Defender Blue 2025 (DB25)
Advancing Cyber Deterrence & Resilience Through Specialized Training
A closed training session.
Dates of Training program: 17 to 24 November 2025
Training Course aligned to a six‑module structure (not by day) and embeds hands‑on labs using Splunk and Microsoft Sentinel.
Resources & Downloads
Access our presentations, guides, policies, and training materials to better understand our programmes and framework.
DB25 Modular Information
DB25 Presentation
DB25 Teams Roles & Responsibilities
DB25 Trainer Information
GDPR Privacy Notice
Certificates of participation for attendees who complete core training and capstone.
Overview
Advancing Cyber Deterrence & Resilience Through Specialized Training
A closed training session.
Dates of Training program: 17 to 24 November 2025
Training Course aligned to a six‑module structure (not by day) and embeds hands‑on labs using Splunk and Microsoft Sentinel.
Defender Blue 2025 is a remote, instructor-led cyber defense training for Blue Teams (BTs). It combines theoretical knowledge, hands-on technical drills, live adversary simulations, and a game-based capstone to strengthen detection, response, and recovery capabilities.
- Modality: Online (remote).
- Primary audience: SOC‑enabled entities with high real‑time cyber defence needs.
- Capacity: Up to eight (8) Blue Teams. Each team is NOT to exceed 10 people.
- Language: English (no translation provided.
- ISO 29993 Compliance Format.
Dates & Daily Schedule
A detailed Schedule of Events (SoE), administrative details, environment guidelines, and joining instructions will be issued well in advance for preparation and familiarization.
Mon 17 - Fri 21 / November 2025
Core Training
09:00–18:00 CET (UTC+1) each day
(includes lunch/coffee breaks)
Mon 24 / November 2025
Game‑Based Training
split into 09:00–13:30 and 14:00–18:30 CET (UTC+1)
(includes coffee breaks)
Training Design (What You’ll Do)
- Days 1–4 (17–20 Nov): Instructor‑guided, hands‑on labs and practical exercises in a live cyber‑range.
- Day 5 (21 Nov): “Live‑fire” challenge scenarios with structured evaluation and feedback.
- Capstone (24 Nov): Game-based training with instructor-mentored sessions (two periods), consolidating skills and measuring progress.
- For more see more the document DB25 Teams Roles & Responsibilities
- Also visit the DB25 Trainer Information for more information
- DB25 Presentation
Aim
Provide a unique, scalable training experience where Blue Teams learn the latest attacker tradecraft and practise advanced defence tactics, techniques, and procedures (TTPs) using a distributed cyber‑range. The training incrementally builds individual and team skills that can be applied immediately at tactical, operational, and strategic levels.
Focal Point Military-Grade Cyber Enduring Resilience
- Is not just another cybersecurity provider
- not just another cybersecurity training program
- comprehensive strategy, aligned with the principles of national defense and operational readiness
- A military cyber Defence ecosystem
- Minimum delegates: 30 Attendees
- Maximum delegates: 80 Attendees
- Delivery: Online (secure digital platform and Cyber Range tailored to the training audience, provided by Focal Point).
- Territory: UAE, KSA, Qatar, Bahrain, Kuwait, Oman and other states in the Middle East or Gulf Region.
- Other territories are open. Focal Point remains the right of acceptance. Note: Focal Point is already active in European and Asian countries and already provides similar training
Modular Course Information
- Module 1 – Threat Landscape, Targeted Intelligence & Scenario Design
- Module 2 – Phishing in Modern Threat Landscapes + Malware Triage & Analysis
- Module 3 – Establishing Foothold: Advanced Web Attacks & Detection
- Module 4 – Linux for Blue Teams: Logging, Persistence, Containers & Privilege Escalation
- Module 5 – Credential Access, Lateral Movement & Internal Reconnaissance
- Module 6 – Hybrid Attacks on ICS & Enterprise Infrastructures (Modbus Focus)
What you Gain
- Standard Training to Continuous Operational Readiness
- One-Off Sessions to a Continuous Security Evolution
- Theoretical Learning to Real-World Tactical Execution
- Generic Simulations to Custom-Built, Tailored Environments
- Individual Learning to a Cybersecurity Community of Excellence
- Traditional Training to Innovative Decision-Making Simulations
- Standard Tools to AI-Enhanced, Future-Proof Cyber Training
Participation & Technical Requirements
- Connectivity: reliable internet; ability to access an external VPN and web tools.
- Workstation: modern laptop/desktop (8 GB+ RAM recommended), updated browser, and admin rights or IT support for client installs (VPN/agent).
- Network: ability to allowlist exercise IPs/domains/ports as per joining instructions.
- A/V: microphone and headset; camera recommended for team coordination.
- Environment: quiet location suitable for sustained operations and team comms.
