- FAQ
Common questions
answered
CCS is an operational cyber wargaming platform designed to help organizations practice and improve their response to cyber incidents. Unlike technical cyber ranges that focus on individual skill development, CCS trains organizational teams - from technical staff to executives - in coordinating their response to complex, multi-faceted cyber attacks. It provides a realistic, scenario-based environment where organizations can strengthen coordination, test procedures, and build resilience without the risks of real incidents.
Traditional cyber ranges teach how to perform specific technical tasks - forensic analysis, malware investigation, SOC procedures. CCS teaches what to do in a given situation, training organizational coordination and decision-making under pressure across all levels. It models the full landscape - infrastructure, security controls, business processes, and people - and simulates at scale without requiring full system emulation.
Tabletop exercises discuss scenarios in theory. CCS makes participants live them - with evolving technical events, time pressure, and incomplete information. Decisions have real consequences in the simulation. The complete structured data log enables objective After-Action Review instead of a discussion of what you think happened. It's the difference between discussing a flight emergency and practising it in a simulator.
Building the cyber landscape typically takes: small organizations 1–2 weeks; medium 2–3 weeks; large 3–5 weeks. Once the landscape exists, each new scenario takes 1–2 days to prepare. The exercise itself runs in 3–6 hours. For repeat exercises, only a new scenario is needed - the landscape is reused.
Yes. CCS is designed for distributed participation across departments, cities, or countries. Remote coordination is itself a training objective. The integrated messaging system captures all communication with simulation timestamps. Participants can be in the same room or on different continents.
No. A representative model is sufficient. A bank with 100 branches might model 10–15. CCS's validation tools ensure your model is functionally complete. Certain technical details - firewall rules, user accounts, system configurations - matter for realism, but full duplication of every system is never necessary.
Yes - and for organizations with suitable expertise, that's often the best approach. Those who design the exercise should not participate as players to maintain integrity. Initial exercises require the most effort; once the landscape is built, subsequent exercises need only a new scenario. Utilis provides training and ongoing support for organizations building internal capacity.
CCS supports organizations in meeting exercise requirements under both directives - but the goal is genuine readiness, not just a compliance checkbox. All exercise data is recorded in structured format, giving organizations the documented basis needed to satisfy auditors. More importantly, the teams that go through CCS exercises are actually better prepared to respond when a real incident occurs.
CCS can simulate virtually any cyber attack type: ransomware, data breaches, supply chain compromise, insider threats, APT multi-stage campaigns, DDoS, zero-day exploitation, and business email compromise. Scenarios can model documented APT group TTPs, be based on threat intelligence, or address custom attack paths specific to your risk profile.
CCS exercises can be configured for any combination of participants - from focused technical drills to full organizational response including C-level leadership. Typical participants include: incident managers, IT/OT security teams, SOC analysts, business process owners, legal and compliance, communications and PR, and CIO/CISO/CEO. The composition depends on the exercise objectives.
Have a question we haven't answered?
We'd be happy to talk it through.
Cookie Policy
- What are cookies?
Cookies are small text files placed on your device (computer, tablet, or mobile) when you visit a website. They allow the website to recognise your device and remember certain information about your visit — for example, your language preference or whether you have already accepted our cookie notice.
Cookies are set either by us (first-party cookies) or by third parties whose services we use on this website (third-party cookies). Some cookies are deleted when you close your browser (session cookies); others remain on your device for a set period (persistent cookies). - What cookies do we use?
Category 1: Strictly necessary cookies
These cookies are essential for the website to function correctly. They do not collect personal information for marketing purposes and cannot be disabled. Without them, services such as page navigation and form submission would not work.
– Session cookie — maintains your session as you navigate the website. Expires when you close your browser.
– Cookie consent cookie — stores your cookie preference so you are not asked again on every visit. Expires after 12 months.
Legal basis: Strictly necessary cookies do not require consent under the ePrivacy Directive.
Category 2: Analytical / performance cookies
These cookies help us understand how visitors use our website — for example, which pages are visited most often and whether users encounter errors. We use this information to improve the website. All data is aggregated and anonymised where possible.
– Analytics tool (e.g. Matomo or Google Analytics) — collects anonymised data on page views, session duration, traffic source, and device type. Expires after 13 months.
Legal basis: These cookies are set only with your consent (Article 6(1)(a) GDPR). You may withdraw consent at any time via our cookie preferences panel.
Category 3: Functional cookies
These cookies enable enhanced functionality and personalisation, such as remembering your language preference (HR/EN). They may be set by us or by third-party providers whose services appear on our pages.
– Language preference cookie — stores your selected language (HR or EN). Expires after 12 months.
Legal basis: Legitimate interests (Article 6(1)(f)) for language preference, or consent where the cookie is set by a third party.
