The MITRE ATT&CK Enterprise Evaluations, often called the Olympics of cybersecurity, released results for Enterprise Round 7 (ER7) in December 2025. The evaluation was the most demanding in the program’s history, incorporating cloud adversary emulation, identity-centric attacks, and cross-environment lateral movement for the first time simultaneously. Nine vendors submitted their platforms for protection testing, with three of the largest—Microsoft, SentinelOne, and Palo Alto Networks—withdrawing before the evaluation began.
The results were stark. The maximum block rate achieved by any ER7 vendor was 31%, with CrowdStrike and Cybereason tying for the highest protection score. The remaining 69% of adversarial actions executed without being stopped. Identity attack blocking rate across all nine vendors was 0%. Test 2 targeted identity providers using Scattered Spider’s core techniques—the exact playbook used against MGM and Caesars Entertainment, which resulted in hundreds of millions in losses. Every vendor, across every substep, scored zero. The cloud attack blocking rate ranged from 0 to 7.7% across the entire cohort, with five of nine vendors blocking nothing.
VectorCertain LLC responded by doing the opposite of the industry giants. Using MITRE’s published ER7 adversary emulations—Scattered Spider and Mustang Panda—as its baseline, VectorCertain ran its SecureAgent platform through a rigorous self-evaluation spanning Sprints 30–34, completed February–March 2026. VectorCertain extended the evaluation beyond ER7’s scope by adding Volt Typhoon, a third adversary targeting U.S. critical infrastructure, and testing behavioral governance via the H-Neuron Overcompliance Test Suite and memory governance via the Adaptive Memory Relevance Scoring framework.
The results: 38 techniques evaluated across three full adversary scenarios, 14,208 total tests executed across all tracks, zero failures—every adversarial technique blocked across every sprint. SecureAgent achieved a 100% protection rate against all three adversaries, with governance decision latency under 100 milliseconds on every test, result determinism reproduced identically across three consecutive independent runs, and a false positive rate of 0%. VectorCertain’s internal evaluation results are not MITRE-published results; the company has formally enrolled in MITRE’s Enterprise Round 8 (ER8) for independent third-party verification.
VectorCertain attributes its success to SecureAgent’s four-gate governance pipeline, which evaluates every proposed AI agent action before it reaches the environment. The pipeline includes HES1-SG for ensemble consensus, HCF2-SG for hierarchical cascading governance, TEQ-SG for execution-layer behavior analysis, and MRM-CFS-SG for incident consolidation. This architecture structurally prevents identity abuse and cloud attacks that generate no endpoint telemetry, addressing the fundamental flaw in detection-based systems.
The ER7 results highlight a global economic problem. Global fraud and cybersecurity losses totaled $485.6 billion in 2023, with AI-specific cyberattacks costing an estimated $15 billion in 2024. IBM’s 2025 Cost of a Data Breach Report puts the global average breach cost at $4.44 million, with organizations deploying AI in prevention workflows saving an average of $2.22 million per breach. VectorCertain calls this a 7% global AI and cybersecurity tax on the world’s economies.
VectorCertain has formally enrolled in MITRE’s ATT&CK Evaluations Enterprise 2026 (ER8), positioning SecureAgent as the first AI Safety and Governance platform in the program’s history. ER8 will introduce a standardized composite scoring framework, moving beyond binary detection flags toward holistic measurement of platform effectiveness. For more information, visit vectorcertain.com. ER7 industry data is available at evals.mitre.org.


