
Competing at the UK Cyber Leaders Challenge
Competing at the UK Cyber Leaders Challenge
In February 2025, I participated in the UK Cyber Leaders Challenge in Cheltenham, a scenario-based competition that put my team in the role of cybersecurity advisers responding to a critical infrastructure cyberattack. The experience was both challenging and eye-opening, demonstrating the real-world complexity of cybersecurity incident response at a national level.
The Scenario
The challenge presented us with a fictional but realistic scenario: a cyberattack affecting two major UK ports: Port of Great Yarmouth and Port of Liverpool. The attack exploited a vulnerability in SHERPA, the ISO container management software used across the ports, allowing threat actors to manipulate vessel stowage plans and potentially disrupt critical maritime operations.
The scenario materials were comprehensive, including intelligence reports from MI5 about Volt Typhoon-style state-sponsored actors, INTERPOL assessments of organised crime groups targeting ports, incident response updates from BAE Systems, and email chains between port operations teams. This wasn't just a technical exercise; it required understanding the broader context: economic impact, supply chain disruption, national security implications, and the coordination needed across multiple stakeholders.
The Challenge
Our team was tasked with preparing a briefing for the Local Resilience Forum (LRF), a group of senior decision-makers from government and industry who needed to understand the situation and decide how to respond. We had to:
- Submit a Briefing Note: A two-page PDF document analysing the situation, implications, and recommendations
- Deliver a 10-minute Presentation: Present our assessment and recommendations to judges acting as port representatives and government officials
- Answer Questions: Respond to 10 minutes of direct questions from the judging panel
The briefing date was set as Monday 3rd February 2025, and we needed to balance multiple competing priorities: security, operational continuity, economic impact, and public safety.
My Role and Contribution
I was responsible for presenting the closing section of our briefing, focusing on our final conclusions and recommendations. This was the most critical part, where we had to clearly articulate what needed to be done and why.
My key recommendation was straightforward but essential: isolate the network first, then decide what to do with the malware. This approach prioritised containment while maintaining flexibility for the response. I explained that before making any decisions about remediation, we needed to prevent further spread and assess the full scope of the compromise.
During the question-and-answer session, the judges (acting as port representatives) asked probing questions about our recommendations. They wanted to understand the technical rationale, the operational impact, and how we balanced security with business continuity. It was challenging but incredibly valuable to defend our approach under pressure.
What Made It Special
What struck me most about this experience wasn't just the technical challenge, but the people involved. Seeing students from other universities brought different perspectives and approaches to the same problem. More importantly, meeting the judges, cybersecurity professionals who are actively shaping how the UK responds to cyber threats, was genuinely inspiring. These weren't just academics or competition organisers; they were people working on real-world cybersecurity challenges that affect national security.
The competition was more enjoyable than I expected. The scenario felt realistic, the materials were detailed and well-crafted, and the pressure of presenting to experienced professionals made it feel like a real briefing rather than just an academic exercise.
The Outcome
We didn't win the competition, but the feedback we received was encouraging. The judges commented that we had done more from a technical perspective than they expected, which was validating. More importantly, we were invited to participate in the next year's challenge and received invitations to other CLC events, recognition that our approach and analysis had value.
Key Learnings
The most valuable takeaway from this experience was simple but powerful: be ready, don't be afraid, and challenge yourself.
This competition pushed me out of my comfort zone. Presenting technical recommendations to experienced professionals, defending our approach under questioning, and working under time pressure: all of this built confidence in my ability to communicate complex cybersecurity concepts to diverse audiences.
I also learned the importance of thinking beyond just the technical aspects. A cybersecurity incident affecting critical infrastructure isn't just about malware and vulnerabilities; it's about economic impact, supply chain disruption, public safety, and national security. Understanding these broader implications is essential for anyone working in cybersecurity, especially in roles that require communicating with non-technical stakeholders.
Why This Matters for Security Operations
Looking back, this was the closest thing to a real incident response exercise I'd done up to that point, and the skills it demanded map directly onto security operations work:
Triage under incomplete information: We never had the full picture. Intelligence reports, vendor updates and internal email chains all arrived partial and sometimes contradictory, which is exactly how a real incident unfolds. The job was to form a working assessment anyway and revise it as new information landed.
Containment decisions: My recommendation was to isolate the network first and decide what to do about the malware second. That is a containment call, and it involves accepting a real operational cost to stop the bleeding. Making that trade deliberately, and being able to justify it, is core incident response.
Understanding blast radius: A compromise of port management software isn't just a technical event. It's supply chain disruption, economic impact and public safety. Knowing how to reason about impact beyond the affected host is what separates useful incident reporting from a list of indicators.
Communicating under questioning: Presenting to judges playing port representatives and government officials, then defending the approach through ten minutes of direct questions, is the same skill as briefing stakeholders mid-incident. They don't want your methodology, they want to know what's happening, how bad it is, and what you need from them.
Conclusion
The UK Cyber Leaders Challenge was a formative experience that combined technical analysis, strategic thinking, and effective communication. It proved I could work an incident scenario from intelligence through to a defensible containment strategy, and present that to people who needed to make decisions off the back of it.
More than anything, it reinforced something I still believe: the technical part of incident response is rarely the hardest part. Deciding what to do with incomplete information, and explaining that decision clearly while the clock is running, is where the real difficulty lives.