Home/Blog/Founders conversation
A CONVERSATION, NOT A BROCHURE

One cyber range cannot serve every sector — unless it is built as a framework.

Tarun, Prince and Mayur sat down for an hour to talk about a question buyers usually ask one year after they sign. This is what they said.

Also available as a printable brochure.
THE SETUP

The question buyers ask one year late

We sit through many procurement debriefs. One question comes up in nearly all of them, and it always arrives one year after the cyber range has been installed. This is our answer to that question.
PART ONE

The part the brochure leaves out

Prince
CEO

Here is how the customer's year goes. You look at a cyber range. The demo is good. You sign. You install. You run the lab scenarios that come with it. The first quarter goes fine.

Six months in, your CISO asks for a scenario built around your own setup — your plant, your operators, your regulator, the threat actor your team is tracking. A fair ask. You have paid for a cyber range.

The reply is where the trouble starts. The vendor sends a Statement of Work. The number is large. Procurement takes three months to clear it. The vendor's engineering team is abroad. They can start in nine months. Delivery is nine months after that. By the time the scenario is ready, the threat picture has moved. The reporting clock has changed. The CISO who asked for it has moved on.

Tarun
Chief Architect

The Statement of Work is not the costly part. The costly part is what happens after two or three such cycles. The customer learns that custom work is slow and dear. So they stop asking.

After that, the same three or four lab scenarios are run for every new batch of trainees. Training stops getting better. The team's skill stops getting better. On paper the investment is fine. On the floor, it is not.

When we sit with the operator at the console and ask if she is happy with what is on the floor, we rarely get a clear yes. People do not write it on the customer survey. They tell us in the corridor, once the review is over.

Mayur
Threat Research

From the threat-research side, the gap is worse. The tradecraft we track changes every quarter. The product on the customer's floor is updated once a year at best, and often less. By the time the range catches up, the actor has moved to a new method. The customer is rehearsing last year's incident.

There is also the question of which actors the product was built against. The ones we worry about in India — those going after our banks, our power utilities, our telecom networks, our defence — are not the same set the foreign products were built for. The names on the screen are wrong. The targeting is wrong. The timing is wrong. The exercise rehearses something. It does not rehearse your incident.

THE SHAPE PROBLEM

Two shapes — a product, and a framework

On the left is the shape most cyber ranges in the market follow. On the right is the shape we chose for SkyVirtRange.

THE TWO SHAPES Framework, not product Custom work lives in the spine of the platform, not in a side door. LEFT — THE COMMON PATTERN Product, with custom work as a side door SEALED OFF-THE-SHELF RANGE Fixed catalogue · fixed adversary fixed canvas · fixed compliance pack Built somewhere else, for someone else. The roadmap is not your roadmap. RELEASE CADENCE the vendor's quarter CUSTOM SOW separate team separate clock · a large Statement of Work for every new scenario · eighteen months from ask to live drill · foreign team, foreign threat model, foreign clocks · ships in the vendor's next release, not your next exercise RIGHT — THE SKYVIRTRANGE SHAPE Framework, with custom work as the spine CUSTOM THE SPINE Scenario authoring — you drive, AI helps, the validator checks Mission Canvas — your operator language, your domain shapes Adversary playbooks — actors from your threat picture Compliance pack — CERT-In · RBI · NCIIPC · DPDP · NLDC · AERB After-Action Report — signed evidence, the shape your auditor knows · weeks to a new scenario, not eighteen months · one team, one release train, one Indian engineering organisation · your custom work survives the next upgrade — it lives inside the platform · every engagement makes the framework sharper for every other customer too
On the left, the common pattern — a sealed product with a side door for custom work, run by a separate team on a separate clock. On the right, SkyVirtRange — a framework of five layers, with a spine running through all of them. Your work lives inside the platform and ships on the same release train as the rest of it. That one choice is what turns the eighteen-month cycle into a few weeks.
PART TWO

Why this happens — it is a shape problem

Tarun
Chief Architect

This is not the vendor being lazy. It is a shape problem. The product was built around a different customer — a utility in Pennsylvania, a SOC in Frankfurt, a C2 cell in Tysons Corner. It was not built around a substation in Raichur, a bank in Mumbai, or a tactical brigade in Ladakh.

When the Indian customer later asks the product to fit their setup, the product has to be opened up from outside. That seam — between the sealed product and the customer's real environment — is where every Indian customer ends up paying. In budget. In time. And worst of all, in the gap between what the rehearsal taught and what the real incident asked for.

