Around 2 hours
Live-Hacking
Hands-on cybersecurity. We show your audience first-hand how real attackers operate. Controlled live demonstrations make attacks tangible whilst also explaining how to protect against them. This makes cybersecurity a tangible experience for management and staff rather than an abstract concept: instead of a slide showing the financial costs of a breach, attendees see how a password can be cracked in seconds.
Request an appointmentView all services
Live
Hacking
Duration
Format
On-site or remotely
Participants
10 to 1,000+
Your systems
remain unaffected
Important: Live-Hacking takes place exclusively in an isolated environment provided by us. Your own systems will not be compromised at any time.
When a Live-Hacking session is appropriate
- Awareness Day or Security Week – as a kick-off to set the tone for the rest of the day.
- Staff training – when the annual compulsory training is no longer effective and a different format is needed.
- Management briefing – when the need for a security budget has to be justified and figures alone aren’t enough to convince.
- Staff meeting or kick-off – an agenda item that people will still be talking about afterwards.
- Customer or partner event – as a specialist presentation that demonstrates your commitment to security to the outside world.
- Following a Phishing incident – to explain how the attack worked without singling out individuals.
- Onboarding new teams – when lots of people are starting at the same time and security needs to be integrated right from the start.
- To accompany a Pentest – the results become more tangible if you’ve shown beforehand how such attacks unfold.
Who will be presenting at your event
There is always an active Pentester from our team on stage, not just a speaker. The techniques demonstrated are taken from projects we actually carry out.
Exactly who will be attending depends on the date and venue. You’ll know who to expect – including a brief biography for your programme announcement – by the time you receive the confirmation of the date at the latest.
We bring with us experience from specialist conferences and corporate events, including TinCon 2026.
Who we tailor the programme for
The same attacks can have a completely different impact on different audiences. That is why we adjust the focus, depth and language.
Staff
Focus on everyday workplace scenarios: Phishing, passwords, and calls from supposed IT support. The aim is not to instil fear, but to ensure that, when in doubt, people ask questions and report anything suspicious, rather than keeping it to themselves out of concern for their own job security.
Managers and management
Shorter, with a stronger focus on speed and scope. Fraudulent calls using voice spoofing and payment authorisations are the most relevant scenarios here, as they target these roles directly.
IT and development teams
A more in-depth technical approach, focusing on attack chains rather than individual techniques. We’ll skip the basics, leaving more time for questions about your own environment.
Trainees and young audiences
Greater interaction, closer links to personal devices and accounts. Those who understand how their own account is managed can then apply that knowledge to the workplace.
Mixed audience
A layout that remains technically viable without losing half the space. This is the most common scenario and the one where planning in advance pays off the most.
How a Live-Hacking Session Works
Initial Consultation
Together, we define the schedule, format (on-site or remote), and target audience.
Scenario Tailoring
We align on which modules to present and adapt the attack scenarios directly to your business context.
Live Demonstration
Our security experts demonstrate attacks in real time, showcasing hands-on attack techniques and specialized hacking gadgets.
Countermeasures & Defense
For every demonstrated attack vector, we break down actionable countermeasures and preventative security controls.
Interactive Q&A
The event wraps up with an open discussion and Q&A—consistently the most engaging segment where practical questions get answered.
What we showcase (Hack Portfolio)
We’d be happy to provide you with consulting services in advance regarding a suitable mix.
Web Hacking
What we’ll be demonstrating: a live demonstration of how a replica online shop can be compromised, and the most common web vulnerabilities.
How to protect against this: Secure development practices and regular assessment of your own applications.
passwords
What we’re showing: How quickly weak passwords can be cracked, including a comparison with known data breaches.
What protects against this: Long, unique passwords from a password manager, combined with two-factor authentication.
Wireless keyboards
What we’re demonstrating: Intercepting and manipulating input from unsecured wireless keyboards.
How to protect against this: Encrypted or wired input devices, particularly in sensitive areas.
Hardware gadgets
What we’ll be demonstrating: Cloning unsecured RFID access cards, setting up man-in-the-middle cables.
What protects against this: Modern, encrypted access cards and being vigilant about unfamiliar cables.
Social Engineering
What we’re demonstrating: A fraudulent call featuring a voice faked using AI.
How to protect yourself: Call back using a number you recognise and apply the dual-control principle when authorising payments.
Malware infection
What we’re showing: A computer becomes infected, shown from the attacker’s perspective.
How to protect yourself: Do not run unknown files and report the issue as soon as possible.
Wi-Fi Hacking
What we’ll be demonstrating: a Wi-Fi attack via a fake captive portal.
How to protect yourself: Do not log in to open networks, take certificate warnings seriously, use a VPN.
Further topics available on request. If you have a scenario in mind that is not listed here, please mention it to us during the preliminary discussion.
For the Social Engineering module, the following applies: if we are to mimic the voice of someone from your organisation, we require their explicit consent. Without this, we will use a neutral sample voice.
On-site or remotely
On-site
We’ll come to you. This is the better option, as it allows you to handle the hardware modules in person and, in our experience, makes for a more lively Q&A session.
Remote
By default, via Microsoft Teams or another platform of your choice. This allows you to reach distributed teams without the need to travel. We’ll be demonstrating all the hacks via livestream.
What you’ll need to provide
On-site
- Room with a projector or large screen and HDMI connection.
- Sound system, provided there are more than around fifty people in the room.
- Sufficient power sockets in the stage or table area.
- Stable Wi-Fi or good mobile phone reception.
- The option to darken the room so that the projection remains legible.
- In large rooms, a camera pointing at the demonstration area (for hardware modules).
Remote
- A platform that enables high-quality screen sharing.
- Someone on your end to moderate the session and handle questions in the chat.
No prior technical knowledge is required on your part, nor is any preparation needed from the participants.
What remains afterwards
A summary of the important recommendations, to be shared with the team.
- Feedback from the Q&A session: Which topics resonated with your audience, to guide your future awareness planning.
- Points for further discussion: If questions arise regarding your own environment, we’ll explain which service addresses those issues.
Protection rather than shock tactics
It’s easy to make an impression. Our aim is to ensure that, by the Monday after the event, things are done a little differently.
Live-Hacking
Tell us the occasion, audience and your preferred date. We’ll get back to you with a proposal for the format and scenarios.
- Your systems remain untouched
- Live Pentester on stage
- Tailored to your audience
- The right protective measure for every attack
Frequently Asked Questions
What customers want to know before working with us.
Is there a risk to our IT systems?
No. All demonstrations run on our own, isolated infrastructure. Nothing is connected to your network and nothing is installed on your systems.
Do you use real data from our company?
No. We work with simulated examples. We only use publicly available information about your company if you expressly request it.
Do participants need any prior knowledge?
No. We do not require any technical knowledge and adapt the level of detail to suit the audience.
Can we record the event?
For remote sessions, this is possible by arrangement. We exclude individual modules from this as they can be misleading without context.
How short notice can a booking be made?
That depends on the date and venue. Simply enquire with your preferred date, and we’ll let you know straight away if it’s available.
Is this also available in English?
Please mention this during the initial consultation; we’ll sort it out depending on the availability of trainers.
Is this suitable for trainees?
Yes, there is a dedicated version of the course designed specifically for them, featuring more interaction and a stronger focus on personal devices.

