The platform

A cybersecurity job simulator built around real investigations

Cyber Career Lab puts you in a simulated security role. You receive alerts, examine the evidence, make decisions and document your work — the same loop security teams run every day.

Your analyst dashboard

Your shift at a glance.

See your open incidents, priorities, completed investigations and SOC readiness in one place — then pick up the next alert in your queue.

How a simulation works

Every shift follows the real investigation loop.

You are never handed the answer. You work from evidence to a decision, then explain it.

Step 01

Receive the alert

An alert lands in your queue with limited context, just like on a real shift. Some are genuine threats. Some are noise.

Step 02

Gather evidence

Review authentication logs, email headers, endpoint activity, network connections and user reports to build the picture.

Step 03

Make the call

Classify the alert, set severity, and decide whether to close, contain or escalate — with your reasoning recorded.

Step 04

Report and improve

Write your investigation notes, receive a score and feedback, and see which skills to practise next.

The investigation workspace

Evidence first. Answers never.

The workspace mirrors the tools analysts use: an incident header, evidence tabs, raw log data and a notes panel. Nothing is highlighted for you.

What you get

Built for practice, not memorisation.

Realistic evidence sets

Each scenario is built from the kinds of artefacts analysts actually review: sign-in logs, email headers, process activity and network events.

True and false positives

Not every alert is an attack. Learning to close benign alerts confidently is as important as catching real threats.

Investigation scoring

Your work is scored on evidence coverage, classification, severity, response decisions and documentation — not on guessing.

Feedback on what you missed

After each investigation you see which evidence mattered and where your reasoning could be stronger.

Skill readiness profile

Results roll up into a profile across eight SOC skill areas, so you know where you stand.

Role-based career paths

Start with the SOC Analyst path. More cybersecurity roles are in development.

How a job simulator is different from a cybersecurity course

Most cybersecurity courses teach concepts: what phishing is, how a SIEM works, which ports matter. That knowledge is necessary, but it is not what an interviewer or a hiring manager tests. They want to know whether you can take an alert you have never seen before, work out what happened and explain it clearly.

A cybersecurity job simulator closes that gap. Instead of watching someone else investigate, you do the investigation yourself:

  • You work from raw evidence. Logs and artefacts are presented as they would be in a real console, without commentary.
  • You make decisions under uncertainty. You decide what is malicious, what is benign and what needs escalation.
  • Your documentation counts. Clear incident notes are a core part of the job, so they are part of your score.
  • Mistakes are safe. Every environment is simulated. You never touch real systems or real user data.

The result is practical experience you can talk about in interviews — specific investigations, the evidence you used and the decisions you made. If you are still building foundations, start with the SOC analyst roadmap and practise alongside it.

What is available today

The SOC Analyst simulator is the first career path on Cyber Career Lab. Penetration testing, cloud security, network security, digital forensics and GRC paths are in development and are clearly marked as coming soon across the site.

FAQ

Frequently asked questions

Do I need cybersecurity experience to use Cyber Career Lab?

No. Scenarios start at an entry level and explain the context you need. If you are completely new, the SOC analyst roadmap and glossary will help you get up to speed.

Are the attacks and data real?

No. Every scenario uses simulated data modelled on real-world incidents. Names, IP addresses and organisations are fictional, and you never interact with live systems.

Do I need to install anything?

No. Simulations run in your browser. There are no virtual machines or tools to install.

Is the platform free?

You can start for free. See the pricing page for what is included now and what is planned.

Your first shift is waiting

Ready to investigate your first incident?

Start with the SOC Analyst path and see how you handle a real-world alert queue.

Start free. No experience required.