Security
You cannot practice on somebody else's network
A range full of well-built generic scenarios teaches tool proficiency, which is real and which transfers. The decisions that go wrong during an actual incident are specific to one estate, and those are the ones a generic environment cannot rehearse.
In short
- Skills transfer between environments and decisions do not. Reading a packet capture is the same skill anywhere; knowing who can authorize disconnecting a production segment at 2am is a fact about one organization.
- Most exercises test the responder when the gap is in the instrumentation. If the replica carries your logging exactly as configured rather than as documented, the exercise finds the blind spot rather than blaming the analyst for not seeing through it.
- A replica is worth building for one segment and not for an estate. Scope it to where an incident would be decided, accept that it decays, and plan to rebuild it rather than to maintain it.
- A generic range is the correct purchase for foundational skills, onboarding and hiring assessment, where the whole point is that the environment is not yours and the candidate cannot have memorized it.
- An exercise output that is a score has measured the wrong thing. The output that justifies the cost is a named gap with an owner and a date, which is a finding rather than a grade.
A cyber range is usually bought the way training content is bought. There is a catalog of scenarios, a set of vulnerable machines, a scoreboard, and a cohort of people who work through it and come out measurably better at things they were worse at before. That improvement is real, it is worth paying for, and it is not the thing most organizations believe they are buying.
The belief is that the exercise is rehearsal for an incident. It is rehearsal for the parts of an incident that are the same everywhere, which is a smaller and more specific claim. Separating the two is what decides whether a range is a training budget line or a control that changes an outcome.
What transfers between environments, and what does not?¶
Skills transfer and decisions do not. Reading a packet capture, pivoting through a host, recognizing what a scheduled task is doing, reversing a loader, querying a log platform: these are the same operations against any estate. Practicing them on somebody else's network makes a person better at them on yours. That is the honest case for a generic range and it is a strong one.
What does not transfer is every fact that is a property of one organization. Who can authorize pulling a production segment off the network at two in the morning, and who can be reached to do it. Whether the finance system's authentication depends on the directory you are about to disable. Which of the four backup mechanisms actually covers the file server, as opposed to the one the runbook names. Whether the OT network's historian will resynchronize after a broker restart or whether somebody has to drive to a plant.
Those questions consume the first six hours of a real incident, and none of them has a generic answer. An exercise that never asks them has tested the half of the problem that was already the strongest.
Why do exercises blame the responder for an instrumentation gap?¶
Exercises blame the responder because the responder is the only participant in the room, and the instrumentation is represented by whatever the scenario author decided to provide. In a purpose-built scenario the evidence needed to solve it is present by construction. A scenario where the evidence is missing is one nobody can finish, and that reads as a broken exercise rather than as a finding.
Real estates are not built that way. The logs that would show lateral movement are frequently not collected, or are collected at a verbosity that omits the field that mattered, or are retained for thirty days when the dwell time was ninety. A replica that carries your logging pipeline as it is actually configured, rather than as the architecture diagram describes it, turns that from an assumption into a result. The exercise ends with a sentence naming a source that was not collected, which is worth more than any score a scoreboard produces.
This is the single strongest argument for building against your own estate, and it is worth putting to whoever controls the budget in exactly these terms: the exercise is not primarily testing the people. It is testing whether the evidence a competent person would need is going to be there.
How much of an estate is worth replicating?¶
One segment, chosen because that is where an incident would be decided, and not the estate. A full replica is a second infrastructure with a second set of costs, and it begins decaying the day it is finished, because the real estate keeps changing and the copy does not. Organizations that attempt the complete version generally build it once, use it twice, and discover in year two that it no longer resembles anything.
Scope it by asking where a decision would be expensive and reversible only with difficulty. For a manufacturer that is usually the boundary between the business network and the plant, because the decision to isolate is the one that stops production. For a professional services firm it is the identity platform, because that is the blast radius of one compromised account. For a public agency it is frequently the single line-of-business application that the public interacts with.
Then treat the replica as perishable. Build it from the same automation that builds the real thing where that exists, rebuild it before each exercise rather than maintaining it continuously, and write down the date it was last accurate. A replica with a stated staleness is a usable instrument. A replica everyone assumes is current is a source of confident wrong answers.
When is a generic range the right purchase?¶
A generic range is the right purchase whenever the point is the person rather than the estate, and there are three cases where that holds. Foundational skill building, where a new analyst needs volume and variety and would learn less from one familiar network. Onboarding, where the objective is competence with tooling before anybody is trusted with production. And hiring assessment, where an environment the candidate cannot have seen before is the entire methodology.
There is a fourth case worth naming because it is the one people are shy about: sometimes the requirement is a certificate, an insurer's checkbox or a contract clause, and a catalog range satisfies it at the lowest cost. That is a legitimate purchase and it should be described as what it is, internally, so that nobody later mistakes the certificate for evidence that the organization can respond to an incident.
It is also worth keeping the exercise pointed at the right outcome. NIST's incident response guidance (opens in a new tab) frames the work as helping organizations "prepare for incident responses, reduce the number and impact of incidents that occur, and improve the efficiency and effectiveness of their incident detection, response, and recovery activities". It sets that inside the risk management activities of the Cybersecurity Framework rather than treating response as a self-contained drill. An exercise that produces no change to detection or recovery has not done the thing the guidance is describing.
What a good exercise leaves behind¶
A good exercise leaves findings with owners and dates, in the same form any other engineering defect would be recorded. Not a percentage, not a pass, and not a report whose recommendations are written at a level of generality nobody can act on.
- A named evidence source that was not collected, not retained long enough, or missing the field the investigation needed, with a ticket to change it.
- A named decision that nobody in the room had the authority to make, and the name of the person who does, added to the callout list.
- A dependency discovered during the exercise that no diagram recorded, which is usually the most valuable single output and almost never the one anybody expected.
- The elapsed time from first indication to first containing action, recorded so that the next exercise has something to compare against.
Sources
Next step
Send us your last exercise report.
The after-action report from your most recent exercise, redacted as you like. We will tell you which of its findings are about people, which are about instrumentation, and which could only have been found in an environment shaped like your own estate rather than a generic one.
- Phone
- (214) 723-2510
- Reply
- A person replies, not a sequence: within one business day, from someone who would be on the engagement.
Related reading
- Security4 min read
Most tabletop exercises are designed not to find anything
An exercise everyone passes has told you nothing you did not already believe. The scenarios are free and published; what makes an exercise worth the room is the two decisions nobody wants to make in it.
- Security6 min read
Your plant network is flat, and the drawing says otherwise
Every site we have assessed had a network diagram showing a segmented plant. On most of them the segmentation was a VLAN with a permissive rule, a vendor laptop, or a spreadsheet nobody had opened in three years.
- Engineering5 min read
Whether you can investigate a breach was decided months ago
The questions asked after an incident are answerable only if somebody made specific, unglamorous logging decisions long before it happened. Almost nobody does.
- Security5 min read
You do not have four thousand critical vulnerabilities
A scanner sorted by severity produces a backlog nobody can work and everybody feels bad about. The federal government stopped prioritizing that way in June 2026, and the reasoning behind the change is worth borrowing whoever you are.