Rehearsals
Security training often treats the problem as something people need to know. Rehearsals start somewhere else: put people in the situation and see what happens.
I build the environment, set the objective, and step back. The situation can be offensive, defensive, operational, technical, organisational, or some inconvenient combination. The exercise can be built from one of the open-source games and ranges, or adapted or newly built around the problem that needs exploring.
Play the attacker. Play a defender. Work through a crisis. Test a decision. Follow an attack through a plant network. Find out what the SOC actually sees. Put the procedure under pressure and see whether it still works.
[14:02] the vendor laptop is on the maintenance VLAN [14:05] the SOC dashboard shows a quiet afternoon [14:31] player two finds the WiFi point nobody documented [14:33] the facilitator says nothing, and writes it down
The point is not to catch someone getting something wrong. It is to find out what the situation makes possible.
What a rehearsal can explore
A rehearsal might look at:
- an attacker trying to reach a particular objective
- a defender working with incomplete information
- a service desk handling a convincing identity request
- an OT engineer handling a vendor arriving with a laptop
- a leadership team making decisions during an unfolding incident
- a security team investigating what a detection system did and did not see
- an engineering team testing segmentation, access or routing assumptions
- a procedure that looks sound until somebody has to use it quickly
- a school project
The scenario and form are shaped around the people, system and question. The same basic environment can therefore support very different rehearsals.
What comes out
The useful part is not a score.
It is the record of what happened: the decisions people made, the routes that opened, the controls that changed them, the assumptions that held, and the conditions that made an undesirable action seem reasonable at the time.
The debrief turns those observations into something the organisation can use.
Sometimes that means changing a control. Sometimes it means changing a process. Sometimes it means accepting a risk that is now better understood. Sometimes it produces a new question.
The games and ranges are open source. They can be played as they are, or adapted to fit a particular environment and problem.
Beyond the rehearsal
Rehearsals can also sit inside wider security work: threat modelling and architecture review, incident-response programmes, detection engineering, resilience work, assurance, or preparation for an exercise or audit.
In those cases the rehearsal is not a separate training event. It is a way of testing the question against something that behaves enough like the real situation to produce useful evidence.