World of Labshock — Use Cases
Who Uses It.
And What For.
Eight things people do with Labshock that they could not do otherwise — because each one needs a real industrial process with no production consequences. Vendors demoing to prospects, startups building detection, security teams and governments testing the stack they already own, universities teaching, and engineers building the topology their own estate has.
Looking for your sector specifically — water, power, oil & gas, manufacturing, rail? See the industry breakdown.
Who runs it
Universities
Teach ICS security with systems students can actually operate
Who does this
Teach ICS and OT security using Labshock environments, on campus and in coursework.
What they do
- Run a full industrial environment per student, isolated, reset between sessions
- Assign structured progression — quests, guides and badges — instead of building coursework from scratch
- Take students from automation fundamentals through protocol analysis to detection engineering
- Manage users and track XP, levels and completed quests through Command Center
What makes it possible
Training providers
Deliver paid OT courses without building the lab yourself
Who does this
Use Labshock to take people into industrial security — veterans transitioning into cyber, practising OT leaders, and academy students.
Delivers training on Labshock at scale.
Uses Labshock to deliver industrial security training to their own customers.
Delivers industrial cybersecurity training on Labshock environments.
What they do
- Deliver instructor-led workshops and bootcamps on environments that already exist
- Grant access to enrolled participants for the duration of a programme
- Record sessions and produce derived course material
- Run the same environment for every cohort, reset each time
What makes it possible
Security vendors
Demo your product on a real plant with no production behind it
Who does this
Run a dedicated Labshock OT environment for their industrial security work.
Built a GE Mark VIe gas turbine environment on Labshock and use it to present their own product to customers.
Tests their own products and services against Labshock environments.
Commissioned a custom railway control lab and uses it to demonstrate their product to their own customers.
What they do
- Stand up an isolated environment matching the prospect's architecture — their protocols, their segmentation, their device mix
- Point your product at live Modbus, S7comm, DNP3 or IEC 104 traffic from a running process
- Trigger a real process event on the OT side and show your product catching it in front of the buyer
- Reset the environment and run the same demo again for the next prospect
What makes it possible
Product integration
Put a working industrial plant inside your own product
Who does this
Integrate Labshock into their own products, both to demonstrate capability to customers and to build a service on top.
What they do
- Embed Labshock environments inside your own platform as the industrial layer
- Show customers your product operating against real PLC, SCADA and protocol traffic
- Build a billable service on top of the environment rather than reselling a demo
- Deploy on-premise where the customer requires it, with no cloud dependency
What makes it possible
Security startups
Get OT traffic to build your detection product against
Who does this
Tests and tunes its IDS against live industrial traffic it has no other way to obtain.
Validates its IDS against multi-protocol OT traffic from running processes.
What they do
- Generate continuous, labelled industrial traffic across several protocols and topologies
- Tune detection logic against genuine protocol behaviour rather than replayed captures
- Test whether your parser handles Modbus pipelining, DNP3 event classes, or S7comm symbolic addressing correctly
- Feed labelled OT traffic into behavioural or AI-based models for training and evaluation
What makes it possible
Security teams
Find out whether the detection you already pay for actually fires
Who does this
Uses Labshock to work on critical infrastructure security capability.
Uses Labshock for industrial security capability development.
Uses Labshock to build and test OT security capability under realistic threat conditions.
What they do
- Mirror industrial traffic from the lab into the same IDS you run in production
- Forward OT telemetry into your live SIEM and check whether ingestion, parsing and normalisation are correct
- Operate an approved command — a breaker, a setpoint, a coil write — and confirm the alert fires and says something useful
- Test the IT-to-OT boundary by sending traffic at it and watching which rules actually engage
What makes it possible
Engineering teams
Build the exact topology your estate has, not a generic one
Who does this
Builds environments matching the architectures they work on rather than using the stock labs.
Construct the topologies their own IDS has to survive — odd segmentation, mixed protocols, traffic they cannot otherwise generate.
Recreate their own plant architecture — their segments, their controllers, their protocols — to test a change before it reaches production.
What they do
- Define your IT, DMZ and OT zones and the routing between them
- Add PLCs, HMIs, SCADA servers, historians and firewalls to match your real device mix
- Model your segmentation and test whether the boundary holds when you send traffic at it
- Export the finished environment and share it with the team, or archive it for repeatable exercises
What makes it possible
Conferences & community
Run a live OT test-and-defend session instead of a talk
Who does this
Ran Labshock on stage as live industrial systems rather than as a slide deck.
Shows Labshock at conferences as hands-on industrial systems for attendees to operate.
What they do
- Give attendees real industrial systems to operate and defend, scored like a CTF but built for OT
- Run a live masterclass where participants write PLC logic and watch the process respond
- Use the free tier so anyone in the room can continue afterwards without a purchase
What makes it possible
Already public
Organisations in the ecosystem
Universities, partners, academies and conferences whose involvement is a matter of record. Commercial customers are not on this list — see below for why.
Why there are no customer logos on this page
Naming an industrial operator as a security customer tells the internet which organisations are working on their OT gaps. Most of ours are contractually entitled to stay unnamed, and we think the rest should be too.
Universities, conferences and partners are named here because their participation is already public and costs them nothing. Commercial customers are described by profile only. If you want a reference conversation before buying, we will arrange one directly — info@labshocksecurity.com.
OT security must be testable, not documented.
Start in the free zone, or tell us what you need to prove and we will show you the environment that proves it.
