An attack and defend round is a competition phase where teams both secure their own environment and try to exploit opponents’ exposed weaknesses. The format shifts the focus from isolated problem solving to operational defense, rapid patching, and offensive monitoring under continuous pressure. It rewards teams that can maintain stability while responding to active threats.
What the format is really testing
An attack and defend round is less about isolated puzzle solving and more about whether a team can keep a live system stable while under active pressure. The competition format measures security judgment, speed, prioritisation, and the ability to absorb partial compromise without losing control of the environment.
That makes the round closer to a miniature operations exercise than a traditional challenge set. Success depends on defending what matters first, recognising attacker movement quickly, and deciding which weaknesses are worth fixing immediately versus which can be contained.
How attack and defend rounds change the objective
In a standard defensive exercise, teams usually work against a fixed set of problems. In an attack and defend round, the environment is dynamic, so every action has a second-order effect: hardening one area may expose another, and a rushed change can create new instability. The format rewards teams that can preserve service while making real-time defensive decisions.
This shifts the goal from perfect completeness to effective control. Teams need enough visibility to know what is exposed, enough discipline to avoid self-inflicted outages, and enough speed to patch or isolate weaknesses before an opponent can exploit them. The pressure comes from the combination of adversarial activity and operational continuity.
Defensive and offensive behaviours in the round
Defense in this format usually includes monitoring your own services, closing obvious gaps, restoring damaged components, and reducing the attack surface before it can be re-used. Offense means finding exposed weaknesses in competing environments and turning them into scoring opportunities, often under time constraints that reward fast reconnaissance and reliable exploitation.
The best teams balance those behaviours rather than treating them as separate jobs. A strong defender knows which services are most likely to be targeted and can apply NIST Cybersecurity Framework functions in a live setting by identifying critical assets, protecting the most exposed paths, detecting changes quickly, responding to active abuse, and recovering without losing momentum. For attack planning, the round mirrors the mindset behind MITRE ATT&CK Enterprise, where defenders and red teamers think in terms of discovery, access, lateral movement, and persistence rather than one-off exploits.
Why teams win or lose
Rounds like this are usually decided by execution quality, not by raw technical breadth. Teams lose time when they over-focus on low-value fixes, fail to monitor for changes, or let one incident distract them from the rest of the environment. They also lose when they treat defense as static, because a live opponent will keep probing for the next gap.
Winning teams maintain a clear prioritisation model. They protect the highest-value services first, verify that fixes actually hold, and keep offensive work disciplined so it does not degrade their own environment. The format rewards resilience, repeatable process, and calm response under uncertainty more than heroic last-minute recovery.
Risk and Threat Considerations
Attack and defend rounds are deliberately adversarial, so the main risk is not just compromise but cascading instability. A weak control, a misapplied patch, or a delayed response can turn a single exposed weakness into repeated loss of service, score, or control of the environment.
Failure mechanism: Attackers exploit exposed services, weak credentials, insecure defaults, or poor segmentation to move from initial access into broader control, while defenders may accidentally widen exposure through rushed changes.
Impact: Teams can suffer service disruption, repeated compromise, privilege loss, and degraded visibility, all of which compound in a time-boxed competition where recovery time directly affects outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems inventory | Attack and defend rounds depend on knowing exposed assets and attack surface. |
| DE.CM-01 — Networks and network services are monitored | Live rounds require continuous monitoring for attacker movement and service changes. | |
| RS.MA-01 — Incident response is executed | The format rewards rapid containment and recovery under active pressure. | |
| Recommendation — Inventory critical assets so defenders can prioritise what needs immediate protection. Monitor network and service activity so active exploitation is detected quickly. Execute containment and recovery actions fast when compromise or degradation appears. | ||
| MITRE ATT&CK | Tactics and Techniques — Enterprise adversary tactics and techniques | Attack planning and defense in this format map directly to adversary movement and exploitation. |
| Recommendation — Map observed behaviour to ATT&CK techniques to prioritise detection and countermeasures. | ||
| CIS Controls v8 | CIS-5 — Account Management | Competition environments often hinge on exposed accounts, privileges, and access paths. |
| CIS-13 — Network Monitoring and Defense | Continuous monitoring is central to spotting exploitation in a live round. | |
| Recommendation — Review and restrict accounts so unnecessary access cannot be used against you. Tune monitoring to flag hostile activity before it spreads across the environment. | ||
Practitioner Guidance
What to watch for: The practical skill in an attack and defend round is knowing which weakness is most exploitable right now, not which one is most elegant to fix. Teams should treat monitoring, containment, and rapid verification as first-class activities, because a patch that breaks the service or a detection gap that misses movement can cost more than the original flaw.
Practitioner takeaway: The best teams do not simply attack harder or defend harder, they keep their own environment steady while reducing the opponent’s room to manoeuvre.