Skip to main content

Cyber Adversary Simulation (CyAS)

Companies assured under the Cyber Adversary Simulation scheme deliver services to test an organisation’s cyber resilience, including their ability to prevent, detect and respond to simulated cyber attacks.

Cyber Adversary Simulation (CyAS) Scheme Standard

version 1.1, September 2026







Examples of scoping goals and objectives

Example goal 1: An actor attempts to deploy ransomware across a network

Example objectives 1:

  • Gain initial access to the network.
  • Reach a position with the relevant access where ransomware could be deployed across a significant amount of the network.

Example goal 2: A hostile threat actor attempts to access operational technology (OT)

Example objectives 2:

  • Gain initial access to the enterprise network and identify how to connect to the OT network.
  • Prove access/connectivity to the OT network and proceed no further.

Go back to paragraph 32