{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T15:33:46Z","timestamp":1781710426860,"version":"3.54.5"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,3,15]],"date-time":"2025-03-15T00:00:00Z","timestamp":1741996800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,3,15]],"date-time":"2025-03-15T00:00:00Z","timestamp":1741996800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"AIT Austrian Institute of Technology GmbH"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Cyber exercises enable the effective training of cyber security skills in a simulated, yet realistic, environment for a wide variety of professional roles. However, planning, conducting, and evaluating customized (i.e., non-standard) cyber exercise scenarios involves numerous time- and resource-intensive activities, which are still mostly carried out manually today. Unfortunately, the high costs related to these activities limit the practical applicability of cyber exercises to serve widely as a regular tool for skill development. Cyber exercise scenarios typically involve a sequence of predefined and carefully planned injects (e.g., events) that are rolled out sequentially, driving the progression of the exercise. The composition of such injects resembles a linear process in its simplest form. Therefore, we argue that the utilization of existing, standardized, and well-researched methods from the business process domain provides opportunities to improve the quality of cyber exercises and at the same time reduce the workload necessary for planning and conducting them. This paper reviews the challenges related to conducting customized cyber exercises and introduces a process-based cyber exercise lifecycle model that leverages the power of process modeling languages, process engines, and process evaluation methods \/ metrics to transform cyber exercises into transparent, dynamic, and highly automated endeavors. Therefore, the approach presented utilizes process modeling to plan cyber exercise scenario in a structured and flexible manner, enabling the creation of dynamic paths that adapt to participants\u2019 actions. These process models are directly executed by process engines, which automate the rollout of injects and collect detailed logs for evaluation purposes. We further describe the application of this lifecycle model in course of a proof-of-concept implementation and discuss technical insights as well as lessons learned from its utilization at a large-scale national cyber exercise together with CERTs and authorities. While the state of the art mostly focuses on optimizing individual tasks or phases within the cyber exercise lifecycle, our contribution aims to offer a comprehensive integrated framework that spans across the phases, providing interfaces between them, and enhancing the overall effectiveness and maintainability of cyber exercises. Further, we are discussing implications of using our approach, identifying opportunities for creating interactive cybersecurity training environments, automated feedback mechanisms and interconnected cyber range exercises.<\/jats:p>","DOI":"10.1007\/s10207-025-00993-6","type":"journal-article","created":{"date-parts":[[2025,3,15]],"date-time":"2025-03-15T02:30:16Z","timestamp":1742005816000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Exploring a comprehensive approach to customize cyber exercises utilizing a process-based lifecycle model"],"prefix":"10.1007","volume":"24","author":[{"given":"Tobias","family":"Pfaller","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Skopik","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Smith","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maria","family":"Leitner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,3,15]]},"reference":[{"issue":"1","key":"993_CR1","doi-asserted-by":"crossref","first-page":"236","DOI":"10.1007\/s11036-019-01442-0","volume":"25","author":"M Andreolini","year":"2020","unstructured":"Andreolini, M., Colacino, V.G., Colajanni, M., Marchetti, M.: A framework for the evaluation of trainee performance in cyber range exercises. Mob. Netw. Appl. 25(1), 236\u2013247 (2020)","journal-title":"Mob. Netw. Appl."