About segfaulter
Segfaulter is a security and compliance workshop game. It teaches people who do not work in security what a company actually buys when it buys security, and what happens when it does not buy enough.
Most people outside the field have never seen a security budget. They have heard the words — backups, encryption, penetration test — without ever having to choose between them with real money. This game makes them choose while the company they are running gets bigger and the decisions get harder.
Game masters need an account, and registrations are reviewed by hand before a first game can be created. Register as a game master.
What the game is
You play a fictional healthcare software company called Alongside Health. It starts as two founders with a hundred thousand dollars in the bank. By the end it has fifty people and is picking the platform the next three years will be built on.
The room splits into teams of three or more. Each team gets a budget and a board of things it can buy. Every control is a real thing a real company pays for, with a real price and a plain note about where the money goes. A team cannot buy everything: the budget is roughly two and a half times too small, which is the same problem every company has.
How a session runs
A game master runs the session from a laptop. Everyone else plays on their phone.
Joining. The game master puts a four-character pin on the screen — something like 37-SZ. Players go to segfaulter.com, type the pin, pick a team, and choose a name. There are no accounts and no passwords.
A pin rather than a QR code, and for a reason the room usually spots before we explain it. Plenty of people have been taught not to scan a code off a screen they do not control, and they are right. Asking a room to do it anyway, in a game about security, would teach the wrong lesson on the way in. The pin is also easier to fix when someone mistypes it: capitals do not matter, the dash does not matter, and the letters I, L and O are read as the digits they look like.
The QR code is still there for anyone who wants it, and a player already in the game can show theirs to somebody sitting next to them.
Choosing a CISO. A CISO is a Chief Information Security Officer, and at most companies the CISO controls the security spend. Each team picks one person to hold the budget. Only that person can spend, so the team has to talk. The argument is the point of the exercise. Everyone else can write on the back of a card — a line saying why this one matters — which their own team sees and no other team does. That is useful for anything you would rather the next table did not overhear, and it leaves a record of what the team decided and why.
Round 1: Bootstrapping
In Round 1, there are two founders, a hundred thousand dollars, and five thousand of it for security. A customer wants to buy and cannot, because Alongside has been asked to sign a Business Associate Agreement and has nothing to base one on.
The round opens and a clock starts. The team reads the board and decides.
Then one thing happens. The game master closes the round, and the screen at the front tells the room what it was. Every team faced the same incident. Each one gets a letter and one sentence saying why.
Round 2: Series A
In Round 2, Alongside has raised money and hired. There are fifteen people, a hundred thousand dollars for security, and a much longer board. The question from buyers has changed from “will you sign a BAA?” to “may we see your SOC 2?”
This round does not wait. Incidents arrive while the round is still running. There are three of them, minutes apart, graded in front of the room as they land. A team is judged on what it was holding at that minute.
What you bought in the first round still counts. A control bought early can decide a later incident.
Round 3: Go to Market
In Round 3, Alongside has fifty people. In this round, the CISO buys nothing; the business has to make a decision.
Alongside needs a clinical records system underneath it and will not build one. There are five possible partners, one decision, and it is not reversible. The team reads five cards and the CISO commits to one.
The board at the front shows only who has decided and who has not. It never says which partner anyone picked until the round is locked.
Then the grades, from the card each team chose rather than from anything it bought.
What it teaches
You cannot buy everything, so the discussion is the work. Every round costs more than the budget covers, and the team has to say out loud what it is prepared to be wrong about.
What you bought before still counts. Nothing resets between rounds. The cheap thing bought in the first ten minutes is the thing that decides an incident forty minutes later.
Timing is a control. In the second round the incidents land while the money is still moving, and a purchase thirty seconds late is a purchase that did not happen.
Not knowing is a finding. By the third round the question is no longer what to buy but who to trust, and half the answers on the cards are “we do not publish that.”
Who it is for
Anyone at a company who is affected by security spending and has never had a say in it: engineers, product managers, finance, operations, founders, and boards.
It assumes no security background. Nothing in it requires you to know what a firewall is, and the cards explain themselves.
It works best with twelve to twenty-four people in three to six teams, and it takes about an hour.
Running one for your team
Segfaulter is still being built and is not yet open to the public. If you want to run a session, or you want to watch one first, get in touch.
Game masters sign in below. Players do not need an account — just the pin on the screen at the front of the room.