Ed Skoudis: Teaching Hackers With Games and a Model City
Most people in cybersecurity learned to hack from a book, a class or a game. Ed Skoudis wrote the book, taught the class and built the game.
For more than 25 years he's been the SANS Institute's attacker-in-chief: the author of its best-known hacking course, the creator of the NetWars tournament and the Holiday Hack Challenge, and the builder of a tabletop town where military cyber warriors learn that a keyboard can black out a city.
Then the man who spent his career making defense fun was handed a college to run. By 2026 he was back on the keynote stage, warning that attackers had cut their work down to eight minutes.
Ed Skoudis at a Glance
- Skoudis studied electrical engineering at the University of Michigan, earned a master's in information networking at Carnegie Mellon and started out in security consulting at Bell Communications Research.
- His 2002 book Counter Hack walked readers through attacks and defenses step by step. Malware: Fighting Malicious Code followed in 2003 and Counter Hack Reloaded in 2005.
- He wrote the SANS courses SEC504 and SEC560, designed the institute's penetration testing curriculum and co-founded the consultancy InGuardians, established in 2003.
- In 2010 he founded Counter Hack and, around the same time, launched NetWars, a multi-level hacking tournament the US military quickly adopted to find talent.
- November 2012 brought NetWars CyberCity, a six-by-eight-foot model town near the New Jersey Turnpike with a working power grid, built so defenders could see the physical damage a cyberattack does.
- The Military Cyber Professionals Association awarded him its Order of Thor medal in 2015 for his contributions to military cyber training.
- The Holiday Hack Challenge he produces every December has run for more than 20 years and became the online conference KringleCon in 2018.
- The SANS Technology Institute named him its president in September 2021. In 2024 he co-wrote The Code of Honor, an ethics book for the field.
- In 2026 he moderated the SANS keynote panel at RSAC and, as "Chief Holiday Officer," was still writing the holiday challenge.
The Life of Ed Skoudis
Skoudis's Engineering Roots
Ed Skoudis came to security the way much of the first generation did: through engineering. He took a bachelor's degree in electrical engineering at the University of Michigan and a master's in information networking at Carnegie Mellon University.
His first security job was at Bell Communications Research, the Bellcore of the old phone-company world, where he worked on security consulting and strategy. It was a good place to learn how large, critical networks actually fail.
His SANS biography now counts more than 20 years of analyzing major cyber incidents and assessing national-scale defenses for US government security programs. The early years at a phone company turned out to be the foundation for all of it.
Writing Counter Hack
In 2002 Skoudis published Counter Hack, a step-by-step guide to computer attacks and the defenses that stop them. It was written for the administrator who needed to understand an intruder's playbook without ever having run one.
Malware: Fighting Malicious Code, written with Lenny Zeltser, arrived in 2003. Two years later he and Tom Liston rebuilt the first book as Counter Hack Reloaded, which is still on sale two decades on.
The books did something subtle. They made attacking sound like a discipline rather than a dark art, and that framing shaped everything he built afterward.
Teaching Hackers to Defend
At the SANS Institute, Skoudis wrote SEC504, "Hacker Tools, Techniques, and Incident Handling," and later SEC560 on enterprise penetration testing. He went on to design the institute's entire penetration testing curriculum, now called Offensive Operations.
By his own count he's taught more than 40,000 students over 25 years.
He kept a foot in the field, too. InGuardians, the consultancy he co-founded, was established in 2003 and sent him into enterprise, government and university networks on penetration tests.
He also had a knack for the unsettling question. "What if we've been in an economic cyber war, and we already lost because we didn't realize we're fighting it?" he asked Computerworld in 2012.
Building NetWars
Around 2010 SANS started a project to fix a shortage Skoudis saw everywhere: not enough people who could actually do the work. It was called NetWars, and he ran it as its director.
NetWars was a hacking tournament, but not the kind DEF CON ran for elite teams. Everyone began at level one, and the challenges climbed through five levels until, as Skoudis told Dark Reading in 2011, "there's castle-on-castle combat."
