Introducing: CyberArrange – A software tool for designing IT training systems and setting up cyber training grounds 

In cybersecurity, drills are conducted so that employees of organizations can acquire the necessary experience before an actual incident occurs. Since it is not advisable to run drills on real systems, they are carried out in simulated environments prepared by specialized experts. Preparing such drills is a very lengthy and complex task, and experts lose a great deal of time on repetitive technical tasks, making the drills expensive and time-consuming. CyberArrange enables experts to describe the basic guidelines of a drill and, based on those guidelines, automatically designs a random, realistic IT training system and creates a complete configuration for the simulation environment. In this way, experts can save weeks or months of work and focus on more important aspects of the drills, providing organizations with a better learning experience.

With the development of digital services and the digitalization of business processes, the risk of cybersecurity threats is increasing. According to some estimates, total damages caused by cyberattacks this year are expected to reach 8 trillion USD, with the potential to grow to more than 10 trillion USD by 2025. During the pandemic measures related to the COVID-19 virus, the number of cyberattacks increased by 33%. Although the growth in the number of attacks has somewhat slowed, it is not expected to stop, nor is the level of damage caused by attacks expected to decline. Accordingly, the cybersecurity solutions market has been growing continuously for two decades, from approximately 3.5 billion USD in 2004 to an estimated 45 billion USD today. The U.S. federal government plans to allocate 15.6 billion USD for cybersecurity in its budget, while Google has committed to invest 10 billion USD in developing new cybersecurity solutions. 

In addition to the high costs resulting from damages caused by cyberattacks, companies also face major problems due to the uncertain outcomes of such attacks. A Sophos study from last year shows that only 4% of organizations affected by ransomware attacks successfully recovered all their stolen or locked data after paying the ransom. The average ransom amount for organizations with 1,000 to 5,000 employees was 812,360 USD. Moreover, in 90% of cases, cyberattacks negatively affect a company’s ability to carry out regular operations, and in 86% of cases, they result in loss of business revenue. The median cost of recovery from an attack is 1.4 million USD, while the period of functional recovery lasts an average of one month. 

Building resilience of companies and other organizations to cyberattacks involves developing response protocols and conducting reaction drills in simulated training environments. However, due to the complexity and high cost of such environments, these drills are relatively inaccessible. Under such conditions, even large international organizations like NATO or the European Union are not able to organize more than one major drill per year. 

Preparing cybersecurity drills consists of two main components. The first is the labor-intensive programming of the training environment, and the second is the creation of the drill scenario and tasks. An example of such an environment is sketched in the image below. Due to the large amount of work required to prepare the training environment, the development of scenarios and tasks is often neglected. Moreover, because the preparation is so demanding, training environments are often recycled with minimal modifications, reducing their unpredictability and educational value. 

Illustration of the architecture of a sample training environment. The training environment includes, among other elements, simulated computers, users, software, data, and their interconnections.

CyberArrange is a solution that addresses this problem by automatically generating training environments for cybersecurity drills. Customers will enter the basic requirements of the drill they want, and the system will generate the necessary configuration for the training environment. In addition to saving them a significant amount of time, this will also allow them to focus their efforts on the more important aspects of the drills and thereby improve their quality. 

The organizers of ENISA’s Cyber Europe—the largest cybersecurity drill in the European Union—in their report on the most recent drill, conducted in December 2022, recognized the need to improve the training environment in order to meet future expectations and enhance the user experience and training of all participants. 

Using CyberArrange will shorten the time needed to prepare the training environment and free up work hours for the preparation of scenarios and tasks for cybersecurity drills. This can increase the frequency of drills, expand the space for creativity and innovation, and thereby increase the learning potential of such drills. The outcome of higher-quality drills will be greater resilience of companies to cyberattacks. 

Team members

The solution we are developing stems from the doctoral research of our Tech Lead, Ivan Kovačević. Ivan holds a Master of Engineering in Computing and works as a research associate at FER. He has years of experience in scientific research at FER and ICENT, and previously worked as a development engineer at several companies. In addition to his practical experience in developing cybersecurity solutions, Ivan is the author or co-author of several scientific papers in the fields of cybersecurity and data warehousing. 

Team members, from left to right: Marta Gračner, Ivan Kovačević and Luka Matić. The team also includes Matko Antun Bekavac and Assoc. Prof. PhD Stjepan Groš, who serves in an advisory role.

Alongside him, developer Marta Gračner works on development; she is a final-year computer science student writing her master’s thesis in cybersecurity. Marta has experience in developing backend software solutions used in the same field. 

Matko Antun Bekavac is a domain expert in cybersecurity and marketing. He completed his computing studies at TVZ, after which he spent four years in the Croatian Armed Forces working on cybersecurity for military systems. He then moved to the private sector, where he has spent the last four years working on software development, and has applied his knowledge of social engineering to the development of marketing strategies. 

Luka Matić is a non-technical team member responsible for applying agile methodologies and preparing project proposals. He is a doctoral student in philosophy, but he has spent the past seven years working professionally in project management and consulting in the area of EU funds. 

The team receives generous advisory support from Stjepan Groš, PhD, Associate Professor at FER. Professor Groš leads a number of research projects and teaches courses in computer, cyber, and information security. 

Motivation for Applying and Vision for the End of the Nuqleus Program

Our team was formed as part of the first phase of this year’s Nuqleus program and is currently developing a business strategy. From a technological perspective, most of the work was previously carried out by Ivan as part of his doctoral research. The greatest challenge we currently face is establishing team procedures and defining a medium-term business strategy. We expect to have an MVP by the end of the first quarter of 2024, and we should complete the product with all currently planned functionalities by the second quarter of 2025. 

03/04/2023