Locked Shields 2026: Inside NATO's Live-Fire Cyber Exercise (and Who Won)

NATO's Locked Shields 2026 put 4,000 defenders from 41 nations against 8,000 attacks on a fictional nation's grid and military networks — with a Latvia–Singapore team on top. The score matters less than the design: here, a defensive mistake has physical consequences.

Share
A stylized padlock with a white network globe inside.

For four days in April, 4,000 cyber defenders from 41 nations fought off roughly 8,000 attacks against a fictional country's power grid, satellites, and military networks — and a joint Latvian-Singaporean team came out on top. That is the headline from Locked Shields 2026, NATO's annual live-fire cyber exercise in Tallinn. But the score is the least interesting part. What makes Locked Shields worth a security team's attention is a design choice most tabletop drills avoid: here, a defensive mistake has physical consequences.

What Happened in Tallinn

Locked Shields is run by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) and bills itself as the world's largest and most complex live-fire cyber-defense exercise. This year's edition ran April 20–24 and pitted 16 multinational Blue Teams against a professional Red Team in defense of “Berylia,” a fictional nation under sustained attack. Per the CCDCOE and reporting from SecurityWeek, teams defended critical infrastructure, military and air-defense systems, and — new emphasis for 2026 — an electronic-voting system, while managing the legal, strategic, and media fallout in parallel.

The top of the table was a study in coalition-building: first place went to a joint Latvia–Singapore team, second to a Germany–Austria–Luxembourg–Switzerland group, and third to France–Sweden. “Our ultimate goal at Locked Shields is to enhance collaboration between nations, and build trust,” exercise director Dan Ungureanu said. The winning result, one Latvian commander noted, came down to teams that could “adapt to situations when it seems that there is no solution.”

  WHEN A CYBER MISTAKE GOES PHYSICAL
Live-fire means a wrong click on a real PLC ends in the dark, not a debrief slide.
A DEFENSIVE MISS
Red Team reaches an industrial control asset the Blue Team failed to lock down.
REAL HARDWARE REACTS
Nearly 70 physical PLCs and HMIs in the SANS power-generation rig respond as they would on a real grid.
PHYSICAL OUTCOME
Turbines throttle, breakers open, generation drops — the fictional nation of Berylia loses power in real time.
Source: NATO CCDCOE; SANS Institute exercise briefing.

Live-Fire, Not a Slide Deck

The detail that separates Locked Shields from a conference-room war game is the hardware. The SANS Institute built a fully operational power-generation system for the exercise using nearly 70 physical industrial control assets — programmable logic controllers (PLCs) and human-machine interfaces (HMIs) — rather than a software model. Blue Teams had to keep power flowing to Berylia's population while that rig was actively under attack.

That changes the stakes of a mistake. In an operational-technology (OT) environment under fire, a missed detection does not produce a red mark on a scorecard; it throttles a turbine, trips a breaker, and drops generation capacity in real time. It is the closest a training environment gets to the nation-state threats aimed at physical infrastructure that Locked Shields exists to rehearse — the muscle memory of defending systems where the failure mode is measured in megawatts, not log entries.

Defense Is No Longer Only Technical

The second thing Locked Shields models is that a national-scale incident is not won or lost purely in the SOC. Blue Teams embed legal advisors and media strategists alongside the technical staff, because a defense that violates international law or loses the information war can fail even when every server stays up. Adding an e-voting system to the 2026 scenario made the point sharper still: some assets are defended less for their data than for public trust in the result.

The Low-Tech Reminder

For all the satellites and 5G in the scenario, the year's most instructive real-world lesson was almost comically analog. In April, a journalist tracked the $585 million Dutch air-defense frigate HNLMS Evertsen for 24 hours by mailing the crew a postcard with a $5 Bluetooth tracker tucked inside — which sailed past screening rules that exempted postcards from X-ray, then piggybacked on crew phones to broadcast the ship's position. Locked Shields defends against nation-state Red Teams; the Evertsen is a reminder that the cheapest attack path is often the one no exercise thought to script.

My Read

The instinct is to file Locked Shields under “NATO does a big drill,” but the transferable lesson is the exercise philosophy, not the geopolitics. Two design choices are worth stealing. First, consequence-based testing: a tabletop where the worst outcome is an awkward debrief teaches less than a rehearsal where a mistake visibly breaks something. Most corporate incident “exercises” are the former. Second, cross-functional defense: the teams that treat legal, communications, and executive decision-making as part of the response — not as an afterthought once the fire is out — are the ones that hold up under a real crisis. You do not need a fictional country or 70 PLCs to apply either idea; you need a scenario with teeth and the right people in the room before the incident, not during it.

What Security Teams Can Borrow

You will not run Locked Shields, but you can steal its best habits:

  • Exercise against real consequences. Run at least one drill where a wrong move has a visible, physical, or costly result — a real staging system taken down, a real failover triggered — instead of a purely verbal walkthrough.
  • Put non-technical roles in the room early. Legal, PR, and an executive decision-maker should train alongside the responders, so the first time they coordinate is not during an actual breach.
  • Treat OT as its own discipline. If you run any operational technology, rehearse it separately from IT: the failure modes, tooling, and safety constraints do not transfer cleanly from the corporate network.
  • Rehearse the whole crisis, not just containment. Fold disclosure decisions, regulator contact, and public messaging into the exercise, because those calls shape the outcome as much as the technical fix.
  • Don't forget the cheap attack path. The Evertsen postcard is a standing reminder to test the low-tech, physical, and human vectors your threat model tends to skip.

Primary Documents