Skip to main content
Labshock✕
LoginStart Free

World of Labshock — Use Cases

Who Uses It.
And What For.

Eight things people do with Labshock that they could not do otherwise — because each one needs a real industrial process with no production consequences. Vendors demoing to prospects, startups building detection, security teams and governments testing the stack they already own, universities teaching, and engineers building the topology their own estate has.

Looking for your sector specifically — water, power, oil & gas, manufacturing, rail? See the industry breakdown.

Who runs it

6
continents
every inhabited one
35
countries buying
paid orders, not signups
27
named organisations
universities, partners, academies and conferences, all public record
4
ways to use it
Learn (training), Test (pentest and cyber range), Validate (your IDS, SIEM and controls), Build (infrastructure)
01

Universities

Teach ICS security with systems students can actually operate

Who does this

University of Arkansas at Little Rock

Public research university, Arkansas. Built a 13-week Industrial System Security course around World of Labshock for 20+ students.

Friedrich-Alexander University

Research university, Erlangen, Germany. Runs the CYBERGY OT and industrial cybersecurity summer school with Labshock, for the second year running.

George Mason University, The Citadel, Texas A&M Corpus Christi, University of Texas San Antonio

US research universities. Teach ICS and OT security using Labshock environments, on campus and in coursework.

See the academic ecosystem →

What they do

  • Run a full industrial environment per student, isolated, reset between sessions
  • Assign structured progression — quests, guides and badges — instead of building coursework from scratch
  • Take students from automation fundamentals through protocol analysis to detection engineering
  • Manage users and track XP, levels and completed quests through Command Center

What makes it possible

Structured progression— levels 1-60 across 10 zones, mapped to competencies
Guides and quizzes— theory tied to the lab it belongs to, with badges on completion
Command Center— user management plus XP, levels, quests and badges per student
G2 review by Jim G., Adjunct Professor, 5 out of 5 stars: "Easy-to-Use ICS/OT Virtual Labs with Responsive Support"
02

Training providers

Deliver paid OT courses without building the lab yourself

Who does this

Boots to Cyber, OT Leaders Club, Netsentinel Academy

Training academies and professional communities. Use Labshock to take people into industrial security — veterans transitioning into cyber, practising OT leaders, and academy students.

Institute of Cybersecurity Excellence

Cybersecurity training and research organisation. Delivers training on Labshock at scale.

ICS Arabia

Regional industrial cybersecurity initiative, Middle East. Uses Labshock to deliver industrial security training to their own customers.

A UK engineering and defence training groupunnamed by request

Large technical training provider, United Kingdom. Delivers industrial cybersecurity training on Labshock environments.

License terms →

What they do

  • Deliver instructor-led workshops and bootcamps on environments that already exist
  • Grant access to enrolled participants for the duration of a programme
  • Record sessions and produce derived course material
  • Run the same environment for every cohort, reset each time

What makes it possible

Enterprise License— external training programme delivery is explicitly permitted
On-premise deployment— no cloud dependency, no shared infrastructure
Portable Lab Format— ship the environment to a classroom or a client site
03

Security vendors

Demo your product on a real plant with no production behind it

Who does this

GuidePoint Security

Cybersecurity services and solutions provider, US. Run a dedicated Labshock OT environment for their industrial security work.

HWG Sababa and Y Cyber

OT security vendors, Italy and international. Built a GE Mark VIe gas turbine environment on Labshock and use it to present their own product to customers.

NVISO Labs

Security research and services team, Europe. Tests their own products and services against Labshock environments.

A major US cybersecurity integratorunnamed by request

Enterprise security solutions provider, United States. Commissioned a custom railway control lab and uses it to demonstrate their product to their own customers.

Enterprise License terms →

What they do

  • Stand up an isolated environment matching the prospect's architecture — their protocols, their segmentation, their device mix
  • Point your product at live Modbus, S7comm, DNP3 or IEC 104 traffic from a running process
  • Trigger a real process event on the OT side and show your product catching it in front of the buyer
  • Reset the environment and run the same demo again for the next prospect

What makes it possible

Surge Router— mirrors raw industrial traffic to any external IDS or hardware appliance
Tidal Collector— streams OT events into any external SIEM or analytics platform
Portable Lab Format— export the environment and hand it to a colleague or reuse it on the next call
G2 review by Tommaso B., OT Security Specialist at Y Cyber, 5 out of 5 stars: "Hands-On, Gamified OT Security Learning with Fast Support and Great Value"
04

Product integration

Put a working industrial plant inside your own product

Who does this

Kasm and SteelDome

Workspace streaming and industrial storage/security platforms, US. Integrate Labshock into their own products, both to demonstrate capability to customers and to build a service on top.

