Cyber Range capabilities and methodology

What VulnTrek Cyber Range does today, how the scenarios are built, how scoring works, and what it deliberately does not do — written for reviewers, buyers and exercise leads.

Scenarios grounded in real incidents

All 14 scenario packs are tied to publicly documented incidents with links to CISA, NIST or Wikipedia sources. Scenario characters and institutions are fictional; five packs are labelled composites rather than single incidents, and any loss figures are illustrative.

Governed access

Cyber Range runs on your VulnTrek sign-in. Access is granted per organisation (standalone or add-on) and per person (exercise lead, participant, observer), and every server action re-checks the role in the database.

Live team exercises

Exercise leads open rooms with a join code and move the room round by round. Participants record one decision per round; observers can watch but not vote. Once recorded, a vote cannot be changed.

Team and cohort invites

Leads paste an email list, name the group and pick a role. People already in your organisation get access immediately; others get it automatically when they accept your organisation invitation.

Training evidence

Round debriefs and live-room votes are written into your organisation's append-only evidence record and export for auditors with the matching evidence hashes. Training evidence is not proof of compliance.

Corrective actions that close properly

Every weakness surfaced in a debrief can be opened as an action with a named owner and a deadline. An action closes only when a follow-up exercise is recorded as passed — a deadline alone never closes it — and the closure is written to the evidence record.

Organisation isolation

Rooms, votes, debriefs, corrective actions and exports are scoped to your organisation in the database itself, not merely hidden in the interface.

Scoring model

Each round produces a composite score from 0 to 100 built from nine decision axes: outcome, process, behavioural, speed, governance, disclosure, containment, communications and cohesion. Debriefs report the composite with the axis breakdown, and the Return on Mitigation view shows a modelled euro value of avoided loss versus a no-decisive-action baseline, always with an explicit uncertainty range.

Methodology: 1. Scenario design

Each scenario pack starts from a publicly documented incident or, for composites, a documented pattern. The sequence of injects follows the incident's public timeline, while the organisation, people and figures in the story are fictional. Pick a documented incident and record its public sources in the scenario register. Turn the timeline into rounds, each ending in one executive decision. Replace real names with fictional ones; an automated check fails the release if a watched victim name appears in scenario text. Mark loss figures as illustrative and label composite packs as composites. Based on: NIST SP 800-84, Guide to Test, Training, and Exercise Programs; CISA Tabletop Exercise Packages.

Methodology: 2. Running the exercise

Exercises are discussion-based tabletop rounds. An exercise lead opens a live room, shares the join code and moves the room round by round; nothing touches production systems. The lead chooses a scenario that a platform admin has made available to the organisation. Participants record one decision per round; observers watch without voting. Once recorded, a vote cannot be changed, so the record reflects what the team decided at the time. Based on: NIST SP 800-84, Guide to Test, Training, and Exercise Programs; CISA Tabletop Exercise Packages.

Methodology: 3. Evaluation and scoring

Each completed round is scored on nine decision axes and combined into a 0–100 composite. The scoring is a training aid that makes trade-offs visible, not an assessment of the organisation's real security. Score the round on outcome, process, behaviour, speed, governance, disclosure, containment, communications and cohesion. Show the composite with its axis breakdown in the debrief. Show modelled avoided loss only with an explicit uncertainty range and labelled assumptions. Based on: NIST SP 800-84, Guide to Test, Training, and Exercise Programs.

Methodology: 4. After-action and improvement

Debriefs and votes are written to the organisation's append-only evidence record. Weaknesses become corrective actions with an owner and a deadline, and an action closes only when a later retest passes. Record the debrief and link it to a hash-chained evidence event. Open corrective actions for weaknesses identified in the debrief. Close an action only when a retest passes; a missed deadline never closes it. Export debriefs, votes and evidence hashes for auditors as training evidence. Based on: NIST SP 800-84, Guide to Test, Training, and Exercise Programs; CISA Tabletop Exercise Packages.

Benchmark assumptions

Benchmark assumptions come from two deliberately separate tables. The flagship table is versioned and platform-controlled, and the organisation-local table is editable only for one organisation's own debrief. Entries whose EU-sourced figure is not yet verified ship with the status "needs-sourcing" and render in Cyber Range as open gaps — no substitute figure is imputed from a non-EU source, and numbers the platform supplies itself are labelled as platform model priors.

Known gap: Illustrative loss figures

Money amounts quoted inside scenarios are illustrative, not sourced estimates of any real organisation's loss.

Known gap: Training evidence is not compliance proof

Debriefs, votes and corrective actions are recorded as training evidence only. They do not demonstrate compliance with any standard or regulation.

Known gap: No cross-institution rounds today

Cross-institution exercises, external stakeholder seats and cross-sector benchmarking are not part of VulnTrek Cyber Range at launch. Exercises run within a single organisation.

Known gap: Votes run alongside the game

Live-room votes record the team's decisions as training evidence; they do not change the game's storyline or outcome.

Known gap: Open benchmark gaps

ENISA pattern weights, dwell time, and BSI cost-per-record and incident-frequency figures are pending verified EU sourcing. Until then the affected curves run on labelled platform model priors with widened ranges.

Scenario catalogue

Black Ice Clearing (incident): 2023 MOVEit Transfer mass exploitation (Cl0p) of a shared file-transfer product Silent Ledger (incident): 2016 fraudulent SWIFT payment instructions; insider-threat guidance Static Sky (incident): July 2024 global IT outage caused by a faulty security-software update Glass Chain (incident): 2020 compromise of a signed software update (SolarWinds Orion) Red Tide (incident): 2016 Dyn DDoS; DDoS extortion patterns North Gate (composite): Combined physical and cyber intrusion patterns (no single incident) Paper Moon (composite): Publicly reported deepfake executive-impersonation payment frauds Cold Current (incident): March 2023 social-media-accelerated deposit run Iron Corridor (incident): 2022 sanctions packages and payment-network exclusions High Water (incident): July 2021 European floods disrupting regional infrastructure Ghost Commit (incident): 2024 xz Utils backdoor (CVE-2024-3094) in trusted open-source code Open Window (composite): Publicly reported staff use of consumer AI tools with confidential data False North (incident): 2023 court filing containing AI-fabricated citations Black Socket (composite): AI provider concentration and service-suspension risk (no single incident)