A capture-the-flag (CTF) competition puts your security team into a scenario that classroom training and multiple-choice exams rarely produce: a time-boxed, hands-on exercise where individual skill, cross-team collaboration, and gaps in coverage all show up in the same window. If you're planning training for a security team, running a CTF raises a set of design and delivery questions well before it raises any technical ones. What follows is a working checklist for those questions, along with a short case for why running one can earn back the planning effort many times over.
TL;DR
- CTFs surface capability under pressure. A time-boxed, hands-on event tests skills in ways that classroom training and multiple-choice exams typically do not.
- The format can be inclusive by design. Jeopardy-style CTFs (a scoreboard of independent challenges across categories) let mixed-skill groups participate together, so a competition can double as security awareness for the wider organization.
- The planning decisions matter as much as the challenges themselves. Format, audience, difficulty progression, and how learning gets consolidated after the event can drive whether it produces evidence of capability or just a good day out.
- The pricing model shapes the guest list. Charging by engagement hours (time spent competing) allows a leader to bring the whole organization in; per-seat pricing quietly caps who gets to play.
Why does running a capture-the-flag event matter for a security team?
A capture-the-flag event gives a security team a scenario where individual capability, teamwork, and gaps in coverage all become visible in the same window, which is difficult to replicate in classroom training or in a written exam. There are several supporting reasons a security leader may want one on the calendar.
- Motivation and return on training spend. Competition can get people to invest evenings and weekends into skill-building they may otherwise treat as background work. That effort compounds the value of the training courses, rooms, and certifications a team already has access to.
- Shared reference points across the team. People who solve challenges together, or watch each other solve them, build a shared vocabulary for the tools, techniques, and gotchas involved. That shared vocabulary can speed up real incident coordination later.
- Capability shown under time pressure. What someone can produce in a two-hour window, against an unfamiliar problem, often differs from what they demonstrate in structured training. A CTF exposes that difference in a way managers can see directly.
- Inclusion of the wider organization. With a jeopardy-style scoreboard and beginner tiers alongside advanced ones, a corporate CTF can bring in developers, IT, and even non-technical colleagues, giving a much broader group a hands-on experience of security work. Advent of Cyber for Business covers a related pattern of structured, competitive training built around daily challenges.
- Evidence that supports the next investment. Scoreboard data, category-level performance, and a follow-up walkthrough session together give a leader material to point at when justifying next quarter's training plan.
What is a jeopardy-style CTF, and how does it differ from other formats?
A jeopardy-style CTF presents a scoreboard of independent challenges organized by category, each worth points based on difficulty, and participants pick which to attempt and in what order. It's a common default for corporate events because it works for mixed skill levels, scales cleanly to any number of participants, and requires relatively little live coordination during the event itself.
Two other formats show up less often in corporate settings. Attack-and-defense events (where teams defend their own infrastructure while attacking others in real time) and King of the Hill (where teams compete to hold control of a shared system) both can suit mature security teams practicing head-to-head competition, and both need more setup, live moderation, and reasonably matched skill levels across the room than jeopardy does. If you want a deeper look at how each one develops specific defense skills, that's covered elsewhere on the blog.
For anyone new to the format entirely, a beginner's guide to CTF hacking walks through the challenge categories at an individual-practitioner level. The rest of this piece assumes the reader is planning an event for a group rather than getting started as a solo participant.
What should a corporate CTF actually test?
The category mix should reflect the team's real work and the risks the organization is exposed to, rather than a generic offensive-security spread. A financial-services SOC (security operations center) team, an operational-technology-heavy manufacturer, and a cloud-first product company each get value out of very different combinations, and the closer the mix maps to their real threat surface, the more the results speak to actual capability.
A corporate CTF should give the planning team a diverse menu of topics to pick from, including:
- Incident response and forensics. Alert triage, evidence collection, timeline reconstruction, and root-cause analysis under time pressure.
- Web application security. Injection flaws, authentication and authorization bypasses, and business-logic abuse.
- Cloud security. Misconfiguration, identity and access management (IAM), and cloud-native detection use cases.
