09/03/2026
How many attacks can we expect and how many of our systems are compromized?" is a very frequent question by all Blue Teams. Taavi has a very simple answer "All of them"
Good luck for the upcoming exercise to all the Blue Teams and see you in your systems!
🎬 A glimpse behind the scenes of Locked Shields: Red Team
Continuing to introduce the people behind Locked Shields – meet Taavi Sonets, who has been leading the Red Team for several years, the hackers who act as an adversary against Blue Teams defending a fictional nation's systems.
🔹How many years have you been involved in Locked Shields, and in what roles?
I’ve been part of Locked Shields since 2015. I started as a web attacks operator on the Red Team, later moved into client-side attacks targeting the internal networks environment, and over time progressed through several leadership roles. Since 2020, I’ve been the overall Red Team lead responsible for coordinating all Red Team subteams. Coincidentally, that was the year the exercise was cancelled due to COVID, and the following year it was held remotely.
🔹The Red Team stays behind the scenes. How much can you tell us about the team?
The Red Team is a diverse group of highly skilled specialists from around the world. We bring together experts in web attacks, client-side attacks targeting back-office environments, and infrastructure attacks that include both traditional networks and cyber-physical or operations technology systems.
Alongside the attack teams, we also have supporting roles responsible for infrastructure, development, innovation, and internal coordination. All of this helps us simulate a sophisticated and realistic adversary during the exercise.
🔹Approximately how many attacks can the Blue Teams expect during the exercise?
The safest assumption for the Blue Teams is: all of them.
🔹How do you ensure the attacks remain realistic and relevant to current threat landscapes?
We base our activities on real-world threat intelligence and lessons from recent incidents. The team continuously monitors how attackers operate and adapts the scenarios accordingly, so the Blue Teams face challenges that reflect today’s threat landscape rather than purely theoretical attacks.
At the same time, we like to give some of the classic techniques a new spin. Locked Shields is a unique exercise environment that allows us to combine realistic attacker behaviour with a level of complexity that can sometimes even exceed what organisations experience in day-to-day operations.
🔹If you could give one wish or piece of advice to the Blue Teams this year, what would it be?
We will hack you. Good luck!
Follow us to meet the teams behind LS26!