SPREAD

Your team already knows risk management. Do they know it the same way?

A facilitated session that surfaces where your security team’s judgment actually diverges, and why, before a real incident does it for you.

Two people call the same thing “high risk.” Do they mean the same thing?

Your security team already knows risk management. That’s exactly the issue. People come from different backgrounds, GRC, red team, OT, incident response, and each carries their own working definition of “threat,” “vulnerability,” and “risk.” Those gaps rarely show up until a real incident, when two experienced people who both called something “high risk” turn out to have meant different things.

Most training assumes the team needs to learn the material. This team already knows the material. What it needs is to discover where its own definitions quietly diverge, before that costs something.

SPREAD is built for that specific gap. Not a 101 workshop. It assumes the expertise is already in the room and gives it somewhere to disagree productively.

Security team members discussing a risk decision during a facilitated session

THE GAME

What SPREAD actually is

SPREAD is a facilitated session built around a realistic attack scenario, drawn from a library of threat and vulnerability cards built for exactly this kind of exercise. A fictional company to start; the scenario is built around your team’s actual composition once we know who’s in the room.

The name comes from how it plays: everyone commits their call privately, then lives with how far apart those calls turn out to be.

I facilitate every session.

WHAT THE REVEAL SHOWS

What SPREAD surfaces

Differing definitions

Two people land on the same square for completely different reasons. One is scoring “likelihood,” the other “how bad it would be.” Same label, different thing measured.

Differing assumptions

Same definition, different unstated fact feeding it. One assumes a control is enforced. The other doesn’t. Neither is wrong, they’re working from different pictures.

Differing risk appetite

Same facts, same definition, different threshold for what counts as “high.” The gap isn’t technical. It’s a values question nobody’s named out loud.

HOW A SESSION RUNS

Commit. Reveal. Trace it to the root.

For each threat, everyone privately places it on the risk matrix, exposure against impact, exposure meaning what’s actually reachable and countable, not an abstract probability guess, and writes a one-line reason for their call.

Everyone reveals at once.

Then I run the discussion with one pointed question aimed at each point of divergence: “Say the one thing you’re seeing that they’re not.” That question sorts the gap into one of three things, a different definition, a different assumption, or a different risk appetite, often more than one at once, so it can be named and addressed directly instead of re-litigated as who placed the marker where.

Sometimes two people land on the same square for completely different reasons. The same question draws that out too.

Once the gap is named, the group re-places that threat, together this time, and often runs a second threat cold to see whether the spread has actually narrowed.

WHAT YOU LEAVE WITH

What your team walks away with

A named map of the divergence

A named map of where your team’s judgment actually diverges, and why, sorted into definition gaps, assumption gaps, and appetite gaps.

A visibly tighter spread

A visibly tighter spread on at least one threat, re-placed together after the discussion.

A shared reference to point back to

A shared reference the team can point back to the next time two people call the same thing different risk levels.

Who SPREAD is for

Any security team whose members came up through different disciplines, GRC, technical operations, incident response, architecture, and needs a shared, working vocabulary for risk, not a shared vocabulary on paper. Internal sessions, not client-facing.

Group size scales in small tables. Duration around ninety minutes for a first run; tuned after that. Facilitated by Klaus Agnoletti.

SPREAD sits in the serious games lineup. Risk Deck does something adjacent for a mixed security and business room reading one incident together, and FAULT LINE puts vulnerabilities and failure cascades on the table instead of risk judgment. If you want the reasoning behind running any of this as a game rather than a briefing, that is game-based learning.

FAQ

Frequently asked questions

Is this a training session for people new to risk management?
No. It assumes real expertise in the room. The value is in surfacing where that expertise quietly diverges, not in teaching definitions from scratch.
What if the team already agrees on most calls?
That’s useful information too, and it still shows up in the reveal, agreement with matching reasoning is the baseline the session is measuring against.
Can the scenario be built around our actual environment?
Yes, once I know your team’s composition. If you want to use a real incident your team has handled, it needs to be one where the outcome is still unresolved or wasn’t shared with the group beforehand, once everyone already knows how it played out, hindsight collapses the exposure/impact judgment the exercise is designed to test.
How is this different from a tabletop exercise?
A tabletop tests whether a plan holds, and tends to surface disagreement retrospectively and verbally, where hindsight and the loudest voice in the room dominate. SPREAD surfaces it simultaneously and privately, every judgment is on the record before anyone’s heard anyone else’s.
How is this different from EXPOSURE?
SPREAD and EXPOSURE share some DNA, same risk matrix, same threat and vulnerability card library, but they’re built for different rooms. EXPOSURE is a broader risk-management session, often bringing in less risk-fluent stakeholders. SPREAD is built specifically for a team of experienced security practitioners who already know the material and need to find out where their own judgment quietly diverges.

Find out where your team actually disagrees.

Reach out and let’s talk about what a first session would look like for your team.

See the full serious games lineup.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.