Skip to main content

Applications now open for Digital4Security microcredentials. LEARN MORE

Cyber Range Scenario Design

Key information

  • Application opening date: July 30, 2026
  • Next application deadline: September 25, 2026
  • Next course starts: October 1, 2026
  • Format: Fully online, asynchronous and synchronous
  • Course duration: 8 weeks
  • Language: English
  • Awarding Institution: Brno University of Technology
  • Delivered by: Brno University of Technology, POLITEHNICA Bucharest, CYBER RANGES
  • Certified by: Brno University of Technology
  • EQF Level: 6 / QF EHEA 1
  • ECTS: 3 ECTS (78 hours of total student workload, including 12 hours of synchronous online lectures and 66 hours of asynchronous self-directed learning).
  • Fees: €210

Microcredential Information

This microcredential is designed for cybersecurity professionals, educators, and aspiring cyber range developers who want to gain both the theoretical foundations and practical skills required to design engaging, realistic, and effective cyber security training scenarios.

What makes this microcredential unique is its combination of academic excellence and real-world industry expertise. The curriculum is jointly delivered by Brno University of Technology, Politehnica University of Bucharest, and the industry partner CYBER RANGES, ensuring that participants learn not only the latest research and educational methodologies but also proven practices used in professional cyber range environments.

Throughout the course, participants progress from cybersecurity fundamentals and gamified learning principles to advanced scenario design, Capture the Flag (CTF) development, AI-assisted content creation, and the deployment of training environments on the Brno University of Technology Cyber Arena (BUTCA) platform. The course culminates in a collaborative project where participants design and implement their own cyber range scenario, applying both technical and pedagogical principles in practice.

By completing this microcredential, participants will be able to create realistic, engaging, and pedagogically effective cyber security exercises for learners with different experience levels, making them valuable contributors to cyber security training programmes in academia, industry, and public institutions.

Key Details

Time Commitment

Approximate Total Workload: 78 hours (3 ECTS)

The micro-credential is designed to fit around professional and personal commitments through a blended online learning approach. Participants will complete:

  • Optional live online lectures: 12 hours
  • Independent practical exercises (BUTCA Cyber Range): 12 hours
  • Practical Team Project: 40 hours
  • Private study, online consultations, and examination preparation: 14 hours

Assessment

Grading Breakdown:

50% Practical Team Project

Participants work in teams of 3–4 to design and implement an original cybersecurity scenario within the BUTCA Cyber Range. The project is presented during a final online defence, where each team member demonstrates their individual contribution and the overall solution.

50% Online Examination

A proctored online examination evaluates participants’ understanding of the theoretical concepts and practical skills covered throughout the module. The exam is conducted online with instructors present and includes questions covering all module topics.

Passing Requirements

To successfully complete the micro-credential, participants must achieve at least 50% in each assessment component (the online examination and the project defence).

Subjects covered

Week 1 – Gamified Cyber Security Training: This lecture provides an introduction to gamification in cyber security training, its principles, needs, benefits, requirements and possible career pathway. Participants will learn why and how gamification and scenario design are pedagogically effective. They will be introduced to basic cybersecurity training providers e.g., SANS, EC-Council, Offensive Security, available cyber security contests, pentesting labs and vulnerable boxes. Participants will also be introduced to basic terms such as InfoSEC color wheel, bug bounty, CTFs and cyber ranges. Finally, participants will learn ethics in cybersecurity training, covering responsible disclosure, simulation realism, and unintended harm.

Week 2 – Cybersecurity Fundamentals: This lecture provides basic content on the fundamentals of cybersecurity. Participants will learn about basic cybersecurity vulnerabilities and attack vectors. They will also gain hands-on experience working with core cybersecurity tools such as Kali Linux, Metasploit, Splunk, ELK Stack, Wireshark, Snort, and Suricata. With MITRE ATT&CK, participants will learn how attackers really work—their goals (tactics), tools, and methods (techniques), and how they persist in networks.

Week 3 – Methodology and Trends in Scenario Design: This lecture provides a strategic overview of scenario design for cyber exercises, emphasizing methodologies that drive realistic, impactful training experiences. Participants will learn to structure scenarios that reflect contemporary threat landscapes, integrating technical, operational, and strategic dimensions to prepare teams for complex cyber challenges. Participants will learn how to choose from the different exercise formats, understand the trends, addressing target audience maturity, realism, gamification and evaluation aspects.

Week 4 – Capture the Flag Concepts & AI/ML: This lecture will discuss CTF concepts and platforms e.g., CTFd.io. Participants will learn about the design and deployment of CTF and Vulnerable Box Challenges. In addition, participants will learn about other automation tools suitable for the design of cyber rangers, including the possibilities of using Artificial Intelligence (AI).

Week 5 – Introduction to BUTCA: This lecture aims to introduce participants to the Brno University of Technology Cyber Arena (BUTCA) platform. Participants will learn about the technological architecture of the BUTCA platform, its functioning, requirements and deployment options. Participants will also learn about the functional capabilities of the platform, the user graphical interface, the principle of operation of game scenarios, and how to incorporate real-time participant analytics.

Week 6 – Scenario Design in BUTCA: Within this lecture, participants will learn how to create new game scenarios in BUTCA, the resulting knowledge will lead to projects focused on developing new game scenarios in BUTCA. In the projects, participants will collaborate in groups, with one of the participants acting as the group leader coordinating the group, reporting on the progress, and results of the joint work.

Learning objectives

Knowledge – The graduate can:

• define basic terminology in the field of cybersecurity, basic security vulnerabilities and attack vectors

• explain current methods and trends in game scenario design and their implementation

• describe the role of gamification in cybersecurity education by evaluating platforms like cyber ranges, bug bounty programs, and cybersecurity contests

• evaluate and adapt methodologies for designing cybersecurity training scenarios, integrating emerging trends and real-world attack behaviours.

Skills – The graduate can:

• design and implement a Capture The Flag (CTF) challenge using platforms like CTFd.io or BUTCA, incorporating vulnerable boxes and realistic attack scenarios

• develop an interactive cybersecurity game scenario within the BUTCA platform, leveraging twin scenarios to simulate attack and defence strategies

• independently create a new cybersecurity training scenario as a semester-long project in BUTCA, demonstrating the ability to synthesize game mechanics, attack tactics, and defensive strategies into an engaging learning experience.

Competence – The graduate can:

• think creatively and work independently

• plan and organize their own activities

• collaborate effectively within a team

• assess and address security requirements defined by the target group

• design training with an appropriate game-based scenario tailored to the needs of the target group.

Module leaders

Name: Petr Dzurenda

Title: Dr.

Organisation:  Brno University of Technology

Dr. Petr Dzurenda

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Apply now
Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Apply now Toggle