Ten More Companies, 100 More Labs — A Bank, a Water Utility, a Hospital, a Defence Machine Shop
In August we launched lab environments with two fictional companies and a promise that more were coming. A Dutch electricity network operator, Vlietstroom, followed the same week. Today there are ten more, and the set now runs to thirteen organisations, 134 labs and ten frameworks.
The idea has not changed. Each company is built whole: its policies name its systems, its systems appear in its registers, its staff appear in its directory exports, its suppliers sign its contracts, and its regulator writes it letters. You get the evidence and the question the job actually asks. Nothing is annotated, nothing hints, and most findings only exist in the gap between two documents.
Ten organisations, nine frameworks
Every pack is marked against the instrument that actually binds that kind of organisation, at the level a real assessment cites. Where a second regime applies, it applies in prose, the way it would in a real report.
Merridale Mutual Bank — a customer-owned bank in Ballarat with 24 branches across western Victoria. Marked against APRA CPS 234, paragraph by paragraph, with CPS 230, the Essential Eight and the Privacy Act's notifiable breach scheme in play. The Board noted a paper saying the bank complied with every paragraph; the CIO who wrote it was holding a memo, in the regulator's own words, saying otherwise. Then a lending officer's phished account downloaded 8,412 loan files and APRA was told on day eleven, with the wrong date of awareness.
Tregarrick Water — a water and wastewater company in south-west England, an operator of essential services under the NIS Regulations. Marked against the NCSC Cyber Assessment Framework, all 39 contributing outcomes. This is the first environment built around operational technology: PLCs, HMIs, telemetry outstations and a systems integrator's always-on remote access. One Sunday morning a session using a shared engineer credential from 2019 cut the chlorine dose at the largest works for 111 minutes. The self-assessment sent to the Inspectorate four months earlier had scored 31 outcomes achieved, with all forty operational sites out of scope.
Kestrel Ridge Precision — an Ohio machine shop making parts for two defence primes from ITAR-controlled drawings. Marked against NIST SP 800-171, all 110 requirements. It posted a self-assessment score of 110 to the Department of Defense on a plan of action that lists 47 unmet requirements; the methodology gives minus 37. Its “CUI enclave” is a folder every domain account can read. Its incident report went in on day nineteen. Its CNC programmer is a foreign person nobody had asked about.
Marrowbay Outfitters — a Vancouver outdoor retailer with 38 stores and a web store. Marked against PCI DSS v4.0.1 at the sub-requirement level, with PIPEDA in play. A skimming script ran on its checkout page for 39 days and the bank found it. The CFO had signed two self-assessment questionnaires for an environment that stopped existing in 2019. Card numbers and security codes turned up in three places nobody had scoped.
Sable Creek Regional Medical Center — a 190-bed community hospital with six clinics, a HIPAA covered entity. Marked against the HIPAA Security Rule. A lost laptop holding 3,412 patients' records was assessed as a low probability of compromise until a patient complained to the regulator; a state senator's chart was opened by people nobody ever reviewed, because every one of 1,552 accounts has break-the-glass enabled and the review has never run.
Thornbury Wells LLP — a Bristol solicitors' practice of 140 people. Marked against ISO/IEC 27001:2022 Annex A with UK GDPR in play. A client's completion funds paid to a fraudster on a Friday morning, an ICO form and an SRA letter that do not agree with the incident record, and a letter to a former client promising an information barrier in a document system that has every matter open to every user.
Ardglen Payments — a Dublin electronic money institution serving 48,000 small businesses across three countries. Marked against DORA at the article level, with the GDPR as the second regime. Nine hours in which every outgoing payment failed, classified P2 and covered in a monthly report; an ICT risk framework adopted from a template three days before DORA applied; and a register of information that lists four of seven providers with the critical-function column blank.
Hallweg Präzisionstechnik — a family-owned German machine-tool maker with a plant in Czechia, an important entity under NIS2. Its data protection officer wrote in 2025 that it should register with the BSI; the memo was filed. Ransomware then stopped the Czech plant for two days and was logged as an IT fault, and the management body told a customer there had been no security incidents.
