UK NCSC: Don’t Assume Your Cyber Defenses Work. Test Them.

September 18, 2026

The U.K. National Cyber Security Centre (UK NCSC) has released new guidance on cyber adversary simulation, along with the first documents supporting its forthcoming Cyber Adversary Simulation assurance scheme.

The message is straightforward and important: having cyber defenses is not the same as knowing they work.

NCSC describes cyber adversary simulation as a structured way for organizations with mature cybersecurity programs to safely test their ability to prevent, detect, and respond to realistic attacks. Effective engagements should determine whether defenders can identify malicious activity early, triage it appropriately, escalate when necessary, and respond effectively under realistic conditions.

Just as importantly, NCSC cautions against turning adversary simulation into another compliance exercise. The objective is not simply to pass or fail. It is to generate meaningful evidence about where defenses work, where they break down, and what needs to improveCyber Adversary Simulation (CyAS): scheme documents now available.

NCSC’s forthcoming CyAS scheme will take a capability-led approach. Rather than simply replaying a fixed script of known attacker behaviors, assured providers will be expected to think and operate adversarially, conduct continuous and tailored reconnaissance, and develop approaches around objectives agreed with the organization being tested.

That distinction matters.

A vulnerability assessment can identify weaknesses. A penetration test can demonstrate whether specific weaknesses are exploitable. But a well-designed adversary simulation can help answer a broader operational question: Can our people, processes, and technology actually detect and respond to a capable adversary trying to achieve an objective in our environment?

That is directly aligned with two of Gate 15’s 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals:

  • Test — Validate that systems, controls, procedures, and capabilities actually work.
  • Exercise — Put the team on the field and practice before game day.

Testing tells you whether individual capabilities perform as expected. Exercising brings those capabilities together under pressure. Adversary simulation can help organizations do both while producing evidence that can inform remediation, planning, training, investment, and future exercises.

Gate 15’s complete 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals white paper expands on these and thirteen other fundamentals, with practical recommendations, government guidance, real-world examples, and lessons for improving organizational cybersecurity and resilience. 15 from 15: Blocking and Tackling Cybersecurity & Resilience — including access to the white paper.

Ask your security team: When was the last time we tested our defenses against someone actively trying to defeat them—and did we test only the technology, or did we also test whether our people could detect, triage, escalate, communicate, and respond?

If the answer is unclear, that may be the next resilience gap worth addressing.


Cyber and all-hazards risk and resilience. At Gate 15 we apply a threat-informed & risk-based approach to analysis, resilience, & operations, helping to secure America’s People, Places, Data, & Dollars. Learn more at www.gate15.global. Join Gate 15’s Resilience and Intelligence Portal (GRIP) and connect to our homeland security community. Join the GRIP!

Additional Info





Previous Podcasts