EXERCISE TYPOLOGY AND DESIGN
installing, and practically securing dedicated
infrastructure, as well as investigating,
analyzing, and handling complex cyber
incidents. One of the best and most used
hands-on concept of technical exercises is the
Red team/Blue team model.1 A Red/Blue team
exercise is based on a model within which
exercise participants form Blue teams that are
responsible for the protection of a dedicated
infrastructure. Defending teams face real-time
attacks (performed by the Red team) escalating
from simple attacks (application denial-ofservice, defacement,…) to the more advanced
ones (exploits, specially crafted malware, logic
bombs, etc). Alongside the technical aspect,
blue teams have to react to company users’
issues and complaints, and assess the potential
legal and media impacts of the incidents. The
range of training objectives is usually wide and
covers the practice of technical skills, work in
increased stress situations, and the
communication aspect. Blue teams are scored
for maintaining usable environments for endusers, for availability, information sharing,
communication with media and legal advisors.
Awarding points should promote healthy
competition and provoke better performance
through gamification.
6/29
Figure 2: An example of the technical infrastructure during the Cyber Czech 2016 exercise.
The infrastructure consists of 4 network segments (DMZ, Clients, Servers, ICS) and a central firewall.
Communication exercises are extremely
important for testing the availability of points
of contact (PoCs) in given institutions, and for
testing whether and to what extent the points
of contact are up-to-date. We would not
strictly classify them as either technical or nontechnical. A major goal of these
communication exercises, (sometimes also
called "comm-checks") is to regularly verify
availability and how much time it takes to reach
out to an institution/person relevant to solving
a potential incident or crisis.
1
Hybrid exercises can be viewed from a variety
of perspectives. For the purpose of this guide,
a hybrid exercise is considered an overlying and
interconnecting
concept
of
the
abovementioned exercises. In this sense, a
hybrid exercise combines a technical exercise
with a strategic level TTX, allowing participants
from the technical layer of cyber security to
train together with the highest-level decision
making entities in one exercise. As such, it
offers an “all-inclusive” package for players to
train both technical and decision making
Technical exercises may also include hackathons, capture the flag, competitions etc.