How to prepare for the International Cybersecurity Olympiad

ICO Guide

Maths has an olympiad. Physics has one. Informatics has one. Now cybersecurity has its own: the International Cybersecurity Olympiad (ICO), where secondary school students from around the world compete on real security problems.

CyberLearner is built on the ICO curriculum, so this is a topic close to my heart. Here is what you need to know, and how to prepare without spending a penny.

Who can take part?

According to the 2026 draft rulebook, contestants must be secondary school students, no older than 20 on 1 July of the competition year. University students are not allowed. Each country sends a team of up to four contestants, usually selected through a national competition.

So the first step is often local: find out whether your country runs a national cybersecurity olympiad or selection, and how to enter.

How does the competition work?

  • Two days, seven hours each. Different problems on each day.
  • Three tasks per day, each worth 100 points.
  • Each task is split into subtasks, roughly 4 to 8, each with its own flag. You get points for every flag you submit, so partial progress counts.
  • One task mixes categories. The same codebase might need a bit of web, a bit of crypto and a bit of reverse engineering. Being great at only one thing is not enough to medal.
  • Your own laptop only. No phones. Everything is solvable with free and open source tools.
  • AI is restricted during the contest. Unrestricted AI use is prohibited, so you need to genuinely know your tools. You can use AI as much as you like while preparing.

Always check the latest official rulebook, as details can change before each edition.

The six categories

  • Binary exploitation. Memory corruption in x86_64 programs. The deep end.
  • Cryptography. From classic mistakes to serious maths.
  • Digital forensics. Files, disk images, network captures, hidden data in images and audio.
  • Reverse engineering. Understand compiled programs without their source code.
  • Web security. Custom web apps, server side and client side.
  • Miscellaneous. Network security, mobile, AI, cloud, radio and more.

A practical preparation plan

Months 1 to 2: foundations

Linux command line, Python scripting, how the web works, number systems (binary, hex, base64). Do the intro labs in every category, not just the fun ones.

Months 3 to 5: breadth

Work through each track in order. On CyberLearner the intro series are built for exactly this: binary intro, reverse engineering intro, forensics intro and crypto intro. The ICO rewards breadth, so fix your weakest category first. It is the cheapest way to gain points.

Months 6 and beyond: depth and speed

Move to the competition-level labs. Practise under time pressure. Set yourself a 7-hour "exam day" once a month with three unseen problems and no AI. Afterwards, read write-ups for what you missed.

All the time: build your own toolkit

Prepare your laptop like a toolbox: debugger, disassembler, Python libraries, your own scripts and notes, all working offline. On the day you do not want to be installing things.

Start the binary track from the very first step. Open Memory Layout →

Tips from the training room

  • Partial points matter. Grab the easy subtasks across all tasks before going deep on one.
  • Read everything first. Spend the first 20 minutes reading all three tasks. Plan where your points will come from.
  • Write notes as you go. Seven hours is long. Your notes are your memory.
  • Sleep. A rested brain finds bugs. A tired one makes them.
Not sure where you stand? Try a lab now, no account needed. Try a lab, no signup →

CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.


TopicsInternational Cybersecurity OlympiadICOCybersecurity olympiadICO preparationCTF trainingCybersecurity competition for studentsBinary exploitationCryptographyDigital forensicsWeb securityReverse engineering
Share this article LinkedIn X Facebook Email
← Back to all posts