How to run a Cyber Range live room

A one-page guide for executives and exercise leads: pick a scenario, open a room, invite your team with a join code, run the rounds and see what lands in the evidence record.

Who does what

Exercise lead: Opens, starts, advances and closes rooms; invites the team; sees the live tally of decisions. Participant: Joins with the room code and chooses one decision per round. A recorded decision cannot be changed. Observer: Joins with the room code and watches the exercise and the running tally, without voting.

1. Before you start

A live room is a real-time exercise with your own team, inside your organisation's own Cyber Range. Only exercise leads can open a room, so start by confirming who in your organisation holds that role.

Check your access

Sign in to VulnTrek and open Cyber Range. If you are an exercise lead, the Live rooms button at the top right opens the room panel. Participants and observers see the same panel, but with the join box only.

Agree who leads

One lead runs the room: they start it, move it on round by round and close it. Organisations with several leads can each open their own room, for example one per department or one per board session.

Plan the session

A room runs round by round, and each round is one decision point for the team. Allow time for the discussion after each round — the debrief is where the value is, not the voting itself.

2. Scenario setup

The scenario decides what your team is reacting to. Every scenario is built around a real, publicly reported incident, and uses fictional organisations and illustrative loss figures so the decisions feel real without naming victims.

Choose a scenario

In the Live rooms panel, open a new room and pick a scenario from the list. Each entry names the real incidents it draws on — for example the MOVEit breach, the Bangladesh Bank SWIFT fraud or the CrowdStrike outage. Scenarios switched off for your organisation by the VulnTrek team do not appear in the list.

Name the room

Type a room name of at least three characters — something your team will recognise, such as “Board drill Q4”. The Open room button unlocks once the name is typed.

Open the room

Opening the room gives it a join code and puts it in the open state. Nothing has started yet: the room waits until you press Start, so you can gather people first.

Invite your team

On the Cohort invites tab, name the group (for example “Executive board”), paste the email addresses and pick the role. People already in your organisation get access at once; anyone outside it gets access automatically once they accept your organisation invitation. Each person receives a Cyber Range invitation email.

3. Joining with a code

The join code is how the rest of the room gets in. It is a short code shown on the room card — share it in your own channel or read it out at the start of the session.

Open the panel

Everyone signs in to VulnTrek with their own account and opens Cyber Range, then Live rooms. No separate Cyber Range account or password exists.

Enter the code

Paste or type the join code into the “Join with a code” box and press Join. The Join button becomes available once the full code is entered.

Waiting for the lead

If the room is still open rather than live, you will see “Waiting for the lead to start.” — you are in the room, and the exercise begins when the lead presses Start.

If the code does not work

Codes are specific to your organisation and to that room. A closed room cannot be joined, and a code from another organisation will not open a room in yours.

4. Running the rounds

Once started, the room moves in rounds. Each round is one decision point, and the team votes before the lead moves on.

Participants decide

Each round shows the decision options for that stage of the incident. A participant picks one option; the choice is recorded immediately and cannot be changed, and each person gets one decision per round.

Leads and observers watch the tally

The running count of the team's decisions is visible to the lead and to observers as votes come in, so the room can see where the team is split before the discussion.

Advance the room

The lead presses Next round to move on, and Close room to end it. Closing stops further decisions; decisions already recorded are never removed.

Debrief

When a round completes, the debrief is written to your organisation's evidence record with the decisions and the reasoning captured at that point. Corrective actions raised from the discussion are recorded separately and close only when a retest passes.

5. The evidence record

Everything that happens in a live room that counts as evidence is written once and cannot be edited afterwards — so an exercise can be shown to a reviewer months later.

What is stored

Two things: debriefs recorded when an exercise round completes, and decisions voted in live rooms. Each one is linked to an entry in VulnTrek's append-only evidence record and carries its own evidence fingerprint.

What is not stored

Live room messages stay in the room and are not part of the evidence record. Only decisions and debriefs are linked to it.

Exporting for a reviewer

Organisation admins export debriefs and evidence-linked decisions, with their evidence fingerprints, as CSV or JSON from Admin → Cyber Range → Evidence record.

What it does and does not prove

This is training evidence: a record that exercises happened and what your team decided. It is not certification and VulnTrek does not claim it proves compliance. Decisions recorded before evidence linking was enabled are not included as evidence-linked decisions.

Session checklist

Confirm who holds the exercise lead role in your organisation Pick a scenario and name the room, then open it Share the join code, or invite a named cohort by email Start the room, let each round be decided, then move on Close the room when the session ends Export debriefs and decisions from Admin → Cyber Range → Evidence record