Prince
CEO

We saw this at three or four customer sites and could not look past it any more. The brochure shows a finished product. A year on, the real artefact is a product with a side door attached. The product looks polished. The side door is where the disappointment collects.

Our position is simple. The customer should not be made to walk through a side door at all. We are not selling you a finished product that you will later need to bolt your reality on to. We are selling you the spine itself.

A product is finished the day the vendor ships it. A framework is never finished. SkyVirtRange is a framework. Custom work is not a paid extra — it is what the platform is for. — TARUN KUMAR KUSHWAHA
PART THREE

Custom work as a built-in capability

Tarun
Chief Architect

To put it plainly — your scenario authoring runs through the same code path our own scenarios run through. Your mission canvas is drawn by the same engine. Your adversary playbooks come from the same atomic-test library. Your compliance pack is on the same release train as everything else.

There is no side door, because there is no split between the platform's work and your work. Both go through the same interfaces, the same review, the same release.

Prince
CEO

Three things change for the buyer because of this. One — a new scenario for a new sector is in front of the trainees in weeks, not months. The framework already knows your operator language. Two — your custom work survives every later upgrade. It lives inside the platform, not on the side. There is no the integration broke after the last release conversation a year from now.

The third one matters most. Mayur, you should take that one.

Mayur
Threat Research

The third one is that the threat-research work compounds across customers. When a customer in a sector flags tradecraft we have not seen before — a new way to move laterally, a new firmware exposure on a piece of plant equipment, a new phishing pattern aimed at the KYC desk — it lands inside the framework. On the next release, every other customer in that sector inherits the rehearsal for it.

This is not just a tick on a comparison sheet. It is a real advantage that grows with every engagement we run. A foreign product cannot copy it by adding a line to its roadmap — their customer in Raichur and their customer in Frankfurt do not share a release train at all.

PART FOUR

What this looks like in the room

Three drills we ran last quarter. Different sectors, different operators, different regulators. The same framework underneath.

Atomic plant
A control engineer asks for a reactor cooling pump anomaly drill, with the AERB reporting clock simulated honestly.
The operator authors the scenario inside the framework, runs the workability probe on real virtual machines, watches the drill play out. The After-Action Report carries an AERB-shaped artefact at the bottom. The regulator's auditor knows the shape on sight.
Ask to live drill: under a quarter.
Bank SOC
A SOC analyst asks for a UPI mandate-abuse drill, with the RBI 2016 reporting clock as the first wall.
The framework already knows the clock — six hours for the first notice, twenty-four for the detailed one. The drill either lands inside the clock or breaches it on screen. The CISO leaves with a clearer view of her real reporting duty.
Reporting clock: 6h initial · 24h detailed.
Tactical brigade
A signals officer asks for a battlefield C2 jamming drill on a mobile ad-hoc network that breaks the way a real one would.
The mission canvas draws the radio-frequency view. The adversary profile is one our threat-research team has prepared for the Indian theatre — not a generic foreign briefing held over from a past engagement.
No translator between operator language and the screen.
No foreign team. No Statement of Work. No translator between operator language and the screen. The customer is driving. The framework is taking the work. — PRINCE KOMAL BOONLIA
PART FIVE

The question we want more buyers to ask

Mayur
Threat Research

One question — and ask it of the right person. One year after the cyber range goes in, not on demo day and not after the first quarter, walk down to the floor. Not the head of training. Not the procurement lead. The person at the console.

Ask her plainly: are you genuinely happy with what is on the floor today?

Tarun
Chief Architect

If the honest answer is anything other than yes, we would be glad to show you what a framework feels like. Not in a demo theatre — on your floor, with your people in the room. Send us a scenario you actually care about. The sector. The operator at the console. The regulator at the wall. The threat actor on your watch list. We will deploy it on real hardware in front of you.

The framework will take the work. The room will read the screen without a translator. The drill will land inside the clocks your auditor cares about. That is what the cyber range we have spent four years building was built to do.

Send us a scenario you actually care about.

Tell us the sector, the operator at the console, the regulator at the wall, and the threat actor on your watch list. We will deploy it on real hardware in front of you. If it does not land inside the clock your auditor cares about, we will say so to your face.

Tarun Kumar Kushwaha
Co-Founder · Director · Chief Architect
Prince Komal Boonlia
Founder & Chief Executive
Mayur Agnihotri
Head of Threat Research
UDAIPUR · MAY 2026