Field guide · Explainer
Cyber range vs tabletop exercise vs hands-on labs
Labs build individual skills. A cyber range tests whether a technical team can detect and contain an attack on real tooling. A tabletop or crisis simulation tests whether the people who own decisions can make them in time. Awareness training changes everyday employee behaviour. Choose by the gap you need to close, not by the platform.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
8-1How do the formats compare?
| Format | What it tests | Who it trains | Typical length | Evidence produced | Example platforms |
|---|---|---|---|---|---|
| Hands-on labs | Individual technical skills | Analysts, engineers, developers | Minutes to hours, self-paced | Completion and performance per person | Immersive Labs, Hack The Box, TryHackMe, Cyberbit |
| Live-fire cyber range | Detection and response by a team on real or realistic tooling | SOC and IR teams | Hours | Detection and response telemetry, team performance | Cyberbit, Immersive Labs (Dynamic Threat Range) |
| Tabletop exercise (discussion-based) | Plans, roles and decisions | Incident commander, legal, communications, executives | 2–3 hours plus planning | Notes and an after-action report | CISA CTEP templates, Hack The Box Crisis Control, TryHackMe, Conducttr |
| Crisis simulation (adaptive) | Decisions under pressure as the scenario reacts | The same group, often with more roles | Around an hour on some platforms | Decision record and generated report | Reflex Security, Immersive Labs Crisis Sim, iluminr, Cyberbit Crisis Sim 360 |
| Awareness training | Everyday behaviour such as phishing reporting | Every employee | Minutes per module | Completion and phishing-simulation rates | KnowBe4 |
8-2What is the difference between a tabletop and a crisis simulation?
A classic tabletop is a facilitated discussion: players read a scenario and say what they would do, and the facilitator releases scripted injects. A crisis simulation keeps the same audience but changes the mechanics: the scenario reacts to what players decide, information arrives through simulated channels, and the platform records decisions for the report. Several vendors in this guide use both terms. Reflex Security positions its product as a replacement for the tabletop; Immersive Labs, Cyberbit and iluminr call theirs crisis simulations; Hack The Box and TryHackMe call theirs tabletop exercises.
8-3When is a cyber range the right answer?
When the problem is technical: slow detection, missed lateral movement, uncertain containment steps. A range puts analysts against an attack on tools like the ones they use every day. It does not test whether legal and communications can agree a statement. See What is a cyber range.
8-4When is a tabletop or crisis simulation the right answer?
When the problem is coordination: who declares the incident, who decides on disclosure, who talks to customers and regulators, who can approve shutting down a system. These are the decisions an incident review usually finds were slow.
8-5Do you need more than one?
Most security organizations need at least two: labs or a range for the technical team, and a tabletop or crisis simulation for the decision-makers. Awareness training is a separate budget line for everyone else. The exercise matrix shows which vendors cover which combinations.
8-6Frequently asked questions
Is a cyber range the same as a capture-the-flag (CTF)?
No. A CTF is a competition of puzzles and challenges, usually solved individually or in small teams. A range simulates an organization's environment for a team to defend.
Can a tabletop exercise include technical work?
Some do. Hack The Box Crisis Control can add optional hands-on investigation, and Cyberbit Crisis Sim 360 feeds SOC findings into executive decisions.
Next lesson: Who should be in a cyber tabletop exercise, and what each seat is for