MITRE's Enterprise Round 7 (ER7) evaluation, published in December 2025, has exposed significant protection gaps across the cybersecurity industry. The evaluation, which emulated real-world adversaries Scattered Spider and Mustang Panda, found that the best-performing vendor blocked only 31% of attacks, with all nine participating vendors scoring 0% on identity-based attacks and near-zero on cloud attack scenarios. The results underscore a systemic failure in protecting against modern identity-centric and cloud-based threats.
Three major vendors—Microsoft, SentinelOne, and Palo Alto Networks—withdrew from ER7, citing internal initiatives or criticism of the evaluation's methodology. Their absence from the evaluation, described as the "Olympics of cybersecurity," raises questions about transparency and the effectiveness of widely deployed security platforms. The participation trend has declined sharply, from 30 vendors in 2022 to just 11 in 2025.
In contrast, VectorCertain LLC, a lesser-known AI safety and governance firm, conducted its own internal evaluation using the same ER7 adversary emulations and reported that its SecureAgent platform blocked 100% of attacks across 14,208 tests. The company extended the evaluation to include a third adversary, Volt Typhoon, and introduced governance tests not covered by MITRE. VectorCertain has formally enrolled in MITRE's Enterprise Round 8 (ER8), which will provide independent verification of its claims.
The architectural difference, according to VectorCertain, lies in SecureAgent's four-gate governance pipeline, which evaluates AI agent actions before execution, rather than relying on post-execution detection. This approach, the company argues, addresses the identity attack gap because identity abuse does not generate endpoint telemetry that EDR systems rely on. The company publishes full methodology and results for independent review.
The broader economic implications are significant. Global fraud and cybersecurity losses reached $485.6 billion in 2023, with AI-specific cyberattacks costing an estimated $15 billion in 2024. IBM's 2025 Cost of a Data Breach Report shows the average breach cost is $4.44 million, with over $4 million spent on detection and recovery after the attacker is inside. VectorCertain frames this as a "7% Global AI and Cybersecurity Tax" on the world's economies.
As the industry grapples with these findings, MITRE's upcoming ER8 evaluation will introduce a standardized composite scoring framework. VectorCertain's participation positions it as a potential disruptor, but independent verification will be critical to validate its claims. The full data from ER7 is available at evals.mitre.org, and VectorCertain's methodology can be found at vectorcertain.com.