},{"issue":"6","key":"993_CR2","doi-asserted-by":"crossref","first-page":"e126","DOI":"10.1002\/spy2.126","volume":"3","author":"GN Angafor","year":"2020","unstructured":"Angafor, G.N., Yevseyeva, I., He, Y.: Game-based learning: a review of tabletop exercises for cybersecurity incident response training. Secur. Priv. 3(6), e126 (2020)","journal-title":"Secur. Priv."},{"key":"993_CR3","unstructured":"Arcus, R., Christoforatos, N., Fanourakis, F., Fern\u00e1ndez, G., Van\u00a0Heurck, C., Zacharis, A.: Cyber Europe 2024: After Action Report. (2024)"},{"key":"993_CR4","unstructured":"Ben-Kiki, O., Evans, C., Ingerson, B.: (2009) Yaml ain\u2019t Markup Language (yaml$$^{\\text{TM}}$$) version 1.1. Working Draft 2008 5(11)"},{"issue":"3","key":"993_CR5","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1111\/j.1468-5973.2009.00575.x","volume":"17","author":"TA Birkland","year":"2009","unstructured":"Birkland, T.A.: Disasters, lessons learned, and fantasy documents. J. Conting. Crisis Manag. 17(3), 146\u2013156 (2009)","journal-title":"J. Conting. Crisis Manag."},{"key":"993_CR6","doi-asserted-by":"crossref","first-page":"101607","DOI":"10.1016\/j.cose.2019.101607","volume":"88","author":"A Brilingaite","year":"2020","unstructured":"Brilingaite, A., Bukauskas, L., Juozapavicius, A.: A framework for competence development and assessment in hybrid cybersecurity exercises. Comput. Secur. 88, 101607 (2020)","journal-title":"Comput. Secur."},{"key":"993_CR7","unstructured":"\u010celeda, P., \u010cegan, J., Vykopal, J., Tovar\u0148\u00e1k, D., et al.: Kypo-a platform for cyber defence exercises. M &S Support to Operational Tasks Including War Gaming, Logistics, Cyber Defence NATO Science and Technology Organization (2015)"},{"key":"993_CR8","unstructured":"Christoforatos, N., Lella, I., Rekleitis, E., Van\u00a0Heurck, C., Zacharis, A.: Cyber Europe 2022: After Action Report (2022)"},{"issue":"1","key":"993_CR9","doi-asserted-by":"crossref","first-page":"105","DOI":"10.30595\/juita.v9i1.9827","volume":"9","author":"R Delima","year":"2021","unstructured":"Delima, R., Wardoyo, R., Mustofa, K.: Goal-oriented requirements engineering: state of the art and research trend. JUITA J. Inform. 9(1), 105\u2013114 (2021)","journal-title":"JUITA J. Inform."},{"key":"993_CR10","doi-asserted-by":"publisher","unstructured":"Doup\u00e9 A, Egele M, Caillat B, Stringhini G, Yakin G, Zand A, Cavedon L, Vigna G.: Hit \u2019em where it hurts: a live security exercise on cyber situational awareness. In: Proceedings of the 27th Annual Computer Security Applications Conference, ACM, ACSAC \u201911, pp. 51\u201361, https:\/\/doi.org\/10.1145\/2076732.2076740(2011)","DOI":"10.1145\/2076732.2076740"},{"key":"993_CR11","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-662-56509-4","volume-title":"Fundamentals of Business Process Management","author":"M Dumas","year":"2018","unstructured":"Dumas, M., La Rosa, M., Mendling, J., Reijers, H.A., et al.: Fundamentals of Business Process Management. Springer, New York (2018)"},{"key":"993_CR12","unstructured":"ENISA - European Network and Information Security Agency.: Good Practice Guide on National Exercises. https:\/\/www.enisa.europa.eu\/publications\/national-exercise-good-practice-guide (2009)"},{"key":"993_CR13","doi-asserted-by":"crossref","unstructured":"Furtun\u0103, A., Patriciu, VV., Bica, I.: