SPREAD
Your team already knows risk management. Do they know it the same way?
A facilitated session that surfaces where your security team’s judgment actually diverges, and why, before a real incident does it for you.
Two people call the same thing “high risk.” Do they mean the same thing?
Your security team already knows risk management. That’s exactly the issue. People come from different backgrounds, GRC, red team, OT, incident response, and each carries their own working definition of “threat,” “vulnerability,” and “risk.” Those gaps rarely show up until a real incident, when two experienced people who both called something “high risk” turn out to have meant different things.
Most training assumes the team needs to learn the material. This team already knows the material. What it needs is to discover where its own definitions quietly diverge, before that costs something.
SPREAD is built for that specific gap. Not a 101 workshop. It assumes the expertise is already in the room and gives it somewhere to disagree productively.
THE GAME
What SPREAD actually is
SPREAD is a facilitated session built around a realistic attack scenario, drawn from a library of threat and vulnerability cards built for exactly this kind of exercise. A fictional company to start; the scenario is built around your team’s actual composition once we know who’s in the room.
The name comes from how it plays: everyone commits their call privately, then lives with how far apart those calls turn out to be.
I facilitate every session.
WHAT THE REVEAL SHOWS
What SPREAD surfaces
Differing definitions
Differing assumptions
Differing risk appetite
HOW A SESSION RUNS
Commit. Reveal. Trace it to the root.
For each threat, everyone privately places it on the risk matrix, exposure against impact, exposure meaning what’s actually reachable and countable, not an abstract probability guess, and writes a one-line reason for their call.
Everyone reveals at once.
What the spread looks like
Before: private calls
After: re-placed together
Exposure means what is actually reachable and countable, not an abstract probability guess. The gap between the two panels is the thing the session is measuring.
Then I run the discussion with one pointed question aimed at each point of divergence: “Say the one thing you’re seeing that they’re not.” That question sorts the gap into one of three things, a different definition, a different assumption, or a different risk appetite, often more than one at once, so it can be named and addressed directly instead of re-litigated as who placed the marker where.
Sometimes two people land on the same square for completely different reasons. The same question draws that out too.
Once the gap is named, the group re-places that threat, together this time, and often runs a second threat cold to see whether the spread has actually narrowed.
WHAT YOU LEAVE WITH
What your team walks away with
A named map of the divergence
A visibly tighter spread
A shared reference to point back to
Who SPREAD is for
Any security team whose members came up through different disciplines, GRC, technical operations, incident response, architecture, and needs a shared, working vocabulary for risk, not a shared vocabulary on paper. Internal sessions, not client-facing.
Group size scales in small tables. Duration around ninety minutes for a first run; tuned after that. Facilitated by Klaus Agnoletti.
SPREAD sits in the serious games lineup. Risk Deck does something adjacent for a mixed security and business room reading one incident together, and FAULT LINE puts vulnerabilities and failure cascades on the table instead of risk judgment. If you want the reasoning behind running any of this as a game rather than a briefing, that is game-based learning.
FAQ
Frequently asked questions
Is this a training session for people new to risk management?
What if the team already agrees on most calls?
Can the scenario be built around our actual environment?
How is this different from a tabletop exercise?
How is this different from EXPOSURE?
Find out where your team actually disagrees.
Reach out and let’s talk about what a first session would look like for your team.
See the full serious games lineup.