Back to News

New funded red team exercises to help councils strengthen cyber resilience

We’re inviting English councils to express their interest to take part in a red team exercise.

Delivered through MHCLG’s Cyber Incident Response (CIR) contract, the exercise is part of our work to strengthen cyber resilience across the local government sector. Participation is fully funded for selected councils.

What a red team exercise is

A red team exercise is a realistic cyber security assessment. It simulates the techniques and behaviours threat actors use to:

  • compromise systems
  • access information
  • disrupt services

Conducted in a safe and controlled environment, the exercise helps you:

  • understand your council’s exposure to cyber risk
  • assess how effectively your existing security controls can detect, prevent and respond to malicious activity

This work started as a pilot with several councils in 2026. The red team exercises identified:

  • previously unknown vulnerabilities
  • security weaknesses
  • opportunities to improve cyber resilience

They also gave councils valuable insight into their ability to detect and respond to attacker activity throughout the cyber attack lifecycle. The findings provided evidence to support internal business cases and recommendations for reducing risk.

Building on the success of the pilot, we’re expanding the programme to help more councils:

  • understand their current risk exposure
  • strengthen their cyber maturity
  • identify practical opportunities to improve their cyber resilience

The insights from participating councils will help us build a better understanding of cyber resilience across the sector and identify areas where additional support may be needed.

What the exercise involves

The exercise is delivered in four stages.

1. Scoping and preparation

We’ll agree the scope of the exercise, define the assessment objectives, and collect the information needed to support delivery.

2. External attack surface and configuration review

We’ll review your internet-facing systems and services to identify:

  • vulnerabilities
  • misconfigurations
  • potential attack paths that could be exploited by an external attacker

3. Internal and post-compromise assessment

We’ll carry out a controlled simulation of attacker activity following an assumed compromise. This helps assess:

  • opportunities for privilege escalation
  • lateral movement risks
  • cloud security controls
  • monitoring capabilities
  • access to sensitive information

4. Reporting and debrief

Participating councils will receive:

  • a technical report
  • an executive summary

This will outline:

  • the assessment approach
  • key findings
  • identified risks
  • recommended actions to reduce risk and improve cyber resilience

How taking part can improve your council’s cyber resilience

If your council takes part, you’ll have the opportunity to:

  • identify vulnerabilities before they are exploited by threat actors
  • assess the effectiveness of your existing security controls
  • understand how an attacker could move through your environment following a compromise
  • test your ability to detect and respond to malicious activity
  • receive practical recommendations to strengthen cyber resilience
  • gain evidence to support cyber risk management and investment decisions
  • help identify cross-sector trends that can inform support for the wider local government sector

How much time you should expect to commit

The red team exercise is designed to have a low operational impact on participating councils.

Your council will need to nominate a primary point of contact, such as a cyber, technology or digital lead, to support planning and act as the main contact throughout the exercise.

During the scoping phase, you’ll work with our provider to agree an assumed breach scenario and suitable access arrangements. Depending on the agreed approach, this may include:

  • a physical laptop
  • a remote access account
  • another agreed method that provides the starting point for the exercise

During testing, our provider will work largely independently and provide regular updates to your nominated contact. No action is normally required unless an immediate risk to council systems is identified.

How to apply and delivery timeline

We will deliver the programme between November 2026 and April 2027.

Each exercise will take approximately three to four weeks and includes:

  • up to two weeks of testing activity
  • one to two weeks for analysis and reporting

You should allow a minimum of three to four weeks before testing begins to complete scoping and approvals.

Register your interest

Complete the expression of interest form to register your interest.

We plan to deliver approximately 15 exercises between November 2026 and April 2027.

We will assess all expressions of interests against agreed criteria to ensure the exercises are delivered where they can provide the greatest value, while helping us build a representative understanding of cyber resilience across local government.

We expect to begin selecting and contacting councils from late October 2026. While there is no deadline to register your interest, we encourage early responses to improve your chances of being selected.

Councils that are not selected will be considered for future opportunities.

Subject to funding, capacity and demand, we may expand this offer to additional councils.

Stay in touch

Categories: Blog posts

Tags: