The number of cyber attacks on sites and applications of Russian companies in the first half of 2026 increased by 27% and reached 849.7 million, while almost half of the attacks became multi-stage. I will try to explain why in these conditions it is not enough for companies to check the perimeter for vulnerabilities, what the penetration test will show and what it will never show, as well as who generally makes sense to invest in a training cyber attack on themselves and how much it will cost.
Who makes sense to invest in cyber exercises
The market responded to the rise in attacks predictably. The demand for cyber training in the red team format (an attacker acting as a real attacker) in Russia in the first quarter of 2026 increased by 50% compared to the same period last year. More than 60% of this demand is formed by industry. This is the most frequently attacked industry in 2025-2026. Another 20% falls on banks and insurance companies, which is quite natural.
Budgets draw a very specific boundary. Companies are on average ready to spend 5-10 million rubles a year on cyber training. At the same time, 14% of organizations have never conducted exercises at all and do not plan, and another 28% are just going to start. It turns out that almost a third of the market is on the outskirts, and more than half of the budget is already concentrated in those who can afford regular practice, and not a one-time experiment.
Hence the difference in focus. Small and medium-sized businesses often need a regular penetration test, that closes the issue of technical vulnerabilities. Large business with distributed infrastructure and a high cost of downtime goes further: it checks not only the equipment, but also how people will behave in a critical situation and how well the regulations stand.
How cyber exercises differ from pentest
The company may have a mature information security system and high technical equipment, but it is on cyber exercises that gaps are found: information about the incident does not reach the management on time, response regulations exist only on paper, and related units (lawyers, PR, IT) do not understand their role in the first hours of the attack.
Experts formulate this problem directly: companies are increasingly faced with a situation when there are regulations, but there are no response skills. Pentest evaluates assets, security settings and the infrastructure itself in isolation from the processes that arise during a real attack. The gap between those who were preparing seriously and those who passed the formal test for reporting becomes apparent only at the time of the real incident. For the first group, the price of the issue is the attack itself or the data leak. For the second one, penalties for violation of compliance and loss of downtime due to late reaction are added.
The red team and blue team model (a team of full-time defenders working in conditions close to real ones, without knowing the scenario and time of the attack) came from the military sphere and became the standard for serious exercises. The attacker does not iterate over vulnerabilities one after another, but simulates a full cycle: from penetration through phishing or exploitation of the perimeter to moving within the network and reaching critical assets. The purple team format assumes that both parties exchange progress information as they exercise with an independent third party who acts as an arbiter.
SOC (security operation center) can participate in the exercises – this allows to check how quickly it notices the attack and how it reacts under pressure. The red team uses legitimate administrative utilities, encrypts traffic through regular VPN channels, and splits operations over time to bypass correlations in monitoring systems (SIEM). Therefore, the blue team in most cases does not record an attack at the stage of penetration: the attacker is already inside the network before his activity becomes noticeable. The main value of the exercises shifts to the development of the next stages – localization, escalation, recovery, because it is possible to prevent the penetration of a targeted enemy only in isolated cases.
Virtual training ground or combat infrastructure
The choice of environment determines which question a company wants answered. A virtual cyber polygon is a digital copy of an infrastructure or its segment in an isolated environment. There are no risks to working systems, you can use several attacking teams at the same time and test several attack directions at once. This format is suitable when the priority is a complete inventory of vulnerabilities and a strength test of the perimeter.
Exercises on real infrastructure give another cut: the attack unfolds on combat systems, with real employees in their workplaces. This is the only accurate way to check how people make decisions under pressure and where communication between departments breaks down. The cyber incident never concerns only the information security service – lawyers, PR service and top management also make decisions in the first hours after the discovery of the attack, and if they have never participated in the exercises, their actions can increase the damage.
How the attack scenario is formed
Preparation begins long before the attack itself: the level of awareness of employees through control phishing is assessed and critical roles are determined – who makes the key decisions, who becomes the entry point for the attackers. A good scenario is not based on typical threats, but on the profile of a particular company: the peculiarities of the infrastructure, the industry, and previous incidents. The range is wide – from opening a malicious attachment to compromising privileged accounts or ransomware attacks (ransomware that encrypt data and demand a ransom for restoring access).
For Russian companies, it is especially important to work out the scenario when part of the infrastructure has already been compromised. The company can show a high level of information security maturity and clean out known vulnerabilities from protective circuits, but as soon as the attack enters the active phase, the fragility of the system is revealed, which relies much more on technology than on processes and people. You can hack any system – this is recognized by the information security specialists themselves. Therefore, the task is not only to be able to prevent an attack, but also, already in a losing position, to repel it with the least losses.
What the final report shows
The report on the results of cyber exercises contains several levels of assessment: the technical condition of the infrastructure, the actions of specific employees, the coherence of the information security team, the quality of communication between units in the event of an escalation of the threat. No level separately gives a complete picture.
The success of the exercises is not an impeccable defense, but an honest diagnosis: where the process failed, at what stage the wrong decision was made, at what point communication was cut off. Based on the diagnosis, a roadmap is formed: priorities for eliminating vulnerabilities, changes in regulations, point training.
The company that pioneered cyber exercises usually draws several conclusions for itself.
- Humans are the weakest link, and social engineering works almost always. Expenses on any protection systems will not save you from the actions of your own employee. The only thing that can be done in advance is to prepare for this scenario.
- A response plan on paper is a hypothesis, not a readiness. Whether it works or not, only exercises show (and most often they show that it does not work).
- If the monitoring did not work in time, the company has already been hacked. Further, one can only assess how much the calculation of potential losses was mistaken.
These three conclusions sound tough, but they are the ones that turn cyber exercises from a formality into a tool that really reduces damage in the next attack.
What companies should do before the first cyber exercises
It makes sense to start with an inventory of critical roles – to determine who in the company makes decisions in the first hours of the attack, and make sure that these people at least once practiced their actions not in theory, but in practice.
One-time exercises give a slice of the state at the time of the conduct. Regular practice forms a different quality of readiness: the team develops stable reflexes, processes become predictable even in an emergency situation, and scenarios of training attacks can be consistently complicated as the team grows in maturity.
It makes sense to conduct complex cyber exercises at least once every two years or with significant changes in the staff of information security specialists and technologies, and in between – to maintain the contours of protection with regular penetration tests. Repeated exercises should be carried out only after the company has closed the problems found on the previous ones: otherwise, it is not clear whether the lessons have been learned.

By Dmitry Livshin, CEO of Cyber Business Consulting


