results would not be made public. In every other way, the pilot was executed as the real thing.

Testing Full Attack Chains, Not Individual Threats

PIVOT is designed to emulate complete attack chains rather than individual threats in isolation. During the pilot, products were subjected to realistic attack scenarios that reflected how modern attackers operate in live environments.

This meant evaluating whether products could do more than simply detect malware. We assessed their ability to:

  • Identify suspicious activity early
  • Detect and disrupt reconnaissance
  • Prevent privilege escalation
  • Block lateral movement
  • Stop data theft and system compromise

Real attackers don’t move in straight lines, and neither do our tests. Each scenario was designed to expose how well products perform as attacks evolve and adapt.

Reconnaissance: Mapping Systems Like an Attacker

Reconnaissance is a fundamental stage of almost every cyber attack. During the pilot, we carried out discovery activities to map systems, users, and access opportunities across the test environment.

Although we built the network ourselves, we deliberately followed attacker workflows. This allowed products to demonstrate whether they could detect suspicious discovery behaviour, flag anomalous activity, or block attackers before an intrusion fully developed.

This approach is central to our Test Like Hackers™ philosophy and provides critical insight into a product’s real-world defensive capability.

Privilege Escalation and Lateral Movement

Successful attacks rarely end with initial access. Attackers aim to escalate privileges, expand control, and move laterally through a network.

During the pilot, we executed realistic escalation and lateral movement attacks based on current criminal techniques. These attacks tested whether products could stop an intrusion from progressing from a single foothold into a full environment compromise.

This stage is not just where security failures can become truly damaging; it’s also where effective products can still prevent a breach from escalating.

Living-Off-the-Land Techniques

Modern attackers increasingly avoid obvious malware in favour of legitimate system tools already present in the environment.

Throughout the pilot, we identified which native utilities could be abused, reviewed recent attacker behaviour from SE Labs’ threat intelligence, and incorporated living-off-the-land techniques directly into our attack scenarios.

This ensured PIVOT measured a product’s ability to detect malicious behaviour, not just known malicious files—an essential distinction in modern cyber security defence.

Email as a Realistic Entry Point

Email remains one of the most common initial access vectors, particularly for Business Email Compromise (BEC) attacks that often contain no malware at all.

Rather than relying on simplistic test cases, the pilot included email-based attacks that reflect how modern attackers actually operate today. These scenarios were informed by SE Labs’ threat intelligence to ensure realism and relevance.

Accuracy Without Sacrificing Protection

False-positive testing plays an important supporting role in PIVOT. A product that blocks legitimate business activity can be almost as disruptive as one that misses real threats.

During the pilot, we verified that detection engines were appropriately balanced—capable of identifying attacks without resorting to overly aggressive blocking. Vendors were not permitted to re-tune their systems during testing beyond standard updates released to all customers, ensuring results reflected real-world deployment rather than test optimisation.

False positives matter, but only insofar as they ensure strong protection doesn’t come at the expense of usability.

From Pilot to the Inaugural PIVOT Test

With the pilot nearing completion, we are analysing not only the results of our tests, but also how clearly and effectively attacks are presented to end users through a product’s reporting and dashboard capabilities.

The inaugural PIVOT test, launching later this year, will follow the same rigorous methodology—with one critical difference: results will be made public, even if they are uncomfortable for individual vendors.

From reconnaissance and initial access through to privilege escalation, lateral movement, and data exfiltration, PIVOT is designed to test security products as attackers encounter them in the real world, and not as laboratory exercises.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us