We started Cyber Melee because we were bored with safe cybersecurity content.
There is already plenty of that.
Plenty of webinars. Plenty of panels. Plenty of people saying the same correct things in the same polished way while nobody has to make a decision under pressure.
We wanted to do something more exposed.
So we built a competition.
Not a trivia contest. Not a raffle with cybersecurity branding slapped on it. A real scenario-based event where people had to think fast, write clearly, and live with the quality of their answer in front of judges and peers.
That was the point.
The last Cyber Melee had an online qualifier, then a live round with seven judged scenarios, and by the end of it Abhi Saini came out on top.
That part landed.
Now that it is over, here is the honest version of how it went.
The idea is better than a lot of the cybersecurity content out there
That sounds arrogant. It is also true.
Most cybersecurity content is passive. You sit there, consume it, maybe take notes, maybe nod along, and then go right back to your normal week without ever having to prove you can actually apply any of it.
Cyber Melee did not let people hide like that.
It forced contestants to take a scenario, make judgment calls, and turn that into an answer on a clock. That immediately made the whole thing more real than another hour-long discussion about “best practices.”
That alone made it worth doing.
What worked
It had actual pressure
This was probably the strongest part of the event.
People had to respond fast. There was not much room to overthink, posture, or polish something into oblivion. You had to read the problem, decide what mattered, and answer.
That exposed a lot, fast.
You could see who actually knew how to think through a problem and who just knew how to sound like they did.
That is useful. That is interesting. And frankly, that is a lot closer to real cyber work than most training environments.
The questions pulled out real judgment, not just memorized answers
This is where the event felt the most worthwhile.
One of the scenarios we gave contestants was:
A client calls and says they just wired $50,000 to an unknown account. How do you proceed?
One contestant answered it like this:
Weep with them.
Move into response playbook for this that you have rehearsed with the client, hopefully.
Congratulate them on calling right away and explain this is tough but we’re here with them.
They need to alert their insurance, who may have a requirement to take over and direct.
Alert their bank and seek support.
They will have an internal alerting structure they need to hit, like board chair, etc. Contain — seek understanding to see how this happened, in case it was a coordinated attack and others in the company are about to do the same. We may need to advise on changes to approval process downstream for big dollar transactions, and knowing how this got through will help there. The attack could be ongoing, so we may need to go into network review, etc.
Learnings — how we got here, what needs to happen in future so the customer doesn’t get hit again. Approval lines, etc.
That answer is a good example of why Cyber Melee worked.
It is not written like a textbook. It is not pretty. It is not trying to sound like a compliance PDF. It sounds like somebody who has actually lived through a bad day with a client.
And that matters.
The answer starts with empathy. Then it moves into incident response. Then insurance. Then bank notification. Then internal escalation. Then containment. Then root cause. Then process fixes so it does not happen again.
That is real thinking.
It is also exactly the kind of thing a normal webinar will never show you. A person can talk about fraud response for an hour and still never reveal whether they actually know how to act when a client is panicking on the phone. A scenario like this forces the issue.
That was one of the best parts of the event. It created moments where you could tell the difference between somebody repeating cyber language and somebody showing operational judgment.
The scoring was not just about sounding technical
We did not want the event to reward the person who could cram the most jargon into a paragraph.
A good cybersecurity answer is not just technically correct. It also has to make sense. It has to show judgment. It has to account for users, communication, tradeoffs, and consequences.
That part of the event worked well.
It gave the judges something more meaningful to evaluate than whether someone had memorized the right language.
And the wire fraud example is a good illustration of that. The strongest answer is not the one with the most acronyms. It is the one that helps a real client survive the moment, contain the damage, and avoid doing it again.
The winner felt earned
That matters.
A lot of events talk big and then end in something that feels half-random or purely performative. This did not feel like that.
Abhi won because he performed well across the board. That gave the whole event more legitimacy.
You want a competition like this to produce a winner people respect, not a result people shrug at. We got the better version of that.
What did not work as well
A strong concept does not automatically make a clean event
This is probably the biggest lesson.
The concept is strong. The execution still needs tightening.
That is not a disaster. That is just what happens when you take an idea out of your head and put it in front of real people. Suddenly all the small things matter more than you expected.
Timing matters. Question flow matters. Submission flow matters. Judge pacing matters. Clarity matters more than you think it will.
We learned that in real time.
We need to be even clearer about expectations
Anytime you run something competitive, ambiguity becomes expensive.
People need to know exactly what makes an answer strong, what gets penalized, how scoring works, what role AI can and cannot play, and what standard they are actually being held to.
Even when you think you explained it well, you usually have not explained it quite enough.
That is fixable. But it is one of the clearest takeaways from this round.
AI is part of the environment now, and pretending otherwise is stupid
One of the funniest moments around Cyber Melee was having an “AI learning agent” sign up.
That was ridiculous. It was also kind of perfect.
Because that is the environment now. AI is here. People are going to use it. The question is not whether it exists. The question is whether a person can still think when it does.
That is where Cyber Melee actually got more interesting.
A copy-paste AI answer is easy to spot. It usually sounds polished, generic, and weirdly hollow all at once. It says the right-sounding things without really showing judgment. And in a competition like this, that should get punished.
Because real expertise is not just producing an answer that sounds clean. It is knowing what matters, what does not, and why.
That distinction matters more now than it did a year ago.
What we learned
The biggest takeaway is simple: this should keep going.
Not because the event was flawless. It was not.
It should keep going because it did something real. It created a setting where people had to demonstrate judgment instead of just talking about it. That is rare, and it is valuable.
It also confirmed something we already suspected: a lot of MSP and cybersecurity people are hungry for something more active than the usual content treadmill.
They do not just want to hear what a good answer sounds like.
They want a shot to give one.
What we would change next time
We would tighten the structure.
We would make the rules even more explicit.
We would sharpen the judging language so contestants and viewers can more easily see what separated a strong answer from a weak one.
We would keep pushing the questions toward realism and away from anything that feels overly abstract or performative.
And we would lean harder into what made the event work in the first place: pressure, judgment, and public problem-solving.
Because that is the whole point.
Final thought
The last Cyber Melee was not polished in the sterile corporate sense.
Good.
That was never really the goal.
The goal was to make people show their work. To put them in a situation where they had to think, decide, and respond in a way that could actually be judged.
That happened.
Some parts were stronger than others. Some parts need work. But the core idea absolutely held up.
Cyber Melee proved that cybersecurity events do not have to be passive to be valuable.
They can be competitive. They can be public. They can be uncomfortable. They can demand something from the people who enter.
And honestly, that is why this one mattered.
Congratulations again to Abhi Saini, who earned the win.
And to everyone who entered, judged, watched, or helped make it happen: thank you.
We learned a lot from the last Cyber Melee.
The next one will be even better!
We cannot wait to reveal to you the next MSP Cyber Melee Battle (soon!)

