About ICSRange
Hands-on ICS security training for the teams that defend critical infrastructure
SectorNine is ICSRange's flagship training platform. We build realistic industrial control system ranges where security professionals practise offensive and defensive techniques against the same protocols, architectures, and failure modes they encounter in production.
Why we built this
Most ICS security training relies on slides, packet captures, or watered-down simulations. Operators leave those courses without the muscle memory to respond when a real adversary is moving through their OT network.
SectorNine gives teams isolated, full-stack industrial environments - domain controllers, historians, SCADA masters, PLCs, HMIs, and engineering workstations - connected by the same protocols that run power grids, water plants, and refineries.
Every lab is deployed on dedicated bare-metal infrastructure with nested virtualisation. No shared tenancy, no performance compromises, no artificial constraints.

What drives us
Realistic Training
Every range mirrors production ICS environments - real protocols, real vulnerabilities, real consequences.
Defence-First Mindset
Offensive skills sharpen defensive instincts. We train teams to protect the infrastructure that keeps societies running.
Industry Collaboration
Built with input from asset owners, integrators, and incident responders across critical infrastructure sectors.
Verified Skills
Per-player flags and completion certificates prove capability - no shared answers, no shortcuts.
Platform capabilities
Built on Ludus cyber ranges with automated provisioning, per-player isolation, and integrated monitoring.
- Full Purdue model L0–L5 attack paths
- Modbus, DNP3, OPC UA, IEC 61850 protocols
- Per-player HMAC-SHA256 unique flags
- Isolated WireGuard VPN access per session
- Wazuh SIEM integration for blue team exercises
- Sector-specific monitoring profiles
- MITRE ATT&CK for ICS technique mapping
- Automated range provisioning and teardown
Start training your team
Business registration required. We verify every organisation before granting access.