How cyber ranges can help build trust in AI

AndreyPopov via Getty Images
The public and private sectors are turning more and more to closed environments to help prepare for a cyberattack. Experts said they can also build an understanding of AI and its capabilities.
Earlier this summer, the Ohio Cyber Range Institute at the University of Cincinnati hosted a cybersecurity defense exercise called Ohio Cyber Guardian 2026.
The four-day exercise brought together the Ohio National Guard, state agencies, the private sector and more to simulate cyberattacks and how to defend against them. The effort comes as an increasing number of states are turning to cyber ranges to build cybersecurity awareness among their employees and agencies and build their talent pipeline, and often work with higher education institutions to do so.
But artificial intelligence is looming over such efforts, with cybersecurity professionals concerned at how it will change the game both from an offensive standpoint — giving hackers and other bad actors more tools and the ability to attack harder and faster — as well as defensively.
Given that collision between AI and cybersecurity, speakers at this week’s Billington Cybersecurity Summit in Washington, D.C. said cyber ranges can play an important role in helping build trust in AI among government leaders and the private sector.
“This might be a scenario where we'll run some executives through some AI scenarios, and then maybe we'll have a separate exercise with the technical team, and maybe start to introduce some AI-enabled attacks and see how they respond,” Dan Waddell, a partner in IBM’s federal cybersecurity practice, said during a panel discussion. “Then maybe the next time, we combine the two teams and see how they react. AI is still a relatively new concept, particularly with a lot of our customers in the federal government. It's really about trust, and cyber ranges can help improve that trust through that safe environment.”
Cyber ranges offer a secure, virtual and interactive environment where representatives from the public sector, private sector, academia and elsewhere can spend time simulating attacks on their IT networks, with that simulation tweaked to include a reflection of the systems they actually operate with. Ranges also offer a place to research new attack types, and how to defend against them.
Given that reliance on scenarios in the range, some speakers said AI’s first role could be to make the range more responsive and customized. Simon Vernon, a certified instructor and principal technical architect at the SANS Institute, a cybersecurity education company, said ranges can often feel “static.”
AI could change the range itself, customize the training and make it more specific and granular, helping participants better understand their goals and achieve their objectives.
Having AI respond as part of a cyber range is “pretty groundbreaking,” said Ben Abramovitz, director of cybersecurity at the Maryland Public Service Commission.
The goal is to “make teams better,” said Zach Tudor, associate laboratory director for national and homeland security at Idaho National Laboratory. Agentic AI, he said, could play a role in instructing participants, correcting them and giving new examples, although panelists all agreed that reality is still a long way off.
For colleges and universities that host cyber ranges, it means an even greater reliance on them, especially if they also run a security operations center for localities that helps mitigate threats in the real world.
Phil Stupak, senior director of advocacy at the cybersecurity membership and training nonprofit ISC2 and a former assistant national cyber director at the White House, said that reliance and the opportunities it will provide students will make them even more attractive to potential employers.
“You couple [real-world experience] with certificates so that you can demonstrate that they actually know what they're doing, and now they are a top hire,” Stupak said in an interview at the conference. “They're going to beat out everyone with a college degree; they're going to beat out people who only have an entry-level certification because they have experience and certification put together.”
Making sure the education and lessons learned from the time spent on the cyber range stay with participants is also critical, Abramovitz said, and that can be made harder as AI has made retaining information more challenging.
“You have to make sure the training sticks,” he said.
And that training has to be constantly evolving to meet the new threats, whether they be from AI or elsewhere. Tudor said that will first involve defining what a cybersecurity team “is and does and should do,” then considering how that can be measured. AI can help with measuring a team’s progress, so they can adapt, but he warned the path ahead remains challenging.
“How do you measure something when it’s evolving?” Tudor asked.




