Skip to main content

About segfaulter

Segfaulter is a security and compliance workshop game. It teaches people who do not work in security what a company actually buys when it buys security, and what happens when it does not buy enough.

Most people outside the field have never seen a security budget. They have heard the words — backups, encryption, penetration test — without ever having to choose between them with real money. This game makes them choose while the company they are running gets bigger and the decisions get harder.

Game masters need an account, and registrations are reviewed by hand before a first game can be created. Register as a game master.

What the game is

You play a fictional healthcare software company called Alongside Health. It starts as two founders with a hundred thousand dollars in the bank. By the end it has fifty people and is picking the platform the next three years will be built on.

The room splits into teams of three or more. Each team gets a budget and a board of things it can buy. Every control is a real thing a real company pays for, with a real price and a plain note about where the money goes. A team cannot buy everything: the budget is roughly two and a half times too small, which is the same problem every company has.

The screen at the front of the room during a round: a countdown reading nine minutes and fifty-one seconds, the total the room has spent, and a row for each of four teams showing how much of its budget it has committed and how many controls it has bought.
The screen at the front of the room while a round is running. Each bar is a team's budget. The bars carry no numbers on purpose — the room can see who is moving without being able to work out exactly what anyone bought.

How a session runs

A game master runs the session from a laptop. Everyone else plays on their phone.

Joining. The game master puts a four-character pin on the screen — something like 37-SZ. Players go to segfaulter.com, type the pin, pick a team, and choose a name. There are no accounts and no passwords.

A pin rather than a QR code, and for a reason the room usually spots before we explain it. Plenty of people have been taught not to scan a code off a screen they do not control, and they are right. Asking a room to do it anyway, in a game about security, would teach the wrong lesson on the way in. The pin is also easier to fix when someone mistypes it: capitals do not matter, the dash does not matter, and the letters I, L and O are read as the digits they look like.

The QR code is still there for anyone who wants it, and a player already in the game can show theirs to somebody sitting next to them.

Choosing a CISO. A CISO is a Chief Information Security Officer, and at most companies the CISO controls the security spend. Each team picks one person to hold the budget. Only that person can spend, so the team has to talk. The argument is the point of the exercise. Everyone else can write on the back of a card — a line saying why this one matters — which their own team sees and no other team does. That is useful for anything you would rather the next table did not overhear, and it leaves a record of what the team decided and why.

Round 1: Bootstrapping

In Round 1, there are two founders, a hundred thousand dollars, and five thousand of it for security. A customer wants to buy and cannot, because Alongside has been asked to sign a Business Associate Agreement and has nothing to base one on.

The round opens and a clock starts. The team reads the board and decides.

One card from the board, with three labels pointing at it. An arrow to the sentence describing what the control does is labelled "What it does". An arrow to a line beginning Cost — two weeks of somebody senior, and an afternoon a quarter after that — is labelled "What it costs that is not money". An arrow to the figure of fifteen hundred dollars is labelled "Price". The card also carries a code, a name, a badge naming the kind of risk it bears on, three small chips and a Buy button.
Every card says the same three things in the same places, so a team reading its fourth card is no longer reading, only comparing.
A phone showing the first cards on the board, one after another down the screen, with the budget left pinned at the top.
The board is a column of these. Some controls are paid in cash and some in your own people's time, and both come out of the same budget — which is why the card says which.

Then one thing happens. The game master closes the round, and the screen at the front tells the room what it was. Every team faced the same incident. Each one gets a letter and one sentence saying why.

The screen at the front of the room after the first round. A headline, the story beneath it, then a line reading what it needed, then each of four teams with a letter grade from A to D and one sentence explaining it.
There is no F. A team that is out of it stops playing, and the rounds after this one need everybody still in the game. C and D are a real distinction: C was ready for something, D was ready for nothing.

Round 2: Series A

In Round 2, Alongside has raised money and hired. There are fifteen people, a hundred thousand dollars for security, and a much longer board. The question from buyers has changed from “will you sign a BAA?” to “may we see your SOC 2?”

This round does not wait. Incidents arrive while the round is still running. There are three of them, minutes apart, graded in front of the room as they land. A team is judged on what it was holding at that minute.

The screen during the second round. A bordered panel carries the incident, what it needed, and every team's grade with its reason. Below the panel the clock is still counting down and every team's budget bar is still moving.
The board stays open underneath. You cannot buy the control after the fire has started, which is the thing this round exists to teach.

What you bought in the first round still counts. A control bought early can decide a later incident.

The end of the second round: a table with one row per incident and one column per team, each cell holding a letter grade.
At the end of the round, all three at once. Read down a column for how a team did; read across a row for how the room handled one incident.

Round 3: Go to Market

In Round 3, Alongside has fifty people. In this round, the CISO buys nothing; the business has to make a decision.

Alongside needs a clinical records system underneath it and will not build one. There are five possible partners, one decision, and it is not reversible. The team reads five cards and the CISO commits to one.

One partner card, with three labels pointing at it. An arrow to the code and name at the top — P-01, Fernwood, the one you build on — is labelled "The partner". An arrow to the paragraph below it is labelled "What it is, in a sentence". An arrow to the rows beneath that, each a coloured pill and a short answer, is labelled "The same four questions, in the same order": headless and API, identity, auditing, isolation, and here a fifth row for support.
The four labelled rows are on every partner card, in this order, and a card may add up to two of its own after them. A row is never left out: not publicly documented is an answer, and telling it apart from a good answer is most of the skill.
A phone showing the partner cards one after another down the screen.
The first row is the one the deal depends on. A card may say a thing is undocumented — not knowing is an answer, and telling it apart from a good answer is most of the skill.

The board at the front shows only who has decided and who has not. It never says which partner anyone picked until the round is locked.

The screen at the front of the room during the third round, showing four teams, three marked Chosen and one marked Still deciding.
No prices, no bars, and nobody's answer. What a room needs to see here is how many tables are still arguing.

Then the grades, from the card each team chose rather than from anything it bought.

The screen after the third round: a headline, a short narration, and each of four teams with a letter grade and one sentence naming what its choice answered and what it gave up.
Nothing has gone wrong and nobody has been breached. There is only a decision, already made, that the next three years sit on top of.

What it teaches

You cannot buy everything, so the discussion is the work. Every round costs more than the budget covers, and the team has to say out loud what it is prepared to be wrong about.

What you bought before still counts. Nothing resets between rounds. The cheap thing bought in the first ten minutes is the thing that decides an incident forty minutes later.

Timing is a control. In the second round the incidents land while the money is still moving, and a purchase thirty seconds late is a purchase that did not happen.

Not knowing is a finding. By the third round the question is no longer what to buy but who to trust, and half the answers on the cards are “we do not publish that.”

Who it is for

Anyone at a company who is affected by security spending and has never had a say in it: engineers, product managers, finance, operations, founders, and boards.

It assumes no security background. Nothing in it requires you to know what a firewall is, and the cards explain themselves.

It works best with twelve to twenty-four people in three to six teams, and it takes about an hour.

Running one for your team

Segfaulter is still being built and is not yet open to the public. If you want to run a session, or you want to watch one first, get in touch.

Game masters sign in below. Players do not need an account — just the pin on the screen at the front of the room.

Sign in to run a game