Operation Electro Magnetic Panic
A scenario-driven cybersecurity exercise built around an EU ground-infrastructure crisis, contributed to the organizations that keep critical infrastructure running.
- Format: 8 challenges, 7 run in 2025
- Fee: None
- Delivery: Self-run or hosted
- Prerequisites: None
Five stations, and only one of them sees the whole attack
An electromagnetic pulse of unknown origin has disrupted EU infrastructure. Power grids collapse across multiple countries. Communications black out. Only five strategic European ground stations remain operational. Five teams, each holding one station, defend AI-enabled space infrastructure under escalating adversarial pressure: deploying secure AI systems, implementing cryptographic protection, mapping controls to governance frameworks, proving those controls are enforced, attacking their own deployment, remediating what they find, and coordinating intelligence across the group.
Run once, on 17 October 2025 in Madrid, with five EU ground-station teams and 21 professionals certified under a pilot micro-credential aligned to the NIST NICE Framework. This pack is that exercise, contributed so any organization can run it themselves or request it hosted, see Hackathon-as-a-Service.
What each challenge assesses
| # | Challenge | What it assesses |
|---|---|---|
| 01 | RAG on the Ground | Deploying a secure, authenticated AI retrieval system under time pressure |
| 02 | Secure the Signal | Encryption in transit and at rest, with an optional post-quantum track |
| 03 | Map the Mind | Selecting and justifying control objectives against real exposure |
| 04 | Prove the Protections | Producing evidence that a control is enforced, not just written down |
| 05 | Prompt the Breach | Adversarial testing of the team's own deployment |
| 06 | Patch the Path | Remediating a high-severity finding, with before and after evidence |
| 07 | METEORSTORM | Distributed intelligence sharing across five independent teams |
| 08 | HETNET Mesh Compromise | Jamming, spoofing, and replay against AI-driven link selection. Written, not run in 2025 |
Challenge 08 was written but never run. It is listed, and its brief is published below, because an exercise record that reports only what went well is not evidence of an assessment.
Download the challenge briefs
All eight briefs, exactly as written for Madrid. Each carries the objective, the required capabilities, the scoring model, and the checks a mentor evaluated against. Seven were run; the eighth is marked. No fee, no registration, no email required.
- 01 RAG on the Ground PDF · 41 KB
- 02 Secure the Signal PDF · 43 KB
- 03 Map the Mind, Apply AICM PDF · 50 KB
- 04 Prove the Protections PDF · 51 KB
- 05 Prompt the Breach PDF · 43 KB
- 06 Patch the Path PDF · 49 KB
- 07 METEORSTORM PDF · 85 KB
- 08 HETNET AI-Enabled Mesh Compromise PDF · 85 KB · not run in 2025
Challenge 08 was written but never run. The teams did not reach it inside the event window, so unlike the others it has never been tested against a room. It is published as written. Treat its timings as unproven and expect to adjust them.
Setup scripts
Two challenges ship with a script so a team spends the hour on the security problem rather than on installing things. Neither is a finished answer: Challenge 01 says plainly that the baseline it stands up must then be reviewed and hardened by the team, which is most of the marks.
- 01 RAG baseline deployment (Docker, Qdrant, FastAPI) SH · 29 KB
- 02 Kyber post-quantum container (liboqs, oqs-python) SH · 5 KB
Both take their API keys from the environment and ship with an empty .env template. Read them before you run them, as you would with any script off the internet.
Running it and want the scoring model, mentor guidance, or a hand setting up the shared MISP and telemetry infrastructure Challenge 07 needs? Ask, and we will send it. That costs nothing either.