What is a Live Fire Exercise and How is it Conducted? image

What is a Live Fire Exercise and How is it Conducted?

Jul 2026

|

8 min read

A cybersecurity live fire exercise helps security professionals simulate and practise defending against real-world cyber attacks. It trains the entire team to work together, building not only their technical skills but also the coordination and communication necessary in responding to cyber attacks rapidly and effectively.

The format is a deep technical Red vs Blue exercise designed for practicing response to a cyber crisis according to a realistic pre-defined scenario. The structures and environments used are standardised and built to allow scoring, benchmarking and effective data capture.

Many exercises now pair the human Red Team with AI-driven automated adversaries in a standardised range environment, so the same scenario can be replayed on demand and run for many teams.

The teams behind a live fire exercise

Every exercise is built around an interplay of teams, each with a distinct role. The Blue Teams are the defenders. The exercise exists to train them. The Red Team provides the live opposition, executing a scripted attack campaign in real time so that every alert the defenders see is caused by a real action, not a simulation. The White Team designs the scenario, sets the rules of engagement and controls the tempo: it can tell the Red Team to intensify or ease its campaign, and it injects events such as management requests or media pressure. It also adjudicates scoring. Behind the scenes, a Green Team builds and maintains the cyber range infrastructure the whole exercise runs on. A live fire exercise differs from a discussion-based or simulated one because the adversary is live, the scenario is controlled and the environment behaves like the real thing.

The structure scales with the exercise: a large national or multinational exercise staffs all of these roles, while a smaller in-house live fire may run with just a Red and Blue Team and a facilitator, and the cyber range delivered as a service, meaning the provider hosts and runs the environment instead of the organisation owning one.

What the Blue Team does during the exercise

The Blue Team enters a pre-prepared environment where a malicious actor is already present, or about to break in. The Blue Team is hence tasked with hardening the environment, detecting the threat, responding to it, recovering their systems and services. When the exercise begins, the Blue Team is immersed in the action and feeling the pressure to perform like they would during the real attack – the Red Team is attacking and the clock is ticking. Alongside the technical work it files incident reports and briefs exercise control, because in a real crisis the people who have to act on the information, management included, are not always the ones watching the screens.

Scoring and situational awareness

The exercise progress is easy to monitor via CybExer proprietary visualisation and awareness software (ISA – Integrated Scoring and Awareness). It is used by the Blue Team, Red Team and instructors to analyse the situation and follow the progress of the exercise. It is also an excellent tool to display to the viewers (management, visiting stakeholders and partner organisations, for example) what is happening during the exercise.

Two views carry most of the exercise. The first is the campaign view, which gives an overview of the systems and performance of one Blue Team at a given point in time, highlighting system structure, presence of attacks, level of availability, timeline of reports and overall ranking. The second is the score breakdown. It plots the cumulative score for each of the currently applied scoring categories: Availability (green), Incident Reports (light blue), Total (white) and Attacks (red), so a team can see at a glance whether it is losing points to downtime or to attacks it never reported.

ISA does not hand the Blue Teams their detections, though. The attacks still have to be found and interpreted with their own security tooling, which is the whole point of the exercise.

The gamenet: the environment teams defend

The gamenet is the simulated network of virtual machines the Blue Teams defend. It has to be broad enough to be realistic, small enough for one team to hold, and consistent enough that scores mean the same thing across teams and across runs. It is usually not a replica of a specific organisation's network. The objective sets the level of detail, and choosing between a standardised gamenet and a replica of your own network is one of the decisions in how to organise an exercise.

Live fire exercise learning objectives

The exercise learning objectives are the following:

  • Fostering cooperation between various actors in the cyber defence at the organisational level
  • Rehearsing specific defensive measures in case of an attack against a particular field or combination of fields
  • Reacting live, planning defence and hardening the environment
  • Monitoring and analysing attacks
  • Synthesising information on the attacks to validate appropriate defence plans and scenarios
  • Discovering and understanding sophisticated attack patterns and vectors against the targets
  • Handling stress and making decisions under pressure with no good options
  • Producing reports that create an accurate basis for decision-making

The benefits of live-fire testing for cybersecurity

The objectives above describe what the team gains. For the organisation the return is evidence it cannot get any other way, results it can compare from one year to the next, and a first crisis that happens somewhere safe.

Evidence a pen test or an audit cannot give you

A penetration test tells you which weaknesses exist in an environment. An audit tells you which controls are documented. Neither tells you whether your people will notice an intrusion at 02:00 on a Sunday, or how long it takes them to get from the first alert to a contained system. Live-fire testing produces that evidence, because every Red Team action is logged against a known timeline. That gives you:

  • which attacks the team detected, and which passed unnoticed
  • how long detection and containment actually took
  • whether the correlation rules fired, and whether the logs the team needed were being collected at all
  • where a sensor has a blind spot or an alert reaches nobody
  • whether the incident reports written under pressure would brief a decision-maker

Results you can compare

A standardised scenario and a consistent scoring model make results comparable. Repeating the same scenario after remediation shows whether the fixes and the training landed. Running it across several teams or business units shows where capability is uneven. For regulated organisations, the exercise record of attack timeline, team actions, incident reports and score is the kind of documented response testing that supervisors and boards increasingly expect to see rather than take on trust.

Less firefighting when it is real

Teams that have never worked a scenario together spend the opening hours of a real incident deciding who owns what, which is usually when the damage is done. Security operations that feel like permanent cyber firefighting are often describing the absence of rehearsal: every crisis is new. A live fire exercise makes the first time cheap, in an isolated environment where an attack can be allowed to succeed and recovery can be practised for real, which nobody would sanction in production.

