#spacecollectivedefense

Hackathon-as-a-Service

Not us running an event for you. Us helping you build the capability to run it yourself, and keep running it. A working session in which we establish the roles, the responsibilities and the open-source tooling your organization needs to plan, run and document its own cybersecurity exercise. Afterwards you can run it again without us, which is the point.

  • Format: A scoping call, then a half day, about four hours
  • Mission target: 12 to 24 support missions a year, taken on a rolling basis
  • You leave with: A roles and responsibilities matrix, and the recommended tooling list
  • Fee: None. No payment details are collected

Three things, written down

  • Roles. Which functions must be represented for an exercise to mean anything, and who in your organization fills each one. Most plans fail here, by rehearsing detection with the people who detect and leaving out the people who decide.
  • Responsibilities. Who decides, who executes, who reports. The authority to contain, the authority to recover and the obligation to notify, assigned to named roles rather than to a team.
  • Tooling. The two tools H3 deploys for you, chosen so the capability stays yours: MISP, which is open source, and Maltego Community Edition, which is proprietary though it carries no charge. H3 writes a deployment guide for each.

The obligation behind it

NIS2 asks for more than written risk-management measures. It requires assessing whether they actually work, and places incident handling and crisis management among the measures in scope. An exercise is the practical way to carry out that assessment, with your own staff, in the roles they hold at work. The provisions are set out in full on the main page.

We deliver this under our mission as a Luxembourg non-profit and an accredited vocational training organiser, to support NIS2 readiness across EU critical infrastructure. It is offered to organizations in the EU that need support with NIS2, to the global Space ISAC community, and to any academic, commercial or government organization in a critical infrastructure sector.

Requesting a session

Tell us your organization, roughly how many people would take part, and when suits. We reply to arrange the scoping call. Nothing is charged and no payment details are collected. If you would rather do it alone, the whole method is published on the portal and asks for nothing in return.

Neither an exercise nor a Hackathon-as-a-Service mission carries any requirement to donate, expected or implied, and no request is weighted by whether you do. We are a non-profit funded by our training work and by donations, which are welcome and are never a condition of anything here.