- Reverse engineering. Analysis of unfamiliar binaries without source code.
- Binary exploitation. Memory-corruption and control-flow-hijack style problems.
- Cryptography and steganography. Cipher, key-handling, and hidden-data challenges.
- Threat intelligence. Pivoting on indicators, mapping activity to known actors and techniques.
- Network analysis and PCAP work. Packet captures (PCAPs) analyzed for lateral movement, exfiltration, or protocol abuse.
- Open-source intelligence (OSINT). Reconnaissance and information gathering from public sources.
- Hardening and defensive security. Hands-on tasks that reward configuring, monitoring, and defending a live system.
- DevSecOps and secure coding. Challenges written into a build pipeline or aimed at reviewing insecure source.
- Operational technology (OT). Industrial control system (ICS) problem sets for teams responsible for manufacturing, energy, and other industrial environments.
A useful shaping question, before committing to categories, is which of these the team is likely to encounter in the next 12 months. The mix that surfaces the most actionable evidence is usually narrower and more work-relevant than a full menu.
| Domain | What it covers |
|---|---|
| Incident response and forensics | Alert triage, evidence collection, timeline reconstruction, and root-cause analysis under time pressure |
| Web application security | Injection flaws, authentication and authorization bypasses, and business-logic abuse |
| Cloud security | Misconfiguration, identity and access management (IAM), and cloud-native detection use cases |
| Reverse engineering | Analysis of unfamiliar binaries without source code |
| Binary exploitation | Memory-corruption and control-flow-hijack style problems |
| Cryptography and steganography | Cipher, key-handling, and hidden-data challenges |
| Threat intelligence | Pivoting on indicators, mapping activity to known actors and techniques |
| Network analysis and PCAP work | Packet captures analyzed for lateral movement, exfiltration, or protocol abuse |
| Open-source intelligence (OSINT) | Reconnaissance and information gathering from public sources |
| Hardening and defensive security | Configuring, monitoring, and defending a live system |
| DevSecOps and secure coding | Challenges written into a build pipeline or aimed at reviewing insecure source |
| Operational technology (OT) | Industrial control system (ICS) problem sets for teams responsible for manufacturing, energy, and other industrial environments |
Who is a corporate CTF for, and how inclusive should it be?
Deciding who the event is aimed at shapes almost every downstream decision about difficulty, categories, and support level, so it belongs at the top of the planning list rather than the end. Three common audience shapes are:
- The core security team. Deep, technical, competitive. Difficulty leans hard, categories are narrower, walkthroughs matter after the fact for skill transfer across the team.
- Extended IT, engineering, and DevOps. Broader, and useful for showing adjacent teams what security work actually feels like. Category mix widens toward web security, cloud, and secure coding.
- The whole organization. Awareness-driven, with beginner tiers alongside advanced ones so a marketing analyst and a senior threat hunter can both engage, learn, and expand their horizons despite their different starting points. Framing shifts from assessment toward experience.
Running an inclusive event well can reveal something a leadership team may not otherwise see: how people outside the security function respond to a live security scenario, and where security instincts already exist in the wider organization. When the wider organization experiences security as something engaging rather than compliance-adjacent, they can show up as champions afterward.
Can a corporate CTF work for people outside the security team?
A corporate CTF can work for people outside the security team when the challenge pool has approachable beginner tiers alongside the deeper technical ones, and when the pricing model does not penalize the leader for opening the guest list. That combination is what turns "everyone is part of the security posture" from a slogan into something the wider organization has actually done.
Cyber attacks reach people well outside the security team. A convincing phishing email lands in someone's inbox, a password gets reused one too many times, a link gets clicked that probably should not have been. A CTF that includes the wider organization can put the same kind of scenarios in front of the people who face them in real work, at a difficulty level they can engage with.
Non-technical challenge tiers commonly cover:
- Phishing recognition. Working through crafted messages to spot the tells, and understanding what happens after someone clicks.
- Password practice. Seeing how weak passwords get cracked, and why reuse across services carries the risk it does.
- Social engineering scenarios. Recognizing the patterns of manipulation used to extract information or access.
