Blue Teaming
diskordia,
Mar 27
2025
In the world of cybersecurity, static assessments and certifications often create a false sense of security. Threats evolve fast—and so should your team.
That’s the main inspiration behind our second Benchmarking Masterclass webinar, From Theory to Action: Applying dynamic benchmarking to real-world threats.
This session gets into the meat of how organizations can implement dynamic benchmarking to build and refine a truly resilient security team, and explores how Capture The Flag (CTF) exercises—sometimes seen as just a fun team-building activity—are actually powerful benchmarking tools.
Missed the live session? Don’t sweat it. We’ve got the recording ready for you on-demand, and we’ve even picked out some of the juiciest takeaways just for you to read up on below.
Traditional training (bootcamps, instructor-led, etc) and one-off assessments can certainly be useful. But let’s be real: they don’t necessarily reflect how your team performs in high-pressure, real-world scenarios. Cyber threats don’t follow a script, so your training shouldn’t either.
“To stay ahead, companies need a culture of continuous learning and skill development. Success comes from making training a priority—whether through Capture The Flag (CTF) exercises, benchmarking, or structured training plans. Providing employees with opportunities to upskill will lead to better results for both them and the company.” —Anthony Wilkinson, Solution Engineering at Hack The Box
Security leaders often fall into the trap of measuring theoretical knowledge rather than practical capability. The ability to recall (or parrot) concepts on an exam doesn’t equate to real-world problem-solving under attack conditions.
Cyber resilience in the face of today’s threat landscape calls for repetition, refinement, engagement, hands-on practice, and the ability to adapt to ever-changing threats.
Dynamic benchmarking—built around continuous skill assessments—ensures that your team isn’t just trained but battle-ready. The organizations leading the way in cyber resilience test their teams constantly, not just once a year.
Capture The Flag exercises aren’t just for fun. They’re one of the most effective ways to benchmark cybersecurity skills at scale.
Think of them as cybersecurity flight simulators—letting teams experience real-world attack and defense scenarios in a controlled environment. They allow teams to:
Expose strengths and weaknesses in real time, offering a clear skills gap analysis.
Practice responding under pressure, mimicking real incident response situations.
Gain hands-on experience across a wide range of security disciplines, from forensics to web exploitation to cloud security.
Get measurable, actionable data to track skill progression over time.
The impact of CTFs goes far beyond technical training. They help build a culture of problem-solving, forcing security teams to think critically, collaborate under pressure, and apply their skills dynamically.
Unlike traditional training methods, which often focus on passive learning, CTFs demand active engagement—and that’s where the real magic happens.
“There are people that pride themselves on being very good at CTF events. They train on CTFs because they’re competitions—but we can also flip that and turn them into a benchmarking exercise. How you leverage this very dynamic tool really depends on your approach as a business owner, a product owner.” —Anthony Wilkinson, Lead Solutions Engineer at Hack The Box
Organizations that integrate CTFs into their benchmarking strategy don’t just train their teams—they future-proof them.
But where to start? Jack and Anthony have you covered. Here’s a practical 5-step framework you can use to bring dynamic benchmarking into your organization:
Clearly define goals: Identify what you’re measuring: defensive skills, incident response time, cloud security knowledge?
Start with a proof of concept: A simple CTF can showcase impact without heavy investment.
Make the most of pre-built challenges: Platforms like Hack The Box offer customizable content packs to fit your specific needs.
Assess and report: Use built-in reporting tools to analyze team performance and benchmark over time.
Iterate and refine: Tweak challenge difficulty, focus on skill gaps, and ensure continuous learning.
Follow this approach, and you’ll be empowered to turn benchmarking from just another checkbox exercise into a core part of your workforce development strategy.
…And your training strategy should reflect that. To that end, organizations can choose from pre-built content or fully customize their own CTFs using an extensive challenge library. This adaptability means that no matter your security focus—cloud, network, red teaming—you can benchmark the skills that matter most. On top of that, CTFs give you a tangible way to measure performance improvements over time, with data-driven insights that drive better hiring, training, and retention strategies.
Watch the full webinar for a deep dive into a real-world CTF exercise showcasing:
Defensive-focused challenges designed to build blue team skills.
Collaboration tools that allow teams to work together seamlessly.
Challenge assessments to understand how teams tackle problems.
Reporting tools that provide clear insights on individual and team performance.
5. Getting started with your first dynamic benchmarking exercise
If you’re new to operationalizing benchmarking, here’s how to kick things off in 10 minutes or less Loading Preview...
Start with an internal CTF event.
Use pre-built challenges available on the platform to slash setup time.
Track performance before, during, and after to measure improvement.
Scale up based on insights (target weaknesses, reinforce strengths).
Done right, CTF-based benchmarking is more than just another training exercise—it’s a strategic advantage that can identify vulnerabilities, reinforce critical skills, and build a security-first mindset that extends well beyond the SOC.
With the right strategy in place, skills benchmarking becomes a continuous process, not a one-time checkbox situation.
This session focused on applying dynamic benchmarking. In our final masterclass, we’ll take it even further—turning benchmarking results into tailored workforce development plans.
Join us for the third and final Benchmarking Masterclass. Learn how to turn insights into action and build a cyber-ready team for the long haul.
And don’t miss the upcoming Global Cyber Skills Benchmark 2025 Loading Preview...