News
NCSC Assured Red Teaming Scheme Opens in November 2026
Three things from UK regulators this week, and none of them is a patch you have to install tonight. One changes how you should buy a red team exercise, one changes the name on the letter if you ever report a breach, and one is a clear description of a social engineering playbook that works just as well against a finance team as against a journalist.
The NCSC is launching an assured red teaming scheme in November
On 17 September the National Cyber Security Centre published new guidance, Adversary simulation: what you need to know, alongside the first documents for its Cyber Adversary Simulation (CyAS) scheme. Adversary simulation is what most of the market calls red teaming: a provider behaves like a real attacker and tests whether you can prevent, detect and respond, rather than listing every vulnerability the way a penetration test does.
The practical news is the timing. The NCSC says CyAS formally launches in November 2026, and from then buyers will be able to pick from providers assured against its standard. The scheme standard and working practices document are already public, so you can hold a supplier to them now. The NCSC admits the scheme is a “minimum viable product” and will change as it learns from early engagements.
The guidance is also honest about who this is for. It says adversary simulation suits organisations that already review their risks, have established defences and run robust monitoring and detection. A typical engagement takes 8 to 12 weeks, and a full spectrum one, which starts from outside your network, can run to around 16 weeks. The alternative is “assumed breach”, which starts from a foothold inside and tests how far an attacker could spread.
For most small and medium businesses the honest reading is that a red team is not the next purchase. A scoped penetration test and a proper cyber security risk assessment come first, and our penetration test cost calculator gives a realistic budget. If you are big enough to need a red team, wait for the assured list or check a quote against the published standard. The NCSC’s announcement is on its blog.
The ICO becomes the Information Commission on 30 September
The government has confirmed that the Information Commissioner’s Office will become the Information Commission on 30 September 2026. The ICO announced it on 15 September and updated the notice on 17 September to say it will keep the ICO name.
The change comes from the Data (Use and Access) Act 2025. It changes how the regulator is governed, moving it to an Information Commission Board, and the seven non-executive members announced in July take up their roles on the same date. The ICO says its regulatory functions and responsibilities are unchanged.
For a business, very little moves. The 72-hour deadline to report a qualifying personal data breach still applies, fines still follow the UK GDPR, and complaints still go to the same regulator. What will change is the wording on letters, notices and guidance, so do not be surprised if a reply after 30 September comes from “the Information Commission”. If you have a breach response plan or data protection policy that names “the Information Commissioner’s Office”, update it at the next review rather than rushing. Our pages on who enforces GDPR in the UK and UK GDPR and the Data Protection Act 2018 cover what the regulator can actually do. The ICO’s notice is here.
UK and allies expose CHOSEN BRICK, Iranian spyware spread through WhatsApp and Telegram
On 15 September the NCSC, the FBI and the Dutch intelligence service AIVD published a joint advisory on CHOSEN BRICK, spyware Iranian state actors have used against dissidents, activists and journalists, including people in the UK. It can collect contacts, emails and social media messages, capture the screen and access the microphone. It only targets Windows and survives a reboot.
The reason it belongs on a business security page is the method. According to the NCSC, the attackers impersonate contacts on messaging apps such as WhatsApp and Telegram, build rapport over time, and tailor the lure to the target, even using fake MRI test results. Only then do they get the victim to download the malware.
That is the same pattern behind most business email compromise and social engineering losses: a message from someone who seems familiar, patience, then a single request. Your staff are unlikely to be targeted by Iran, but they are very likely to receive a friendly message on a personal messaging app followed by a file or a link. Two checks are worth making. First, does your training cover messaging apps as well as email? Our explainer on phishing attacks covers the variants. Second, does your cyber policy’s social engineering cover respond when the first contact happened on a staff member’s own phone? Read the wording. The NCSC’s announcement is here.