Category 4: Marketing / tracking cookies
We do not currently use marketing or advertising tracking cookies on this website. If this changes, this policy will be updated and your consent will be requested before any such cookies are set. - Third-party cookies
If we embed content from third-party services (such as LinkedIn “Follow” widgets, YouTube videos, or map embeds), those providers may set their own cookies subject to their own privacy policies. We have no control over third-party cookies. We will inform you where third-party content that may set cookies is present on a page. - How to manage cookies
You can control and manage cookies in the following ways:
Cookie consent banner
When you first visit utilis.biz, a cookie banner will appear allowing you to accept or decline non-essential cookies. You can change your preferences at any time by clicking the “Cookie settings” link in the website footer.
Browser settings
Most browsers allow you to refuse or delete cookies through their settings. The following links explain how to do this in common browsers:
– Google Chrome: Settings → Privacy and security → Cookies and other site data
– Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
– Microsoft Edge: Settings → Cookies and site permissions
– Safari: Preferences → Privacy
Please note that disabling strictly necessary cookies may affect the functionality of this website.
Opt-out tools
For analytics cookies, you may also use the opt-out mechanism provided by your analytics provider. If we use Google Analytics, the Google Analytics Opt-out Browser Add-on is available at: tools.google.com/dlpage/gaoptout - Cookie retention periods
Cookie retention periods are set out in Section 2 above alongside the description of each cookie. We review our cookie usage annually and will update this policy if we add, change, or remove any cookies. - Changes to this Cookie Policy
We may update this Cookie Policy to reflect changes in technology, legislation, or the cookies we use. The “Last updated” date at the top of this page will be revised accordingly. Significant changes will be brought to your attention via an updated cookie consent notice. - Contact
If you have any questions about our use of cookies, please contact us:
Utilis d.o.o.
Fallerovo šetalište 22, 10000 Zagreb, Croatia
Email: info@utilis.biz
Tel: +385 1 36 35 666
Terms of Use
- About this website
This website (utilis.biz) is operated by Utilis d.o.o., a company registered in the Republic of Croatia, with registered office at Fallerovo šetalište 22, 10000 Zagreb (OIB: [insert OIB]). References to “Utilis”, “we”, “us” or “our” in these Terms refer to Utilis d.o.o.
By accessing or using this website, you agree to be bound by these Terms of Use. If you do not agree, please do not use this website. - Purpose of the website
This website provides information about Utilis d.o.o. and its services, including cybersecurity audit, information systems security management, software development, information systems audit, business continuity services, and our software products (CCS, Secutools, Hefesto). It is intended for informational purposes only and does not constitute a binding offer of services unless confirmed in a separate written agreement. - Intellectual property
All content on this website — including text, graphics, logos, product names, and software — is the property of Utilis d.o.o. or its licensors and is protected under applicable Croatian and EU intellectual property laws.
You may view and print content from this website for personal, non-commercial reference only. You may not reproduce, redistribute, publish, or use any content for commercial purposes without our prior written consent. - Accuracy of information
We make reasonable efforts to keep the information on this website accurate and current. However, we do not warrant that all content is complete, accurate, or up to date at all times. Information about our services, products, and regulatory guidance is provided for general informational purposes and does not replace professional advice tailored to your specific situation. - No professional advice
Content on this website — including any references to cybersecurity standards, regulations (such as NIS2, GDPR, ISO 27001, or the EU Cyber Resilience Act), or industry practices — is provided for informational purposes only. It does not constitute legal, regulatory, or professional advice. For advice specific to your organisation’s circumstances, please contact us directly or consult a qualified professional. - Limitation of liability
To the fullest extent permitted by applicable Croatian and EU law, Utilis d.o.o. shall not be liable for any direct, indirect, incidental, or consequential loss or damage arising from:- your use of, or inability to use, this website;
- reliance on any information contained on this website;
- any interruption, suspension, or termination of the website or its content;
- any unauthorised access to or alteration of your data or transmissions.
- Third-party links
This website may contain links to third-party websites. These links are provided for convenience only. Utilis d.o.o. has no control over the content of those websites and accepts no responsibility for them or for any loss or damage that may arise from your use of them. - Privacy and cookies
Your use of this website is also governed by our Privacy Policy and Cookie Policy, which are incorporated into these Terms by reference. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Croatian data protection legislation. - Changes to these Terms
We may update these Terms of Use from time to time to reflect changes in law, our services, or our website. The “Last updated” date at the top of this page indicates when the Terms were last revised. Your continued use of the website after any changes constitutes acceptance of the revised Terms. - Governing law and jurisdiction
These Terms of Use are governed by the laws of the Republic of Croatia. Any dispute arising from or in connection with these Terms shall be subject to the exclusive jurisdiction of the competent courts in Zagreb, Croatia. - Contact
If you have any questions about these Terms or our website, please contact us:
Utilis d.o.o.
Fallerovo šetalište 22, 10000 Zagreb, Croatia
Email: info@utilis.biz
Tel: +385 1 36 35 666