Venue PHDCCI, New Delhi — Oct 24–25, 2026. Open in Maps
CRACCON 26 Logo
// Hands-On Workshop · Phase I

The Cardwell Doctrine: Phase I.

Stop Defending the Perimeter. Start Controlling the Blast Radius.

Participants build an operational OpenBSD Packet Conditioning Gateway, create segmented network zones, implement traffic-control policies, and validate how segmentation, packet conditioning, visibility, and deception establish the first technical foundation of the Cardwell Doctrine.

70/30Hands-On / Concept
08:30–16:30Single-Day Schedule
6Live Labs
OpenBSDGateway Platform
ARCHITECTURE
// SEGMENT · CONDITION · CONTAIN
// Facilitator

Taught by the doctrine's author.

Kevin Cardwell President - Cyber2Lab & CybastionTech

Kevin developed the Cardwell Doctrine from decades of hands-on network architecture and penetration testing work, applying mission-assurance and compartmentalization principles from military doctrine to enterprise network design. He has trained security teams across government, defense, and critical infrastructure worldwide, and leads Cyber2Lab and CybastionTech.

// Executive Abstract

Beyond the unattainable perimeter.

Traditional cybersecurity architecture design continues to focus on an increasingly unattainable objective — preventing every attack. Organizations invest heavily in perimeter defenses, yet attackers continue to compromise networks, move laterally, and disrupt critical operations.

The Cardwell Doctrine introduces a different paradigm. Rather than assuming perfect prevention, the doctrine applies the enduring principles of mission assurance, compartmentalization, and active defense to modern network architectures. The first phase begins with the Packet Conditioning Gateway (PCG) — a purpose-built architectural component designed to condition, validate, observe, and shape network traffic before it enters the operational environment.

In this workshop, participants will learn how the PCG serves as the foundation for digital bulkheads, network mines, active deception, segmentation, and resilient network design. Through practical demonstrations and hands-on implementation guidance, attendees will acquire the architectural blueprints required to deploy these concepts immediately within enterprise, government, and critical infrastructure environments.

This session establishes the foundational layer for the complete Cardwell Doctrine framework, equipping practitioners with actionable techniques that can be implemented upon returning to the workplace.

// Technical Outline

Build. Segment. Condition. Observe. Contain.

8:30–9:001. The Cardwell Doctrine: Why We Are Building ThisUnderstand Mission Assurance, Digital Bulkheads, Network Mines, PCG, and blast-radius control.
9:00–9:452. OpenBSD & PCG ArchitectureReview OpenBSD, interfaces, routing, PF, segmentation model, logging, and target architecture.
9:45–10:45Lab 1: Build the OpenBSD GatewayInstall/configure OpenBSD, assign interfaces, enable forwarding, establish management access, verify connectivity.
10:45–11:45Lab 2: Build the Digital BulkheadsCreate at least two network segments, configure addressing/routing, establish isolation, test permitted and prohibited paths.
11:45–12:15Lab 3: Establish the pf Security PolicyBuild default-deny policy, explicit flows, stateful filtering, logging, and basic traffic conditioning.
12:15–1:00Lunch
1:00–1:454. Packet Conditioning vs. Traditional FirewallingExamine why the gateway is more than another firewall; introduce normalization, shaping, observation, and policy enforcement.
1:45–2:45Lab 4: Condition and Observe TrafficConfigure PF normalization/traffic controls appropriate to the lab, logging and visibility; generate traffic and examine what the gateway sees.
2:45–3:30Lab 5: Introduce the Network MineDeploy a controlled deception/canary service inside a lab segment and demonstrate how unexpected interaction creates a high-value signal.
3:30–4:00Lab 6: Attack, Contain, ObserveGenerate authorized adversary-like activity inside the isolated lab and observe segmentation, policy enforcement, detection, and containment.
4:00–4:305. From the Lab to the Cardwell DoctrineMap the completed architecture to Phase I and develop an implementation plan for participants' environments.
// Participants Will

Walk out with a working gateway.

Build and configure an OpenBSD gateway from the ground up
Configure multiple interfaces and network segments
Implement Digital Bulkheads using network segmentation
Develop PF rules around explicit authorized communication paths
Apply packet-conditioning and normalization concepts
Configure logging and network visibility
Deploy an introductory Network Mine/deception service in an isolated lab environment
Generate controlled traffic to validate allowed and prohibited paths
Observe what happens when activity crosses a Digital Bulkhead
Demonstrate how segmentation limits the potential blast radius
Map the completed lab architecture into the first phase of the Cardwell Doctrine
// Before You Arrive

Come with the fundamentals.

// Prerequisites

Required Background

This is a technical, hands-on workshop. Deep OpenBSD expertise is not required — the workshop builds the Packet Conditioning Gateway from the ground up. Participants should have:

  • Foundational TCP/IP networking knowledge — IP addressing, subnetting, routing, gateways, ports, common protocols
  • Basic command-line experience in a Unix/Linux-style shell
  • Basic firewall concepts — rules, allowed/denied traffic, stateful filtering (prior pf experience helpful, not required)
  • Understanding of network segmentation — VLANs, subnets, security zones, or similar isolation mechanisms
  • Basic cybersecurity knowledge — lateral movement, attack surfaces, logging, monitoring, containment
  • Ability to run hands-on labs — configuring interfaces, editing config files, running diagnostics, generating test traffic; familiarity with virtualization
  • Administration-level authorization on your machine and willingness to conduct controlled security testing in the isolated workshop environment
// Helpful, Not Required

Nice to Have

Previous experience with OpenBSD, pf, network security appliances, packet analysis, virtualization, intrusion detection, deception technologies, or enterprise network architecture will be beneficial but is not required.

Participants do not need to be OpenBSD experts — the objective is to understand and implement the architectural principles of the Cardwell Doctrine through a working Packet Conditioning Gateway.

// Who Should Attend

Built for the people who architect resilience.

This workshop is designed for technical practitioners, architects, and operational leaders responsible for building, securing, or assuring resilient network environments — particularly organizations seeking to move beyond perimeter-centric security toward segmentation, controlled communication paths, visibility, deception, containment, and blast-radius reduction.

Network Engineers & Architects
Cybersecurity Engineers & Security Architects
Firewall & Network Security Administrators
SOC Engineers & Senior Security Analysts
Incident Response & Threat Detection Practitioners
Red Team & Blue Team Personnel
Cyber Defense & Mission Assurance Professionals
Infrastructure & Platform Engineers
Enterprise & Government Security Architects
Critical Infrastructure / OT Security Professionals
Technical Cybersecurity Leaders (Architecture & Implementation)
// Recommended Audience Mix

Network + Security + Architecture + Operations

For organizations sending a team, this is the strongest combination — it lets the team leave not only understanding the Cardwell Doctrine, but with a shared technical model for translating the Packet Conditioning Gateway, Digital Bulkheads, and Network Mines into their operational environment.

Seats are limited to the lab capacity.

Reserve Your Seat