Service
Technical cyber drills
Hands-on exercises where your defenders face a realistic attack on an isolated range: measured, repeatable and away from production.
A cyber drill tests what a tabletop cannot: whether your tools see the attack, whether your analysts read the signal correctly, and whether containment and recovery work at the speed you assumed. Your team defends a replica environment while a red team runs a scripted, threat-informed intrusion, and a white cell controls pace and safety.
The range is isolated by design, with no route to the internet or to your production systems, so techniques can be run for real without risk to the business. Every action is timestamped, which turns the debrief into evidence instead of impressions.
Who it is for
Teams that detect, decide and recover
Best run once roles and playbooks exist, so the drill tests them instead of inventing them. A tabletop first is a common path.
- SOC and detection engineeringDo your detections fire, and does the analyst on shift know what to do with them?
- CSIRT and incident respondersTriage, scoping, containment and evidence handling under time pressure.
- IT operations and platform teamsIsolation, rebuild and restore, and the handover between security and operations.
- Management observersSeeing how long the real decisions take, with the facts on a timeline.
Formats
Scenario types
Scenarios are mapped to MITRE ATT&CK techniques so results can be compared between exercises.
- Detection and response drillBlue team against an emulated adversary following an agreed attack path.
- Purple teamRed and blue work in the open, technique by technique, to tune detections together.
- Ransomware readinessFrom initial access to encryption attempt: can you stop it, and can you restore?
- Playbook validationRun your own incident playbooks against live events and see where they break.
How an engagement runs
From objectives to measured results
The range, the attack path and the scoring are agreed with you before anyone logs in.
- 01
Scope
Objectives, teams, tooling and the parts of your environment the range must mirror.
- 02
Rules of engagement
Permitted techniques, safety stops, data handling, who may call a halt.
- 03
Build and rehearse
Range prepared, attack path scripted, dry run by the red and white cells.
- 04
Run
Live exercise with a control cell, timestamped actions and observers.
- 05
After-action report
Timeline of attacker and defender actions, detection coverage, findings and a prioritised plan.
Deliverables
Evidence for every action
Measured, repeatable results you can compare with the next exercise.
- Exercise plan and rules of engagementscope, safety stops, roles
- Attack path and ATT&CK mappingwhich techniques ran and when
- Detection and response timelinewhat was seen, when, by whom
- After-action reportfindings and evidence
- Improvement planprioritised fixes with owners
- Executive summarya short readout for leadership
What we need from you
- A named exercise lead and a technical point of contact
- Participant list and the tools they use day to day
- Network and system information so the range can reflect the relevant parts of your environment
- Agreement on rules of engagement, including who can stop the exercise
Next step
Scope your cyber drill
Tell us what you want to test and who should take part. We reply with a proposed format and next steps.
Also