Welcome to Day 1
Today kicks off the Introduction to Cybersecurity STEM workshop. Over the next five days, you will build a company, defend it against cyberattacks, and learn the foundations of how security professionals protect organizations every day.Camp dates: June 23-27, 2026 | Time: 9:00 AM - 1:00 PM ET each day
- Form your Cyber Defense Challenge team and assign roles
- Understand the four categories and six types of security controls
- Learn the CIA Triad - the foundation of all information security
- Explore authentication factors and access control models
The Cyber Defense Challenge
Your mission for the week:Your team just started a new company. Every business faces cyber threats. Build your company, protect it, and respond when attacks happen.This is a multi-day competition that runs alongside your lessons. Each day you learn new concepts and apply them to your company’s defenses. By Day 4, your defenses will be put to the test with live attack scenarios.
1
Day 1: Build your team and learn the basics
Form your team, assign roles, learn security controls, the CIA Triad, and authentication. These are the building blocks for everything that follows.
2
Day 2: Understand your enemies
Study threat actors, the cyber kill chain, and common attacks like phishing, SQL injection, and malware. Know your enemy before you build your defenses.
3
Day 3: Build your defenses
Purchase security controls for your Donuts & Dragons donut shop on a limited budget. Every dollar counts - choose wisely.
4
Day 4: Survive the attacks
Face live attack scenarios. Your defenses are tested, your team responds to incidents, and you see what held up and what didn’t.
5
Day 5: Final project
Unbox your USB Rubber Ducky hardware, write DuckyScript payloads, and see offensive security in action.
Breaking into teams
Your instructor will divide the class into teams of 3-5 students. Each team will:- Choose a team name and create a company name for the wargame
- Assign roles to each member (detailed below)
- Work together all week to build, defend, and respond
Team roles
Every team member plays a specific part. Some roles overlap, and that’s by design - cybersecurity is a team sport.Team Captain
Team Captain
The Team Captain is the leader. You run team discussions, make final decisions when the group can’t agree, and brief the main room during presentations.Responsibilities:
- Lead team discussions and keep everyone focused
- Make the final call when the team is split on a decision
- Present your team’s strategy to the class
- Coordinate between team members during attack scenarios
Being the captain doesn’t mean you make every decision alone. The best captains listen to their team and make informed calls.
Budget Specialist
Budget Specialist
The Budget Specialist controls the money. In the Donuts & Dragons wargame, your team has a limited budget to purchase security controls. You decide what to buy, track spending, and calculate the cost of attacks.Responsibilities:
- Track the team’s total budget and remaining funds
- Purchase security controls from the pricing guide
- Calculate financial losses when attacks hit
- Recommend where to spend (and where to save)
Report Specialist
Report Specialist
The Report Specialist is the team’s historian. You document every decision, every incident, and every lesson learned. When the team is asked “what happened?” - you have the answer.Responsibilities:
- Record all team decisions and the reasoning behind them
- Document incidents as they happen (what, when, how)
- Create incident reports after attack scenarios
- Track lessons learned for future rounds
Incident Responders (everyone)
Incident Responders (everyone)
Every team member is an incident responder. When an attack hits, the whole team works together to analyze, contain, recover, and improve.Responsibilities:
- Analyze attacks to understand what happened and how
- Contain incidents to stop them from spreading
- Recover systems and restore normal operations
- Improve defenses so the same attack can’t work twice
In real cybersecurity, incident response is everyone’s job - from the CEO to the newest intern. The same applies here.
Red vs Blue
Throughout this camp, you will hear the terms Red Team, Blue Team, and Gray Team. Here’s what they mean:Blue Team - Defenders
That’s you. The Blue Team defends the organization. You build defenses, monitor for threats, respond to incidents, and recover from attacks. Your goal is to protect your company’s assets.
Red Team - Attackers
The Red Team simulates real attackers. In our wargame, the instructors control the Red Team. They will launch attack scenarios against your defenses to test how well you prepared.
Gray Team - Referees
The Gray Team referees the exercise. Your instructors serve as the Gray Team - they set the rules, judge whether your defenses stopped an attack, and calculate the results.
In professional cybersecurity, there is also a Purple Team that combines Red and Blue team exercises for collaborative improvement. You will learn more about this concept as the week progresses.
What to expect today
Here is your Day 1 schedule:Team business briefing
At the end of today, your team will create a business briefing for your new company. You will present:- Your team name and company name
- What your company does (pick an industry - tech, food, healthcare, retail, etc.)
- Who holds each role on the team
- What you think your company’s biggest cyber risk will be

