The Presumption Deck

The Presumption Deck

Real IR isn’t about being right. It’s about how sure you are.

Optional add-on to Malware & Monsters · Facilitated session · Deck free to print

The Presumption Deck calls Type, Confidence, Severity, and Resource face-down, then flips together. It’s a confidence-calibration add-on for teams who already run Malware & Monsters and want to work specifically on how sure they are, not just whether they’re right.
The Presumption Deck field notes card

THE MECHANIC

What The Presumption Deck actually is

It’s a call, commit, reveal mechanic layered on top of an incident response exercise. Four card types: Type ID, Confidence (Confident, Probable, or Uncertain), Severity, and Resource. Players call their read of the situation across three gates, Identification, Containment, Response, committing a card face-down before anyone sees what actually happened.

Confidence is called once, at the Identification gate, not at every decision point. That’s deliberate. The point isn’t to grade every call your team makes, it’s to catch the specific moment where a team commits to a read of the situation, then find out afterward whether their confidence matched reality.

Cards flip together, so the team sees not just who was right, but who was confidently wrong, and who correctly said “uncertain” when the room wanted a confident answer.

Presumption Deck Type ID card, Ransomware

Type ID (9 cards)
what kind of threat this is

Presumption Deck Confidence card, Confident

Confidence (3 cards)
how sure you are of that call, called once at Identification

Presumption Deck Severity card, Dumpster Fire

Severity (6 cards)
how bad the room thinks it actually is

Presumption Deck Resource card, Heavy Lift

Resource (7 cards)
what it will cost the team to respond

HOW A ROUND FEELS

Call, commit, reveal

1. Call

The facilitator names the question and starts a short clock. Discussion stays open right up to the moment of commitment.

2. Commit

Everyone places a card face down at the same time. No changing it once it’s down.

3. Reveal

All cards flip together. The spread gets read aloud, split and all.

Committing before anyone can see the others is the whole trick. A session hangs three gates on the scenario, one at each natural commitment point:

Gate When The team commits to
Identification Once the team has its first solid indicators Type ID + Confidence
Containment When the team must decide how to contain, before the threat escalates Severity
Response When the team commits its main response, before the window closes Resource

Runs on top of any Malware & Monsters scenario.

WHY IT EXISTS

Wrong isn’t the failure mode. Confidently wrong is.

Every estimate a team makes has two independent dimensions: how confident they said they were, and whether they turned out to be right. Cross them and you get four outcomes, and they are not equally good or equally bad.

Outcome: Right Outcome: Wrong
Said: Confident Calibrated. Earned confidence, the evidence backed it up The Trap. Confident and wrong, the dangerous quadrant
Said: Uncertain Under-called. Right, but hedged more than the evidence needed Honest. Wrong, but the doubt was flagged so the team stayed open

Uncertain-and-wrong beats confident-and-wrong, every time. A team that says “we’re sure it’s ransomware” and is wrong commits in the wrong direction and stops investigating. A team that says “we think it’s ransomware, but we’re not sure” and is wrong keeps the second hypothesis on the table and recovers faster. The Trap is the quadrant worth building a session around.

Most IR training grades outcomes: did the team contain the threat, yes or no. That misses the more common, more expensive failure: a team that was certain and wrong, or a team that quietly knew it was guessing and said nothing. Both look identical from the outside until something breaks.

The Presumption Deck makes the confidence call visible and comparable, in the room, so the gap between “we said we were sure” and “we were actually right” becomes something the team can see and talk about, not something that only shows up months later in a postmortem.

HOW IT FITS

An add-on, not a replacement

The Presumption Deck is optional. It’s not a substitute for Malware & Monsters, it’s a targeted layer on top of it for teams who’ve already run the core exercise and want to work specifically on calibration and teamwork under uncertainty, not on incident mechanics they’ve already covered.

One session buys your team the vocabulary and the experience of seeing the gap. It doesn’t buy calibration itself, that comes from doing it more than once, the same way the core game does.

FAQ

Frequently asked questions

What is the Presumption Deck?
A confidence-calibration add-on for Malware & Monsters. Teams call Type, Confidence, Severity, and Resource face-down, then reveal together. The gap between stated confidence and actual outcome is the whole point.
Who is it for?
Teams who’ve already run Malware & Monsters and want to work specifically on how sure they are, not just whether they’re right. It is not a starting point, it assumes the core exercise first.
Is it standalone?
No, by design. It sits on top of any Malware & Monsters scenario. The choreography is fixed, only the scenario changes.
How do we get the deck?
The cards, the facilitator guide, and the print sheets are free on malwareandmonsters.com. Print it yourself, no form, no demo.
What's the paid part?
The facilitation. Running it properly on a specific team, targeting how that team estimates and argues under pressure, is a facilitated engagement booked through this site. Running it yourself with the free materials is a completely legitimate outcome too.
How long is a session?
It layers onto a Malware & Monsters session rather than adding session time on its own, three gates hung on the scenario you’re already running.

AVAILABILITY

The deck itself stays free

The cards, the facilitator guide, and the print sheets are all free and open on malwareandmonsters.com, regardless of whether you book a facilitated session. What’s sold is the facilitated session, the deck as an artifact isn’t gated behind it.

Runs alongside Malware & Monsters, or explore the full serious games lineup.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.