Live fire exercise, step by step

Live fire exercises are always conducted in teams: running one is never a one-person job. A typical exercise on a cyber range runs in three phases.

  1. Planning and Preparation. The White, Green and Red Teams prepare the scenario, define the scope of the exercise, build the cyber range and ready the attack campaign. The Blue Teams will study the environment of the exercise. They will also determine the roles and responsibilities of each member, identify the necessary equipment and tools, and ensure that all necessary resources are available for the exercise.
  2. Deployment and Execution. The Red Team launches its campaign and the White Team runs and scores the exercise, dialling the intensity and injecting events. The team will start defending their environment against the Red Team cyber attacks and execute their response plan. The participating team members will work together to identify and respond to the attack and restore normal operations.
  3. Evaluation and Debriefing. The participating team will take part in an evaluation and debriefing session. In this phase, the team (along with the White Team and instructor who has been monitoring the team’s performance throughout the exercise) will assess their performance, identify areas for improvement, and develop an action plan to address any weaknesses or gaps in their response plan. The team will also document the results of the exercise and use this information to improve their response plan for future incidents.

How to organise a live fire exercise

The phases above describe how an exercise runs. Before any of them begins, the organisation sponsoring the exercise has a handful of decisions to make, and those decisions determine how much the exercise is worth.

  • Write the objective down first. Validating a new SOC playbook, proving out a new EDR and building cohesion in a newly assembled team are three different exercises, and the objective drives the scenario, the scoring and the difficulty.
  • Decide who sits in the Blue Team and how many teams you field. Four to eight defenders per team is typical, and running several teams in parallel adds comparative scoring.
  • Choose the environment. The exercise runs on a gamenet, the simulated network of virtual machines the teams defend. A standardised one is quick to stand up and comparable between runs. Building it as a digital twin of your own estate takes longer, and it is the right choice when the question is whether your own defences would hold.
  • Decide which roles you staff and which you buy in. Few organisations keep a Red Team, a White Team and range engineers idle between exercises, and taking those as a service keeps your own specialists in the Blue Team seat, where the training value sits.
  • Fix the rules of engagement. What is in scope, whether destructive actions are permitted, whether the Blue Team may rebuild from backups, and when the White Team eases off. Ambiguity here turns an exercise into an argument.
  • Agree the measurements before the first attack lands. Service availability, incident report quality, time to detect, attacks blocked. Scoring is only useful evidence when the categories map back to the objective.
  • Protect the debrief and the follow-up. Hold it while the detail is fresh, and leave with findings that have named owners and dates. Repeating the scenario later is what measures improvement.

Who should take part?

The target audience for the exercise is technical personnel involved in technical IT security and cyber defence: SOC analysts, incident responders, and system and network administrators, the people who would defend the organisation during a real incident. The aim is to take the Blue Teams out of their comfort zone and give them the challenge of dealing with an unfamiliar environment.

Management and the C-suite are not usually Blue Team participants, because the exercise tests hands-on defence. They watch from the scoring dashboard, and some organisations run a session for decision-makers on the same scenario so both levels are tested together.

Frequently asked questions

How long does a live fire exercise last?

Most live fire exercises run from one to three days: an introduction and familiarisation phase, followed by the live attack-and-defence phase and a debrief. One day is enough to run a single scenario against a small number of teams. Two or three days allows a longer attack campaign, a second wave once the teams have hardened what they can, and a debrief that is not rushed.

Can a live fire exercise be run on our production systems?

No, and it should not be. The exercise depends on the Red Team being free to compromise systems and on the defenders being free to make mistakes, and neither is acceptable against live services. That is what the cyber range is for. Teams work in an isolated environment, a gamenet that is either standardised or built as a digital twin of your own architecture, configurations and tooling, which gives you the fidelity of exercising your own estate without the exposure.

Do the defenders know the scenario in advance?

They know the environment and the rules, not the attack. The familiarisation phase exists so that teams are not scored on how fast they can read a network diagram, and they are told what is in scope and what the White Team will and will not do. What they are not told is which systems are already compromised, what the Red Team will attempt, or when. That combination is deliberate: an unfamiliar environment with an unknown attack is realistic, while an unfamiliar environment with a known attack would only measure reading speed.

Who starts the fire in a live-fire exercise?

The Red Team executes the attack, but it does not decide when the attack begins or how hard it pushes. The White Team authorises the start, sets the pace and can tell the Red Team to escalate or ease off while the exercise is running. The reason is the exercise objectives rather than realism. A Red Team that already has access and knows the environment perfectly would, at full speed, be finished inside the first hour, which would leave most of the scenario unused and the defenders with nothing left to work on. Pacing keeps every team in long enough to reach the things the exercise was built to teach.

How is a live fire exercise different from a CTF?

A capture-the-flag competition breaks the problem into separate challenges, each with a right answer and a point value, and an individual can do well on their own. A live fire exercise hands a team one environment to keep running while somebody attacks it, so there is no task list and nothing to submit. Credit comes from spotting the attack, containing it and restoring service. The two are complementary rather than competing: a CTF is the better way to build and spot individual skill, while a live fire exercise shows how a team holds up under sustained pressure.

Is a live fire exercise the same as cyber firefighting?

They are closer to opposites. Cyber firefighting is not an exercise at all. It is what happens when an incident arrives and nobody has rehearsed for it: improvising under pressure while the business watches. A live fire exercise is the controlled burn beforehand, with the same conditions and none of the consequences, and its purpose is to make the real event something the team has already worked through once.