The MITRE ATT&CK Enterprise Round 7 (ER7) evaluations, published in December 2025, represent the most challenging test in the program's history, incorporating cloud adversary emulation, identity-centric attacks, and cross-environment lateral movement for the first time. The results are stark: the maximum block rate achieved by any participating vendor was 31%, with CrowdStrike and Cybereason tying for the highest protection score. Critically, all nine vendors scored 0% in blocking identity attacks, which are the core techniques used by Scattered Spider, the criminal group behind the MGM Resorts and Caesars Entertainment breaches that caused hundreds of millions in losses. Additionally, cloud attack blocking rates ranged from 0% to 7.7% across the cohort, with five vendors blocking nothing.
Three of the largest cybersecurity vendors—Microsoft, SentinelOne, and Palo Alto Networks—withdrew from ER7 before the evaluation began, citing reasons such as internal innovation focus or describing the evaluations as "PR-driven." This marks a 63% decline in participation from the peak of 30 vendors in 2022. VectorCertain LLC, a relatively small player, took the opposite approach. Using MITRE's published ER7 adversary emulations as a baseline, VectorCertain ran its SecureAgent platform through a rigorous self-evaluation spanning Sprints 30–34, completed in February–March 2026. The company extended the evaluation beyond ER7's scope by adding Volt Typhoon, a third adversary targeting U.S. critical infrastructure, and testing behavioral governance and memory governance dimensions. VectorCertain reports that SecureAgent blocked 100% of 14,208 tests across 38 techniques and three adversary scenarios, with a false positive rate of 0% and governance decision latency under 100 milliseconds.
VectorCertain attributes its results to a fundamentally different architecture. SecureAgent is an AI safety and governance platform that uses a four-gate governance pipeline to evaluate every proposed AI agent action before execution. This contrasts with traditional detect-and-respond systems that rely on endpoint telemetry. The reason all nine ER7 vendors scored 0% on identity protection, according to VectorCertain, is that identity abuse does not generate endpoint telemetry—Scattered Spider manipulates identity systems through authentication flows that appear legitimate. SecureAgent governs actions at the point of intent, using policy rather than signatures. The company has formally enrolled in MITRE's Enterprise Round 8 (ER8) evaluation, which will introduce a standardized composite scoring framework.
The ER7 results have broader economic implications. Global fraud and cybersecurity losses totaled $485.6 billion in 2023, and AI-specific cyberattacks cost an estimated $15 billion in 2024. TransUnion's H2 2025 Top Fraud Trends Report found that companies lose an average of 7.7% of annual revenue to fraud, which VectorCertain terms a "7% Global AI and Cybersecurity Tax." IBM's 2025 Cost of a Data Breach Report shows that organizations deploying AI in prevention workflows saved an average of $2.22 million per breach. VectorCertain's Joseph P. Conroy, founder and CEO, has a 25-year history of building AI systems for critical applications, including the ENVAIR2000 and ENVAIR4000 platforms used for industrial gas detection and predictive diagnostics. SecureAgent represents the latest iteration of this lineage, now applied to AI governance. The company's full test methodology and reproducibility protocols are available for independent review. For more information, visit vectorcertain.com. ER7 industry data is published at evals.mitre.org.


