Recent research indicates that cyber-attacks against critical national infrastructure are on the rise, with the US facing the most targeted intrusions followed by the UK, Germany, India and Japan. Most of these attacks are reported to originate from China, Russia and Iran, with communications networks, transportation systems and power grids among the infrastructures at highest risk.
Earlier this month in the US meanwhile, the FBI and CISA (Cybersecurity and Infrastructure Security Agency) released a joint statement in conjunction with the Department of Defense Cyber Crime Center highlighting that critical infrastructure in the US is currently at heightened risk of cyber-attacks from criminal ransomware groups linked to Iran.
In part response to these growing threats, live fire exercises are increasingly being used by military and defence organisations to provide teams with a comprehensive and immersive training experience.
Designed to simulate real-world cyber-attacks, live fire exercises are team training sessions (typically set up with Red Team vs Blue Team) that provide participants with a realistic training experience in defending critical IT-systems during pre-defined cyber specific scenarios.
As well as providing the scope for delivering effective training, the scenarios developed for live fire exercises are typically designed to enable military and defence departments to capture data for future benchmarking and analysis. The exercises are typically broken down into three core phases:
- Planning: The goals/objectives, scope and environment of the exercise are all defined in advance alongside the roles and responsibilities of each participant, and the tools and systems required.
- Deployment: Team members start defence of their environment against cyber-attacks carried out by the other team and work on delivering their response plan.
- Evaluation: Upon completion, an debrief of everything that took place is crucial. Assessment of performance and areas for improvement are all vital to inform future incident response.
In practice we’re already seeing many use cases of live fire exercises amongst military and defence organisations as the manner and proliferation of cyber-attacks continues to evolve at a rapid pace, posing significant threats to critical national infrastructure.
For example, late last year the Army Cyber Spartan 23 cybersecurity exercise was held at the Defence BattleLab in Dorset Innovation Park in the UK. A five-day long event, this was one of the latest iterations of a large-scale live fire training exercise designed to educate army personnel and help them develop their cyber capabilities in a simulated cyber environment.
Over 300 participants from six different countries participated, with the opportunity to practice key skills including threat detection, reconnaissance, intelligence gathering and response plans in the face of real-world cyber threats in realistic cybersecurity scenarios.
The very nature of live fire exercises provides participants with a standardised gamenet environment (representing a typical IT infrastructure set up for an enterprise) so scoring can be tracked against specific tasks. In this respect participants are able to assess their performance against key objectives including live reactions and defence planning.
In summary, Army Cyber Spartan 23 aimed to strengthen the expertise and resilience of the British Army’s cybersecurity professionals as well as develop and foster better collaboration with other nations and the sharing of best practices.
Another recent example is Defence Cyber Marvel 3 (DCM3), which took place earlier this year with over 1,000 participants from 17 different countries, bringing together 90+ organisations to enhance their cyber capabilities in a six-day long competition and controlled and hosted online from Estonia.
The British Army described DCM3 as “the first pan-Defence initiative to build a grass roots community across Defence, His Majesty’s Government and international allies and partners.” Throughout the exercise, which was held in a live fire format, all participants were able to test their skills and knowledge in identifying ways to detect, prevent, and respond to the latest cyber-attacks in real-world scenarios in a controlled environment.
Various technical challenges were designed for competing teams, with one of these including needing to build and train AI to support the decision making of commanders on the ground. The primary objectives of the exercise were based around the following key areas:
- Co-operation – foster better co-operation between organisations and among individual team members.
- Learning – conduct more detailed analysis of feedback from simulated exercises and provide better clarity on individual responsibilities in the face of a cyber-attack.
- Planning – enhance defence planning to ensure better preparedness for the increasingly varied nature of cyber threats.
- Skills – identify, develop and retain talented personnel in cybersecurity, helping address the current skills gap.
The overall game dynamics within live fire exercises help to create an engaging and immersive experience for participants. By simulating real-world cybersecurity scenarios and challenging team members to use their skills and knowledge to react against attacks in real-time, organisations are able to better understand how to defend critical IT systems in the face of intense cyber-attacks.

