← Back to news
NCSC (UK)19 Sept 2026 · 2 min read

NCSC outlines when adversary simulation can strengthen cyber defences

The UK National Cyber Security Centre (NCSC) has published guidance on adversary simulation, often called red teaming, describing how organisations can use the exercise to assess their ability to with...

The UK National Cyber Security Centre (NCSC) has published guidance on adversary simulation, often called red teaming, describing how organisations can use the exercise to assess their ability to withstand realistic cyber attacks.

Adversary simulation involves authorised teams attempting to achieve agreed objectives that, if reached by a real attacker, could disrupt important business functions. The work is intended to test whether security controls can prevent, identify and contain malicious activity, rather than simply catalogue technical weaknesses.

The NCSC distinguishes the approach from conventional penetration testing. While a penetration test generally seeks to identify vulnerabilities across systems, adversary simulation examines the effectiveness of defensive controls, monitoring, incident triage and escalation under attack-like conditions.

Suitable organisations

The guidance says the method is most valuable for medium and large organisations with a mature understanding of their cyber risk. Candidates should already have established safeguards, regularly reviewed risk assessments, and effective logging, monitoring and detection capabilities.

It may be particularly relevant to operators of critical national infrastructure and government bodies. Organisations with smaller or less complex environments, or those still building foundational security practices, may gain more from other assessment services first.

How engagements work

A typical engagement takes around eight to 12 weeks, according to the NCSC, while a broad full-spectrum assessment may run for roughly 16 weeks. Scope and duration should reflect the organisation’s size, complexity and the objectives agreed for the exercise.

The NCSC advocates a capability-led model rather than one limited to imitating a named threat group or a fixed list of attack scenarios. Assessment teams conduct reconnaissance to understand the target’s technology estate, external exposure and likely threats, then develop attack plans tailored to those findings.

  • Preparation: Define objectives, authorisation, rules of engagement and safety measures.
  • Testing: Use controlled adversarial techniques to evaluate prevention, detection and response capabilities.
  • Reporting: Document findings, defensive gaps and remediation priorities for stakeholders.

The agency also stressed that responsible providers should use safeguards in their tools and processes to reduce the chance of harm to customer environments or other users. External providers can seek assurance through the NCSC’s Cyber Adversary Simulation scheme, which assesses suppliers against the agency’s technical standards.

Share this article:TwitterLinkedIn