- Spotting anomalies. Reading a screen or a log for the thing that looks slightly off, and knowing what to escalate.
Standard compliance training can state the rules; a hands-on CTF tier gives the same audience a chance to see how the underlying attacks actually work. That shift from being told to seeing it happen is what can make the lessons stick.
The pricing model matters here because per-seat pricing quietly caps who gets to play. Engagement-hour pricing (charging by the time participants spend competing, rather than per participant) makes the difference between running a CTF for a fixed twenty-person security team and running one for the whole organization on the same budget.
Should you build your own CTF challenges, or use a curated pool?
For a small one-off internal event, writing a handful of challenges in-house is workable and can be a good exercise for the challenge author. For a repeatable, enterprise-scale event that has to hold up in front of a broad audience, a curated and unpublished challenge pool can be more practical, largely because it avoids two common failure modes for corporate CTFs (challenges someone can look up, and unbounded design time).
- Build your own from scratch. Full control and a real learning exercise for the person building it. Any challenge that has been used publicly before is often searchable, and design and testing can consume weeks of a security engineer's time.
- Off-the-shelf public challenges. Fast and cheap to source. Walkthroughs for public challenges can be a search away, which flattens the difficulty and undermines the assessment value at a corporate event.
- A middle path with an in-tool builder. The CTF Builder lets a business or education license holder spin up an event from a bank of over 200 challenges, with topics, difficulty, and duration configurable per event.
- Curated, unpublished pools with delivery support. Challenges that are not indexed anywhere online, shaped against the specific team, and paired with facilitator support during and after the event. This is what a dedicated corporate CTF partnership is built to provide, and it can hold up best for enterprise-scale events.
What format and duration works for a corporate CTF event?
Corporate CTF events can run well when their duration is shaped around participants' actual availability rather than the ambition of the challenge set. A rich challenge pool that no one has time to attempt produces frustration rather than evidence of capability.
- Half-day sprint. Concentrated, high-energy, and well-suited to team-building or organization-wide awareness. Category count stays narrow, difficulty stays approachable, and the walkthrough afterward has to work hard because the competitive window itself is short.
- Full-day event. Enough runway to include harder challenges and to let mixed-skill teams find their footing. Common shape for a core security team offsite.
- Multi-day event. Deeper competition, richer post-event learning, and more opportunity for cross-team collaboration. Coordination overhead is higher, and it may be worth pacing challenge releases across the days rather than dropping everything at once.
- Hybrid formats. Asynchronous challenge play with scheduled live sessions and walkthroughs, which can fit distributed teams and multi-time-zone organizations better than a single live window.
The right combination often comes from what a security leader can realistically ask people to give up. Two focused half-days across two weeks can outperform a single crammed multi-day event, particularly if the goal includes learning consolidation alongside the competitive window.
How do you keep CTF challenges from being solved on GitHub before the event?
The most reliable approach is to use challenges that have not been published anywhere online, either by working with a provider that maintains an unpublished pool or by writing bespoke challenges the team cannot look up. Public CTF challenges often accumulate walkthroughs on personal blogs, YouTube, and GitHub repositories within days or weeks of being released, which flattens difficulty and turns a capability event into a searching exercise.
A related consideration is whether the challenge set can be tailored to internal specifics, since anything referencing proprietary tooling, internal systems, or an industry-specific scenario is by definition unpublished. A dedicated corporate CTF partner can usually deliver either bespoke narratives threaded across a scenario or curated unpublished content pulled from a private pool; a self-hosted event built on public challenges usually cannot.
How do you turn a corporate CTF into evidence and a training plan?
The competition itself surfaces gaps; the consolidation afterward is what turns those gaps into a training decision. Treating the post-event window as part of the deliverable rather than a bonus can make the difference between a memorable offsite and an actual capability signal.
- Walkthroughs published to participants. Solutions for every challenge, with the reasoning made explicit, so people who did not solve a challenge learn from those who did.
- Optional live consolidation sessions. A facilitated walkthrough where the room can ask questions turns individual solves into team knowledge.
