2026-10-23 –, Redbud B
Technical knowledge alone does not make someone ready to defend an organization. Cybersecurity professionals must interpret incomplete information, correlate evidence from multiple systems, make decisions under pressure, and explain why their response is justified.
WSU Tech’s Cyber Range provides learners with a broad collection of realistic simulations modeled on real-world threats and security incidents. Working through varied scenarios allows a learner to practice responding to different attack methods while developing the investigative reasoning and technical judgment required in the workplace.
This session demonstrates that process using a simulated FIN7 intrusion as a case study. The investigation begins when law enforcement reports finding an organization’s financial information in a threat actor’s possession. Learners must determine what happened, identify the affected systems, establish the scope of the compromise, and recommend an appropriate response.
Learners correlate SIEM alerts, firewall traffic, Windows events, and system artifacts to uncover a phishing-enabled compromise, lateral movement, persistence, financial-data staging, and exfiltration. Observable performance criteria evaluates ability to identify the initial compromise, reconstruct the attack, confirm data loss, and propose defensible containment and recovery actions.
FIN7 represents one of the many scenarios available in the Cyber Range. Exposure to multiple incidents helps a learner develop transferable capabilities rather than memorize a single investigative process. Structured debriefing then turns missed evidence and incomplete conclusions into targeted opportunities for additional practice.
Attendees will leave with a practical understanding of how they and their teams can use WSU Tech’s Cyber Range to develop, refine, and evaluate job-ready cybersecurity competencies through realistic, scenario-based practice.
WSU Tech's Cyber Range uses a broad collection of realistic simulations to develop and evaluate job-ready incident-response skills.
Using a simulated FIN7 intrusion as a case study, the session follows an investigation that begins when law enforcement reports finding an organization’s financial information in a threat actor’s possession. Learners correlate SIEM alerts, firewall traffic, Windows events, and system artifacts to identify the initial compromise, trace lateral movement and persistence, confirm data exfiltration, and recommend response actions.
The session shows how varied threat scenarios, observable performance criteria, and structured debriefing develop transferable skills, reveal competency gaps, and guide additional practice. Attendees will learn how WSU Tech’s Cyber Range can support continued development for individuals and teams. The Cyber Range is available to individuals and organizations seeking realistic, scenario-based cybersecurity practice.
No specialized equipment or account is required for the session.
Matthew Lewis has over 20 years of experience building partnerships through industry collaboration. As a leader at WSU Tech, he leads academic programs that bridge industry needs and academic rigor, ensuring students are ready for success in Kansas’ tech sector. By actively engaging with industry partners, Matthew helps shape both credit and non-credit programs that meet specific workforce needs, supporting students in achieving their career goals. Through education, mentorship, and collaboration, Matthew is committed to driving innovation and fostering growth within the community.
Jacob Buck is a Program Director at WSU Tech, helping faculty and students alike with learning Cybersecurity and IT skills for a digital future. Jacob has been teaching for 3 years and working in Education for 5, in addition to having a mixed background in VFX for film using code and IT at places such as Textron Aviation.