On June 12, 2026, a two-week siege ended. For twelve days, defensive teams inside Kiewit Hall on the University of Nebraska-Lincoln campus had been under sustained, escalating cyberattack — waves of simulated intrusions that grew more sophisticated by the day, each one mapped to real adversary tradecraft. The targets weren’t abstract. They were stand-ins for the systems that keep the lights on, the water running, the hospitals open, and the money moving across the American heartland.

This was Cyber Tatanka 2026, the fifth annual running of what has quietly become one of the most interesting cyber exercises in the country. It drew 243 participants from federal, state, military, and private-sector organizations, plus service members from five allied nations and a contingent of local university students. And unlike most exercises of its scale, it is not run by a military command. It’s civilian-led, coalition-built, and free to participate in — and that structure is exactly what makes it worth studying.

If Cyber Shield 2026 is the large federated military model for building defensive talent at national scale, Cyber Tatanka is its complement: a hyper-local, public-private-academic model that shows how a community actually manufactures defenders for the infrastructure it depends on.

What Cyber Tatanka Is

Cyber Tatanka ran June 1–12, 2026, at the University of Nebraska-Lincoln. The name comes from the Lakota word tatanka — the bison that once ranged across a seven-state stretch of the Great Plains, and on which the region’s peoples depended for food, shelter, clothing, and tools. The metaphor is deliberate: the interconnected infrastructure systems underpinning modern life are the new tatanka, essential and requiring protection.

The exercise is organized by Cyber Strong Nebraska, a non-profit, and it operates as a genuine coalition. The defensive “enclaves” — the blue teams — were built from a striking mix: Nebraska National Guard personnel, active-duty service members, private industry defenders, allied international military, and university students, all working shoulder to shoulder. The organizations represented read like a map of critical infrastructure itself: Nebraska Public Power District, Lincoln Electric System, Metropolitan Utilities District, Union Bank & Trust, Bryan Health, and Union Pacific Railroad, alongside the Nebraska Emergency Management Agency and the State CIO’s office.

The structure was two-phase. Week one was academic and preparatory: specialized coursework (including Antisyphon training and “Backdoors & Breaches” tabletop exercises), plus network validation. Week two was the live-fire range — teams defended a simulated business enterprise network on Cloud Range’s platform against daily threat scenarios that escalated in sophistication and were mapped to the MITRE ATT&CK framework. You learn the theory, then you get hit with it, in that order, under real time pressure.

Over its five-year run from 2022 to 2026, Cyber Tatanka has trained roughly 750 military, civilian, academic, and government professionals — including 250 U.S. military and more than 50 allied international personnel. This year’s international contingent spanned the United States, Austria, the Czech Republic, Jordan, Chile, and Tanzania, with Tanzanian and Czech service members embedded directly into the defensive enclaves.

”The Person Is the Program”

The single most quotable — and most important — line of the whole exercise came from Dana Turner, director of Cyber Strong Nebraska: “The person is the program. If you’re not stress-testing your people on realistic conditions, you have no idea how they will perform when it actually matters.”

That sentence should be printed on the wall of every SOC. It cuts against the dominant instinct in enterprise security, which is to treat capability as a function of tooling and headcount. Cyber Tatanka’s founding premise is the opposite: your defense is only as good as how your actual people perform under actual pressure, and the only way to know that — or to build it — is to put them through realistic, consequential scenarios before the real incident arrives.

Turner also named the threat shift that gives the exercise its urgency: “Nation states used to target military and government systems. That has shifted. They now go after utilities in small Nebraska towns, regional hospitals, corner pharmacies, community banks.” That is the strategic reality the last few years have made undeniable — the attack surface that matters most is no longer the hardened federal network but the under-resourced regional utility, the rural hospital, the community bank. These are organizations that individually cannot afford elite security teams, which is precisely why a coalition model matters.

And that’s Turner’s other core argument: “You cannot defend a threat landscape that broad with a single organization. You need a coalition.” Cyber Tatanka is that thesis made operational.

Why the Public-Private-Academic Model Works

There are three ingredients in Cyber Tatanka that most corporate training programs are missing, and it’s worth naming each because they’re all reproducible.

First: genuine cross-sector integration. When a National Guard operator, a power-company defender, a bank’s incident responder, an allied foreign soldier, and a college junior are all in the same enclave defending the same network, knowledge flows in every direction at once. The Guard member brings doctrine and structure; the utility defender brings deep OT/ICS domain knowledge; the private-sector responder brings current commercial tradecraft; the student brings fresh eyes and hunger. No single-employer training environment can manufacture that diversity of perspective — and diversity of perspective is a security control, because homogeneous teams share blind spots that adversaries exploit.

Second: live-fire realism over checkbox theory. The whole design forces application. As one framing from the exercise put it, Cyber Tatanka “is not just about theory — it’s about applying that theory in a realistic scenario with real consequences.” A defender who has watched a MITRE ATT&CK-mapped intrusion unfold against infrastructure they care about, in real time, has something no certification exam confers. Czech 2nd Lt. Jakub Richder of the 92nd Cyber Warfare Group put it simply: “Seeing the threats in real time has helped me understand it better.”

