Skip to main content

The Identity at the Core

The Definitive Chronicle of Identity & Access Management

NCSC publishes Cyber Adversary Simulation (CyAS) scheme documents

NCSC has released the scheme documents for Cyber Adversary Simulation, setting out its view of good practice and how assured providers should deliver it.

By Paulo Barrilli
3 min read3 views0 comments

The UK's National Cyber Security Centre (NCSC) has published the scheme documents for Cyber Adversary Simulation (CyAS). In the blog post announcing the release, the NCSC describes the material as its view of what good cyber adversary simulation looks like, and how assured providers can deliver it. The announcement is on the NCSC website: Cyber Adversary Simulation (CyAS): scheme documents now available.

The documents are addressed first to providers. Firms that are assured under the scheme, or that want to be, now have the NCSC's written expectation of how this kind of engagement should be scoped, run and reported. Organizations that commission adversary simulation are the second audience, even if the documents aren't written for them. If a supplier is going to be measured against a published standard, the buyer benefits from knowing what that standard says.

It's worth being clear about what the announcement does and doesn't tell us. The blog text sets out the purpose of the documents and who they're for. It doesn't, in the summary available at the time of writing, spell out dates, transition arrangements, costs, or how CyAS sits alongside other NCSC assured services. Anyone who needs those details should go to the scheme documents themselves rather than rely on a second-hand write-up, including this one.

Some background for readers who haven't sat through one of these engagements. Adversary simulation, as a general practice, is a test in which a provider behaves like a real attacker against a live organization. The provider pursues agreed objectives, such as reaching a specific system or dataset, rather than working through a list of vulnerabilities. The point is to test detection and response as much as prevention: not just whether a door is locked, but whether anyone notices when it's opened.

That is why identity teams should care about a scheme document nominally aimed at red teamers. In practice, these engagements run through identity more often than not. Phished credentials, password spraying against an exposed login page, token theft from a compromised endpoint, a forgotten service account with a static secret, a help desk that resets MFA on a friendly phone call, and privilege escalation through a group nobody has reviewed since the last reorg. None of those techniques are specific to CyAS. They are simply the routes attackers actually take, and a well-run simulation tends to find them.

A published standard for how providers do this work has a knock-on effect for the people being tested. It gives an identity or security team a reference point for asking whether an engagement was thorough. It also makes it harder for a report to declare victory after a single phishing test while the identity provider, the PAM tool and the sign-in logs went untouched.

So, what should an identity or security team do this week? Read the NCSC documents in full and note what they expect of a provider before the next engagement is scoped, then ask your current red team supplier whether they are assured under CyAS or intend to be, and treat a vague answer as an answer. Pull your last adversary simulation report and check whether it actually tested identity: MFA coverage including legacy authentication paths, conditional access gaps, service account inventory and secret rotation, help desk reset procedures, and whether the SOC saw the relevant sign-in and audit log events at the time. A red team that never went near your identity provider either found something far worse or wasn't looking very hard, and neither is comforting. The encouraging part is that the standard is now written down and free to read, so the checklist for your next engagement more or less writes itself.

#uk#policy#pam#mfa#ncsc#red-teaming
Share:XLinkedInFacebook

Be the first to comment

Members only: sign up if you have something worth saying.

Want to weigh in? Sign in or create a free account.

No comments yet.