A structured approach for implementing cyber security exercises. In: 2010 8th International Conference on Communications, IEEE, pp 415\u2013418 (2010)","DOI":"10.1109\/ICCOMM.2010.5509123"},{"key":"993_CR14","doi-asserted-by":"crossref","unstructured":"Jans, M.J., Alles, M., Vasarhelyi, M.A.: Process Mining of Event Logs in Auditing: Opportunities and Challenges. Available at SSRN 1578912 (2010)","DOI":"10.2139\/ssrn.2488737"},{"key":"993_CR15","doi-asserted-by":"crossref","unstructured":"Karjalainen, M., Kokkonen, T., Puuska, S.: Pedagogical aspects of cyber security exercises. In: 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), IEEE, pp 103\u2013108 (2019)","DOI":"10.1109\/EuroSPW.2019.00018"},{"key":"993_CR16","doi-asserted-by":"crossref","unstructured":"Karjalainen, M., Puuska, S., Kokkonen, T.: Measuring learning in a cyber security exercise. In: Proceedings of the 12th International Conference on Education Technology and Computers, pp 205\u2013209 (2020)","DOI":"10.1145\/3436756.3437046"},{"key":"993_CR17","unstructured":"Keller, G., Scheer, AW., N\u00fcttgens, M.: Semantische Proze\u00dfmodellierung auf der Grundlage\" Ereignisgesteuerter Proze\u00dfketten (EPK)\". Inst. f\u00fcr Wirtschaftsinformatik (1992)"},{"key":"993_CR18","doi-asserted-by":"crossref","first-page":"102470","DOI":"10.1016\/j.jnca.2019.102470","volume":"151","author":"S Kucek","year":"2020","unstructured":"Kucek, S., Leitner, M.: An empirical survey of functions and configurations of open-source capture the flag (CTF) environments. J. Netw. Comput. Appl. 151, 102470 (2020)","journal-title":"J. Netw. Comput. Appl."},{"key":"993_CR19","doi-asserted-by":"crossref","DOI":"10.1201\/9781003129509","volume-title":"Requirements Engineering for Software and Systems","author":"PA Laplante","year":"2022","unstructured":"Laplante, P.A., Kassab, M.: Requirements Engineering for Software and Systems. Auerbach Publications, Boca Raton (2022)"},{"key":"993_CR20","doi-asserted-by":"publisher","unstructured":"Leitner, M.: A scenario-driven cyber security awareness exercise utilizing dynamic polling: Methodology and lessons learned. In: Proceedings of the 9th International Conference on Information Systems Security and Privacy - ICISSP, INSTICC, SDciTePress, pp. 634\u201364. https:\/\/doi.org\/10.5220\/0011780400003405 (2023)","DOI":"10.5220\/0011780400003405"},{"key":"993_CR21","doi-asserted-by":"crossref","unstructured":"Leitner, M., Frank, M., Hotwagner, W., Langner, G., Maurhart, O., Pahi, T., Reuter, L., Skopik, F., Smith, P., Warum, M.: Ait cyber range: flexible cyber security environment for exercises, training and research. In: Proceedings of the European Interdisciplinary Cybersecurity Conference, pp. 1\u20136 (2020)","DOI":"10.1145\/3424954.3424959"},{"key":"993_CR22","doi-asserted-by":"crossref","unstructured":"Maennel, K.: Learning analytics perspective: Evidencing learning from digital datasets in cybersecurity exercises. In: 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), IEEE, pp. 27\u201336 (2020)","DOI":"10.1109\/EuroSPW51379.2020.00013"},{"key":"993_CR23","unstructured":"Manger, J., Rinderle-Ma, S.: Cloud Process Execution Engine: Architecture and Interfaces. arXiv preprint arXiv:2208.12214 (2022)"},{"key":"993_CR24","unstructured":"Mangler, J., Stuermer, G., Schikuta, E.: Cloud Process Execution Engine-Evaluation of the Core Concepts. arXiv preprint arXiv:1003.3330 (2010)"},{"key":"993_CR25","doi-asserted-by":"crossref","unstructured":"M\u00e4ses, S., Maennel, K., Toussaint, M., Rosa, V.: Success factors for designing a cybersecurity exercise on the example of incident response. In: 2021 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), IEEE, pp. 259\u2013268 (2021)","DOI":"10.1109\/EuroSPW54576.2021.00033"},{"issue":"2","key":"993_CR26","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1016\/j.infsof.2009.08.004","volume":"52","author":"J Mendling","year":"2010","unstructured":"Mendling, J., Reijers, H.A., van der Aalst, W.M.: Seven process modeling guidelines (7pmg). Inf. Softw. Technol. 