Capability portfolio
Build capability through connected learning and realistic practice.
Choose one capability or combine them into mission-specific pathways. Every module shares identity, policy, evidence and readiness services.
CLIP · Shared foundation
Illustrative view- Identity
- Policy
- Range orchestration
- Telemetry
- Evidence
- Analytics
Every capability inherits these services rather than reimplementing them.
The portfolio
Six capabilities, one governed foundation.
Cyber Range & Wargaming
Rehearse realistic cyber missions without risking operational systems.
SOC & DFIR Simulation
Turn telemetry into defensible incident decisions.
Secure Development & DevSecOps
Connect adversary insight to secure product engineering.
Agentic AI Training
Adaptive cyber training, bounded by policy and accountable to humans.
Workforce & Readiness
Replace attendance metrics with defensible readiness evidence.
Cryptography & Crypto-Agility
Build practical cryptographic competence and prepare for controlled change.
Progression
From foundation to mission rehearsal.
Difficulty increases with supervision, blast radius and the level of evidence required — not simply with tooling complexity.
- 01FoundationConcepts and guided practice.
- 02Guided labSupervised, checkpointed tasks.
- 03Team labCoordination within a role.
- 04Integrated exerciseMulti-team, correlated timeline.
- 05Mission rehearsalFull exercise control and adjudication.
In sequence: Foundational knowledge leads to guided laboratories, then team laboratories, then integrated multi-team exercises, and finally mission rehearsal under full exercise control.
Combination examples
Capabilities combine into role pathways.
These are illustrative starting points. Pathways are built from your approved role profiles and competency framework.
SOC analyst pathway
- Foundations
- SOC simulation
- Purple validation
- Readiness assessment
Secure product engineering pathway
- Foundations
- Secure development
- Exploit-to-fix
- Supply-chain assurance
Cyber crisis leadership pathway
- Role briefing
- Tabletop exercise
- Multi-team wargame
- Decision assessment
DFIR investigator pathway
- Foundations
- Evidence handling
- Forensic analysis
- Case adjudication
Shared foundation
What every capability inherits.
Because these services are shared, evidence from one capability is usable by another without a translation layer.
Identity
Federated authentication with role and attribute conditions.
Policy
Centralised decisions for tools, targets and approvals.
Range orchestration
Approved templates, isolation and lifecycle control.
Telemetry
Normalised events with exercise and time-quality context.
Evidence
Immutable originals, provenance and chain of custody.
Analytics
Learner, team, readiness and platform views by authorization.
Optional modules
Domain extensions.
Added where a mission requires them, each with its own safety review and deployment considerations.
- OT/ICS training environments with explicit safety modelling
- Cloud security scenarios across identity, workload and configuration
- Mobile application and device security laboratories
- IoT and embedded device analysis
- AI security: model, prompt, tool and supply-chain risk
Evidence
Every capability produces reviewable evidence.
- Cyber Range & WargamingObjective completion against the exercise plan
- SOC & DFIR SimulationDetection timeline with contributing telemetry
- Secure Development & DevSecOpsThreat model and identified misuse cases
- Agentic AI TrainingPrompt, context reference, model and version
- Workforce & ReadinessRole requirement and its version
- Cryptography & Crypto-AgilityCryptographic inventory with dependency mapping
Build a capability roadmap.
We will map your roles and missions onto a sequence of capabilities with realistic phasing.