The ongoing war in Ukraine has put an international spotlight on the growing cyber threats to critical national infrastructure and the role of state-sponsored cyber-attacks. But for the defence and military forces engaged in the conflict, while this may represent a peak, it is not the first shift we have seen to hybrid cyber-attacks and kinetic warfare.
(Photo: Aare Reintam)
This can be mainly attributed to the 2008 Russo-Georgian War. In this case, Russian forces were seen taking out almost everything they were able to communication wise, enabling the spread of misinformation to the public and taking it out to the media organsiations and banks.
Think back to what that was like 15+ years ago. Now fast forward to today, when digital transformation on a global level is even more advanced and congested, with practically everyone relying on the information they receive via a smartphone or tablet.
However, going back to the Ukraine war and the attacks by Russia, what we have seen are significant ransomware attacks that cause maximum disruption, particularly to means of communication. To prepare for these types of attacks it is vital to have already acted from a training perspective. But what sort of training is involved here, and who exactly needs to be trained?
Within the military, we can effectively see two different types of training. The first is individual – how every member of the forces learns and hones their knowledge and skill over the years while they serve and along whichever career path they choose to take.
Then there is the second type, which can be classified as collaborative or collective training. This is where the use of Cyber Ranges and training in these technologies comes in. A Cyber Range is a virtual, simulated environment used to train cybersecurity personnel and test an organisation or team’s capability to respond to cyber-attacks and critical incidents caused by cyber threats.
With this type of collective training using Cyber Ranges there are a number of questions and considerations involved. How should you best conduct collective training exercises? What specifically should you include and train teams on? How do you benchmark the exercises? This is were training to the point of failure is vital in order to enable organisations to safely learn to prioritise high value assets and practice response and recovery procedures.
And this is all before you even consider technology testing and validation. Are the tools and technologies being used fit for purpose? Are today’s military systems capable of speaking to other systems? This article will address those questions and guide you through the process.
Different classifications
Cyber Ranges have different layers of classification. For those that are unclassified, you can conduct exercises to detect talent within your department or regiment. This type of training can enable military teams to see who responds well to which type of activity and, therefore, where they could be best deployed in the future. Another key point here is that unclassified ranges can be used by everyone and used to train teams against specific concepts as opposed to classified and contextualised environments.
For example, is someone clearly showing aptitude for recognising offensive activities?
Is someone else demonstrating prowess in forensics? Does anyone else look well suited to operate in a SOC? It is through Cyber Range training and exercises that military and defence
teams can detect these talents and put the right personnel in the right positions.
Also falling within this unclassified layer of Cyber Range training is dedicated technology testing. This is where military teams can be put into a pre-prepared or digital twin environment, such as a battlefield scenario with attacks launched against it, so you can truly test its capabilities and then benchmark the results against other tools and systems. This type of testing, simulation and modelling is risk free, rapidly reconfigurable and does not require operational equipment to be taken out of service to conduct the training
Then, there is the classified layer where you can conduct command and control and operability tests with military systems using the real physical twins of dedicated environments found on the battlefield. With this in place, you can actually test the people, tools, and systems that will be operationally responsible in ongoing conflict situations. Furthermore, this can all be conducted within a classified and specific context where tactics, techniques, and procedures can be validated and tuned in a safe to fail and need to know environment.
Finally, there is the secret (and above) level that can be used for explicit and highly sensitive use cases. Air forces and other military departments utilise Cyber Range platforms in this way for very specific operational tasks to test how scenarios would play out ahead of combat missions and assess how prepared their people are not only from a personal or collaborative perspective but also from a technological point of view.
What we see from our relationships with military customers all over the world is that threats and threat intelligence are just one part of the cyber puzzle for them to solve. What is just as crucial is a process-driven approach – how these teams can ensure their people, systems, and entire ecosystems are better prepared to tackle the threats.
In other words, the actual threats themselves are the second or third layer in the whole process after the preparation. The key is knowing you have the capabilities in terms of the people and technologies to detect and mitigate the threats once they present themselves.
Common threats present themselves
Military systems, as you would expect, are very isolated and difficult to access from the perimeter side. The focus of cyber training exercises is, therefore, often around social engineering type attacks as part of Army Personnel Testing as the threat and risk of
state-sponsored attacks of this nature grows. Another growing trend is supply-chain-focused attacks against media or communications-focused organisations, resulting in the spread of disinformation via deep fakes. With deep fake technology, the threats are extremely serious.