52(2), 127\u2013136 (2010)","journal-title":"Inf. Softw. Technol."},{"key":"993_CR27","unstructured":"OMG.: Business Process Model and Notation (BPMN), Version 2.0. Object Management Group, http:\/\/www.omg.org\/spec\/BPMN\/2.0 (2011)"},{"key":"993_CR28","doi-asserted-by":"crossref","unstructured":"Petersen, R., Santos, D., Smith, M., Witte, G.: Workforce Framework for Cybersecurity (Nice Framework). Tech. rep, National Institute of Standards and Technology (2020)","DOI":"10.6028\/NIST.SP.800-181r1-draft"},{"key":"993_CR29","doi-asserted-by":"crossref","unstructured":"Pfaller, T., Skopik, F., Smith, P., Leitner, M.: Towards customized cyber exercises using a process-based lifecycle model. In: European Interdisciplinary Cybersecurity Conference, pp. 37\u201345 (2024)","DOI":"10.1145\/3655693.3655713"},{"key":"993_CR30","doi-asserted-by":"crossref","unstructured":"Rajasekharaiah, K., Dule, CS., Sudarshan, E.: Cyber security challenges and its emerging trends on latest technologies. In: IOP Conference Series: Materials Science and Engineering, IOP Publishing, vol. 981, p. 022062 (2020)","DOI":"10.1088\/1757-899X\/981\/2\/022062"},{"issue":"1","key":"993_CR31","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.is.2007.07.001","volume":"33","author":"A Rozinat","year":"2008","unstructured":"Rozinat, A., Van der Aalst, W.M.: Conformance checking of processes based on monitoring real behavior. Inf. Syst. 33(1), 64\u201395 (2008)","journal-title":"Inf. Syst."},{"key":"993_CR32","doi-asserted-by":"crossref","unstructured":"Seker, E., Ozbenli, HH.: The concept of cyber defence exercises (cdx): Planning, execution, evaluation. In: 2018 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), IEEE, pp. 1\u20139 (2018)","DOI":"10.1109\/CyberSecPODS.2018.8560673"},{"key":"993_CR33","doi-asserted-by":"crossref","unstructured":"Shin S, Seto Y (2020) Development of iot security exercise contents for cyber security exercise system. In: 2020 13th International Conference on Human System Interaction (HSI), IEEE, pp 1\u20136","DOI":"10.1109\/HSI49210.2020.9142678"},{"key":"993_CR34","doi-asserted-by":"crossref","unstructured":"Skopik, F., Leitner, M.: Preparing for national cyber crises using non-linear cyber exercises. In: 2021 18th International Conference on Privacy, pp. 1\u20135. IEEE, Security and Trust (PST) (2021)","DOI":"10.1109\/PST52912.2021.9647795"},{"key":"993_CR35","doi-asserted-by":"crossref","unstructured":"van Der Aalst, W.M., Ter Hofstede, A.H., Kiepuszewski, B., Barros, A.P.: Workflow patterns. Distrib. Parallel Databases 14, 5\u201351 (2003)","DOI":"10.1023\/A:1022883727209"},{"issue":"1","key":"993_CR36","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/MCI.2009.935307","volume":"5","author":"WM van der Aalst","year":"2010","unstructured":"van der Aalst, W.M.: Process discovery: capturing the invisible. IEEE Comput. Intell. Mag. 5(1), 28\u201341 (2010)","journal-title":"IEEE Comput. Intell. Mag."