A Game of Cyber Consequences

What a Bonkers Game of Cyber Consequences Taught Us About Real Cyber Security

When we launched our LinkedIn game Cyber Consequences, we expected a bit of fun, collaboration and some thoughts provoked for real life Cyber security education.

What we didn’t expect was an abundance of people thinking like attackers.

Over the course of seven days, our community collectively wrote the story of a cyber incident. It started with a simple phishing email and quickly descended into stolen credentials, social engineering, mailbox compromise, business email fraud, catnapping, GPS trackers, nine backups of treasured cat photos and a Finance Director with a previous career in animal welfare.

Yes, it became wonderfully ridiculous.

But beneath the humour was something far more interesting.

Every comment represented a decision.

Every plot twist reflected real cyber-attack techniques.

Every day demonstrated why organisations should have the correct security controls in place, couple with the power of tabletop exercises.

Tabletops really do and can include everyone in the organisation and bring the importance of security to life, from the board to individual teams.


Every Comment Was Someone Thinking Like an Attacker

Without prompting, contributors suggested techniques that mirror those used by real threat actors every day.

They talked about:

  • Credential theft and password reuse.
  • Logging into Microsoft 365 using stolen credentials.
  • Identifying areas of value to exploit.
  • Social engineering.
  • Creating malicious mailbox rules.
  • Business Email Compromise.
  • Waiting patiently rather than deploying ransomware immediately.
  • Reconnaissance before taking action.
  • Emotional manipulation through extortion.

What started as a game became an excellent example of how attackers rarely follow a script. They adapt, improvise and exploit opportunities as they appear and they all have varying motives, from financial gain, disruption, hacktivism or ‘script kids’ as we know them just seeing what they can get to.

That is precisely why organisations need to have appropriate playbooks for varying scenarios and practice responses. Our advice would be to keep these simple as they may need to be quickly looked at and deployed and, in a situation, or urgency, no one wants to read ‘war and peace’.


Cyber Incidents Rarely Go to Plan

One of the biggest lessons from the game was that incidents evolve.

The attacker didn’t simply deploy ransomware.

Instead they:

  • Stole credentials.
  • Looked around quietly.
  • Gathered information.
  • Changed tactics when their original plan failed.
  • Looked for other routes to achieve their objective.

This reflects real world incidents.

Modern attackers are often patient. They understand your environment before making their move, making early detection far more valuable than reacting after the damage has already been done.


Would Your Team Know What to Do?

Imagine this wasn’t a game.

Your Finance Director’s account has been compromised.

A suspicious login appears overnight.

Supplier conversations are being monitored.

Invoices are quietly being altered.

Who notices? Who owns the incident? Who contacts suppliers? Who informs leadership? Who preserves evidence? Who decides whether systems should be isolated?

Tabletop exercises can help you answer these questions before a real attacker forces you to and organisations can feel prepared and confident of their moves.


Technology Alone Isn’t Enough

Many organisations invest heavily in cyber security technology.

But technology only works if the right people from a ‘whole organisation’ level have the right understanding of what they’re seeing and know how to respond, breaches impact the organisation and people on many levels, from confidentiality of data, company availability and operations and integrity/reputation.

A tabletop exercise helps organisations test:

  • Decision making under pressure.
  • Communication between technical and business teams.
  • Escalation processes.
  • Roles and responsibilities.
  • Third-party involvement.
  • Incident response plans.
  • Business continuity arrangements.

Perhaps most importantly, they expose assumptions before attackers do.


Detection Matters

Towards the end of our story, the attacker quietly collected valuable information and disappeared.

No dramatic ransomware.

No flashing warning messages.

Just a successful compromise from a plan B.

That raises an important question.

Would your organisation have known the attacker was there?

Would your security controls detect:

  • An impossible travel login?
  • A successful sign-in from an unusual location?
  • A suspicious mailbox forwarding rule?
  • A user suddenly downloading unusually large amounts of data?
  • Behaviour inconsistent with that user’s normal activity?

These are exactly the types of signals security monitoring and a Security Operations Centre (SOC) are designed to identify, giving you round the clock security defences.


The Real Lesson

The cat made people laugh.

The story kept people engaged.

But the real lesson was that cyber security is about people as much as technology.

Good tabletop exercises don’t just test firewalls or endpoint protection.

They test communication.

Decision making.

Leadership.

Assumptions.

And ultimately, resilience.

If a fictional Finance Director, an overconfident attacker and one extremely well-protected cat can spark meaningful conversations about cyber security, imagine what a structured tabletop exercise could do for your own organisation.

Hopefully your next exercise doesn’t involve a cat.

But if it does, we’d recommend keeping the GPS tracker.


What’s Next

Watch this space for our next one whilst we scratch our brains for a great starter scenario.

Share This Post

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Do You Want To Boost Your Business?

drop us a line and keep in touch