SlideShare a Scribd company logo
GAMIFICATION OF
TABLETOP EXERCISES
Playing D&D For Fun And Security
Kelly Ohlert
@gwyddia
WHAT IS A KELLY OHLERT?
• Risk Advisor at Leviathan Security Group
• Tabletop Roleplayer and Scenario Designer
• Lawyer (Nacho Lawyer) since 2005
• @gwyddia
WHAT IS THIS TALK ABOUT?
• What is a traditional tabletop exercise (TTX?)
• What is a tabletop game (TTRPG?)
• How do they compare?
• Why are TTRPGs more interesting?
• How can we use TTRPGs to improve information retention and security?
tabletop exercise [ˈteɪbəlˌtɑpˈɛksɚˌsaɪz]
(noun)
A discussion-based session where team members meet in an informal,
classroom setting to discuss their roles during an emergency and their
responses to a particular emergency situation.1
tabletop game [ˈteɪbəlˌtɑpˈɡeɪm]
(noun)
A group experience designed to get participants to solve problems by
together in an immersive setting.
1 https://www.ready.gov/exercises. Last accessed 7July 2021.
Traditional tabletop exercises
(TTX) have serious flaws.
Tabletop roleplaying games
(TTRPG) are fun.
Why are TTRPGs fun?
Why do we care?
How can you use this
information to improve your
existence?
EXERCISES ARE
KIND OF A BIG
DEAL
• Traditional exercises are designed to test people or
processes before the worst happens
• Widely used to meet compliance requirements
• Can be extremely detailed simulations
BUT THEY’RE
NOT THAT
GREAT
ACTUALLY
• Often more about checking off boxes than
exploring possibilities
• Can be stressful for the players because they
fear “failing”
• Rarely use dice
Gamification of Tabletop Exercises
TABLETOP GAMES ARE PRETTY GREAT
• Designed to entertain by making people work together to solve problems
• Encourage novel solutions and welcome failure
• Are more suspenseful than stressful
• Often use dice
Gamification of Tabletop Exercises
Almost all creativity involves purposeful play.
– Abraham Maslow
WELCOME
TO
FUZZBUTS V.
FUZZBUTTS1
• Fuzzbuts.com is an up-and-coming cat picture
aggregator site. Their Deep Purring algorithm harnesses
the ability of real cats to hate each other to allow for
excellent feline sorting.
• Security budget of yes.
• CEO who likes to go rogue.
1 Not a typo.
COMMON ISSUE#1:
NONE OF THESE
PEOPLE HAVE EVER
BEEN IN THE SAME
ROOM
SOLUTION: CHARACTER CLASSES
Billie Kottur
Class: C-suite
Abilities: Budget of Yes
Social Media
Credentials
Minotaur Security
Class: Security Team
Abilities: Eager Pentesters
License to Kill
Fuzzbutts.com
Class: Direct Competitor
Abilities: Trade Secrets
I Just Hate You So
Much!
COMMON ISSUE#2:
ONE PERSON IS
DOING ALL THE
TALKING
SOLUTION: KILL OFF THEIR CHARACTER
COMMON
ISSUE #3: EVERYONE
IS HALF ASLEEP
SOLUTION: ARIZONA BAY SCENARIO
Learning needs to have taken place
at the conclusion of a learning journey.
- Rudland, J.R., Golding, C., & Wilkinson, T.J. (2019).
• If you like this, what can you do?
• If you’re in charge of running these things, steal a
few ideas and spice it up.
• If you have to do these things, and you can, rock
the boat during the exercise.
Gamification of Tabletop Exercises
RESOURCES
• Backdoors and Breaches (BHIS)
https://www.blackhillsinfosec.com/projects/backdoorsandbreaches/
• Oh Noes! (Bruce and Robert Potter – expel)
https://info.expel.io/oh-noes
• Adam Shostack
https://adam.shostack.org/games.html
• Me
@gwyddia on Twitter
REFERENCES
• Operation CyberStorm
https://www.cisa.gov/cyber-storm-2020
• Department of Homeland Security
https://www.ready.gov/exercises
• Maslow, A. H. (1943). A theory of human motivation. Psychological Review, 50(4), 370–396.
https://doi.org/10.1037/h0054346
• Rudland, J.R., Golding, C., & Wilkinson, T.J. (2019). The stress paradox: how stress can be good for learning.
Medical Education, 54(1), 41-45. https://onlinelibrary.wiley.com/doi/full/10.1111/medu.13830
• Wallace, Jennifer. “Why It’s Good for Grownups to Go Play” The Washington Post 20 May 2017: n.
pag. Washingtonpost.com. Web. 23 June 2021 https://www.washingtonpost.com/national/health-
science/why-its-good-for-grown-ups-to-go-play/2017/05/19/99810292-fd1f-11e6-8ebe-
6e0dbe4f2bca_story.html

