Women's Internation Cybersecurity Challenge 2026 - Dublin, Ireland
I took 3 days of unpaid leave to attend the inaugural Women’s Internation Cybersecurity Challenge (WICC) 2026 and the experience was invaluable.
We went into the competition with one goal: Don’t be last on the scoreboard.
WICC 2026 Overview
WICC 2026 — the Women’s International Cybersecurity Challenge — is an international CTF event for elite women cybersecurity competitors, taking place in Dublin on 9–10 July 2026. It brings regional teams from around the world together for two days of advanced technical competition.
I am glad that I was able to represent Team Asia (Singapore) as Team Captain for this competition, alongside my wonderful teammates Verity, Ezann, Reanee, Lyris and Sandra.
Thank you to Mirkhoff for letting me know about this opportunity and Emil for registering us!
Huge shoutout to Cybersecurity Agency of Singapore (CSA) and the Singapore Cyber Olympians (SGCO) programme for sponsoring our trip.
Preparations and Obstacles
Compared to Teams like Team Europe, Team US and the other well established teams, the group of us came together to form this team just 1 month before the competition, while juggling our internship responsibilties. The process of confirming our travel plans and training (?) for the competition was not easy.
Tough Times
WICC introduced a new CTF format developed by Overseers specifically for the competition. Teams were given two demo slots to familiarise themselves with the platform’s mechanics and begin developing strategies. However, coordinating a session that worked for everyone proved difficult because of time-zone differences and internship commitments.
As with any new competition format, the playtesting period also highlighted areas that could be improved. Teams shared feedback with the organisers, particularly where certain game mechanics needed further clarification. Because we were unable to spend as much time on the platform as we would have liked, and did not have Attack-Defense tooling available beforehand, we could not fully develop our tooling or gain a complete understanding of every mechanic before the event.
Nevertheless, drawing on my previous Attack-Defense CTF experience, Codex + Claude and with Verity’s help, we built a basic set of Attack-Defense tools. It was not a complete solution, but it gave us a foundation and helped ensure that we would not be starting from scratch on competition day.
New Perspective on CTF Modes
One of WICC 2026 Dublin’s most exciting additions is the new Encounter mode, which turns chance meetings on the map into optional head-to-head CTF duels. When two eligible teams come within vision range, one can issue a challenge; if it is accepted, the teams alternately ban Jeopardy-style categories before racing to solve a randomly selected challenge from the category that remains. The winner earns points, while declining a duel carries a small strategic cost—creating tense moments where positioning, category knowledge, and nerve matter just as much as technical skill.
This differs markedly from a traditional Jeopardy-style CTF, where every team independently selects from the same challenge catalogue and races to submit a solution. WICC’s Bonus challenges retain that familiar first-blood model, but Encounters make competition deliberately interpersonal: the matchup depends on another team’s location, willingness to engage, and choices during the category draft. Instead of focusing solely on which challenge a team wants to solve, competitors must also assess their own strengths, anticipate an opponent’s preferences, and decide whether a potential duel is worth taking.
King of the Hill offers a different kind of competition again. Rather than pitting two teams directly against one another, KotH is an ongoing, field-wide optimisation contest in which every participating team submits a candidate solution to a shared challenge—in this case, a Python opcode challenge. The platform ranks active submissions each round, meaning that points depend on relative placement and teams must continue refining their solutions as rivals improve theirs. Where KotH rewards sustained iteration and the ability to remain ahead of the wider leaderboard, Encounters reward quick analysis, strategic decision-making, and the ability to outperform one specific opponent under pressure.
The contrast with Attack-Defense is equally clear. Attack-Defense is a long-running, many-to-many contest in which every team patches and operates its own vulnerable service while attacking the services maintained by the rest of the field. Success depends on balancing service reliability, defensive patching, and automated flag-stealing over repeated scoring rounds. Encounters, by comparison, are short and self-contained: there is no service to maintain, exploit pipeline to operate, or recurring score to protect. This gives the mode a different kind of intensity, adding direct competition and tactical decision-making to the technical problem-solving at the heart of a CTF.
Our Approach
WICC showed us that success was not only about technical ability, but also about strategy.
Knowing that we might be outmatched by some teams in certain technical areas, we focused on making the most of the map and planned an efficient route before the competition began. Since the locations of the main challenges were visible in advance, we decided to activate the nearest one first, begin earning SLA points while investigating it, and then travel towards the next challenge (using that travel time to keep working on the first).
We repeated this approach across the map, and it paid off: although we did not manage to develop a working exploit, our early activations and patches allowed us to keep our services running and earn valuable SLA points.
Day 2 was a complete switch up. On day 1, we were only able to see teams within out small radius of vision but now, the whole map is visible (each team’s character location too). Strategy remains unchanged but now we can gauge the working path of all other teams (means we can see if they are walking in our direction for a 1v1 encounter :eyes:). Welp, that indeed happened multiple times while we were just trying to walk to our next challenge. First few times, yes, we tried to walk in a different direction to dodge the 1v1 but after awhile… nah let’s just do it. I’m proud we managed to win most of them! (and draw afew :P)
Tabao (Takeaways)
I am proud to share that we managed to score 6th on Day 1 and 3rd on Day 2 (before hardware challenge points)! I could not be more proud of my team :D
One of my biggest takeaways from WICC was the opportunity to meet and interact with incredibly talented competitors from teams such as the US, Europe, Oceania, and LAC, as well as people from across the world. The competition also strengthened our teamwork and communication, especially as we supported teammates with less CTF experience. I learned the importance of adapting quickly and thinking strategically in an unfamiliar CTF format, and I genuinely enjoyed the game-like element it added to the competition. Most of all, I loved the adrenaline of the Encounters—the 1v1 CTF duels—which made every decision feel immediate, competitive, and exciting.
I love seeing people come together to brainstorm how we can keep the CTF scene thriving in an AI-driven future and I am glad to be part of this community.
Thank you to all the challenge creators, Zerodays and everyone that made this event so amazing.