City of Corvane, Oregon — a council-manager city of 68,000 residents whose nine-person IT department runs everything from the police records system to the water plant's control network. Marked against NIST CSF 2.0. Four configurations decide who can reach the city from outside, including the vendor agent on the water plant's control workstation; a phished billing clerk's mailbox held 2,140 residents' bank details; and the notifications the city owed ran sixty-one days.
Tarnbeck Technology Services — a Leeds managed service provider looking after 140 organisations and 3,400 endpoints. Marked against ISO/IEC 27001:2022. A remote-management console that runs code as SYSTEM on every device it manages, a departed engineer whose identities live in four directories, and a phished analyst who forwarded a GP practice manager's mail for five days while the incident plan took six to notice what it owed the customer.
The same failure, thirteen ways
The first lab of every company is the same lab. Somebody has left. Their directory account was disabled on the day and the leaver ticket was closed complete. Then you open the other account stores: the core banking platform, the integrator's remote access portal, the PDM system, the cloud console, the clinical system, the tag manager. The mechanism is identical every time and the framework it gets written up against never is. That is the point. Watching one failure become an Annex A finding, a CPS 234 paragraph, a CAF outcome and an SP 800-171 requirement is the fastest way we know to stop treating a framework as a vocabulary test.
The regulator's paper trail
A new kind of artefact runs through the later packs: the representation. The self-assessment as submitted to the Inspectorate. The score as entered in SPRS, with the affirmation. The Board paper that says “compliant” on every line. The notification as filed, with the date of awareness the company chose to give. And then the letter back — from APRA, from the Inspectorate, from the prime contractor, from the acquirer — saying it cannot reconcile what it was told with what happened.
Several labs are structured by that letter. You answer each of its demands the way the evidence answers it, and then you draft the substance of the covering statement: which statements were untrue when made, why, what the Board knew and when, what has been done since and what has not. The rubric rewards refusing to promise a date and refusing to write anything the artefacts contradict. Real covering statements are written under exactly that constraint.
Every pack ends the same way
A three-hour capstone with the full evidence set: a findings register against the framework, an executive summary for a board that did not see the paper, the two documents the company owes, and a question about which findings share a systemic cause. A report listing 24 unconnected findings does not score well, which is also true in practice.
The numbers
The ten new companies add 100 labs, 532 artefacts and 240 findings, roughly 103 hours of work and 7,177 points. Across all thirteen organisations there are now 134 labs. Each new company is about ten hours from front door to capstone.
The first lab of every company is free
As before, the front door of each environment is free to work end to end, evidence and marking included. That is fourteen free labs across the thirteen companies. The rest come with a paid membership, and paid labs are still listed with their full brief so you can see what you would be working on.
Start at /lab-environments for how it works, or go straight to /labs if you already have an account.
Three honest notes
Everything in a lab is invented. The companies, staff, customers, suppliers, systems, documents and regulator correspondence were written for the exercise. Company names, product names and place names that resemble real ones are coincidence. Real identifiers — company numbers, licence numbers, CAGE codes, merchant IDs — are redacted rather than invented. None of it evidences any real organisation's controls or may be relied on outside the exercise — see the disclaimer.
The frameworks are paraphrased. The dropdowns you mark findings against carry abridged texts of CPS 234's paragraphs, the CAF's outcomes, SP 800-171's requirements and PCI DSS's sub-requirements, written as a teaching aid. Numbering and clocks — 72 hours here, ten business days there — are stated as facts of the scenario. Verify the current instrument before you rely on any of it at work.
Written answers are marked by an AI. Your answer, the prompt and its rubric are sent to our AI provider; the structured fields never leave our database. You are writing about an invented company, so a lab answer should not contain anything about you or your employer. The AI transparency page and the privacy policy set out exactly what is sent and what is not.