More Related Content

PDF
CA_Module_2.pdf
PPT
Image secret sharing using Shamir's scheme with Steganography
PPTX
mimikatz @ phdays
PPTX
Red team Engagement
PPTX
Digital Forensics
PPTX
Cryptographic protocols
PPTX
Breaking the cyber kill chain!
PDF
100 Security Operation Center Tools.pdf
CA_Module_2.pdf
Image secret sharing using Shamir's scheme with Steganography
mimikatz @ phdays
Red team Engagement
Digital Forensics
Cryptographic protocols
Breaking the cyber kill chain!
100 Security Operation Center Tools.pdf

What's hot (14)

PDF
The Game of Bug Bounty Hunting - Money, Drama, Action and Fame
PDF
Building an InfoSec RedTeam
PDF
ATT&CKing the Red/Blue Divide
PDF
Hard-Won Lessons In Responsive Email Design - SmashingConf Oxford 2014
PDF
CNIT 141: 6. Hash Functions
PDF
Understanding "Red Forest" - The 3-Tier ESAE and Alternative Ways to Protect ...
PDF
제12회 IT4U 강연회 - 악성코드 분석 잘하고 싶어요
PPT
DDOS Attack
PDF
Adversary Emulation - Red Team Village - Mayhem 2020
PPT
Secure Socket Layer (SSL)
PPTX
CompTIA Security+: Everything you need to know about the SY0-601 update
PPTX
Join the hunt: Threat hunting for proactive cyber defense.pptx
PPT
Info Security - Vulnerability Assessment
PPTX
Creating Domain Specific Languages in F#
The Game of Bug Bounty Hunting - Money, Drama, Action and Fame
Building an InfoSec RedTeam
ATT&CKing the Red/Blue Divide
Hard-Won Lessons In Responsive Email Design - SmashingConf Oxford 2014
CNIT 141: 6. Hash Functions
Understanding "Red Forest" - The 3-Tier ESAE and Alternative Ways to Protect ...
제12회 IT4U 강연회 - 악성코드 분석 잘하고 싶어요
DDOS Attack
Adversary Emulation - Red Team Village - Mayhem 2020
Secure Socket Layer (SSL)
CompTIA Security+: Everything you need to know about the SY0-601 update
Join the hunt: Threat hunting for proactive cyber defense.pptx
Info Security - Vulnerability Assessment
Creating Domain Specific Languages in F#
Ad

Similar to Gamification of Tabletop Exercises (20)

PPTX
Gadgets, Games and Gizmos for Learning: Teach on the Beach
PPT
Modelling "Effects" in Simulation and Training.
PPT
Achieving Collective Intelligence: A Thinker's Guide on Why We Need to Think ...
PDF
Gamified Education Workshop (Octalysis) in SIngapore
KEY
Bus475.Nov09.2
PDF
Learning is The Constraint
PDF
Reading, Writing, Technology and Young Learners
PDF
Crowdsourced keynote: co-creating learning
PDF
Agile Traps: Common practices that wreck teams (Lesbians Who Tech 2020)
PPT
Learning Technology
PPT
Key Competencies In E Learning
PPTX
Gamification lecture for #BR4041UL
PDF
GDC Taipei 2013: Creating International Hits from China
PPT
082409 Gov Team First Day Freedom 50m
PDF
5 Realities of 21st Century Living
PPTX
A survival guide for UX in complex environments
PDF
Designing for behaviour change
PPTX
Enterprise SEO and AI - Houston IMA Interactive Strategies 17
PDF
Launchstack Manifesto
PPTX
Red vs. Blue Why we’ve been getting it wrong for 25 years
Gadgets, Games and Gizmos for Learning: Teach on the Beach
Modelling "Effects" in Simulation and Training.
Achieving Collective Intelligence: A Thinker's Guide on Why We Need to Think ...
Gamified Education Workshop (Octalysis) in SIngapore
Bus475.Nov09.2
Learning is The Constraint
Reading, Writing, Technology and Young Learners
Crowdsourced keynote: co-creating learning
Agile Traps: Common practices that wreck teams (Lesbians Who Tech 2020)
Learning Technology
Key Competencies In E Learning
Gamification lecture for #BR4041UL
GDC Taipei 2013: Creating International Hits from China
082409 Gov Team First Day Freedom 50m
5 Realities of 21st Century Living
A survival guide for UX in complex environments
Designing for behaviour change
Enterprise SEO and AI - Houston IMA Interactive Strategies 17
Launchstack Manifesto
Red vs. Blue Why we’ve been getting it wrong for 25 years
Ad

More from Kelly Ohlert (7)

PPTX
Live Interactive Blue Team Village at DEF CON 2024 TTX Deck
PPTX
Area DC32 Tabletop Deck for BLue Team Village at DEF CON
PPTX
Multimedia SaaS Timed Game
PPTX
Crunchy malware scenario for multiple verticals
PDF
Insect invasion Rules
PPTX
Insect invasion slide deck
PPTX
Fuzzbuts TTX
Live Interactive Blue Team Village at DEF CON 2024 TTX Deck
Area DC32 Tabletop Deck for BLue Team Village at DEF CON
Multimedia SaaS Timed Game
Crunchy malware scenario for multiple verticals
Insect invasion Rules
Insect invasion slide deck
Fuzzbuts TTX

Recently uploaded (20)

PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
cuic standard and advanced reporting.pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPT
Teaching material agriculture food technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Approach and Philosophy of On baking technology
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Advanced methodologies resolving dimensionality complications for autism neur...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Review of recent advances in non-invasive hemoglobin estimation
cuic standard and advanced reporting.pdf
Machine learning based COVID-19 study performance prediction
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Teaching material agriculture food technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Unlocking AI with Model Context Protocol (MCP)
Encapsulation_ Review paper, used for researhc scholars
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Diabetes mellitus diagnosis method based random forest with bat algorithm
Approach and Philosophy of On baking technology
Per capita expenditure prediction using model stacking based on satellite ima...

