Skip to content

Cyber Ranges & Security Training

Nobody learned to respond to an incident from a slide deck.

Annual awareness training is a compliance artifact, and everyone involved knows it. If you want an engineer who can actually triage an alert, a developer who can actually spot the injection, or a plant team that can actually execute the safe-state procedure, they have to do it, under time pressure, and be allowed to get it wrong somewhere it does not cost anything. Building that environment is a real engineering problem: provisioning, isolation, scoring, reset, and content that is hard in the ways the job is hard.

To reset an environment, not days
MinutesTo reset an environment, not days
Capability before and after, per cohort
MeasuredCapability before and after, per cohort
Platform and content you run without us
YoursPlatform and content you run without us

Sounds like

You might recognise one of these.

  • Our security training is a video everyone clicks through in eleven minutes.

  • We hire junior analysts and it takes nine months before they are useful.

  • We have a range nobody uses because standing up a scenario takes two days.

  • We want a hiring pipeline out of the local university and do not know how to build one.

  • Our tabletop exercise was a conversation. Nothing was actually tested.

What this includes

The work, specifically.

Not every engagement needs all of it. This is the range we cover and what each part is actually for.

  • Range platform engineering

    Automated provisioning of isolated multi-machine environments: templated topologies, per-team network segmentation, snapshot and reset in minutes rather than days, and enough capacity planning that a hundred concurrent machines is a scheduled event rather than an incident. Built on virtualization you already own where possible.

  • Scenario and exercise design

    Scenarios modelled on your estate and your threat profile, with injects, a scoring model and a defined learning objective per exercise. Ransomware in the ERP, credential theft through a supplier portal, unauthorized logic change on a controller, whichever version of the bad day is actually yours.

  • Competition and CTF platforms

    Challenge infrastructure, per-team instancing, dynamic scoring, anti-cheat and the operational tooling to run an event without the organizers spending the day firefighting. We have built and run competitions across forensics, reverse engineering and cryptography, from beginner events through multi-university ones.

  • Curriculum and instruction

    Labs, exercises and assessment written by people who do the work, delivered to cohorts that have included several hundred students. Content is versioned and maintained like software, because a lab that no longer works is worse than no lab.

  • Cohort and program operations

    The unglamorous system underneath a training program: enrolment, cohort tracking, progress, completion evidence and reporting to whoever funds it. Programs die from administrative overhead more often than from bad content.

  • Developer and OT-specific tracks

    Secure coding taught against your own codebase rather than a generic vulnerable app, and operational-technology exercises built around your controller families so the plant team practises on something recognisable.

What you get

Deliverables, not documents.

  • Provisioned range platform with infrastructure as code and reset automation
  • Scenario library with stated learning objectives and a scoring model
  • Instructor and facilitator guides, so you can run it without us
  • Participant progress and completion reporting
  • Competition or exercise event, run end to end, if you want one
  • Measured before-and-after capability assessment per cohort

Shapes

How this usually runs.

  1. Exercise design & delivery

    3–6 weeks

    One realistic scenario, built and facilitated for your team, with a written debrief that names the gaps found. A good way to test whether this is worth more investment.

  2. Range build

    8–16 weeks

    The platform, the automation, the first scenario set and enablement for the people who will run it after we leave.

  3. Program operation

    Ongoing

    Content maintenance, new scenarios, event delivery and cohort reporting on a recurring cadence.

Tooling

What we build it with.

No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.

Virtualization
  • Proxmox
  • VMware
  • KVM
  • Docker
  • Terraform
Network
  • Palo Alto
  • pfSense
  • VLAN isolation
  • VPN access
Platform
  • CTFd-class scoring
  • Per-team instancing
  • Ansible
  • Kubernetes
Content
  • Forensics
  • Reverse engineering
  • Cryptography
  • OT scenarios
  • Secure coding

Questions

Ranges & training, honestly.

  • Often yes, and for general upskilling that is usually the right answer. Building is worth it when the training has to reflect your specific estate, when you are running events for outside participants, or when you need the environment for validation rather than education. We will ask which of those you are in before quoting anything.

  • A tabletop tests whether people know what they would say. A range tests whether the tooling, the access and the procedure actually work under time pressure. Both are useful, and the tabletop is far cheaper, so run that first. The reason to build a range is that tabletops consistently fail to surface the practical failures: the runbook that references a decommissioned system, the responder who does not have the permission the plan assumes.

  • We can, and for the first cycle we usually should. The goal is to hand it over: instructor guides, a maintained scenario library and enough automation that running one is a scheduling decision rather than a project.

  • It is one of the better reasons to do it. Competitions and university partnerships put you in front of people whose ability you have watched directly, which is a considerably better signal than an interview. We have built these programs on the university side and know what makes an industry partner worth engaging with rather than tolerated.

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.