Cybersecurity Learning Hub — From Knowledge to Practice
Cyber Hiroshima

What Can You Learn from CTF? — Making Cyber Challenge More Than a Competition

CTF (Capture The Flag) is an exercise in which participants test their cybersecurity knowledge and skills by solving challenges. But the aim is not simply to find Flags as quickly as possible. At Cyber Hiroshima, we see CTF as a Challenge: a way to use what you have already learned, identify what you are still missing and move on to the next stage of learning.

What is CTF?

CTF stands for Capture The Flag.

A common format involves solving cybersecurity-related challenges and finding strings or other information hidden within them, known as “Flags”.

Challenges can cover a wide range of topics, including:

  • Web
  • Network
  • Cryptography
  • Forensics
  • Reverse Engineering
  • OSINT
  • Vulnerability Analysis

Some CTFs are tackled individually, while others involve working together as a team.

Many CTFs are competitions in which participants compete for points and rankings. But their value goes beyond competition alone.

CTF is a place to “use” knowledge

Something that seemed clear when you learned it from a book or lecture may become much harder when it is presented as a problem to solve.

For example,

“I can explain HTTP”

is not the same as

“I can identify unusual HTTP traffic and explain what caused it.”

Likewise, knowing the name of a cryptographic method is different from looking at a set of data and deciding:

“What is being used here?”

In a CTF, the challenge does not begin by telling you:

“Use Chapter 3 of Network Security.”

You first have to observe the situation and work out what kind of problem you are facing.

That is where the value of the Challenge begins.

There is value in the problems you cannot solve

The most important outcome of a CTF is not simply your score.

When you cannot solve a challenge, you can ask:

“What was I missing?”

Was it Linux knowledge?

Networking?

Cryptography?

Knowing how to read logs?

Understanding how web applications work?

Or did you already have the necessary knowledge but lack experience applying it to a problem?

Used in this way, CTF can create a cycle of:

Challenge → Gap Discovery → Learning

What you could not solve tells you what you should learn next.

Do not make it a one-off activity

In its Human Factors Knowledge Area, CyBOK discusses Security Awareness Games, including CTFs. It explains that seeing how vulnerabilities can be exploited may help develop an understanding of defence, while also pointing to the importance of placing games and simulations within planned learning and behaviour-change activities rather than treating them as one-off events.

This is also an important point in how Cyber Hiroshima approaches the Cyber Challenge.

The event was enjoyable.

You found several Flags.

You achieved a particular ranking.

If the experience ends there, the learning value is limited.

After the Challenge, reflecting on:

  • Which problems you solved
  • What you did not understand
  • Which knowledge was missing
  • What you should learn next

Turns CTF into part of a Learning Path.

CyBOK → SudoRange → Challenge

Cyber Hiroshima does not see CTF as an isolated event.

Our basic learning flow is:

KNOW — Learn with CyBOK

PRACTICE — Practice with SudoRange

EXPLORE — Deepen your understanding with AI and other resources

CHALLENGE — Test yourself through CTF

If a Challenge reveals something you do not understand, you return to CyBOK.

In other words:

Challenge is not the end of the Learning Loop. It is also the starting point for the next stage of Learning.

Beginners can take part too

The term CTF may make some people feel:

“You have to be an expert to take part.”

But if the difficulty of the challenges is designed appropriately, CTF can also be used by beginners.

For example, learners can start with challenges such as:

  • identifying an IP address
  • finding a file in Linux
  • extracting information from a simple log
  • examining the structure of a web page
  • looking for clues in publicly available information

The important point is not to make everyone attempt the same difficult challenge.

It is to take on a problem that is:

Just beyond your current level of knowledge.

Learning happens at the boundary between what you can already do and what you cannot yet do.

Why work as a team?

Cyber Challenge can also reveal capabilities that cannot be measured through individual technical skills alone.

When working as a team, roles naturally emerge:

“I’ll look at the network.”

“I’ll investigate the Web challenge.”

“Someone can organise the information.”

There are also more opportunities to explain what you do not understand and hear how other people approach the same problem.

Real-world cybersecurity work is not always completed by one person working alone.

A Challenge can therefore become a place to experience not only technical skills, but also:

problem solving, communication and collaboration.

A Cyber Challenge connecting Hiroshima and Wales

Cyber Hiroshima has already been involved in Challenges that cross national borders.

At a CyberFirst-related event in 2024, Cyber Hiroshima operated a CTF in Tokyo, while SudoCyber provided the exercise environment from Brecon in Wales using SudoRange. The Cyber Challenge was delivered in both English and Japanese.

This is one example of using CTF as:

Competition × Learning × International Community

Looking ahead, Cyber Challenge can potentially be used for a range of purposes, not only for students, including:

  • Exercises for educational institutions
  • Corporate training
  • Team capability assessment
  • Introductory Cyber Experiences
  • Joint UK–Japan Challenges

These are also identified in the specification as examples of how Cyber Challenge could be developed for different purposes.

From Challenge to the next stage of learning

The most important question after a CTF is not only:

“How many challenges did I solve?”

After it is over, it is also important to ask:

“What did I learn?”

“What do I still not understand?”

“What should I learn next?”

At Cyber Hiroshima, we want Cyber Challenge to become not simply a place to compete over learning outcomes, but:

A place to understand where you are now.

Gain knowledge through CyBOK.

Practise with SudoRange.

Deepen your understanding with AI and other resources.

Test yourself through a Challenge.

Then learn again.

Learn. Practice. Understand. Challenge.

By placing CTF within this cycle, a Challenge can develop from a one-day event into part of a continuous learning environment.

5. Read Next

Cyber Challenge

Cyber Hiroshima’s approach to CTF, educational use, corporate training and international collaborative Challenges.

Turning Knowledge into Practice — What Can You Learn with a Cyber Range and SudoRange?

How to build practical experience in a Cyber Range before moving on to a Challenge.