CMD+CTRL Security
Application security training platform using hands-on labs and cyber ranges built from intentionally vulnerable software.
Visit Website ↗ + Add to CompareOverview
CMD+CTRL Security is a software security training provider offering more than 250 interactive modules, 125+ scenario-based labs, and 11 hands-on cyber ranges built around deliberately insecure applications that let developers and security practitioners practice finding and exploiting real vulnerabilities. The company traces its roots to Security Innovation’s training division, founded in 2002, which was rebranded as CMD+CTRL Security in 2024.
Headquartered in Woburn, Massachusetts, the company reports more than 300 companies and 3.5 million users trained, ranging from Global 100 software firms to mid-size financial services and retail companies. Recent expansion includes a direct-to-individual B2C training tier and new labs covering cloud database security, API vulnerabilities, and MITRE ATT&CK-aligned enterprise tactics.
Innovation Matrix Assessment
Rebranded and relaunched its training platform in 2024/2025 with new labs and a B2C tier, a moderate but steady innovation pace.
Hands-on labs against realistically vulnerable applications build developer security skills more effectively than passive training content.
Over two decades of operating history and 3.5 million trained users indicate durable, if not explosive, market presence. Recognized in Cyber Defense Media Group's 2026 Global InfoSec Awards (2 awards), independently juried industry validation of market traction.
Hands-on AppSec training is an established category; CMD+CTRL is a long-running, credible provider rather than a category disruptor.
Two decades of continuous use by Global 100 companies is a meaningful real-world adoption signal for training efficacy.
As secure-coding skills gaps persist and AI-generated code introduces new vulnerability classes, developer-focused training stays relevant.
Why CISOs Should Care
Builds developer security skills through realistic hands-on practice rather than compliance-checkbox video training.
What Makes It Different
Deliberately vulnerable, realistic application environments rather than abstract quizzes or slide-based courses.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
A long-established, credible training provider with steady but incremental evolution rather than disruptive innovation.
Editorial Note: Claims vs. Verified Findings
User and customer counts are vendor-published.
Sources
Alternatives to CMD+CTRL Security
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…