Skip to main content
Cyber ranges & training, Cyber (Cyber & Critical Infrastructure), Unstrat

Cyber ranges & training

Live-fire cyber training environments

Overview

Cyber ranges where defenders train against live attacks on realistic replicas of their own environments, including a maritime cyber range built around ship bridge, navigation and OT systems. Exercises, curricula and certification that turn security teams into practised crews.

You do not find out whether a security team can handle an intrusion by reading their certificates. You find out by running one at them. A cyber range is where that happens safely: live-fire exercises on realistic replicas of your own environment, including a dedicated maritime cyber range, so the first time a team meets a scenario is not on the production system it was supposed to protect.

Unstrat represents this capability to a market only once classification and the end-user-certificate chain are confirmed. Full specifications are shared under briefing.

Capabilities

  • Infrastructure replicas, not abstractions. An exercise runs on a model of the systems your team actually defends: the network segments, the servers and services, and for OT the real protocols and controllers. The closer the replica, the less a team can lean on knowing it is a drill, and the more the exercise tells you about the estate rather than the classroom
  • Scenario design tied to your own threat picture. An exercise begins with a decision about what is being rehearsed: a ransomware outbreak spreading from IT toward OT, a compromised vendor account, a slow intrusion that hides for weeks. The scenario sets the attacker's objective, the starting foothold and the pace, so the day rehearses an incident you are plausibly going to face rather than a generic capture-the-flag
  • Red and blue teams, rotated. The red team plays the adversary, working to the scenario's objective; the blue team defends and responds. Rotating people through both roles is where the learning is, because a defender who has spent a day as the attacker reads their own alerts differently afterwards
  • Scoring that reflects the mission, not the scoreboard. Exercises are measured on what matters operationally: how quickly the blue team detected the intrusion, how far the red team got before they were caught, whether the response contained the incident without taking the whole system down. The score is a prompt for the after-action review, not the point of the day
  • Structured after-action review. Every exercise ends by walking the timeline: what the attacker did, what the defenders saw, where the two diverged, and which gap to close first. That review, fed by the scoring, is what turns a training day into a change to how the team works
  • Structured curricula and certification pathways, so an individual's progress is legible and a team can show it has rehearsed the incidents it is expected to handle

Specifications

TypeCyber range & training
SpecialismMaritime cyber range
FormatLive-fire exercises / certification
OriginIndependent / non-aligned

In depth

A replica makes the exercise answerable

A cyber range gives defenders somewhere to meet an intrusion before production becomes the classroom. The catalogue describes replicas of the systems a team actually defends, including network segments, servers, services, OT protocols and controllers. A scenario can begin with a ransomware outbreak moving from IT toward OT, a compromised vendor account or a slow intrusion that hides for weeks. The exercise is tied to the threat picture and the defender's environment rather than a generic capture-the-flag problem. That distinction matters because the purpose is not to produce a high score in an unfamiliar lab. It is to show how a team detects, contains and recovers when the systems and decisions resemble its own.

Defenders working through a live-fire exercise in a cyber-range training suite.
Defenders working through a live-fire exercise in a cyber-range training suite.

Red, blue and after-action work

Red teams play the adversary and blue teams defend against the defined objective, with people rotated through both roles. Exercises are measured against operational questions: how quickly the intrusion was detected, how far the red team progressed, and whether containment avoided taking the whole system down. The score starts the after-action review rather than ending the exercise. Teams walk the timeline, compare what the attacker did with what defenders saw, and identify which gap to close first. Structured curricula and certification pathways make progress legible for individuals and teams. The training therefore connects an event on the range to a change in working practice, instead of leaving the result as a day of familiarisation.

Maritime systems are not office labs

The dedicated maritime cyber range is built around ship bridge, navigation and operational-technology systems. That environment gives crews a place to rehearse cyber incidents against the systems and relationships found on a vessel, rather than applying only an office-network scenario. The catalogue classifies the offer as cyber-range and training, with live-fire exercises and certification, delivered from an independent and non-aligned origin. Related capabilities include maritime cybersecurity, drone simulators and defensive cybersecurity. Training can therefore sit beside the operational defence programme while keeping its own purpose clear: build a practised crew, expose weaknesses in procedure and give the buyer a structured basis for deciding what to change before the real incident.

A maritime cyber range replicating a ship's bridge and navigation systems.
A maritime cyber range replicating a ship's bridge and navigation systems.

Why Unstrat: the difference

Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.

