NCSC issues advice on cyber adversary simulation
The guidance for potential suppliers comes as the cyber authority prepares to launch a formal scheme
The National Cyber Security Centre (NCSC) has released guidance on cyber adversary simulation, in the run-up to its launch of a new assured Cyber Adversary Simulation (CyAS) scheme.
Also known as red teaming, cyber adversary simulation involves testing an organization's defenses by mimicking the actions an adversary is likely to use in a real attack. This can be carried out by either internal or external teams.
It's not quite the same as penetration testing, as it focuses on the effectiveness of an organization's technical controls and detection, rather than identifying technical vulnerabilities.
The NCSC CyAS scheme will see a number of commercial organizations approved to offer their services, but is still in its early stages, with plans to refine the scheme in light of feedback from partners, buyers and providers.
When it formally launches in November, there should be a range of approved providers – currently, the NCSC said, the quality of services available across the market can vary significantly.
These first documents include the Scheme Standard and the Working Practices Document, detailing what potential providers need to do. They cover everything from how services should be set up and managed to security, ethics and technical competence.
"These documents give an early and transparent view of the standard we will use to assess applicants, including expectations on companies, key role holders, technical delivery and reporting," the NCSC said.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"As a result, buyers will have a transparent and consistent benchmark for assessing providers, helping them make more informed procurement decisions and giving them greater confidence in the quality of NCSC-assured services."
The scheme supports two different approaches to evaluating an organization's ability to detect and respond to a cyber attack, depending upon the attacker's starting location.
A full-spectrum approach starts from outside the network, and evaluates an organization during an end-to-end attack that attempts to breach the perimeter.
Alternatively, an assumed breach approach starts from a point within the customer network and simulates a threat once an attacker has managed to gain an initial foothold.
"For organizations with a mature security posture, assumed breach can provide greater value by bypassing the initial access phase and concentrating on the consequences of a successful compromise, specifically whether an attacker can expand their access beyond the initial point of entry and reach high-value targets," the NCSC advised.
The CyAS scheme is best suited to organizations with a mature understanding of the cyber risks they face – larger firms, or those operating within critical national infrastructure or the UK government.
To make the most of the services on offer, they should have already identified and assessed their risks, and have well-established mitigations and defences and robust network monitoring and detection systems in place.
"A carefully scoped adversary simulation engagement will help organizations understand where their defences are working, where they are not, and what needs to improve," the NCSC said.
"It will also evaluate whether an organization can identify threats early, triage them quickly and appropriately, and escalate where necessary."
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AINews Organizations are urged to identify shadow AI use and tighten up security procedures
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
NCSC issues warning over Russian intelligence-backed threat groupNews The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations”
-
UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilitiesNews The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks
-
Hostile states behind three-quarters of UK critical infrastructure attacksNews NCSC CEO warns that with the rise of AI, the danger is only set to get worse
-
NCSC urges organizations to shore up supply chain security practicesNews With attackers increasingly compromising open source packages to spread malware, organizations need to be on their guard
-
A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’News NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
-
The NCSC says it’s time to switch to passkeysNews UK security organization calls for companies to step up and offer more secure ways to login

