PREPARE · LIVE FIRE

TRAIN UNDER PRESSURE.

C3SA live-fire exercises place teams in controlled adversarial scenarios where people, process and technology are tested together against realistic attacker behavior.

OUTCOMES

WHAT CHANGES.

Our work is designed around practical outcomes, not activity for its own sake.

  • Validate detection and response under pressure
  • Exercise technical teams using real tooling
  • Identify breakdowns between people, process and technology
  • Generate evidence-based improvement actions
DETAILS

WHAT EACH SCENARIO TESTS.

In a C3SA live-fire exercise, an authorized team uses real attack techniques against a defined target, in a cyber range or an agreed part of your environment, while defenders respond in real time. Scope, safety limits and stop conditions are written into rules of engagement first.

RED / BLUE

Red vs Blue

An attacking team pursues defined objectives while defenders work to detect and stop them, without advance notice of the techniques used.

What you get

  • Scored objectives for both teams
  • A record of detected and missed techniques
  • A joint debrief
Talk to C3SA about Red vs Blue
PURPLE

Purple Team

Attackers and defenders work together technique by technique, tuning detection and response as they go.

What you get

  • Technique-by-technique results
  • Improved detections
  • Repeatable test cases
Talk to C3SA about Purple Team
RANSOMWARE

Ransomware Simulation

A multi-stage scenario covering initial access, persistence, lateral movement, impact and recovery, testing both technical response and business decisions.

What you get

  • A realistic ransomware attack chain
  • Response and recovery timings
  • Decision and escalation gaps
Talk to C3SA about Ransomware Simulation
CLOUD

Cloud Attack Scenarios

Attack paths through cloud identities, control planes and workloads, testing whether cloud logging and detection catch them.

What you get

  • Cloud attack paths exercised
  • Cloud detection coverage results
  • Cloud playbook improvements
Talk to C3SA about Cloud Attack Scenarios
OT / ICS

OT / ICS Scenarios

Safety-aware scenarios for operational environments, normally run in isolated or simulated industrial environments rather than live production. See OT/ICS exercises.

What you get

  • Scenarios that respect safety constraints
  • IT/OT coordination findings
  • Safe recovery actions
Talk to C3SA about OT / ICS Scenarios
MISSION

Mission Scenarios

Custom exercises tied to a business, defence or critical-infrastructure mission, testing whether the mission can continue under attack.

What you get

  • A mission-specific scenario
  • Mission-impact observations
  • Prioritized improvements
Talk to C3SA about Mission Scenarios
ENGAGEMENTS

HOW WE CAN HELP.

Engagements can be targeted, project-based or part of a broader transformation program.

Exercise designRange orchestrationRed / blue facilitationObserver controlAfter-action and readiness scoring
READY TO TURN THIS INTO ACTION?
WHERE C3SA ADDS VALUE

EVIDENCE OF HOW YOU PERFORM UNDER PRESSURE.

Teams need to know whether they can act under realistic pressure. C3SA runs authorized, controlled scenarios that test technical detection, decision-making, communication and recovery together, using your real tooling wherever possible.

Live-fire is only valuable if it leads to change. Each exercise produces performance measures and an after-action plan, and follow-on exercises verify the improvements.

COMMON QUESTIONS
What exactly does “live fire” mean?

Real offensive techniques are executed by an authorized team against a defined target, and defenders respond with their real tools and procedures. The target can be a cyber range or an agreed part of your environment. Nothing happens outside the written rules of engagement.

Is it safe to run in production?

Only within an agreed scope, with safety limits, stop conditions and a control team that can halt activity. Many exercises run entirely in a range to avoid production risk.

How is live-fire different from a tabletop exercise?

A tabletop exercise talks through decisions. Live-fire tests whether people, processes and technology actually perform when an attack is under way.

THE C3SA DIFFERENCE

ADVICE. IMPLEMENTATION. PROOF.

THE NEED

Teams need to know whether they can act under realistic pressure.

WHAT C3SA DOES

C3SA runs authorized, controlled scenarios that test technical detection, decision-making, communication and recovery together.

WHAT YOU GET

Rules of engagement, observations, performance measures and an after-action plan.

UNDER ATTACK? CYBERFIRE →