Summary
Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks. This guidance is for organisations wanting to understand if adversary simulation (sometimes known as ‘red teaming’) is right for them. It is designed for system owners and security professionals within medium to large-sized organisations. Providers of adversary simulation services may also find this guidance useful, especially those considering joining the NCSC’s assured Cyber Adversary Simulation (CyAS) Scheme, as the methodology within the scheme aligns to this guidance. The scheme assures commercial organisations providing adversary simulation services which meet the NCSC’s What organisations benefit from adversary simulation? Adversary simulation best practice 'Full spectrum' vs 'assumed breach' approaches Alternative NCSC assurance schemes and resources Adversary simulation is designed to test an organisation’s defences against a realistic cyber attack by systematically testing an organisation's ability to prevent, detect and respond to a range of cyber attack scenarios.