He founded Counter Hack the same year, 2010, as the company that'd build these ranges. The military noticed fast: "Between one and three times per month we run a NetWars tournament at a military base," he said in 2011, and several branches were using it to spot skilled people.
The prizes were modest, an iPad for the winner and what Skoudis called a "wonderful shirt" for the runner-up. The ambition wasn't. He told Network World in 2012 that the goal was a pipeline of 10,000 or more skilled practitioners to defend the country.
A City Off the Turnpike
The military wanted something more. Officials asked for training that captured the "kinetic effects" of cyber warfare, which Skoudis translated as "stuff in the physical world breaking down or blowing up."
So in November 2012 SANS unveiled NetWars CyberCity: a six-by-eight-foot model town near the New Jersey Turnpike with a bank, a hospital, a water tower, a train system, an electric grid and a coffee shop with free Wi-Fi.
Much of it came from a hobby shop, but the control systems were real. "It is lighting tiny little lights inside tiny little buildings," Skoudis told Wired, yet the power grid components were the same ones you'd find in an actual city.
The town had 15,000 virtual residents with their own data records and hospital files, and more than 18 missions for Department of Defense teams to run, starting that December. In 2015 the Military Cyber Professionals Association gave Skoudis its Order of Thor medal for his contributions to US military cyber training.
The Chief Holiday Officer
Long before CyberCity, Skoudis had a December habit: every year he wrote a hacking puzzle wrapped in a holiday story. By December 2013 SANS was calling it the tenth annual holiday hacking challenge, and that edition, themed on It's a Wonderful Life, was built from CyberCity's real industrial components.
The grand prize for the best answer was a free SANS course worth over $4,000. The puzzles themselves were free, and still are.
In 2018 the challenge grew into KringleCon, a virtual conference wrapped around the game. SANS now says the holiday challenges have been running for more than 20 years.
The 2025 edition, "Revenge of the Gnome(s)," ran into January 2026 with Skoudis credited as producer and "Chief Holiday Officer." The title tells you how seriously he takes the fun.
Skoudis Takes Over the College
On September 1, 2021, the SANS Technology Institute, the institute's degree-granting college, announced Skoudis as its new president. The college carries the NSA's Center of Academic Excellence in Cyber Defense designation, and its president still teaches.
He kept his other hats. He remains a SANS Fellow and the CEO of Counter Hack, and in March 2026 he moderated the SANS keynote panel at RSAC in San Francisco.
Off the clock, his biography lists a hobby of collecting antique encryption systems and tech gear, including an 1861 telegraph key he turned into a "MorseCodinator" and a 1951 porthole television wired to a Raspberry Pi. He also sits on the board of Manasquan Bank in New Jersey.
Honor Codes and Eight-Minute Attacks
In June 2024 Skoudis and Paul J. Maurer, the president of Montreat College, published The Code of Honor: Embracing Ethics in Cybersecurity. Medicine, law and engineering have long had codes of conduct, they argued, and a field that teaches people how to break in needs one too.
At RSAC 2026 he moderated the SANS panel on the most dangerous new attack techniques alongside Rob T. Lee, Robert M. Lee, Heather Barnhart and Joshua Wright.
His warnings were blunt. Organizations are "completely unprepared for 100 critical vulnerabilities in a week," he said, and an attacker "can go from initial breach through lateral movement" in the space of eight minutes.
By August 2026 he was telling SANS readers that AI had become "astonishingly good at finding vulnerabilities" but that fixing them "is a very different problem," a line Brian Krebs quoted the same day. The attacker-in-chief had become the voice telling everyone to slow down and verify.
Ed Skoudis: The Man Who Made Defense a Game
Skoudis's career is one long argument that the best way to build defenders is to let them play attacker, safely, with a scoreboard and maybe a shirt.
The game pieces grew up. NetWars became a military talent scout, a December puzzle became a 20-year tradition, and a model train set became the place where cyber warriors learned what a blackout looks like.
Today he runs a college, co-wrote the field's ethics book and still signs off every December as Chief Holiday Officer. Not bad for a man whose city fits on a table.
QUOTE:
"Amateurs hack systems, professionals hack people."