Home > Digital technologies > Cybersecurity > Serious games: train your cyber and IT teams through play

Serious games: train your cyber and IT teams through play

Published on 30 September 2026
Share this page :

Understanding a cyberattack in theory is one thing. Dealing with it in near-real conditions is quite another. Scenarios, simulations, decision-making… Serious games plunge IT professionals into the thick of the action, where experience and instinct count just as much as theory. Discover how serious games are transforming IT training into a real-life training ground.

Image: Serious game article

9.17 am. An alert is raised with the SOC: several accounts are showing unusual activity. A few minutes later, applications become unavailable and the support team receives its first calls. Should the network be isolated, a critical service shut down, or should senior management be notified? What if shutting down the system caused more damage than the attack itself?

In a course handout, the correct answer seems obvious. But with only partial information and the clock ticking, many teams find themselves hesitating.

That is what a serious game is for: to place IT professionals in a situation that closely resembles reality so that they can practise dealing with it before they are actually faced with it. The approach was first developed in the fields of cyber security and crisis management, and is now being adopted in ITSM, SRE and DevOps.

More frequent and faster attacks

In 2025, ANSSI handled 1,366 incidents, compared with 831 in 2022. Data breaches increased by 51 % in one year. Around 29 % of the exploited vulnerabilities were exploited on the day they were disclosed, or even before. ENISA has made the same observation at European level, with vulnerabilities being exploited just a few days after their disclosure.

According to the CESIN 2026 survey, 40 % of the organisations surveyed suffered at least one significant cyber-attack in 2025, and 81 % of the victims reported that their business operations had been affected.

For a safety manager, it is therefore not enough simply to know whether the teams are familiar with the procedure. It is also necessary to know whether they will apply it in a real-life situation, when several problems arise at the same time.

An analyst may know the solution to an incident but find themselves at a loss when faced with conflicting logs. An infrastructure manager may have a thorough grasp of their disaster recovery plan but realise, in the midst of a crisis, that they do not know who has the authority to suspend a service.

A serious game is not a video game

The term can be misleading. An IT serious game requires neither a virtual reality headset nor avatars.

It can take the form of a cyberrange, using real machines and isolated networks on which participants detect and counter attacks. It can also be a table-top crisis exercise, in which a team is gradually given information and must decide how to respond. It may also be based on a simulation digital, a jplayed a parta escape game online or a combination of several formats.

What matters is not the level of graphical sophistication, but the educational mechanics: an objective, a credible scenario, constraints, decisions and their consequences, followed by a debriefing.

The different formats of cybersecurity serious games

Format Principle Who is it for?
Table-top exercise Information provided step by step, collective decisions Crisis management team, management, business units
Cyberrange Real-world attacks on an isolated network SOC analysts, security experts
Role-playing game / escape game Puzzles and role-play, under time pressure Awareness-raising, team cohesion
Incident simulation Step-by-step re-enactment of a fault or incident Operations, SRE, support
CTF (Capture the Flag) Timed technical challenges to capture «flags» Technical profiles, young talent
Red team vs blue team One team attacks, the other detects and defends SOC, CERT, security teams
Game Day Failure induced under controlled conditions DevOps, on-call teams

Technical resources are less important than the realism of the scenario. An exercise that replicates the organisation’s environment, tools and constraints engages participants deeply, even with a simple set-up.

Lessons learnt from major exercises

You don’t wait until the day of a fire to find out the evacuation procedures. Cybersecurity is gradually adopting the same approach.

On 18 September 2025, ANSSI organised REMPAR25, which simulated a «digital blackout». 5,680 professionals from 1,263 organisations took part. And perhaps the most interesting figure is not even that one: 50 % of the participants did not work in either the digital sector or cyber security. This is an important lesson. A real cyber crisis never remains the sole responsibility of the CISO for long. Senior management, the CIO, business units, communications, legal, HR, business continuity and suppliers… all may be called upon to make decisions.

According to the feedback published by the agency, participants have a fairly good grasp of detection, incident response and internal communication. Crisis communication, on the other hand, is often improvised, business continuity is poorly planned for, and support functions are not sufficiently involved. 80 % of organisations plan to create or update their crisis management systems.

Another example: in June 2026, ENISA’s Cyber Europe 2026 exercise brought together more than 5,000 participants to simulate attacks on European rail and maritime networks. The teams had to manage complex technical issues, ensure service continuity and share information whilst under pressure.

Companies obviously do not need to replicate these large-scale exercises. But the principle can be applied in a similar way: put teams through a realistic scenario, observe what actually happens, and learn from any discrepancies.

CTF, red team and blue team

Capture the Flag (CTF) is the most common format for practising technical skills. Participants tackle timed challenges in cryptography, reverse engineering, web security and digital forensics to collect «flags».

In April 2026, ANSSI’s France Cybersecurity Challenge attracted more than 2,000 participants. It also serves to select the French team for the European Cybersecurity Challenge, to be held in Bochum in October 2026. The 2025 edition, held in Warsaw, brought together 39 teams, featuring one day of traditional challenges and one day of attack and defence exercises.

