Creative Dad CompanyCreative Dad Company
TechnologyMath

Cybersecurity Operations Center

Log in to save
Grades 9-1290 minSource: Creative Dad Company

Teens run a mock security operations center, analyzing simulated suspicious login attempts and network activity to spot real attack patterns, then write plain-language policies to defend against them. Great for a teen who likes puzzles, patterns, and a bit of detective work.

Choose your version

Every level teaches the same core idea — pick the one that fits your time, budget, and energy today.

Prep: 10 minActivity: 30 min1 session~$2/groupOne table for the Cybersecurity Operations Center evidence and prototypeBeginner-friendly

Setup

Print or handwrite the four Cybersecurity Operations Center challenge steps and place common paper supplies on one table. Prepare one small sample, dataset, scenario, or recycled-material model drawn directly from the project description; no device, paid tool, room decoration, or purchased kit is required.

Activity

  1. Read the Cybersecurity Operations Center challenge aloud, then review a printed set of mock login logs and predict which entries look like a real person versus a scripted attack.
  2. Use paper, index cards, recycled objects, or facilitator-provided sample data to build a simple flagging system—colors, tags, or a flowchart—that sorts the logs into safe, suspicious, and confirmed threats.
  3. Run one tabletop trial and run a fresh batch of logs through the system and discover it flags too many false alarms, then tighten the rules to cut the noise.
  4. Finish by present a one-page security policy explaining the top three defenses the team recommends and why, to a mock management audience; record the evidence that supports the decision.

Done when: The group completes a defensible Cybersecurity Operations Center solution, records at least one test result or comparison, changes one claim or design in response, and supports its final decision with that evidence.

Materials

printed log sheets, colored highlighters, poster board, sticky notes, index cards

Shown for the Quick Start version — switch tabs above to see what changes.

Disclosure: Materials links below go to Amazon. As an Amazon Associate, Creative Dad Company earns from qualifying purchases at no extra cost to you.

Steps

  1. Review a printed set of mock login logs and predict which entries look like a real person versus a scripted attack.
  2. Build a simple flagging system—colors, tags, or a flowchart—that sorts the logs into safe, suspicious, and confirmed threats.
  3. Run a fresh batch of logs through the system and discover it flags too many false alarms, then tighten the rules to cut the noise.
  4. Present a one-page security policy explaining the top three defenses the team recommends and why, to a mock management audience.