Incident response range

A private cyber range where your responders work a full incident on systems modelled on yours, from first alert to recovery. Each exercise ends with a debrief on detection, response and areas to improve.

On this page

What it is

The range gives your responders a working copy of the relevant parts of your estate and an incident in progress. They collect evidence, scope the incident, contain it and restore service with the tools and playbooks they use at work.

It suits incident response leads, SOC managers and IT operations teams, along with the managers who make decisions during an incident. Facilitated courses are covered under incident response training.

Scenarios

Ransomware outbreak

Encryption spreads from one endpoint to file servers. Responders isolate hosts, find the entry point, and restore from backups in the range.

Business email compromise

A mailbox is taken over after AI-written phishing, and forwarding rules redirect invoices. Responders trace the access and recover the account.

Deepfake-led account takeover

A cloned voice persuades the help desk to reset MFA. Responders connect the help desk ticket to the sign-in activity that follows.

Compromised cloud credentials

An access key is used to create resources and read storage. Responders revoke access, review audit logs and remove persistence.

Data exfiltration

Staged files leave the network over an allowed channel. Responders establish what left, when, and from which systems.

Web application breach

A vulnerable internet-facing application leads to a web shell and access to an internal database.

How an exercise runs

We choose the scenario and the playbooks to test, and agree who takes part: responders, IT operations, and legal, communications and management as needed. We write a timeline of injects and the decisions each role will face.

What the range includes

Systems in scope

Endpoints, servers, identity services, email and cloud resources modelled on yours, with backups that can be restored.

Evidence sources

SIEM and EDR data from your tools or from Wazuh, Security Onion and OpenSearch, plus disk images, memory captures and audit logs for forensic work.

Response tooling

Forensic and triage tools, ticketing, and a communication channel for the incident, matched to what your team uses where possible.

Exercise control

Scenario timeline, inject schedule, and a facilitator log of decisions and timing.

Exercise formats

FormatHow it worksWhen it fits
TabletopParticipants discuss decisions at each stage using range artifacts, without hands-on work.Management, legal and communications roles, or a first review of a new playbook.
Live-fireResponders work the incident hands-on in the range.Testing technical procedures, tool access and evidence handling.
CombinedTechnical responders work in the range while a management group runs a parallel tabletop fed by their updates.Testing escalation and decisions between technical and leadership teams.

Aligned with NIST SP 800-61

Exercises follow the incident handling stages described in NIST SP 800-61: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. Revision 3 places this work within the Cybersecurity Framework 2.0 functions, and we can map findings to either structure.

Your own incident response plan remains the reference during the exercise. Where your plan and the guidance differ, the debrief notes it for your review.

What you receive

Each exercise ends with a debrief while the incident is fresh. Written findings follow and are yours to keep.

Debrief session

  • Response timeline against the scenario timeline
  • Decisions reviewed with the people who made them
  • Notes from technical and management groups

Detection and analysis

  • Evidence found, missed or found late
  • Accuracy of scoping at each stage
  • Gaps in logging or tool access

Containment and recovery

  • Containment actions and their side effects
  • Recovery steps and how they were verified
  • Communication and escalation between teams

Improvements

  • Playbook updates and tooling changes
  • Scenario stored for a rerun
  • Option to rerun with a new group or after changes

Questions

Does the exercise affect production?

No. The incident runs in an isolated range with its own network, identities and backups. Containment and recovery actions are taken on range systems only.

How close is the range to our environment?

We model it on your architecture, tools and log sources, as far as the scenario needs. The brief records any differences that affect what responders can see.

Who facilitates?

A facilitator from our team runs the exercise, sends injects and leads the debrief. Our operators handle the attack activity behind the scenario.

Can management and non-technical staff take part?

Yes. Legal, communications, HR and executives can join through the tabletop track or through injects addressed to them.

Can we rerun scenarios?

Yes. Each scenario is kept in a library for your range, with its configuration and scoring sheet. You can rerun it with a new group, or after changing a rule or procedure to compare results.

How is data handled?

Range data, recordings and findings stay in the deployment you choose. We agree retention and deletion rules before the first session and sign an NDA on request. Synthetic data is the default, and production data is used only with your written approval.

How to prepare

Share your incident response plan, the playbooks in scope, and your escalation and contact lists. Name the people for each role, including decision-makers outside the security team.

Tell us which tools responders use for evidence collection and ticketing so the range matches. If you want to include backup and restore, name the systems and backup method in scope.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.