Cyber Incident Exercising

Information for Cyber Incident Exercising service providers
On this page
About the Scheme
The CIE Scheme assures Service Providers which deliver controlled, scenario-based, tailored exercises which simulate cyber incidents, allowing organisations to practise, evaluate and improve their cyber incident response plans.
These services are typically delivered to a wide range of UK businesses, charities, public sector, and government organisations to rehearse, evaluate, and improve their cyber incident response plans.
The scheme’s remit covers organisationally significant incidents that have the potential for significant operational, financial, or regulatory impacts on the victim. The scheme covers Category 3, 4 and 5 incidents on the UK’s Cyber Attack categorisation system.
All CIE Assured Service Providers are assessed by NCSC’s scheme Delivery Partners before being assured as meeting the NCSC technical standard for CIE. The NCSC expects its CIE Assured Service Providers to be able to offer:
- Table-top exercises – discussion-based sessions where representatives from relevant teams meet to discuss their roles and responsibilities, expected activities and key decision points (in accordance with an incident response plan), facilitated by the CIE Assured Service Provider and driven by a cyber incident scenario.
- Live-play exercises – where team members execute their roles and responsibilities from their normal work environment, in response to controlled injects which represent a given cyber incident scenario. Different participants typically receive different sets of injects. Activities and decisions happen in close to real-time although the incident pace and timeline is managed by an exercise control function.
As part of their Scheme membership, Assured Service Providers will be required to share with the NCSC limited, non-attributable information about the exercise being conducted. We will use this information for trend analysis purposes, to inform future advice and guidance to the UK and to help improve our products and services.
How to join the Scheme
If your company would like to apply to become an NCSC Assured Service Provider of CIE services, please contact our Delivery Partners CREST or IASME directly.
You will need to submit information to demonstrate your organisation’s compliance with the NCSC’s CIE technical standard.
Crown Commercial Services Procurement Agreement
The central dedicated procurement route for government and wider public sector buyers to obtain cyber security services is the Crown Commercial Service (CCS) Procurement Agreement for Cyber Security Services. As a CIE Assured Service Provider, you can apply to be registered as an NCSC Assured supplier for the service(s) you offer under the scheme.
At the NCSC, we are taking action to remove artificial barriers to entry to all our Schemes. So, if you spot something which you think unfairly prevents you from applying, please let us know.