Decoding the world of cybersecurity

English councils offered funded red team testing

English councils are being invited into a funded red team programme designed to test how their systems withstand realistic attacker behaviour.

English councils offered funded red team testing
Summary
  • The government plans around 15 funded red team exercises between November 2026 and April 2027.
  • Testing will examine internet-facing systems and what an attacker could do after gaining an agreed foothold.
  • A 2026 pilot identified previously unknown vulnerabilities and weaknesses in participating councils.

English councils are being offered funded red team exercises designed to test how their security controls respond to realistic attacker behaviour rather than examining individual safeguards in isolation.

Local Digital plans to deliver around 15 exercises between November 2026 and April 2027 through the Ministry of Housing, Communities and Local Government’s Cyber Incident Response contract.

Participation will be funded for councils selected for the programme. The initiative follows a pilot conducted during 2026 that Local Digital says identified previously unknown vulnerabilities and other weaknesses in participating authorities.

A red team assessment attempts to reproduce realistic attacker behaviour under controlled conditions. Instead of asking whether one security control works in isolation, the exercise examines whether several weaknesses can be combined into a route through the organisation.

Each engagement is expected to take around three to four weeks, including active testing followed by analysis and reporting. Councils will agree the scope, objectives and access arrangements before the exercise begins.

Testing continues after an assumed breach

The programme includes examination of internet-facing systems and services. Testers will look for vulnerabilities, weak configuration and other routes that could provide an initial foothold.

Exercises can then move into an agreed post-compromise scenario in which access is assumed to have been achieved. That allows the assessment to examine what happens inside the environment rather than spending the entire engagement trying to reproduce the first compromise.

Internal testing can include attempts to increase privileges, move between systems, assess cloud controls and determine whether monitoring detects suspicious activity. The purpose is to establish whether one point of access can be contained or developed into a wider compromise.

The approach reflects the limits of relying solely on prevention. Organisations can reduce the likelihood of an initial breach without assuming that every barrier will work in every case. Internal access controls, monitoring and containment determine how much damage can follow when prevention fails.

Councils will receive findings after the exercise that can be used to understand weaknesses and plan remediation. Local Digital also intends to use combined findings from the programme to improve its view of cybersecurity across English local government.

Selection will therefore consider both the value of an exercise to the individual council and whether the participating authorities provide a useful spread of organisations for the wider programme.

Local authorities operate a complicated mix of public services, information and technology. A council can depend on cloud platforms, older infrastructure, externally hosted applications and specialist suppliers while running services ranging from social care and housing to revenues and planning.

No individual red team exercise can cover that entire estate. Its findings depend on the agreed scope and the systems that can safely be tested, but a controlled attack can reveal combinations of weaknesses that may not be visible when products and controls are assessed separately.

Local Digital expects selection to begin in late October, with the first exercises starting in November and the programme continuing through April 2027.

×