Best Adversary Simulation Providers

Adversary simulation is a higher-tier, threat-led form of offensive security testing. Engagements are longer than typical red teams, usually 4 to 12 weeks of active testing, and built around assumed-breach scenarios, custom tooling, and the goal of mimicking a specific real-world threat actor mapped to MITRE ATT&CK. Financial regulators are the primary source of demand: TIBER-EU under DORA in the EU, CBEST under the Bank of England, and parallel national frameworks like TIBER-DE and TIBER-NL drive most of the spend at this tier. The engagement model differs from a generalist red team in that it is goal-oriented, slow-paced by design, and informed throughout by bespoke threat intelligence.

About this list

When choosing an adversary simulation provider, look for CBEST or TIBER-EU eligibility (these schemes pre-vet a small number of providers), evidence of custom offensive tool development, demonstrated EDR-evasion experience, attribution restraint and clean operational tradecraft, and a methodology rigorous enough to satisfy a regulator's threat-led test plan. The shortlist below filters the directory down to providers with documented experience in this category.

Related: Threat-led penetration testing (TLPT) · DORA TIBER-EU testing · STAR methodology providers

Featured partnerFeatured
SECFORCE logo

SECFORCE

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

CRESTCBESTSTARISO 27001ISO 9001
  • Holds CREST, CBEST, STAR, ISO 27001, ISO 9001, and Cyber Essentials accreditations.
  • In business since 2008 (Companies House 06488355); CREST-accredited for penetration testing since 2011.
  • CBEST-accredited since 2015; first TIBER engagement in 2018.
  • CREST accreditations: penetration testing, vulnerability assessment and threat-led penetration testing (formerly STAR).
View SECFORCE
35 providers
Oxford, United Kingdom · Checked Sept 2026

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Accreditations: CREST, CHECK, STAR, ISO 27001, PCI QSA +1
Services: Web Application, Network, Red Teaming, Purple Teaming +7
London, United Kingdom · Checked Sept 2026

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +1
Services: Web Application, Network, IoT, Cloud +9
Southam, United Kingdom · Checked Sept 2026

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +2
Services: Web Application, Network, Cloud, Red Teaming +6
London, United Kingdom · Checked Sept 2026

Full-service London-based cybersecurity consultancy with CREST, CHECK, and NCSC accreditations delivering offensive testing, managed detection, and strategic advisory services.

Accreditations: CREST, CREST AI Penetration Testing, CHECK, ISO 27001, Cyber Essentials +2
Services: Web Application, Network, Cloud, API +5
Atlanta, Georgia, United States · Checked Sept 2026

US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.

Accreditations: OSCP Employer
Services: Web Application, Network, Mobile App, Cloud +12
Worcester, United Kingdom · Checked Apr 2026

CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +3
Services: Web Application, Network, Mobile App, Cloud +4
Birmingham, United Kingdom · Checked Sept 2026

CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Mobile App, Cloud +7
Reston, Virginia, United States · Checked Apr 2026

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Accreditations: SOC 2, ISO 27001, FedRAMP 3PAO
Services: Red Teaming, Purple Teaming, Network, Web Application +5
Cheltenham, United Kingdom · Checked Sept 2026

Award-winning Cheltenham-based cybersecurity consultancy with NCSC CHECK Green Light status and CREST approval, specialising in defence, government, and critical national infrastructure security.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Cloud, API +5
Fairlawn, Ohio, United States · Checked Sept 2026

Offensive security firm founded by former NSA operator David Kennedy, delivering CREST-accredited penetration testing, red teaming, and adversary simulation to Fortune 500 and government clients.

Accreditations: CREST, PCI QSA
Services: Web Application, Network, Cloud, API +7
Paris, France · Checked Sept 2026

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Accreditations: CREST, FedRAMP 3PAO, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, IoT +9
Helsinki, Finland · Checked Sept 2026

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

Accreditations: CREST, ISO 27001
Services: Web Application, Network, Cloud, API +6

Best Adversary Simulation Providers, FAQs

What is adversary simulation?+

Adversary simulation is a threat-led form of offensive security testing in which a tester emulates the tools, techniques, and procedures (TTPs) of a specific real-world threat actor to test an organisation's detection and response capabilities end-to-end. Engagements are goal-oriented (e.g. reach a defined crown-jewel asset), use assumed-breach scenarios, and are mapped to frameworks like MITRE ATT&CK.

How is adversary simulation different from red teaming?+

Red teaming is the broader category, any objective-driven, end-to-end attack simulation. Adversary simulation is a more specific tier within it: longer engagements, driven by bespoke threat intelligence about a named actor, deliberately slow-paced to test detection over time, and usually required by financial regulators rather than chosen voluntarily. A typical commercial red team is faster and less prescriptive about which actor is being emulated.

What is TIBER-EU?+

TIBER-EU (Threat Intelligence-Based Ethical Red Teaming for the European Union) is the European Central Bank's framework for intelligence-led red teaming of significant financial entities. National variants, TIBER-DE in Germany, TIBER-NL in the Netherlands, and others, implement the same model. Under DORA, threat-led penetration testing aligned to TIBER-EU is mandatory for many large financial institutions across the EU.

How long does an adversary simulation engagement last?+

Adversary simulation engagements typically run 4 to 12 weeks of active testing, with an additional 2 to 4 weeks of threat intelligence and scoping work upfront and 2 to 4 weeks of reporting and purple-team replay afterwards. The full programme, including regulator engagement under TIBER-EU or CBEST, often spans 6 to 9 months end-to-end.