Security instinct is built, not briefed.

A slide deck can tell your team what good security looks like. It can’t make them do it when the room is tense and the clock is running. Instinct doesn’t come from being told about a decision. It comes from making it, getting it wrong somewhere it’s safe to get wrong, and making it again. That’s the whole reason these games exist.

Each one is a serious game, the same category as planning poker or a well-run tabletop. Not gamified slideware, and not a party game. Each takes a security problem that normally lives in a document, a board decision under NIS2, a continuity plan, a system architecture, an incident, a risk number, and puts it on the table, where your technical people and your business people have to work it out together and out loud. Most of them run against your real environment, not a case study, so what you practice is the thing you’ll actually face.

Six games. Pick the problem you need your team to practice.

EXPOSURE

Your board approves the security budget without ever feeling what the unfunded part costs. They run the company through three rounds of governance decisions, budget, incident escalation, vendor risk, and watch the consequences land on choices they made themselves.

FAILOVER

Your continuity plan has an owner, a version number, and no evidence that anyone can actually invoke it. We put your real plan on the table, break something, and find out who has the authority to act, then your team amends the plan and we break something else.

FAULT LINE

Every risk on your register looks worth fixing and there is no budget to fix all of them. Teams build a company out of physical parts, choose where to spend, then watch attacks hit the parts they left open.

Malware & Monsters

Your team has rehearsed the incident in the plan. It has not rehearsed the one that changes shape while they are working it, an incident master narrates symptoms, each player takes one action, and the threat evolves in response to what they actually did.

Risk Deck

Your technical people and your business people each hold half the picture, and neither can say the other half out loud. Both sides commit their read of the same incident privately, reveal at once, then have to explain the other side’s half in plain language. Solo or group, print and play.

SPREAD

Two of your experts both call it high risk. They are not talking about the same thing, and nobody notices until an incident makes it expensive. Everyone scores the same threat privately, reveals at once, and one facilitated question sorts the gap so the team can close it.

Already running Malware & Monsters? Add The Presumption Deck to work specifically on calibration under uncertainty.

Want facilitated training rather than a game? See the workshops.

Not sure which fits?

Tell me about your team and what you want them to practice, and I’ll point you to the right game or a custom session.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.