As cyber threats grow in complexity and scale, many security incidents remain poorly managed due to the lack of proper training among C-level executives. Thus, there is a need for targeted cybersecurity education to enhance executive decision-making and crisis response. Traditional training methods, such as cyber wargames and Tabletop Exercises (TTX), aim to develop abilities to face critical incidents, however, they often lack the interactive and dynamic elements required to prepare individuals for real-world cyber incidents. This paper presents a novel approach to cybersecurity and cyberdefense education through the design of a specialized hybrid TTX for the maritime domain, which uses a framework to model mathematically how a cyberattack spreads along multiple nodes and impacts infrastructure. Our proposal was validated through exercises in Argentina and the United States, demonstrating a positive impact in developing the comprehension and projection levels of Cyber Situational Awareness (CSA), and reinforcing governance. Documentation about the Hybrid TTX, scenario, datasets and implementation of the SERDUX-MARCIM model, is available at the project repository at https://github.com/diegocabuya/SERDUX-MARCIM
翻译:随着网络威胁日益复杂且规模不断扩大,由于企业高层管理人员缺乏适当培训,许多安全事件仍得不到妥善处理。因此,需要开展有针对性的网络安全教育,以提升高管的决策能力和危机应对水平。传统培训方法(如网络兵棋推演和桌面推演)旨在培养应对关键事件的能力,但往往缺乏必要的互动性和动态要素,难以使受训者为真实网络事件做好充分准备。本文提出了一种网络安全与网络防御教育的新方法,通过为海事领域设计专门的混合桌面推演来实现。该推演采用一个框架,通过数学模型模拟网络攻击如何在多个节点间传播并影响基础设施。我们在阿根廷和美国开展的推演验证了本方案的可行性,结果表明该方法对提升网络态势感知的理解与预测水平具有积极作用,并能强化治理能力。关于混合桌面推演、场景设置、数据集以及SERDUX-MARCIM模型实现的详细文档,可在项目代码库https://github.com/diegocabuya/SERDUX-MARCIM中获取。