Adversary simulation: what you need to know
UK NCSC publishes guidance on adversary simulation, comparing full spectrum and assumed breach approaches across prerequisites, testing, and reporting phases.
NCSC guidance describes two adversary simulation approaches: full spectrum, starting outside the network with an end-to-end attack, and assumed breach, starting from an internal foothold. The preferred methodology spans three phases - prerequisites (scoping, passive reconnaissance, preparation), testing (active reconnaissance, initial access, internal phase, cleanup), and reporting. The document distinguishes adversary simulation from penetration testing and stresses customer-defined objectives and minimal information sharing.