A hostile group can make somebody in a position of power appear to issue a message, and it will be extremely difficult to determine its legitimacy. These kinds of deep fakes can be used in very narrow fields, and knowing how to detect them and how to tackle them is a topic that we still don’t have a true understanding of right now.
So for these and many other reasons, we are seeing more and more nations building up their cyber offensive capabilities, including INFOWAR Information Warfare or PsyOPS psychological warfare. The driving motivation now is not only to make sure you are doing likewise faster than the rate of relevance in order to provide an advantage over adversaries.
Training for all types of personnel
During the early adoption of Cyber Ranges in the military and defence industries, most engagement would have been with the J-6 staff at a very senior and technical level. However, today, the selection of people engaged with the unclassified layer of Cyber Range training is extremely wide. Cyber Ranges have evolved into a hybrid of physical and virtual environments. A simple example would be networking – Software Defined (logically vulnerable) or physical network devices (vulnerable to physical interference).
This will include infantry and the lowest level of cadets to the highest layer of technical leads.
We see this as a particularly positive shift because it enables a rotation of skills within a team and the same level of experience as you would expect to see in a more closed environment.
The same environment can be replayed to include different professional groups from ‘hands on engineers’ being tested against skills, or ‘decision makers’ interpreting the signs and symptoms to decide the most likely course of action to bring about mission success. This further develops team role understanding and cohesion.
Within Cyber Range training programmes, we are also able to see how the structure of the command chain operates in real-time. So if, for example, there is an attack against a dedicated unit or military base, you have oversight of how the command chain goes up and down.
For some very senior-level personnel, this can sometimes present a challenge initially. These individuals are primarily responsible for the armed forces, the navy, or the air force and how these divisions operate together.
However, what cyber training does is show what the impact can be operationally if there is an interference somewhere along the lines. The key is being able to present the information in a meaningful way so they actually understand the significance and impact of cyber activities in a real-life context. This becomes even more important as younger people enter the military and require detailed training as they become the next layer of defence.
Cyber Range exercises in practice
One example exercise we have done as part of the Federated Mission Networking initiative is to put Russian nuclear submarines on the coast of the Baltic Sea during operations. We took over the commanding officer’s email web server and sent out emails from the commanding officer to the units. So what will you do if this happens? What are the communication channels?
This is where education and training are vital to ensure the wrong decisions aren’t taken or, at the very least, the chances of this happening are minimised. Another consideration is the frequency with which these types of training exercises are conducted.
We have found this varies depending on the country and its capacity, but most will do at least one per year as a way of benchmarking. For others, it will be more frequent, particularly those that have their own cyber security standards, such as the UK.
In threat-hunting exercises, an interesting dynamic is between the detection and mitigation work and seeing how personnel collaborate because those responsible for the former are generally not also tasked with the latter. In fact, in most cases, those who are responsible for detection are not even allowed to log into the systems that generate alerts in the event of a potential attack.
They will see it and triage it but then pass it over to those responsible for mitigation, highlighting that said platform or machine has been corrupted and isolated and now needs to be taken care of. In this type of scenario, military teams are able to see how quickly this process is managed. An example of this is white box/black box hacking where people are asked to scan/exploit a digital twin of an unknown network to identify any overlooked vulnerabilities.
R&D in the military
From a cyber perspective, there is a huge amount of R&D within the military, and this, of course, requires a closed environment with dedicated testing grounds to develop, test, and make sure new systems are interoperable with existing tools.
This includes the adoption of AI, advanced language learning models, and neural networks so systems can be taught to think like people and make correct decisions, but in a faster and potentially more efficient way.
Going back to the war in Ukraine, we are seeing this type of new technology in use in a military setting with the use of drones with payloads. Many of these are prototypes without a human operator – they scan the environment, and if they detect something that could be a threat, the payload is released. Training for these use cases is clearly vital as we see the growth of autonomous killing machines on the battlefield, making decisions without human input.
Overall, what’s clear is that as cyber threats continue to evolve, defence and military teams need to be able to adapt, prepare their personnel and react to protect themselves and their assets. It’s for this reason that Cyber Ranges are being seen as increasingly valuable platforms for detailed training exercises, given their capabilities for simulating cyber-attack scenarios in real time and assessing the preparedness, capabilities, and skills of personnel.






