Training Analysts Without Making the News
Traditional cybersecurity education often teaches incident response through isolated exercises that bear little resemblance to the realities of a modern Security Operations Centre (SOC). Real incidents are messy, time-sensitive, and require technical expertise, critical thinking, and effective teamwork.
This talk introduces Nordvakt, an enterprise SOC simulation platform developed over more than a year and shaped by six years of teaching digital forensics and incident response. Every aspect of the platform has been designed around sound pedagogical principles and informed by observing how students learn, where they struggle, and what helps them develop into confident incident responders.
Rather than completing scripted labs, students investigate realistic cyber incidents using logs, memory captures, network traffic, endpoint telemetry, and digital evidence. They triage alerts, document their findings, make investigative decisions, and experience the complete lifecycle of an incident in an environment that reflects modern security operations.
This session explores the educational philosophy behind Nordvakt, the challenges of designing authentic investigative scenarios, and the lessons learned from building a simulation that places learning—not technology—at its core.
