Answers about Cyber Range by VulnTrek: pricing and sign-up, live rooms and team exercises, the real-incident scenarios, and how debriefs and votes become training evidence.
Launch pricing is per organisation, per month, in EUR excluding applicable taxes: €199 standalone, or €99 per month as an add-on to an existing VulnTrek platform subscription. Both offers include up to 15 people across exercise lead, participant and observer roles. Larger teams agree their scope in a custom written quote.
No. Cyber Range is quote-led: you request access, and billing schedule, renewal, cancellation and team scope are confirmed in a written quote or order form before purchase. Requesting access does not start a subscription or take payment.
No. Cyber Range works standalone: your organisation gets a VulnTrek account with only Cyber Range enabled, and your team lands directly in Cyber Range after signing in. You can add the full platform later on the same account and organisation.
Choose your offer on the pricing page, send the request-access form with your work email and organisation, and the team replies. Once the order form is agreed, Cyber Range is switched on for your organisation.
A live room lets your organisation run an exercise together in real time. An exercise lead picks a scenario, opens a room and shares its join code. The lead starts the room and moves it on round by round.
Exercise leads open, start and advance rooms. Participants join with the code and choose one decision per round. Observers can watch but not vote. Leads and observers see the team's choices add up live.
Exercise leads can paste a list of email addresses, name the group (for example “Executive board”) and pick a role. People already in your organisation get access straight away; others get it automatically once they accept your organisation invitation.
No. Once a vote is recorded it cannot be changed, and each person gets one vote per round. This keeps the exercise record intact.
The scenarios are built around real, publicly reported cybersecurity incidents — for example the MOVEit breach, the Bangladesh Bank SWIFT fraud, the CrowdStrike outage, SolarWinds, the Dyn attack and the xz Utils backdoor. Each scenario lists its public sources, drawn from CISA, NIST and Wikipedia.
No. Scenarios use fictional organisations. An automated check scans the scenario text and flags any pack that names a real organisation, and none of the current scenarios does. Some scenarios are marked composite: they blend patterns from several incidents rather than retelling one.
No. Loss figures shown in exercises are illustrative, included to make decisions realistic. They are not figures from the actual incidents.
Two things: debriefs recorded when an exercise round completes, and decisions voted in live rooms. Each is linked to an entry in VulnTrek's append-only evidence record, so the history cannot be edited afterwards.
Yes. Organisation admins can export debriefs and evidence-linked live-room votes, with their evidence references, as CSV or JSON from the Cyber Range admin area.
No. Debriefs and evidence-linked votes are training evidence — a record that exercises happened and what was decided. They are not certification, and VulnTrek does not claim they prove compliance. Votes recorded before evidence linking was enabled are not included as evidence-linked votes.