GDS signs £500k deal for ‘live cyberattack simulation’


Digital unit signs a specialist deal lasting two years and covering the provision of services to test digital defences with attacks aimed at ‘identifying and exploiting a variety of vulnerabilities’

The Government Digital Service has signed a potential £500,000-plus deal for a specialist supplier to simulate sophisticated cyberattacks aimed at “identifying and exploiting a variety of vulnerabilities”.

Earlier this month, the digital unit entered into an initial two-year contract with security consultancy Cyberis.

According to details contained in a newly published commercial notice, the supplier has been retained “to provide threat-led, live cyberattack simulation… based on current threat intelligence”. Such exercises are intended to help identify potential vulnerabilities in digital systems and services and are often referred to as ‘red teaming’.

In service description documents, Cyberis – which last year won a major deal to support the cross-department work of the Cabinet Office’s Government Security Red Team (GSRT) – claims that its red team service “is guided by relevant threat intelligence and aims to emulate a real-world attack using the same tactics, techniques and procedures as your adversaries, [and] each simulated targeted attack is tailored to the threat profile of your business, and the risks that you face specifically”.


Related content


The text of the contract between the firm and GDS indicates that the government tech team required the services to be accredited under the STAR – Simulated Target Attack and Response – framework developed by cyber industry accreditation body Crest.

The commercial document reveals that red-team exercises will be delivered in phases that will be aligned with guidelines for penetration testing set out by the National Cyber Security Centre.

The supplier will be expected to “possess and be proficient in using a range of advanced penetration testing tools and software, to perform thorough assessments of systems and networks,” according to the contract.

“The team should have deep technical skills in identifying and exploiting a variety of vulnerabilities, and must be adept at simulating realistic attack scenarios,” it adds. “The supplier must have the skills and tools necessary to perform in-depth network and systems analysis, including packet analysis, traffic inspection, and endpoint security evaluations, to identify potential entry points and weaknesses… [and] should be capable of creating and executing comprehensive simulations, including coordinated attack scenarios and post-exploitation techniques, to test the effectiveness of the organisation’s detection and response mechanisms.”

The deal will be worth £150,000, plus VAT, to Cyberis. The agreement can be extended for a further 12 months beyond its initial two-year term, which would take its end date to 7 August 2027, while total spending would reach £540,000.

The contract won by the Gloucestershire-based company with the GSRT – a unit also known as OPEN WATER – covered the provision of support for government’s own cyberattack simulation services: GBEST and GCASE.

Sam Trendall

Learn More →

Leave a Reply

Your email address will not be published. Required fields are marked *