Skip to content
CyberBench
Early accessCyberBench

Know what your security team
can actually do.

CyberBench turns hands-on labs into skill KPIs: per person, per team, per capability. Measured on real work, not certificates or self-assessments.

Blue team · Q3 readiness

Live

Role coverage

0%

+6 pts this quarter

Capabilities mastered

0

+14 this quarter

Single points of failure

0

3 critical

Fading skills

0

no practice for 120 days

Mastery by person and capability

Phishing triage · M365Lateral movement · ADMemory forensics · WindowsWeb shell hunting · IISRansomware IR · ESXiSigma rules · SysmonCloud logs · AWSKerberoasting · AD
Léa M.
Karim B.
Sofia R.
Tom D.
Inès C.
Hugo L.
Nora V.
Not yetMastered

Team coverage, last 12 weeks

Ransomware IR · ESXi
Kerberoasting · AD
Cloud logs · AWS

The problem

You can't manage what you can't see.

01

Certificates age badly

A certification says what someone passed years ago, on a syllabus that wasn't yours. It doesn't say what they can do on your stack today.

02

Self-assessments flatter

Skills matrices filled in by the team are optimistic where it matters least and silent on the gaps that hurt.

03

Gaps show up in incidents

The day you find out only one person can investigate your Active Directory is the day they're on holiday.

How it works

From the work people do to the numbers you report.

  1. 1

    Map roles to capabilities

    Pick the roles you staff (SOC analyst, pentester, cloud engineer) and the capabilities each needs, from a shared skills graph: actions on the technologies you actually run.

  2. 2

    Your team practises on real labs

    Realistic red and blue team labs run on each person's machine. Every lab exercises precise capabilities and is proven with per-person evidence that can't be copied.

  3. 3

    Get live KPIs

    Mastery is tracked per person and capability, decays without practice, and rolls up into team coverage, gaps and trends you can show your board.

KPIs

The numbers a CISO actually needs.

Coverage against role targets

For each role, the share of required capabilities the team masters, and which ones are missing.

Single points of failure

Critical capabilities only one person masters. The bus factor of your security team, made visible.

Skill decay alerts

Mastery fades without practice. Know which capabilities need a refresh before you need them.

Time to mastery

How long people take to master a capability, so training plans rest on data, not hopes.

Training that targets gaps

Each gap links to the right Cyber Courses lesson or lab. Spend your training budget where it moves the numbers.

Hiring benchmark

Candidates take the same labs as your team. Compare on the same scale, at the capability level.

Method

Measured, not declared.

Every number comes from evidence: a lab is passed by bringing back an artefact that only exploiting or investigating the system reveals, unique to each person.

Skill×Product=Capability

Capabilities, not buzzwords

A capability is a precise action on a precise technology, e.g. exploiting blind SQL injection on PostgreSQL. That is the unit we measure.

Bayesian knowledge tracing

Each person has a mastery probability per capability, updated with every attempt. One lucky success doesn't make an expert.

Mastery fades

Without practice, the estimate decays. Your dashboard shows today's level, not last year's.

Related skills inform each other

Mastering a capability on one technology raises the estimate on its neighbours, so the map fills in faster than people take labs.

Trust

Built for teams, not surveillance.

  • People see their own results first.
  • You decide which views managers get: team-level by default.
  • Labs run on your people's machines; no production access needed.

See your team's real level.

CyberBench is in early access with a small number of security teams. Tell us about yours.

Request early access