SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsSecurity is an infinite game, where “winning” means reducing risk sustainably while maximizing available resources.
Cybersecurity leaders often operate in a world of trade-offs where no option is strictly right or wrong. Security is an infinite game, where “winning” means reducing risk sustainably while maximizing available resources. With this in mind, SANS built Cyber42, a leadership simulation that challenges participants to make the same difficult decisions they will have to make on the job. As in real life, time and resources are in short supply, while difficult decisions, trade-offs, and unexpected challenges are not.
Each version of Cyber42 in the SANS Leadership Curriculum is tailored to reflect scenarios and choices relevant to a specific course. In LDR551TM: Building and Leading Security Operations CentersTM, players assume the role of a new Security Manager tasked with building and managing a security operations center (SOC) at fictional tech company Ops Outpost. We have been working hard on a new Cyber42 release for the SANS LDR551 course which will be available to students starting in Spring 2025. This post describes our approach to building a realistic simulation that embraces ambiguity while enriching the SANS learning experience.
Cyber42 is fundamentally a decision-making game. Each choice has a cost and may impact your score positively or negatively. In LDR551, scoring is tracked across four dimensions: Prevent, Detect, Respond, and Morale. Players can proactively invest in technical areas to drive a positive score, but building the best technical solution is only part of the objective. Burnout, fatigue, lack of advancement opportunities, and interpersonal conflict can all affect team morale and by extension, the final score.
In each round, participants navigate planned and unplanned decisions—most requiring time and/or money—that impact each of the four dimensions. Each answer is followed by a debrief explaining the outcomes of the player’s decision.
Excelling in all four dimensions results in bonuses but exceeding the allotted time or budget results in steep penalties. The player(s) with the highest aggregate score at the end of the game wins. This sounds simple enough, but designing a realistic simulation using finite game mechanics is no easy task!
Unlike other gamified simulations that rely on binary right-or-wrong choices, the Cyber42 approach embraces ambiguity. Participants must weigh competing priorities, such as whether to invest in cutting-edge technology, prioritize training, or enhance automation. Each choice has pros and cons, and success is measured not by selecting a single correct answer but by how well participants balance technical capabilities, team morale, and limited resources. Context, experience, and judgment are key in striking the right balance.
Creating a simulation that feels authentic requires scenarios where every option has merit but also some risk. This means:
Unpredictability, creativity, and feedback are important elements of any gamified experience, and Cyber42 leverages them to great effect to make decisions-making feel more grounded in the real world. The scenarios are designed to spark debate and encourage players determine the best decision under the circumstances, if not always the objectively correct decision. This should sound familiar to anyone operating in a leadership role.
You can read more about Cyber42 and the SANS Leadership courses featuring the game here. By immersing students in realistic decision-making scenarios, Cyber42 provides a practical application of leadership concepts. The game’s emphasis on trade-offs, ambiguity, and real-world constraints mirrors the challenges of security professionals outside the classroom.
In the end, Cyber42 isn’t just a game, it’s a hands-on method of promoting balanced, collaborative decision-making skills that every security leader must possess.
Mark Orlando brings extensive cybersecurity leadership experience from the Pentagon, White House, and Fortune 500 sectors. As Bionic Cyber's CEO, he's a respected security operations expert with military and academic credentials.
Read more about Mark Orlando