
Lab
The proof behind our advice.
We benchmark security tools against the same tests, so the stack we recommend is matched to evidence, not sales decks.
Get startedSee our assessmentsWhat we've tested.
Assessment
Browser Security
How the leading browser security tools handle shadow AI, credential theft, and the risks that reach your people through the browser.
Read the assessmentAssessment
Email Security
Where the main email security platforms catch phishing and business email compromise, and where the gaps sit.
Read the assessmentAssessment
Security Awareness Training
How the leading human-risk platforms compare on changing behaviour, not just recording completion, and which genuinely calibrate to the user.
Read the assessment
The depth behind our rankings.
After years of vendor analysis into key domains, we are making the benchmark data public. We shortlist the market and benchmark on capability.
54
vendors assessed head-to-head
3
product categories benchmarked since 2025
114
capabilities benchmarked in total
0
vendors who paid for their place
100% vendor-independent benchmarks, surfacing the most comprehensive platforms.
Assessments are weighted against ASD threat data and the compliance frameworks you answer to. Full methodology and sources are published with every ranking.
Advice you can check.
We test security tools so our recommendations stand on evidence, not vendor claims. The Lab is where that work happens, and it is the reason we can tell you what actually fits your business rather than what sells.
The research feeds the advice, not the other way around. Everything we publish here is the same benchmarking we lean on when we build a stack for a client.
How we testHow we test.
Every product faces the same benchmarks.
- 01
Same tests, every tool
We run each product through an identical set of tests, so the results compare like for like.
- 02
Scored on outcomes
We measure what a tool prevents, catches, or eases, not the length of its feature list.
- 03
Published in full
We publish what we find, including where a tool falls short, so you can see the reasoning.
Shorter reads from the Lab.
Quick insights between the full assessments.
Four of the eight, from one stack
Most businesses buy a separate tool for each Essential Eight control. A consolidated endpoint stack can carry up to four of them, which is usually cheaper and easier to run.
You bought the EDR. Who's watching it at 2am?
An endpoint tool nobody is watching at 2am is a cost with no outcome. The EDR decision is really about who operates it, and how fast they contain.
Most security waits for software to prove it's bad
Traditional endpoint security lets anything run unless it recognises it as a threat. Application control inverts that assumption and closes the window attackers now live in.
Your team completed the training. Did their behaviour change?
Completion proves attendance, not competence. Most awareness programs measure the wrong thing, and the number that matters is whether people behave differently under pressure.
The email gaps Microsoft and Google leave open
Microsoft and Google catch the bulk of it. Two kinds of email are shaped to get past them, and one of them does not arrive from outside at all.
See every AI prompt your staff send
Your staff paste the business's most sensitive data into AI tools every day, and most companies cannot see a single prompt. Browser security is where leadership finally can.
Get the research first.
Subscribe to the Lab for our assessments and shorter insights as we publish them. No noise, just the work.
Turn the research into your stack.
Tell us what you need to protect.
We'll match you to the tools that fit.
No fit, no obligation.