License scope →

What they do

  • Embed Labshock environments inside your own platform as the industrial layer
  • Show customers your product operating against real PLC, SCADA and protocol traffic
  • Build a billable service on top of the environment rather than reselling a demo
  • Deploy on-premise where the customer requires it, with no cloud dependency

What makes it possible

Portable Lab Format— complete environments exported and deployed inside another product
On-premise deployment— no shared infrastructure, no cloud requirement
Partner Program— embedding Labshock in your own product runs under a separate agreement
05

Security startups

Get OT traffic to build your detection product against

Who does this

Ultrametrix

Passive OT mapping and cyber-risk platform, France. Generated OT traffic on Labshock to validate their own discovery module.

A Houston security startupunnamed by request

Early-stage detection vendor, United States. Validates its IDS against multi-protocol OT traffic from running processes.

See the lab environments →

What they do

  • Generate continuous, labelled industrial traffic across several protocols and topologies
  • Tune detection logic against genuine protocol behaviour rather than replayed captures
  • Test whether your parser handles Modbus pipelining, DNP3 event classes, or S7comm symbolic addressing correctly
  • Feed labelled OT traffic into behavioural or AI-based models for training and evaluation

What makes it possible

Live process behaviour— traffic comes from PLC logic actually executing, not from a replay
Multi-protocol coverage— Modbus TCP, Siemens S7comm, DNP3, IEC 60870-5-104
Repeatability— run the same scenario twice and get the same conditions
06

Security teams

Find out whether the detection you already pay for actually fires

Who does this

A US state governmentunnamed by request

State-level public sector, United States. Uses Labshock to work on critical infrastructure security capability.

A European national governmentunnamed by request

National public sector, Europe. Uses Labshock for industrial security capability development.

An industrial operator under elevated threatunnamed by request

Critical infrastructure operator. Uses Labshock to build and test OT security capability under realistic threat conditions.

How the Wazuh lab works →

What they do

  • Mirror industrial traffic from the lab into the same IDS you run in production
  • Forward OT telemetry into your live SIEM and check whether ingestion, parsing and normalisation are correct
  • Operate an approved command — a breaker, a setpoint, a coil write — and confirm the alert fires and says something useful
  • Test the IT-to-OT boundary by sending traffic at it and watching which rules actually engage

What makes it possible

Wazuh lab— free, deployed, connected to a running industrial environment
Splunk and ELK labs— full pipelines from OT telemetry into a production-grade SIEM
Zeek and Suricata— network detection over industrial traffic, next in the same chain
07

Engineering teams

Build the exact topology your estate has, not a generic one

Who does this

A US engineering and infrastructure firmunnamed by request

Engineering services, own OT estate. Builds environments matching the architectures they work on rather than using the stock labs.

Detection startupsunnamed by request

Early-stage OT security vendors, Europe and the US. Construct the topologies their own IDS has to survive — odd segmentation, mixed protocols, traffic they cannot otherwise generate.

Industrial operatorsunnamed by request

Asset owners with their own OT estate. Recreate their own plant architecture — their segments, their controllers, their protocols — to test a change before it reaches production.

See the release →

What they do

  • Define your IT, DMZ and OT zones and the routing between them
  • Add PLCs, HMIs, SCADA servers, historians and firewalls to match your real device mix
  • Model your segmentation and test whether the boundary holds when you send traffic at it
  • Export the finished environment and share it with the team, or archive it for repeatable exercises

What makes it possible

Labshock Builder— dynamic environment generation across IT, DMZ and OT layers
Multi-PLC scenarios— master-slave topologies and distributed process control
Command Center— user management and XP progression tracking across your team
08

Conferences & community

Run a live OT test-and-defend session instead of a talk

Who does this

BSides São Paulo, BSides Aarhus, BSides Paris, DEF CON, HOU.SEC.CON, OT.SEC.CON, CYBR.SEC.CON

Security conferences, three continents. Ran Labshock on stage as live industrial systems rather than as a slide deck.

YNOW2026, a Yokogawa Users Conference

An industrial automation vendor's own users conference, not a security conference. Named Labshock in its own speaker spotlight, introducing it to an audience of automation engineers and operators.

ICS Village

Industrial cybersecurity community. Shows Labshock at conferences as hands-on industrial systems for attendees to operate.

Read the announcement →

What they do

  • Give attendees real industrial systems to operate and defend, scored like a CTF but built for OT
  • Run a live masterclass where participants write PLC logic and watch the process respond
  • Use the free tier so anyone in the room can continue afterwards without a purchase

What makes it possible

Free starter zone— Loginward, no card, so attendees keep going after the session
Isolated installation— runs entirely on your own hardware, air-gapped if required
Reset between runs— the same scenario for every group

Why there are no customer logos on this page

Naming an industrial operator as a security customer tells the internet which organisations are working on their OT gaps. Most of ours are contractually entitled to stay unnamed, and we think the rest should be too.

Universities, conferences and partners are named here because their participation is already public and costs them nothing. Commercial customers are described by profile only. If you want a reference conversation before buying, we will arrange one directly — info@labshocksecurity.com.

OT security must be testable, not documented.

Start in the free zone, or tell us what you need to prove and we will show you the environment that proves it.