- The scoreboard read as a capability map. Category-level performance points at where the team is strong, where a single expert is carrying a whole domain, and where a broader gap sits.
- A follow-up training plan that changes because of the event. Mapping the areas that surfaced into specific rooms, learning paths, or certification tracks gives leaders a defensible reason for the next quarter's training investment.
What should you look for in a CTF provider, and what pricing model actually scales?
Not every CTF provider clears the same bar, and the ones that do can look similar on a small set of specifics. Treating this list as questions to hold any provider to, rather than as universal industry standard, can sharpen the shortlist quickly.
- Designed and delivered by facilitators with real event experience. A platform login is not the same as an event, and a track record of delivered corporate CTFs is a materially different starting point from a first delivery.
- Support end to end. Someone owns setup, live scoring, in-event hints, and post-event walkthroughs, rather than handing the license over and disappearing.
- Content freshness. Challenges are not already sitting in a GitHub write-up. Ask directly, and be skeptical of answers that dodge the question.
- Broad domain coverage. From incident response and forensics to application security, cloud, OT, and developer-focused work, so the category mix can be shaped to the team.
- Shaping against the team's goals. Difficulty progression, category weighting, and event narrative aligned to the team's actual capabilities and risks, rather than a stock event pushed out unchanged.
- Flexible formats. Half-day through multi-day, individual, team, and hybrid options, so the event fits the team rather than the other way round.
- Support for internal specifics. Whether the provider can build against proprietary tooling, industry-specific topics, or a threaded scenario tied to the organization's environment.
- Pricing that scales with the event rather than the headcount. This is often where seat-based providers quietly cap the guest list at exactly the point a leader wants to open participation wider. Charging by engagement hours (the time participants spend competing) allows a whole organization to take part inside a single fixed cost.
The corporate CTFs we run with enterprise teams are built around this shape: curated unpublished content, end-to-end delivery support, coverage across the domains listed above, formats from half-day through multi-day, and engagement-hour pricing rather than per-seat.
Should the CTF run on the same platform your team already trains on?
Continuity between the platform a security team trains on and the platform the CTF runs on can make both more impactful. The practice people put in during the run-up applies directly on the day. The gaps that surface on the scoreboard map straight back into specific rooms and learning paths afterward. Certifications on the same platform become the natural next step from a strong individual performance, rather than a separate progression program to sell in from scratch.
If you're evaluating training platforms right now, whether the same platform can also host your CTFs is worth adding to the criteria. The bar a platform has to clear to serve both roles well can be higher than the bar a training-only or CTF-only tool has to hit, which sharpens the shortlist quickly.
A training platform worth building a CTF on is worth checking against the following:
- Hands-on practice as the default. Real, sandboxed labs across offensive, defensive, cloud, application, threat intelligence, and OT work, where people write, run, and break things. Video-only or reading-only content fades fast; hands-on practice is what carries into the event.
- Content that stays current. New rooms and updates land on a regular cadence and reflect the threats, techniques, and tooling teams are actually seeing right now. What someone practiced last month should still be applicable on the day.
- Realistic environments. Sandboxes faithful to how the tools and systems behave in production, so the CTF isn't the first time someone works with an environment that resembles their own.
- Coverage across roles and difficulty. From complete beginners through advanced practitioners, and across every domain your team touches, so one platform can serve the whole team's journey rather than one slice of it.
- CTFs deliverable from the same environment. Running the CTF from the same platform the team already trains on removes the context switch on the day and lets results feed directly back into the training plan afterward, without a data-export step.
- Reporting leaders can use. Category-level performance, individual progress, and completion records that map to real skills, so the training and CTF investments produce evidence a leader can point at.
- Certifications aligned to the training paths. Practitioner-facing certifications that build on the same rooms and paths, so a strong CTF result, the training plan, and the progression track all sit inside one story.
TryHackMe sits inside this shape: hands-on labs across every domain, refreshed on an ongoing cadence, with training paths, certifications, and corporate CTFs all delivered from the same environment. That continuity is what lets a leader tie a colleague's CTF performance directly to the room they should attempt next, rather than treating the CTF as a standalone event with its own follow-up program.
