EXERCISE TYPOLOGY AND DESIGN installing, and practically securing dedicated infrastructure, as well as investigating, analyzing, and handling complex cyber incidents. One of the best and most used hands-on concept of technical exercises is the Red team/Blue team model.1 A Red/Blue team exercise is based on a model within which exercise participants form Blue teams that are responsible for the protection of a dedicated infrastructure. Defending teams face real-time attacks (performed by the Red team) escalating from simple attacks (application denial-ofservice, defacement,…) to the more advanced ones (exploits, specially crafted malware, logic bombs, etc). Alongside the technical aspect, blue teams have to react to company users’ issues and complaints, and assess the potential legal and media impacts of the incidents. The range of training objectives is usually wide and covers the practice of technical skills, work in increased stress situations, and the communication aspect. Blue teams are scored for maintaining usable environments for endusers, for availability, information sharing, communication with media and legal advisors. Awarding points should promote healthy competition and provoke better performance through gamification. 6/29 Figure 2: An example of the technical infrastructure during the Cyber Czech 2016 exercise. The infrastructure consists of 4 network segments (DMZ, Clients, Servers, ICS) and a central firewall. Communication exercises are extremely important for testing the availability of points of contact (PoCs) in given institutions, and for testing whether and to what extent the points of contact are up-to-date. We would not strictly classify them as either technical or nontechnical. A major goal of these communication exercises, (sometimes also called "comm-checks") is to regularly verify availability and how much time it takes to reach out to an institution/person relevant to solving a potential incident or crisis. 1 Hybrid exercises can be viewed from a variety of perspectives. For the purpose of this guide, a hybrid exercise is considered an overlying and interconnecting concept of the abovementioned exercises. In this sense, a hybrid exercise combines a technical exercise with a strategic level TTX, allowing participants from the technical layer of cyber security to train together with the highest-level decision making entities in one exercise. As such, it offers an “all-inclusive” package for players to train both technical and decision making Technical exercises may also include hackathons, capture the flag, competitions etc.

Select target paragraph3