Structured Defense: Martial Arts as a Blueprint for Cybersecurity Training
Travis Van Winkle
BSides Seattle 2026 · Day 1 · Track 2
Overview
This talk proposes a training framework for cybersecurity professionals drawn directly from the pedagogy of traditional martial arts. The speaker, who has a cross-section background in IT operations, cybersecurity, and martial arts instruction, argues that cybersecurity training in most organizations is fragmented, goalless, and too often follows the "thrown to the wolves" model where new hires are expected to figure things out on their own.

Key moments
- 0:00 Introduction and the three common training failures
- 3:29 Why the framework must be scalable and adaptive
- 5:45 Benefits: easy to organize, show progress, see gaps
- 9:45 Basics stage: the beginner's mindset and foundations
- 15:30 Moving basics: drilling procedures and handling fragility
- 19:30 Kata stage: repetition, muscle memory, and letting them fly
- 22:00 Why failures and mistakes are the primary learning mechanism
- 23:30 Freestyle sparring: hands-off training and belt milestones
Structured Defense: Martial Arts as a Blueprint for Cybersecurity Training
Speakers: Unknown (IT Operations / Cybersecurity / Martial Arts Instructor)
Conference: BSides Seattle 2026
YouTube: https://www.youtube.com/watch?v=XhsiBE8pGjQ
Overview
This talk proposes a training framework for cybersecurity professionals drawn directly from the pedagogy of traditional martial arts. The speaker, who has a cross-section background in IT operations, cybersecurity, and martial arts instruction, argues that cybersecurity training in most organizations is fragmented, goalless, and too often follows the "thrown to the wolves" model where new hires are expected to figure things out on their own.
The core thesis is that martial arts already provides a proven, scalable, and adaptive training structure -- one that moves students from basics through movement drills, kata (patterned sequences), one-step sparring, and eventually freestyle sparring. By mapping this progression onto SOC analyst onboarding and other security roles, organizations can build training programs with clear milestones, measurable progress, and flexibility to accommodate different skill levels and learning styles.
The talk is less about specific security tools and more about the meta-problem of how organizations develop their people. It addresses a gap that most security conferences ignore entirely: the human development pipeline that determines whether defenders can actually do their jobs.
Background
▶ Watch: Introduction and the three common training failures (0:00)
The speaker opens with three common training failures observed across IT operations and cybersecurity organizations: fragmented training that delivers incomplete knowledge, unknown goals or progression where trainees have no visibility into what they still need to learn, and the pervasive "thrown to the wolves" approach where new hires receive minimal onboarding.
These problems persist because most organizations lack a rigid-yet-flexible framework for training. The speaker draws on martial arts experience training people of wildly varying backgrounds -- from individuals with Tourette's syndrome to people ranging from 5'0" to 6'8" in height -- to illustrate that effective training requires a core set of requirements while remaining adaptable to individual needs, learning styles (visual, auditory, kinesthetic), and scale (one person to 25+).
Key Findings
▶ Watch: Benefits: easy to organize, show progress, see gaps (5:45)
The martial arts training progression maps naturally to cybersecurity workforce development through five distinct stages:
Basics (Stance): Establishing foundational knowledge -- organizational policies, the CIA triad, basic tool familiarity. Trainers must verify incoming skill levels and fill gaps to get everyone to a common baseline. The speaker emphasizes a "beginner's mindset" where the trainee's primary question should always be "why?"
Moving Basics (Structure): Drilling core procedures -- ticket creation, DNS lookups using tools like dig or DNS Recon, report writing. This is described as a "fragile time" for trainees where imperfection must be accepted and acknowledged. Continuous feedback loops are critical.
Kata (Patterns): Putting basics together into repeatable workflows -- for example, combining IP address research, domain lookup, and header analysis to analyze a phishing email. Repetition builds muscle memory so analysts can execute without consulting documentation every time.
One-Step Sparring (Guided Practice): Transitioning from memorization to problem-solving. Trainees work exercises solo or in guided pairs, tackling challenges that reveal remaining gaps.
Freestyle Sparring (Independence): The trainee operates autonomously and begins training others. The speaker notes that you only need to be "one step ahead" of someone to teach them the basics.
Technical Deep Dive
▶ Watch: Moving basics: drilling procedures and handling fragility (15:30)
The talk is intentionally non-technical in the tool-specific sense. The framework is designed to be tool-agnostic and role-agnostic -- the speaker repeatedly emphasizes "concepts, not words." The same structure applies whether onboarding a SOC analyst, a digital forensics examiner, an incident responder, or a red teamer.
The technical contribution is the training architecture itself. Each stage has concrete deliverables for both the learner and the trainer. For example, during the "Moving Basics" stage, the trainer's job is to drill fundamentals (consuming roughly half of available training time, analogous to the 30-60 minutes of basics drilling in a two-hour martial arts class) while being prepared to handle trainee stumbles with constructive acknowledgment rather than punishment.
The speaker also addresses the mathematics of training progression -- using the analogy that you would not teach a four-year-old linear algebra before addition. Trainers must temper their knowledge delivery to what the trainee needs now, not what they will need later.
Demo / Proof of Concept
▶ Watch: Kata stage: repetition, muscle memory, and letting them fly (19:30)
No live demo or technical proof of concept was presented. The talk walked through two parallel examples on the same slides: the journey of becoming a SOC analyst and the process of training a SOC analyst, mapped stage-by-stage against the martial arts progression. The speaker invited the audience to mentally substitute their own roles and organizational contexts into the framework.
Defensive Implications
▶ Watch: Freestyle sparring: hands-off training and belt milestones (23:30)
The primary defensive implication is organizational: security teams that adopt a structured, progressive training methodology will produce analysts who reach operational competence faster and with fewer gaps. Specific takeaways for defenders include:
- Use the framework to audit existing training programs and identify documentation gaps
- Implement belt-level milestones (gamification) to motivate progression and provide visible markers of competence
- Leverage senior analysts as trainers, not just the team lead -- anyone "one step ahead" can teach
- Build continuous feedback loops into the training process rather than relying on periodic reviews
- Prioritize in-person, one-on-one or two-on-one coaching during early onboarding phases before transitioning to broader group training
Key Takeaways
- Cybersecurity training failures stem from fragmented programs, unclear goals, and sink-or-swim onboarding -- the martial arts framework addresses all three
- The progression from basics through kata to sparring provides a proven model for moving trainees from foundational knowledge to autonomous operation
- Training frameworks must be flexible enough to accommodate different skill levels, learning styles, and organizational contexts
- Trainees must be allowed to fail -- mistakes are the primary learning mechanism, not something to be avoided
- Trainers only need to be one step ahead of the trainee to be effective teachers
- Continuous feedback loops and visible progress tracking are essential for trainee development and retention
About the Speaker(s)
The speaker has a background spanning IT operations, cybersecurity, and martial arts instruction. They have experience training individuals across a wide range of physical abilities and skill levels in martial arts, and have applied those training principles to cybersecurity workforce development. Their LinkedIn is available via the QR code shown during the talk.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A soft-skills talk that maps martial arts training stages onto cybersecurity onboarding. While the framework is organized and the speaker is clearly passionate, there is zero technical depth -- no tools, no exploits, no measurable security outcomes. This is an HR and training management talk wearing a cybersecurity conference badge.
Heather Calloway (CISO) — STRONG
A structured approach to cybersecurity workforce development that adapts martial arts pedagogy into a progressive training framework. While lacking metrics or case studies, the framework addresses a real and costly gap in how security teams onboard and develop talent -- a problem every CISO faces.