01

Independent, non-aligned origin, with no political exposure to any major-power ecosystem.

02

One accountable team from first briefing through delivery and in-region sustainment.

03

A maritime cyber range built around real bridge, navigation and OT systems, not generic IT labs.

How it reaches you

Independent maker
Non-aligned manufacturer
Unstrat
Single accountable channel
End user
Government or enterprise buyer
In-region sustainment · training · classification & end-use governance

Related capability

View all

Procurement & sustainment

Classification & EUC

Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.

Non-aligned origin

Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.

One accountable channel

A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.

In-region sustainment

Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.

Questions buyers ask

What is a cyber range?

A replica of a real environment where defenders face live attack under controlled conditions, scored and reviewed afterwards. The point is muscle memory: repeated exposure to realistic attack is what holds up when a live system is under pressure. Our ranges are built on replicas of the defender's own environment, including a maritime range made from real bridge, navigation and OT systems.

See: Cyber ranges and trainingAgainst Cyberbit and SimSpace

Best cyber range for SOC training

For a corporate SOC, Cyberbit and SimSpace are both strong and well documented: Cyberbit publishes four training packages with instructor recording, playback and trainee auto-scoring, and more than 100 attack narratives on its cloud range, while SimSpace emphasises emulating a full APT kill chain against a model of your production environment. The choice usually comes down to curriculum with certification against an adversary-emulation proving ground. Where the estate is not an office, neither publishes a specialist environment and we do.

See: Range platforms compared

Does cyber range training improve incident response?

The published evidence is vendor-generated, so read it carefully. SimSpace reports customer figures including a 45% improvement in attack and defence performance and 48% better time to detect; Cyberbit points to more than 20 training centres running thousands of trainees a year. Our case is qualitative: repeated live-fire exposure builds the reflexes that hold under pressure, and we would rather not invent a percentage.

See: Published outcomes, side by side

Maritime cyber range for ship crew and bridge teams

This is the clearest split in the market. Our maritime range spans bridge, navigation and OT systems with real protocols and PLCs, aligned to IACS E27, and it is used for crew training, certification and equipment research rather than as a demonstration. Cyberbit lists an ICS Security training package and SimSpace models production environments in detail, but nothing in either document describes a bridge, an ECDIS or a navigation bus.

See: Maritime cyber rangeMaritime cybersecurity platform

On-premises or cloud cyber range for a government SOC?

The decision is rarely technical. Cyberbit sells both an on-premises enterprise range and a browser-delivered cloud range, and either can be made to work. A range holds a working replica of your defences and a scored record of how your people perform, so the real question is which jurisdiction that model may sit in and who can compel access to it. For a national SOC or a defence ministry, that usually settles it.

See: Delivery models and ownership

Red team versus blue team exercise design for a national team

Design the exercise around the incidents you are actually likely to face, then debrief it properly, because an unreviewed exercise teaches very little. We provide red-blue exercise design and after-action review, with scenario libraries tuned to the customer's own threat picture. Cyberbit publishes stronger instructor tooling than we do, including session recording, playback and trainee auto-scoring, which is worth weighing.

See: Exercise and instructor tooling compared

ICS and OT training environment for utility engineers

Rehearsing plant engineers on a Windows domain teaches the wrong reflexes, because an OT incident is decided by what can safely be isolated. Our ranges use replicas of the defender's own environment, and the maritime range runs real protocols and PLCs. Cyberbit's four packages include an ICS Security curriculum, which is the closest published equivalent among the platforms we compare.

See: IT and OT security comparedCyber ranges and training

How many attack scenarios should a cyber range library contain?

Fewer well-chosen scenarios that match your threat picture beat a large generic catalogue, though scale still helps a training centre. Cyberbit's cloud range product page states more than 100 attack narratives and three exercise types. We tune scenario libraries to the customer's own threat picture and do not publish a count, which is a fair thing to press us on.

See: Attack content compared

We are standing up a national cyber training centre. What should the range contain beyond enterprise IT?

Whatever your defenders will actually protect: grid, port, rail or shipboard systems, with the protocols they speak. Our ranges replicate the defender's own environment, and the maritime range is built from bridge, navigation and OT systems aligned to IACS E27, which also makes it usable for equipment research. Cyberbit and SimSpace both replicate enterprise networks well, so the question is how much of your national estate is an enterprise network.

See: Cyber ranges and trainingRange comparison

Who ends up holding the model of our defences once we buy a range?

