Service

Technical cyber drills

Hands-on exercises where your defenders face a realistic attack on an isolated range: measured, repeatable and away from production.

A cyber drill tests what a tabletop cannot: whether your tools see the attack, whether your analysts read the signal correctly, and whether containment and recovery work at the speed you assumed. Your team defends a replica environment while a red team runs a scripted, threat-informed intrusion, and a white cell controls pace and safety.

The range is isolated by design, with no route to the internet or to your production systems, so techniques can be run for real without risk to the business. Every action is timestamped, which turns the debrief into evidence instead of impressions.

Who it is for

Teams that detect, decide and recover

Best run once roles and playbooks exist, so the drill tests them instead of inventing them. A tabletop first is a common path.

  • SOC and detection engineeringDo your detections fire, and does the analyst on shift know what to do with them?
  • CSIRT and incident respondersTriage, scoping, containment and evidence handling under time pressure.
  • IT operations and platform teamsIsolation, rebuild and restore, and the handover between security and operations.
  • Management observersSeeing how long the real decisions take, with the facts on a timeline.

Formats

Scenario types

Scenarios are mapped to MITRE ATT&CK techniques so results can be compared between exercises.

  • Detection and response drillBlue team against an emulated adversary following an agreed attack path.
  • Purple teamRed and blue work in the open, technique by technique, to tune detections together.
  • Ransomware readinessFrom initial access to encryption attempt: can you stop it, and can you restore?
  • Playbook validationRun your own incident playbooks against live events and see where they break.

How an engagement runs

From objectives to measured results

The range, the attack path and the scoring are agreed with you before anyone logs in.

  1. 01

    Scope

    Objectives, teams, tooling and the parts of your environment the range must mirror.

  2. 02

    Rules of engagement

    Permitted techniques, safety stops, data handling, who may call a halt.

  3. 03

    Build and rehearse

    Range prepared, attack path scripted, dry run by the red and white cells.

  4. 04

    Run

    Live exercise with a control cell, timestamped actions and observers.

  5. 05

    After-action report

    Timeline of attacker and defender actions, detection coverage, findings and a prioritised plan.

Deliverables

Evidence for every action

Measured, repeatable results you can compare with the next exercise.

  • Exercise plan and rules of engagementscope, safety stops, roles
  • Attack path and ATT&CK mappingwhich techniques ran and when
  • Detection and response timelinewhat was seen, when, by whom
  • After-action reportfindings and evidence
  • Improvement planprioritised fixes with owners
  • Executive summarya short readout for leadership

What we need from you

  • A named exercise lead and a technical point of contact
  • Participant list and the tools they use day to day
  • Network and system information so the range can reflect the relevant parts of your environment
  • Agreement on rules of engagement, including who can stop the exercise

Next step

Scope your cyber drill

Tell us what you want to test and who should take part. We reply with a proposed format and next steps.

Get in touch