#spacecollectivedefense

Operation Electro Magnetic Panic

A scenario-driven cybersecurity exercise built around an EU ground-infrastructure crisis, contributed to the organizations that keep critical infrastructure running.

  • Format: 8 challenges, 7 run in 2025
  • Fee: None
  • Delivery: Self-run or hosted
  • Prerequisites: None

Five stations, and only one of them sees the whole attack

An electromagnetic pulse of unknown origin has disrupted EU infrastructure. Power grids collapse across multiple countries. Communications black out. Only five strategic European ground stations remain operational. Five teams, each holding one station, defend AI-enabled space infrastructure under escalating adversarial pressure: deploying secure AI systems, implementing cryptographic protection, mapping controls to governance frameworks, proving those controls are enforced, attacking their own deployment, remediating what they find, and coordinating intelligence across the group.

Run once, on 17 October 2025 in Madrid, with five EU ground-station teams and 21 professionals certified under a pilot micro-credential aligned to the NIST NICE Framework. This pack is that exercise, contributed so any organization can run it themselves or request it hosted, see Hackathon-as-a-Service.

What each challenge assesses

#ChallengeWhat it assesses
01RAG on the GroundDeploying a secure, authenticated AI retrieval system under time pressure
02Secure the SignalEncryption in transit and at rest, with an optional post-quantum track
03Map the MindSelecting and justifying control objectives against real exposure
04Prove the ProtectionsProducing evidence that a control is enforced, not just written down
05Prompt the BreachAdversarial testing of the team's own deployment
06Patch the PathRemediating a high-severity finding, with before and after evidence
07METEORSTORMDistributed intelligence sharing across five independent teams
08HETNET Mesh CompromiseJamming, spoofing, and replay against AI-driven link selection. Written, not run in 2025

Challenge 08 was written but never run. It is listed, and its brief is published below, because an exercise record that reports only what went well is not evidence of an assessment.

Download the challenge briefs

All eight briefs, exactly as written for Madrid. Each carries the objective, the required capabilities, the scoring model, and the checks a mentor evaluated against. Seven were run; the eighth is marked. No fee, no registration, no email required.

Challenge 08 was written but never run. The teams did not reach it inside the event window, so unlike the others it has never been tested against a room. It is published as written. Treat its timings as unproven and expect to adjust them.

Setup scripts

Two challenges ship with a script so a team spends the hour on the security problem rather than on installing things. Neither is a finished answer: Challenge 01 says plainly that the baseline it stands up must then be reviewed and hardened by the team, which is most of the marks.

Both take their API keys from the environment and ship with an empty .env template. Read them before you run them, as you would with any script off the internet.

Running it and want the scoring model, mentor guidance, or a hand setting up the shared MISP and telemetry infrastructure Challenge 07 needs? Ask, and we will send it. That costs nothing either.