In a red team/blue team exercise, an attacking team (red team) mounts real attacks and a defensive team (blue team) must detect them, contain them and keep services running. A purple team can then bring the two sides together to improve the detection rules.

Locked Shields, organised in Tallinn by NATO’s Centre of Excellence for Cooperative Cyber Defence, operates on this model. In April 2026, more than 4,000 participants from 41 nations, divided into 16 multinational defence teams, protected critical infrastructure, air defence systems and electronic voting systems. And France performed well: the Franco-Swedish team finished third.

A company can adapt these formats to suit its own scale, for example by using a Internal CTF to identify technical profiles, or a red team exercise that tests the SOC within its own perimeter, sometimes without warning the team.

Turning knowledge into second nature

This is where the serious game differs from purely top-down training.

According to CESIN, 85 % of cyber security managers believe their staff are aware of the risks of phishing. Yet phishing remains the primary vector for successful attacks. Knowing best practice does not guarantee that it will be applied at the right time.

Rather than asking «What should you do when faced with ransomware?», the serious game forces the participant to make a decision. Should twenty workstations be isolated immediately, or should we wait for confirmation? Should remote access be cut off? Should the disaster recovery plan be activated? Each decision requires participants to draw on their knowledge, set priorities and accept the consequences.

A scenario can also be replayed by changing a parameter or testing a different decision, which allows the results to be compared. Any mistakes made then serve as a basis for the debriefing. This requires a well-designed scenario that is integrated into a training programme.

Learning to make decisions… but above all, learning to make decisions together

In a cyber crisis, individual expertise is not enough. We need to coordinate a number of specialists who do not share the same vocabulary or the same priorities.

The SOC is looking for indicators of compromise, the IT infrastructure team wants to ensure service availability, the business units are asking when the service will return to normal, and the communications team wants to know what it can announce.

A well-designed serious game recreates these tensions.

It highlights problems that a multiple-choice questionnaire fails to detect: escalation taking too long, information not being passed up to the crisis management team, two teams dealing with the same issue without coordinating with one another, or senior management interfering in technical decisions that it should delegate.

Training therefore develops team spirit, the ability to take a step back and operational instincts. It also helps us to gain a better understanding of other people’s roles. This is particularly valuable in organisations where certain teams only really collaborate when a major incident occurs.

The debrief: where learning really begins

In fact, the most valuable part of a serious game isn’t always the actual gameplay. It’s often what comes afterwards.

Why was this decision made? What information was missing? Who should have been notified? Which tools held us back? What would we have done if the incident had lasted three hours longer?

A debriefing transforms what can sometimes be a chaotic experience into a structured learning opportunity. It helps to distinguish between individual errors and organisational issues, and to turn observations into action: amending a runbook, clarifying a responsibility, or establishing a backup communication channel.

ANSSI incorporates this very approach into its crisis training resources. It offers a kit to replicate REMPAR25 within your organisation, using scenarios, timelines, observation checklists, logbook templates and a method for gathering feedback. The exercise therefore serves both to assess the organisation and to train staff.

Beyond cybersecurity, IT is a vast playground

The serious game approach is by no means limited to cyber-attacks.

In operations and ITSM, we can simulate a business application failure on a Monday morning, with an overloaded service desk and an external supplier to coordinate. We must then appoint an incident manager, assess the priority and decide when to escalate the issue.

SRE teams re-enact past incidents: an engineer explains, step by step, how he would carry out the diagnosis, without affecting production.

In DevOps, simulations highlight silos, bottlenecks and technical debt. A serious game tailored to DevOps, the Game Day, a practice derived from chaos engineering, is a simulation exercise that involves introducing a controlled failure to observe the real-time response of systems and teams in a secure environment.

The same logic can be applied to Agile project management, cloud migrations, business continuity and distributed architectures.

In all these cases, the approach is similar: to create a situation that is realistic enough to force participants to draw on their skills, yet controlled enough to allow them the freedom to try, fail and try again.

A few tips for success

The starting point must be the learning objective, not the format : improving technical troubleshooting, testing a crisis response team, facilitating collaboration between Dev and Ops, or preparing new recruits for on-call duty.

The level of immersion depends on this objective. A desk-based exercise is sufficient for initial awareness-raising, whilst a cyberrange is better suited to training SOC analysts.

The scenario benefits from reflecting the organisation’s structure, roles and procedures. Participants recognise their own day-to-day work in it, and the lessons learnt are easier to put into practice.

The assessment focuses on detection time, the appropriateness of escalations, the flow of information and the time taken to resolve the issue, rather than on the number of correct answers.

Finally, the exercise must be repeated. A single session raises awareness, whilst regular sessions help to develop muscle memory.

In a simulated environment, a bad decision costs almost nothing. CIOs and CISO can identify vulnerabilities that procedures and audits had failed to reveal. Operational teams can develop best practices without having to wait for the next incident. And training managers have a tool where learners take action rather than just listening.

It’s best for everyone to know their role before the game gets underway.

Our experts

Made up of journalists specialising in IT, management and personal development, the ORSYS Le mag editorial team [...]

field of training

associated training