The Stanford Cyber Emergency Response Team (CERT) recently held its inaugural Incident Response (IR) Exercise on July 23, 2026. This was a collaborative effort that brought together the University IT (UIT) community and many teams across Stanford.
The exercise simulated a real-world cyber incident and was led by Alex Keller (School of Engineering), Bhavya Gupta (UIT ISO), Tem Velasquez Ysmael (Hoover IT), Nelia Lanets (UIT ISO), and Xavier Jimenez (VPSA).
The goal of the event was to provide a full-scope environment to facilitate an IR exercise where participants could coordinate and execute with composure under realistic, demanding conditions. The event was a success, bringing together cross-functional teams from varied business units and empowering them to self-organize and reason through the ambiguity and chaos that characterize real-world cyber triage.
Diverse participation
The exercise involved participants from diverse technology backgrounds, including managers, technical leads, service desk analysts, software developers, and interns. Each individual's unique skillset and role contributed to a successful day of learning and collaboration.

The power of an immersive virtual environment
Participants engaged in a realistic hands-on scenario that challenged them to further develop their expertise in areas such as open-source intelligence (OSINT), digital forensics, network analysis, active defense, and the construction of detailed narratives and timelines related to cyber incidents. This multifaceted approach ensured that everyone had opportunities to contribute and learn from one another.
Behind the scenes: Exercise setup and purpose
To support the event’s goals, organizers built a sprawling fictitious organization from the ground up—the PLIANT Institute, complete with its own researchers, published work, online presence, and internal dynamics. This gave event participants a living, believable world to investigate rather than a static scenario on paper.
Bringing that world to life required the organizing infrastructure team to create a complex virtual environment featuring components such as social media platforms, websites, servers, and workstations seeded with artifacts and clues for the teams to trace and synthesize. The ultimate goal for participants was to evict the attackers and perform attribution.
Underpinning the entire exercise was a fully live technical environment where every system that participants touched was real and running, requiring participating teams to interface with genuine infrastructure under real-time pressure.
Building and maintaining that environment to support a full day of investigation was a considerable engineering effort, providing an immersive atmosphere for participants to learn about authentic attacker tradecraft and test the efficacy of their incident response strategies in a low-risk setting.
Thanks to all involved
Special thanks go to the event’s sponsors—UIT Information Security Office (ISO), the School of Engineering, and the Hoover Institution—and to everyone who contributed to making this event a success.
The Stanford CERT also deserves recognition, as a voluntary campus advisory group and key strategic partner for cybersecurity at Stanford. The CERT plays a vital role in championing defensive readiness and expert cyber skill-building across campus.
Looking ahead
For the Stanford CERT, the exercise marked a significant milestone. While the team has long convened to track emerging threats and discuss important cybersecurity topics, this was its first time designing and executing a full-scale exercise of this nature.
As the team looks ahead, there is excitement about organizing more exercises like this to foster continuous learning and resilience within the community. Stay tuned for more updates and opportunities to engage in our Slack channel: #cop-infosec. In the meantime, explore more photos from the event.