How do you know a corporate CTF worked?
Signals that a corporate CTF has landed can be visible during and immediately after the event, before any longer-term training results come through. Voluntary engagement outside the scheduled hours (people continuing to work challenges into the evening), leadership getting a clearer view of individual technical level than they had before, and a concrete change in the next training decision are three signals that come up commonly. One security leader described a recent event as the moment they finally got to see the real technical level of the engineers on their team, alongside participants who "stayed up nights doing the challenges," which is a reasonable description of what a successful corporate CTF can look like from the inside.
| Metric | What it tells you |
|---|---|
| Challenges completed | Overall practical capability |
| Score by category | Strengths and weaknesses by skill |
| Completion rate | Team-wide proficiency |
| Time to solve | Speed and efficiency |
| Individual vs team performance | Individual capability and collaboration |
| Difficulty progression | Ability to handle increasingly complex problems |
| Failed challenges | Potential skill gaps |
| Post-event performance | Whether training translated into improvement |
What's the difference in impact between a CTF and traditional training
CTF events and traditional cybersecurity training aren't competing approaches. They reinforce one another. The key is how hands-on the training content is. When teams learn through interactive, practice-first platforms like TryHackMe, where they're already working in real environments and solving real problems, the skills built in a CTF stick far more effectively. And it works the other way too: competitive CTF pressure reveals exactly which skills need more practice, sending people back into training with sharper focus. The more practical the training, the better the CTF performance. The stronger the CTF performance, the more targeted the training becomes. That feedback loop is where the real capability growth happens.
| Traditional training | Corporate CTF | |
|---|---|---|
| Knowledge | Strong | Strong |
| Hands-on practice | Variable | High |
| Engagement | Variable | High |
| Competition | Low | High |
| Individual assessment | Limited | Strong |
| Team assessment | Limited | Strong |
| Real-time performance | Limited | Strong |
| Skill-gap identification | Moderate | Strong |
| Feedback | Usually delayed | Immediate |
| Scalability | High | High with a platform |
FAQ
What is a capture-the-flag (CTF) competition in cybersecurity?
A capture-the-flag competition is a time-boxed cybersecurity exercise where participants solve technical challenges to find hidden "flags" and earn points on a scoreboard. Challenges typically span categories such as web application security, digital forensics, cryptography, and reverse engineering, and can be attempted individually or as a team.
What is a jeopardy-style CTF?
A jeopardy-style CTF is a format built around a scoreboard of independent challenges organized by category, with each challenge worth points based on difficulty. Participants pick which challenges to attempt and in what order, competing individually or in teams, and the format works well for mixed-skill groups because everyone can start at their own level.
How long should a corporate CTF event run?
Corporate CTF events commonly run from a half day to several days, depending on the depth intended and the availability of participants. Half-day and single-day formats can work well for team-building and organization-wide awareness; multi-day formats allow deeper competition, more challenge variety, and richer post-event consolidation.
How much does a corporate CTF event typically cost?
Corporate CTF pricing varies substantially by provider and delivery model. Some providers price per participant, which can cap the effective guest list once an organization tries to include the wider business. The corporate CTFs TryHackMe runs are priced by engagement hours (the time participants spend competing), which allows an organization to include as many participants as it wants inside a fixed cost.
Should a corporate CTF include non-technical staff?
A corporate CTF can include non-technical staff when the challenge pool has approachable beginner tiers alongside deeper technical ones and when the event is framed as a hands-on introduction to security rather than a pure technical assessment. Including a broader audience can be most effective when the goal is security awareness, cultural change, or building internal champions for the security function.
Is it better to build a CTF internally or use a provider?
Building a small internal CTF can work well for a one-off event with modest scope, and gives the person building it a real learning exercise. Using a provider can be more practical at enterprise scale, because a provider with an unpublished, curated challenge pool avoids two common failure modes for internal events: challenges that turn out to be solvable via a public walkthrough, and design and testing time that expands well beyond what was planned.
Ready to see what a corporate CTF could look like for your team? Start with TryHackMe for Business.