The supplier does, along with a performance record for every analyst who plays, which is why ownership matters more here than in most software purchases. Cyberbit's datasheet states it is a subsidiary of Elbit Systems, with an office in Ra'anana, and SimSpace states it was founded in 2015 by people from US Cyber Command and MIT Lincoln Laboratory. Neither fact makes those platforms bad. We are independent and non-aligned, with no political exposure to any major-power ecosystem.

See: Ownership and exposure

How do we prove training spend was worth it at budget time?

Measure something before and after: time to detect in the exercise, escalation accuracy, or how long containment took under the same scenario twelve months apart. This is where we are behind our competitors on paper, since Cyberbit publishes auto-scoring and evaluation tooling and SimSpace publishes four customer-reported outcome percentages. We publish after-action review and certification pathways, without numbers attached, and we would rather fix that than invent it.

See: Measurement gaps, stated plainly

Can a cyber range be used to test equipment before we accept it from a shipyard?

Ours is, which is one reason it exists. The maritime range runs real protocols and PLCs, supports equipment research alongside crew training, and aligns to IACS E27, the requirement covering onboard equipment and systems. That makes it useful during newbuild acceptance rather than only during annual training.

See: Maritime cyber rangeMaritime platform and E26 alignment

Our analysts are trained but have never handled a real incident. What closes that gap?

Live-fire exercises on a replica of your own environment, run often enough that the sequence becomes routine, and reviewed hard afterwards. That is the whole design of our ranges: turn a security team into a practised crew rather than a group of certificate holders. The exercises are tuned to your threat picture, and the same team that runs our defensive operations designs them.

See: Cyber ranges and trainingDefensive operations

Should range exercises use our real security stack or a generic one?

Your real stack, if you can. Rehearsing on generic tooling trains people on a console they will never use during an incident. Both leading competitors agree on this point, with SimSpace allowing customers to bring their own security stack and Cyberbit replicating the customer's tools, topology and normal traffic. We work the same way, from replicas of the defender's own environment.

See: Environment fidelity compared

Can range training lead to a recognised certification for our staff?

We provide structured curricula and certification pathways as part of the offer, and the specific recognising bodies are agreed per programme rather than published here. Cyberbit publishes four structured training packages with trainee evaluation built in, if a packaged curriculum is what you need. Ask us in writing which pathway applies to your team before you build the training plan around it.

See: Curricula and certification compared

Cyber ranges & training: questions

What is Cyber ranges & training?

Cyber ranges & training is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: Cyber ranges where defenders train against live attacks on realistic replicas of their own environments, including a maritime cyber range built around ship bridge, navigation and OT systems. Exercises, curricula and certification that turn security teams into practised crews.

How does Cyber ranges & training work?

Cyber ranges & training delivers its effect through infrastructure replicas, not abstractions. An exercise runs on a model of the systems your team actually defends: the network segments, the servers and services, and for OT the real protocols and controllers. The closer the replica, the less a team can lean on knowing it is a drill, and the more the exercise tells you about the estate rather than the classroom, Scenario design tied to your own threat picture. An exercise begins with a decision about what is being rehearsed: a ransomware outbreak spreading from IT toward OT, a compromised vendor account, a slow intrusion that hides for weeks. The scenario sets the attacker's objective, the starting foothold and the pace, so the day rehearses an incident you are plausibly going to face rather than a generic capture-the-flag and Red and blue teams, rotated. The red team plays the adversary, working to the scenario's objective; the blue team defends and responds. Rotating people through both roles is where the learning is, because a defender who has spent a day as the attacker reads their own alerts differently afterwards, capabilities matched to the requirement and confirmed under briefing rather than published.

Who provides Cyber ranges & training?

Cyber ranges & training is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.

Why choose Cyber ranges & training over a major-power alternative?

Cyber ranges & training is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: a maritime cyber range built around real bridge, navigation and OT systems, not generic IT labs. The capability is accountable to you, not to a foreign vendor's government and its release schedule.

How is Cyber ranges & training procured, and where can it be delivered?

You do not find out whether a security team can handle an intrusion by reading their certificates. You find out by running one at them. A cyber range is where that happens safely: live-fire exercises on realistic replicas of your own environment, including a dedicated maritime cyber range, so the first time a team meets a scenario is not on the production system it was supposed to protect. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. Cyber ranges & training is then sustained in-region by one accountable team from briefing through long-term operation.

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.