TRAINING & SECURITY EXERCISES
Train on real findings. Rehearse real decisions.
Ready modules on Rust, Substrate, and NEAR, or a session built around your own systems, procedures, and roles.
Training scope
Formats
Two ways in. Take a ready module on a specific stack, listed further down, or have a session built around your own system, procedures, and roles. The formats below can be run either way.
-
01 Secure-design workshops Challenge a real system and turn issues into design decisions. -
02 Technical training Rust, blockchain, and smart-contract security tied to the stack. -
03 Custody tabletops Practice key-management failures and high-impact decisions. -
04 Key ceremonies Rehearse roles, evidence, exceptions, and recovery. -
05 Incident exercises Test playbooks, escalation, and control behavior. -
06 Executive workshops Practice digital-asset security decisions under realistic constraints.
Timing
Best used before the real thing.
Before a critical event
A team is preparing for launch or a high-impact operation.
Procedures are untested
The playbook exists but has not been exercised.
Engineers need depth
Training should connect directly to the actual stack and issues.
Leadership must practice
Decision-makers need experience under realistic constraints.
Process
From realistic scenarios to stronger security response.
- 01
Set the objective
Choose the technical skill, operational procedure, or leadership decision the session needs to strengthen.
- 02
Build the scenario
Use the team’s stack, roles, threat model, and constraints to create realistic events and decision points.
- 03
Run the session
Facilitate hands-on training or an exercise while capturing decisions, assumptions, and control gaps.
- 04
Debrief and improve
Turn observations into owned actions, updated procedures, and focused follow-up work.
Outputs / What you receive
What the team leaves the room with.
Scenario design
A practical session shaped around the team, system, and behavior.
Facilitated session
Technical training or exercise with clear decision points.
Follow-up actions
Observations, control gaps, decisions, and improved playbook material.
Ready modules
Training we already teach.
Each module is taught from findings in our own published reports for that ecosystem.
Rust security training
The issue classes we keep finding in production Rust, taught from real findings rather than a syllabus.
Substrate and Polkadot SDK security training
Pallet design, runtime logic, and the failure modes we have reported in Substrate-based chains.
NEAR security training
Smart contract and protocol security for NEAR, drawn from the reviews we have published.
Public training material
Watch how we teach it before you book it.
Typical engagement team
Who typically leads this work
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

José C. Ramírez
Specialist Advisor
Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.

Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
FAQ
Questions before scoping
Do we take a ready module or have something built for us?
Either. The ready modules cover Rust, Substrate and the Polkadot SDK, and NEAR, and suit a team that wants depth in a specific stack. A built session starts from your architecture, procedures, and roles instead, which is the better choice for tabletops, key ceremony rehearsals, and anything where the point is how your people decide.
What makes the ready modules different from a generic course?
They are taught from findings in our own published reports for that ecosystem, so the examples are real issues in real systems rather than textbook ones. Two of the modules have public recordings further down this page, so you can judge the teaching before booking it.
Do you use our real systems and our real playbooks?
For a built session, yes, wherever the scenario allows it. An exercise run on a generic company teaches generic lessons. We work from your architecture, your procedures, and your threat model, and we run the session against the playbook you would actually reach for.
Who should be in the room?
Whoever would be in the room during the real event. For a key ceremony rehearsal that means the signers and approvers; for an incident exercise it means engineering, operations, and whoever can authorize a decision under pressure. Mixed-function sessions surface more than single-team ones.
What do we need to prepare beforehand?
Access to the architecture, the relevant procedures, and a short conversation about what you want the session to strengthen. If a playbook does not exist yet, that is useful information rather than a blocker, and the session can be shaped to produce a first one.
What do we get afterwards?
The scenario design, the observations captured during the session including where decisions stalled or controls behaved unexpectedly, and follow-up actions with owners. Where the exercise exposed gaps in a procedure, you get improved playbook material to fold back in.
Related services
Next step
Practice the decision before the real event.
Share the team, system, scenario, and behavior you need to strengthen. We will shape a practical session around it.
Discuss your scope