From reactive to resilient: How SOC Maturity and Attack Simulation Assessments transform cyber defence

Published
2026-09-30T10:50:34.237+02:00 30 September 2026
Business Digital Intelligence
Location United Kingdom
In today’s increasingly volatile geopolitical climate, particularly with escalating global tensions such as ongoing conflicts in the Middle East, cyber warfare has evolved into a critical extension of traditional warfare.
Image of a city skyline - Malaysia

Nation-state actors, hacktivists and organised cybercrime groups are actively targeting Critical National Information Infrastructure (CNII) sectors worldwide, including telecommunications, energy, finance, healthcare and government systems.

Malaysia is not insulated from this threat. During heightened geopolitical tensions in October 2023, the National Cyber Coordination and Command Centre (NC4) observed malicious cyber activity, particularly malware and DDoS activity, surge to approximately 40 million events, while identifying threat actors with a history of targeting Malaysian CNII sectors1. More recently, threat telemetry recorded over 106,000 DDoS attacks against Malaysia's wireless telecommunications sector in the first half of 2025 alone2.

The question is therefore no longer simply whether organisations are secure, but how rapidly and effectively they can detect, respond to and recover from a real cyber-attack. Against this backdrop, the combined implementation of Security Operations Centre Maturity Assessment (SOCMA) and Attack Simulation Assessment (ASA) together becomes not just relevant, but a key method of assessing the effectiveness of your SOC and how to improve. 

1National Cyber Security Agency (NACSA), Heightened Alert for Cyber Activities on Domains and Infrastructures in Malaysia, National Security Council, Prime Minister's Department, 27 October 2023.
2NETSCOUT Systems, Inc., DDoS Threat Intelligence Report – Malaysia, Issue 15: January 2025 to June 2025, 2025.

Assessing defence posture

The BAE Systems SOCMA framework is a measurable model that assesses organisational capability across 17 domains spanning SOC, management, infrastructure and ICT functions. Each capability is evaluated across multiple dimensions such as organisational structure, processes, technology, policies and third-party dependencies. The outcome is a clear understanding of the current state, supported by a case for improvement where needed, to drive changes that support a more effective and resilient Security Operations capability. 

While SOCMA is used to collaboratively identify and define the target state for a mature security operations environment, ASA tests and simulates what works under real-world conditions. ASA is an objective-based adversarial exercise designed to emulate advanced threat actors operating within a compromised environment. 

Unlike traditional penetration testing, which focuses primarily on identifying vulnerabilities, ASA adopts a purple teaming approach that integrates both offensive and defensive perspectives. Red teams simulate attacker behaviours using real-world tactics, techniques, and procedures, while blue teams – representing the SOC – respond in real time, creating a collaborative environment focused on improving detection and response capabilities. An ASA exercise is underpinned by cybersecurity SMEs who deliver and operationalise these exercises with proven, real-world experience.

Building resilience

The true value of these assessments lies in their integration. ASA provides the ground truth by exposing real operational weaknesses, while SOCMA contextualises these findings within a structured maturity framework and enables root causes to be identified. For instance, if ASA reveals poor detection capabilities, SOCMA can attribute this to deficiencies in monitoring tools, lack of skilled personnel, or immature processes. Often technical deficiencies and vulnerabilities are symptoms of deeper underlying root causes.

We have extensive experience of putting this integrated approach into practice, having supported multiple organisations in Asia following attacks by advanced threat actors. Along with incident response support, we have delivered SOCMA and ASA in combination to identify weaknesses within organisations’ security operations capability and validate their ability to detect and respond to realistic adversary activity. The resulting findings provided the organisations with a structured basis for prioritising improvements and strengthening their overall cyber defence maturity. 

Ultimately, SOCMA and ASA equip organisations across the public and private sectors to simulate real world, nation state level threats, align with recognised frameworks, and build end to end resilience across detection, response and recovery. Just as importantly, their quantitative results provide a clear direction to help turn cyber security investment into measurable business outcomes.

In today’s landscape where threat actors are becoming increasingly sophisticated, this could be the difference between falling victim to an attack or building a posture of proactive cyber resilience. 

We provide security consultation services across the globe, bringing together proven best practices, expertise and insights from diverse markets to help organisations strengthen their cybersecurity posture and maintain the integrity of their digital environments. We incorporate regional perspectives, emerging threat intelligence, regulatory considerations, and industry best practices to help organisations identify risks, strengthen resilience and implement security strategies that are both internationally informed and locally relevant.


Contact our experts 

Abstract image of a woman with information security warnings

Threat Intelligence Insights

Understanding the evolving threat landscape is a key part of maintaining robust defences. BAE Systems' Threat Intelligence team generate original insights through research and collaboration with customers and partners.

Subscribe now 

Get in touch
Dr. Vicknesh Gunasingam