Third: it’s a talent pipeline by design, not by accident. Embedding university students directly into enclaves alongside working professionals does something a career fair never will — it exposes students to real practitioners, builds relationships, and lets employers watch candidates perform under pressure. This is recruiting and training and workforce development collapsed into a single event. The students aren’t observers; they’re on the team.

Why This Matters for Security Leaders

Cyber Tatanka is a template, and the barrier to copying it is imagination, not budget. Here’s the playbook.

Stress-test your people, not just your tools. Turner’s line is the whole strategy. Budget for recurring, adversarial, hands-on exercises against systems your team actually defends — purple-team engagements, live-fire range time, realistic scenario drills. You do not know how your SOC performs until it has been genuinely tested, and the worst time to find out is during a real breach. This is the same shift from generalist checkboxes to demonstrated, hands-on depth that’s reshaping the military’s own cyber force under CYBERCOM 2.0.

Build coalitions if you can’t build an army. Most regional utilities, hospitals, and community banks cannot staff an elite internal security team. Cyber Tatanka’s answer — pool defenders across organizations, sectors, and the public/private line — is directly applicable. Information-sharing groups, sector ISACs, joint exercises with peer organizations, and partnerships with your state National Guard cyber unit are all ways to punch above your individual weight. The threat is shared; the defense should be too.

Partner with universities as a talent strategy, not charity. Embedding students in real defensive work is one of the highest-return recruiting moves available. You get an extended, live audition; they get experience that makes them hireable on day one. If your organization sits near a university with a cyber program, an integrated exercise or internship-in-a-SOC arrangement will out-perform your job postings.

Treat OT/ICS defense as its own discipline. Cyber Tatanka centers on utilities, hospitals, railroads, and banks — cyber-physical environments that behave nothing like corporate IT. Defenders who can bridge the IT/OT divide are scarce and increasingly essential. If your organization touches any physical or operational system, this is a capability to build deliberately, not assume.

The Career Angle

For anyone building a career — or advising people who are — Cyber Tatanka is a signal about where durable value lives.

Live-fire experience is the credential that’s hard to fake. The exercise’s own framing is that it’s a “differentiator for those entering the cybersecurity workforce.” A student or early-career professional who has defended simulated critical infrastructure against escalating, ATT&CK-mapped attacks has a story and a skill set that beats a stack of certifications on a résumé. Seek out these experiences — Guard service, community cyber ranges, CTFs, volunteer defensive exercises — and put them front and center.

Critical-infrastructure and OT defense is a strategic career bet. The threat has migrated to utilities, hospitals, and community banks, and the talent to defend them hasn’t caught up. Specializing in the intersection of security and operational technology puts you in one of the tightest, most defensible talent markets in the field — and one that isn’t going to be automated away, because it’s judgment-heavy and consequence-laden.

The National Guard remains an underrated accelerator. Cyber Tatanka is partly a Guard exercise, and serving part-time in a Guard cyber unit remains one of the highest-leverage career moves available: real training, clearances, and adversarial experience while you keep your civilian job. For people trying to break in without a traditional path, it’s a door that too few know is open.

For hiring managers: watch these events for talent. Every participant in an exercise like Cyber Tatanka has been tested in exactly the conditions you care about. The university students embedded in those enclaves are pre-vetted, pre-trained early-career defenders. If your pipeline doesn’t reach into community cyber ranges, Guard units, and university programs, you’re leaving some of the best-prepared talent in the country untouched.

The Bigger Picture

Cyber Tatanka started, in Brig. Gen. Robert Hargens’ telling, as a military event and “since transformed into a civilian-led event” requiring “an incredible amount of planning and work.” Ryan Carlson, the retired Nebraska Army National Guard major who originally built it, framed the stakes in plain terms: “Interconnected systems are extremely important to maintaining our way of life. And they are something that we must protect.”

That evolution — from a military drill into a self-sustaining, community-owned institution that trains hundreds of defenders a year across every sector — is the real lesson. Nebraska didn’t wait for a federal program to protect its two million residents’ utilities, hospitals, and banks. It built a coalition, put its people under realistic fire, and made a training pipeline out of the whole thing.

Most security leaders can’t run a two-week, six-nation exercise. But the underlying model — stress-test your people, build coalitions across the sector, pull in the next generation and let them fight alongside your veterans — is available to almost anyone willing to organize it. The person is the program. Cyber Tatanka just proves what happens when a community decides to take that seriously.

Sources: U.S. Army — “Nebraska Guard strengthens defenses in Cyber Tatanka 2026” (article 293430); DVIDS — “Defending the Heartland: Cyber Tatanka strengthens shield over vital infrastructure” (June 2026); Cyber Strong Nebraska / cybertatanka.org; University of Nebraska-Lincoln College of Engineering coverage; quotes attributed to Dana Turner (Cyber Strong Nebraska), Brig. Gen. Robert Hargens (Nebraska Air National Guard), Ryan Carlson (retired Nebraska Army National Guard), and 2nd Lt. Jakub Richder (Czech Armed Forces) as reported in official releases.

This article is provided for informational purposes only and reflects reporting available as of mid-July 2026. Participant figures, quotes, and exercise details are drawn from official Department of Defense, U.S. Army, National Guard, university, and organizer public releases and are subject to update as further reporting becomes available.