Skip to content

CMD+CTRL Security

Application security training platform using hands-on labs and cyber ranges built from intentionally vulnerable software.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

CMD+CTRL Security is a software security training provider offering more than 250 interactive modules, 125+ scenario-based labs, and 11 hands-on cyber ranges built around deliberately insecure applications that let developers and security practitioners practice finding and exploiting real vulnerabilities. The company traces its roots to Security Innovation’s training division, founded in 2002, which was rebranded as CMD+CTRL Security in 2024.

Headquartered in Woburn, Massachusetts, the company reports more than 300 companies and 3.5 million users trained, ranging from Global 100 software firms to mid-size financial services and retail companies. Recent expansion includes a direct-to-individual B2C training tier and new labs covering cloud database security, API vulnerabilities, and MITRE ATT&CK-aligned enterprise tactics.

Innovation Matrix Assessment

Innovation Velocity 5/10

Rebranded and relaunched its training platform in 2024/2025 with new labs and a B2C tier, a moderate but steady innovation pace.

Operational Value 6/10

Hands-on labs against realistically vulnerable applications build developer security skills more effectively than passive training content.

Market Momentum 9/10

Over two decades of operating history and 3.5 million trained users indicate durable, if not explosive, market presence. Recognized in Cyber Defense Media Group's 2026 Global InfoSec Awards (2 awards), independently juried industry validation of market traction.

Category Disruption 4/10

Hands-on AppSec training is an established category; CMD+CTRL is a long-running, credible provider rather than a category disruptor.

Real-World Efficacy 6/10

Two decades of continuous use by Global 100 companies is a meaningful real-world adoption signal for training efficacy.

Enduring Relevance 6/10

As secure-coding skills gaps persist and AI-generated code introduces new vulnerability classes, developer-focused training stays relevant.

Why CISOs Should Care

Builds developer security skills through realistic hands-on practice rather than compliance-checkbox video training.

What Makes It Different

Deliberately vulnerable, realistic application environments rather than abstract quizzes or slide-based courses.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A long-established, credible training provider with steady but incremental evolution rather than disruptive innovation.

Editorial Note: Claims vs. Verified Findings

User and customer counts are vendor-published.

Sources