Schema einer Cyber Range: ein vom Internet abgeschottetes, virtuell nachgebautes Firmennetzwerk in der Mitte, daneben das rote Angreiferteam, das blaue Verteidigerteam und das weiße Team als Übungsleitung mit Auswertung.

Cyber Range

A cyber range is a replicated computer environment in which professionals practice attacks on IT systems without endangering real systems. It works like a training ground: attack and defense take place under realistic conditions, but the consequences remain within the closed system.

A cyber range is a self-contained training ground for computer attacks. Inside it, a company network is artificially rebuilt: servers, workstations, user accounts, sometimes even the machines of a factory. Everything is real enough to feel like the actual event, but shielded from the real internet. One group plays the attacker, another defends. If something breaks, only the simulation is affected. The name comes from the English “shooting range”: a place where dangerous things can be practiced without danger.

Why real-world emergencies aren’t rehearsed on the real network

Hospitals, municipal utilities, and banks cannot simply shut down their systems to simulate an attack. A test on a live system could lose patient data or disrupt the power supply. Nevertheless, practice is essential, because in a real emergency every minute counts. The cyber range resolves this contradiction: the real event takes place in a copy.

On top of that, there is a tangible staffing problem. In Germany, tens of thousands of IT security positions remain unfilled. Those fresh out of training have learned the theory but have rarely experienced a real attack. In a cyber range, experience can be gained without anyone suffering harm. That is why the Bundeswehr, German states, universities, and large corporations now operate their own facilities.

A third reason is the testing of procedures. Defense often fails not because of technology but because of organization: nobody knows who informs management or when to call the police. Such gaps become apparent during an exercise, before they become costly.

What actually runs in the simulation

Technically, a cyber range mostly consists of virtual machines. These are computers that exist only as software on a powerful server. Hundreds of them can be started within minutes and deleted again after the exercise. This allows the same scenario to be played out as often as needed, always starting from the same initial state.

Participants are traditionally divided by color. The red team attacks, using the same tools as real criminals. The blue team defends, analyzes alerts, and tries to stop the intruder. A white team runs the exercise, sets the rules, and evaluates at the end what went well and what didn’t.

To make the environment feel credible, the cyber range generates artificial everyday activity: simulated employees write emails, open files, and browse the web. Without this background noise, an attack would be far too easy to spot. Artificial intelligence plays a growing role here. It generates this traffic, controls automated attackers, and afterwards evaluates how quickly the blue team reacted.

From school competitions to NATO exercises

The cyber range is best known from large-scale exercises. At “Locked Shields,” an annual NATO exercise in Estonia, thousands of participants from many countries simultaneously defend a fictional country against a simulated attack. Such events regularly appear in the news whenever state-sponsored hacking attacks are reported.

On a smaller scale, the same principle appears in Capture the Flag competitions. There, participants must find hidden codes in deliberately insecure systems. Many schools, universities, and online platforms offer such challenges, some of them free of charge. For getting started in IT security, they are the usual path.

Economically, this has become a market of its own. Providers rent out cyber ranges as a service in the cloud, meaning on third-party data centers that are booked by the hour. A distinction is worth making: a penetration test checks a real system for vulnerabilities, while a cyber range trains people on a copy. A common misconception is also that this is purely about technology. In fact, many exercises primarily test communication and decision-making under time pressure.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.