},{"issue":"8","key":"993_CR37","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1145\/2240236.2240257","volume":"55","author":"W Van Der Aalst","year":"2012","unstructured":"Van Der Aalst, W.: Process mining. Commun. ACM 55(8), 76\u201383 (2012)","journal-title":"Commun. ACM"},{"key":"993_CR38","doi-asserted-by":"crossref","unstructured":"Vir\u00e1g, C., \u010cegan, J., Lieskovan, T., Merialdo, M.: The current state of the art and future of european cyber range ecosystem. In: 2021 IEEE International Conference on Cyber Security and Resilience (CSR), IEEE, pp. 390\u2013395 (2021)","DOI":"10.1109\/CSR51186.2021.9527931"},{"key":"993_CR39","doi-asserted-by":"publisher","unstructured":"Vykopal, J., Vizvary, M., Oslejsek, R., Celeda, P., Tovarnak, D.: Lessons learned from complex hands-on defence exercises in a cyber range. In: 2017 IEEE Frontiers in Education Conference (FIE), p. 1. https:\/\/doi.org\/10.1109\/FIE.2017.8190713 (2017)","DOI":"10.1109\/FIE.2017.8190713"},{"key":"993_CR40","doi-asserted-by":"crossref","unstructured":"Vykopal, J., O\u0161lej\u0161ek, R., Bursk\u00e1, K., Z\u00e1kop\u010danov\u00e1, K.: Timely feedback in unstructured cybersecurity exercises. In: Proceedings of the 49th ACM Technical Symposium on Computer Science Education, pp. 173\u2013178 (2018)","DOI":"10.1145\/3159450.3159561"},{"key":"993_CR41","doi-asserted-by":"crossref","unstructured":"Weiss, R., Locasto, ME., Mache, J.: A reflective approach to assessing student performance in cybersecurity exercises. In: Proceedings of the 47th ACM Technical Symposium on Computing Science Education, pp. 597\u2013602 (2016)","DOI":"10.1145\/2839509.2844646"},{"key":"993_CR42","doi-asserted-by":"crossref","unstructured":"Wen, S.F., Yamin, MM., Katt, B.: Ontology-based scenario modeling for cyber security exercise. In: 2021 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), IEEE, pp. 249\u2013258 (2021)","DOI":"10.1109\/EuroSPW54576.2021.00032"},{"key":"993_CR43","unstructured":"Weske M, et\u00a0al.: Concepts, languages, architectures. Business Process Management. (2007)"},{"issue":"1","key":"993_CR44","first-page":"117","volume":"32","author":"CV Wright","year":"2016","unstructured":"Wright, C.V., Mache, J., Weiss, R.: Hands-on exercises about DNS attacks: details, setup and lessons learned. J. Comput. Sci. Coll. 32(1), 117\u2013125 (2016)","journal-title":"J. Comput. Sci. Coll."},{"key":"993_CR45","doi-asserted-by":"crossref","unstructured":"Yadav, T., Rao, AM.: Technical aspects of cyber kill chain. In: Security in Computing and Communications: Third International Symposium, SSCC 2015, Kochi, India, August 10-13, 2015. Proceedings 3, Springer, pp. 438\u2013452 (2015)","DOI":"10.1007\/978-3-319-22915-7_40"},{"key":"993_CR46","unstructured":"Yamin, MM., Katt, B.: Inefficiencies in cyber-security exercises life-cycle: A position paper. In: AAAI Fall Symposium: ALEC, pp. 41\u201343 (2018)"},{"key":"993_CR47","doi-asserted-by":"crossref","first-page":"102635","DOI":"10.1016\/j.cose.2022.102635","volume":"116","author":"MM Yamin","year":"2022","unstructured":"Yamin, M.M., Katt, B.: Modeling and executing cyber security exercise scenarios in cyber ranges. Comput. Secur. 116, 102635 (2022)","journal-title":"Comput. Secur."}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-00993-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-025-00993-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-00993-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T08:01:40Z","timestamp":1743321700000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-025-00993-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,15]]},"references-count":47,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["993"],"URL":"https:\/\/doi.org\/10.1007\/s10207-025-00993-6","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,15]]},"assertion":[{"value":"15 March 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have received research support from their respective affiliations.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Financial interests"}},{"value":"The authors have no relevant non-financial interests to disclose.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Non-financial interests"}}],"article-number":"96"}}