Team Roles & Responsibilities (Exercise Control)
- Blue Teams: defend the enterprise range; maintain CIA of services; sustain mission operations under attack.
- White Team: design scenarios, control execution, oversee scoring and learning outcomes.
- Red Team: act as instructors/adversaries; plan and execute attack chains; mentor detection/response.
- Green Team: operate the cyber‑range; provision environments; implement monitoring/logging and automated scoring.
Executive Value Mapping (Why This Matters)
- Protect operations and revenue by shortening time‑to‑detect and time‑to‑respond across the kill chain.
- Workforce development: build specialised Red/Blue/Purple skills; convert tools into outcomes.
- From monitoring to disruption: proactive detection engineering and incident response.
- Outcome metrics: uptime preserved, faster recovery readiness, reduced risk to reputation/compliance.
Post Seminar: What Focal Point Offers
- Training (Defender Series)
- Networking (Alumni)
- Advising (SAB)
- R&D (incl AI)
- Automated & controller scoring mapped to scenario objectives and ATT&CK coverage
- Performance report per BT, including strengths, gaps, and targeted recommendations
- After Action Review (AAR) and facilitated feedback session post exercise
- Certificates of participation for attendees who complete core training and capstone
Registration Process
Registration and payment are due by 7 November 2025, with late registration accepted until 12 November 2025 (23:59 CET) subject to a 10% penalty.
Defender Blue 2025 (Individual Registration Form)
Note: Upon your succesful registration, you will be send on your registered email, an invoice and payment link to pay on PayPal.
How to Apply
- Each Individual has to make an application and registration but ensure that each company has a group of 6 people per company.
- A payment link for the PayPal business will be sent along with an invoice via email to the registered individual user.
- Payment to be made and upon confirmation, a confirmation email will be sent to you.
Note: Any Cancellation of 10 or Less Days of the group or team will result to a penalty of 50% of the Fee. The Return amount will result to 50%
Eligibility & Selection & Pricing
Due to limited capacity, up to eight (8) BTs will be selected per iteration.
Strategy International (SI) will coordinate selections in collaboration with Focal Point (FP).
Priority is given to teams with active SOC functions and mission‑critical cyber defence responsibilities.
- Automated & controller scoring mapped to scenario objectives and ATT&CK coverage
- Performance report per BT, including strengths, gaps, and targeted recommendations
- After Action Review (AAR) and facilitated feedback session post exercise
- Certificates of participation for attendees who complete core training and capstone
Prices
Registration & Payment: 7 November 2025
Late registration: Until 12 November 2025
Note: This will include a 10% penalty increase plus VAT on the total price of 19%.
Please try to register by 7 November 2025 to avoid late registration fees
Pricing Details
Seminar Price Per person:
€9.000,00 + 19% of VAT per Attendee (Republic of Cyprus Tax apply).
Registration and Payment to be completed by 7 November 2025
Later Seminar Price Per person:
€9.000,00 + 19% of VAT per Attendee + 10% for late registration
(Republic of Cyprus Tax apply).
Registration and Payment to be completed by 12 November 2025
In case you wish to follow the seminar with more than one company (Each of 6 people) with no less than 5 companies as a group please email us at ewallerstrom@strategyinternational.org with the subject Group of Companies/6 per
Upon initial registration, an invoice will be sent to you to facilitate payment, along with an online payment link for payment.
Upon payment an email will be sent to you that payment has been completed by our associates.
Points of Contact (POCs)
Registration POC for Strategy International:
Emily Wallerstrom
+357 96886872
Who are we:
Focal Point (FP)
Focal Point (FP) is a trusted partner specializing in the design and delivery of cyber training programs of specialty. Established in Belgium since 2012 it includes, Certified cybersecurity specialists with many years of experience in NATO Best Practices, Techniques and Tactics, Consulting NATO Computer Incident Response Capability (NCIRC) for more than 8 years, Focusing on Cybersecurity and Cyber Risk Management Services and Assessments, Cyber Defense Exercises and Training, as well as Research & Innovation Initiatives. With an ISO 29993 for Quality requirements for learning services outside formal education, such as corporate training and professional development. It ensures transparency, consistency, and effectiveness in the design, delivery, and evaluation of learning programs.
Strategy International (SI)
Strategy International (SI) is a two pillar approach think tank and consulting company based in Cyprus. Strategy International provides risk analyses and assessments, collaborates with leading institutions and institutes, engages in networking events and creates events related to market professional and scientific awareness. In addition, SI also provides support with regards to public affairs, scientific and development process and project management and training, through our numerous engagements/ interactions with national and international experts in their respective fields. It is also a place for network and policy creativity. We are pioneering new and innovative ideas with the end goal of generating positive results and outcomes in policies and practices.