Gamification of Tabletop Exercises

  • 1. GAMIFICATION OF TABLETOP EXERCISES Playing D&D For Fun And Security Kelly Ohlert @gwyddia
  • 2. WHAT IS A KELLY OHLERT? • Risk Advisor at Leviathan Security Group • Tabletop Roleplayer and Scenario Designer • Lawyer (Nacho Lawyer) since 2005 • @gwyddia
  • 3. WHAT IS THIS TALK ABOUT? • What is a traditional tabletop exercise (TTX?) • What is a tabletop game (TTRPG?) • How do they compare? • Why are TTRPGs more interesting? • How can we use TTRPGs to improve information retention and security?
  • 4. tabletop exercise [ˈteɪbəlˌtɑpˈɛksɚˌsaɪz] (noun) A discussion-based session where team members meet in an informal, classroom setting to discuss their roles during an emergency and their responses to a particular emergency situation.1 tabletop game [ˈteɪbəlˌtɑpˈɡeɪm] (noun) A group experience designed to get participants to solve problems by together in an immersive setting. 1 https://www.ready.gov/exercises. Last accessed 7July 2021.
  • 5. Traditional tabletop exercises (TTX) have serious flaws. Tabletop roleplaying games (TTRPG) are fun. Why are TTRPGs fun? Why do we care? How can you use this information to improve your existence?
  • 6. EXERCISES ARE KIND OF A BIG DEAL • Traditional exercises are designed to test people or processes before the worst happens • Widely used to meet compliance requirements • Can be extremely detailed simulations
  • 7. BUT THEY’RE NOT THAT GREAT ACTUALLY • Often more about checking off boxes than exploring possibilities • Can be stressful for the players because they fear “failing” • Rarely use dice
  • 9. TABLETOP GAMES ARE PRETTY GREAT • Designed to entertain by making people work together to solve problems • Encourage novel solutions and welcome failure • Are more suspenseful than stressful • Often use dice
  • 11. Almost all creativity involves purposeful play. – Abraham Maslow
  • 12. WELCOME TO FUZZBUTS V. FUZZBUTTS1 • Fuzzbuts.com is an up-and-coming cat picture aggregator site. Their Deep Purring algorithm harnesses the ability of real cats to hate each other to allow for excellent feline sorting. • Security budget of yes. • CEO who likes to go rogue. 1 Not a typo.
  • 13. COMMON ISSUE#1: NONE OF THESE PEOPLE HAVE EVER BEEN IN THE SAME ROOM
  • 14. SOLUTION: CHARACTER CLASSES Billie Kottur Class: C-suite Abilities: Budget of Yes Social Media Credentials Minotaur Security Class: Security Team Abilities: Eager Pentesters License to Kill Fuzzbutts.com Class: Direct Competitor Abilities: Trade Secrets I Just Hate You So Much!
  • 15. COMMON ISSUE#2: ONE PERSON IS DOING ALL THE TALKING
  • 16. SOLUTION: KILL OFF THEIR CHARACTER
  • 19. Learning needs to have taken place at the conclusion of a learning journey. - Rudland, J.R., Golding, C., & Wilkinson, T.J. (2019).
  • 20. • If you like this, what can you do? • If you’re in charge of running these things, steal a few ideas and spice it up. • If you have to do these things, and you can, rock the boat during the exercise.
  • 22. RESOURCES • Backdoors and Breaches (BHIS) https://www.blackhillsinfosec.com/projects/backdoorsandbreaches/ • Oh Noes! (Bruce and Robert Potter – expel) https://info.expel.io/oh-noes • Adam Shostack https://adam.shostack.org/games.html • Me @gwyddia on Twitter
  • 23. REFERENCES • Operation CyberStorm https://www.cisa.gov/cyber-storm-2020 • Department of Homeland Security https://www.ready.gov/exercises • Maslow, A. H. (1943). A theory of human motivation. Psychological Review, 50(4), 370–396. https://doi.org/10.1037/h0054346 • Rudland, J.R., Golding, C., & Wilkinson, T.J. (2019). The stress paradox: how stress can be good for learning. Medical Education, 54(1), 41-45. https://onlinelibrary.wiley.com/doi/full/10.1111/medu.13830 • Wallace, Jennifer. “Why It’s Good for Grownups to Go Play” The Washington Post 20 May 2017: n. pag. Washingtonpost.com. Web. 23 June 2021 https://www.washingtonpost.com/national/health- science/why-its-good-for-grown-ups-to-go-play/2017/05/19/99810292-fd1f-11e6-8ebe- 6e0dbe4f2bca_story.html