CTF (Capture The Flag) is an exercise in which participants test their cybersecurity knowledge and skills by solving challenges. But the aim is not simply to find Flags as quickly as possible. At Cyber Hiroshima, we see CTF as a Challenge: a way to use what you have already learned, identify what you are still missing and move on to the next stage of learning.
CTF stands for Capture The Flag.
A common format involves solving cybersecurity-related challenges and finding strings or other information hidden within them, known as “Flags”.
Challenges can cover a wide range of topics, including:
Some CTFs are tackled individually, while others involve working together as a team.
Many CTFs are competitions in which participants compete for points and rankings. But their value goes beyond competition alone.
Something that seemed clear when you learned it from a book or lecture may become much harder when it is presented as a problem to solve.
For example,
“I can explain HTTP”
is not the same as
“I can identify unusual HTTP traffic and explain what caused it.”
Likewise, knowing the name of a cryptographic method is different from looking at a set of data and deciding:
“What is being used here?”
In a CTF, the challenge does not begin by telling you:
“Use Chapter 3 of Network Security.”
You first have to observe the situation and work out what kind of problem you are facing.
That is where the value of the Challenge begins.
The most important outcome of a CTF is not simply your score.
When you cannot solve a challenge, you can ask:
“What was I missing?”
Was it Linux knowledge?
Networking?
Cryptography?
Knowing how to read logs?
Understanding how web applications work?
Or did you already have the necessary knowledge but lack experience applying it to a problem?
Used in this way, CTF can create a cycle of:
Challenge → Gap Discovery → Learning
What you could not solve tells you what you should learn next.
In its Human Factors Knowledge Area, CyBOK discusses Security Awareness Games, including CTFs. It explains that seeing how vulnerabilities can be exploited may help develop an understanding of defence, while also pointing to the importance of placing games and simulations within planned learning and behaviour-change activities rather than treating them as one-off events.
This is also an important point in how Cyber Hiroshima approaches the Cyber Challenge.
The event was enjoyable.
You found several Flags.
You achieved a particular ranking.
If the experience ends there, the learning value is limited.
After the Challenge, reflecting on:
Turns CTF into part of a Learning Path.
Cyber Hiroshima does not see CTF as an isolated event.
Our basic learning flow is:
KNOW — Learn with CyBOK
↓
PRACTICE — Practice with SudoRange
↓
EXPLORE — Deepen your understanding with AI and other resources
↓
CHALLENGE — Test yourself through CTF
If a Challenge reveals something you do not understand, you return to CyBOK.
In other words:
Challenge is not the end of the Learning Loop. It is also the starting point for the next stage of Learning.
The term CTF may make some people feel:
“You have to be an expert to take part.”
But if the difficulty of the challenges is designed appropriately, CTF can also be used by beginners.
For example, learners can start with challenges such as:
The important point is not to make everyone attempt the same difficult challenge.
It is to take on a problem that is:
Just beyond your current level of knowledge.
Learning happens at the boundary between what you can already do and what you cannot yet do.
Cyber Challenge can also reveal capabilities that cannot be measured through individual technical skills alone.
When working as a team, roles naturally emerge:
“I’ll look at the network.”
“I’ll investigate the Web challenge.”
“Someone can organise the information.”
There are also more opportunities to explain what you do not understand and hear how other people approach the same problem.
Real-world cybersecurity work is not always completed by one person working alone.
A Challenge can therefore become a place to experience not only technical skills, but also:
problem solving, communication and collaboration.
Cyber Hiroshima has already been involved in Challenges that cross national borders.
At a CyberFirst-related event in 2024, Cyber Hiroshima operated a CTF in Tokyo, while SudoCyber provided the exercise environment from Brecon in Wales using SudoRange. The Cyber Challenge was delivered in both English and Japanese.
This is one example of using CTF as:
Competition × Learning × International Community
Looking ahead, Cyber Challenge can potentially be used for a range of purposes, not only for students, including:
These are also identified in the specification as examples of how Cyber Challenge could be developed for different purposes.
The most important question after a CTF is not only:
“How many challenges did I solve?”
After it is over, it is also important to ask:
“What did I learn?”
“What do I still not understand?”
“What should I learn next?”
At Cyber Hiroshima, we want Cyber Challenge to become not simply a place to compete over learning outcomes, but:
A place to understand where you are now.
Gain knowledge through CyBOK.
Practise with SudoRange.
Deepen your understanding with AI and other resources.
Test yourself through a Challenge.
Then learn again.
Learn. Practice. Understand. Challenge.
By placing CTF within this cycle, a Challenge can develop from a one-day event into part of a continuous learning environment.
Cyber Hiroshima’s approach to CTF, educational use, corporate training and international collaborative Challenges.
How to build practical experience in a Cyber Range before moving on to a Challenge.