
Backdoors & Breaches
A tabletop exercise to train a team to investigate, prioritise, and contain a cyber incident.
Backdoors & Breaches is a security incident response card game created by Black Hills Information Security. It is played as a tabletop exercise, either in-person or remotely, with an incident master and a team of defenders. The scenario consists of four secretly drawn attack cards: initial compromise, pivot and escalation, command and control with exfiltration, persistence. The defenders use procedure cards and a 20-sided die to attempt to reveal the four cards in 10 rounds while managing unforeseen events.
Walkthrough
- 1
Set the framework and roles
5 minThe facilitator presents the intention: "We are going to simulate an incident response, not test individuals. Your goal is to reason together under pressure." They designate an incident master, who will guide the scenario and keep the information hidden. The other participants form the team of defenders, ideally 3 to 8 people in total. Remind them of the targeted duration, between 30 and 60 minutes, and the objective: to reveal the four attack cards in 10 rounds.
Tip — Frame the right to make mistakes very early: otherwise, players will look for the 'correct answer' instead of verbalising their hypotheses, which greatly reduces the educational interest.
- 2
Prepare the attack scenario
5 minThe incident master secretly draws four attack cards from the official game. They represent, in the logical order of the scenario, the initial compromise, pivot and escalation, command and control with exfiltration, and then persistence. They do not show these to the defenders and keep them as the reference truth. They also prepare the unforeseen event cards, which can complicate the game according to the rules of the official material used.
Tip — Before starting, the incident master should read their four cards and imagine a coherent narrative in one sentence; this will make their responses smoother without revealing free hints.
- 3
Present the defenders' means
7 minThe facilitator provides the procedure cards from the official game, such as log analysis, isolation, or workstation analysis. They explain: "In each round, you choose a procedure, justify why, and then roll a 20-sided die to see if it succeeds." Some procedures are called established and grant a bonus according to the indications on the official card. If a successful procedure allows for the detection of an attack card, the incident master reveals that card.
Tip — Have the players read the cards aloud themselves: this prevents the facilitator from becoming the sole expert and encourages the team to take ownership of their options.
- 4
Launch the incident and formulate initial hypotheses
5 minThe incident master gives a simple starting alert, compatible with the drawn cards, without revealing the four elements of the scenario. They might say: "You receive a troubling signal: something indicates that an incident may be underway. What do you do first?" The defenders discuss their hypotheses: possible initial entry, affected assets, immediate risks, exposed data. The facilitator ensures that the first decision is a playable procedure, not an unlimited investigation.
Tip — Deliberately limit the initial information: learning comes from the gradual construction of evidence, not from a brief that already contains the solution.
- 5
Play the investigation rounds
15 à 35 minIn each round, the team chooses a single procedure and explains their intention: "We want to confirm or refute this hypothesis." They then roll a 20-sided die; the result, modified if necessary by the bonuses from the established procedures indicated on the official cards, determines success. If the successful procedure corresponds to a detectable attack card, the incident master reveals that card. The round is counted, and the team must reveal the four cards before the end of the tenth round.
Tip — Keep a visible board with rounds 1 to 10, attempted procedures, successes, and revealed cards; it supports collective memory and speeds up the debrief.
- 6
Introduce unforeseen events
Integrated into the roundsThe incident master uses the unforeseen event cards from the official game to complicate the situation at the moment specified by the material or chosen within the framework of the facilitation. They announce the event clearly, then apply its effects without altering its meaning. The defenders must integrate this constraint into their next decision, just like in a real incident where the context evolves. The facilitator observes how the team balances investigation, containment, and crisis management.
Tip — Do not play the events as punishments: relate them to the narrative, then allow a minute of silence for the team to reassess their priorities before voting on an action.
- 7
Conclude the game and reveal the scenario
5 minThe game ends when the four attack cards are revealed or when the 10 rounds are up. The incident master then shows the remaining cards if there are any and reconstructs the complete scenario: initial compromise, pivot and escalation, command and control with exfiltration, persistence. The team compares their reasoning with the hidden reality. The facilitator highlights good hypotheses, useful decisions, and missed signals, without turning the closure into a lecture.
Tip — Ask the defenders to first recount their version of the incident before revealing yours; the gap between perceived narrative and actual scenario is often the best educational material.
- 8
Debrief and transfer to real practices
10 à 15 minThe facilitator opens the debrief with the game traces: rounds consumed, procedures chosen, cards revealed, events experienced. They ask: "What does this game say about our way of responding to an incident?" Participants identify what helped: established procedures, information sharing, explicit hypotheses, prioritisation. Conclude with one or two concrete commitments to test within the organisation, rather than a long list of good intentions.
Tip — Encourage distinguishing between 'technical' and 'coordination' learnings: in this game, both mix, but the resulting action plans do not fall under the same responsibilities.
Variants
- Short variant: play with a strict timer for each decision round to fit within 30 minutes. Keep the same rules, the same objective of revealing four cards, and the limit of 10 rounds.
- Learning variant: after each revealed attack card, take a two-minute pause to name the clues that led to the discovery. This version slows the pace but reinforces understanding of the reasoning.
- Observers variant: add one or two people outside the game who only note the decision-making modes, formulated hypotheses, and blind spots. They present their observations during the debrief, without intervening during the rounds.
- Remote variant: use the online version or an official digital support, with a voice channel and a shared board to track the 10 rounds. The incident master keeps the cards hidden, and the defenders announce their procedures aloud before each die roll.
Debrief guide
- At what point did we start reasoning from evidence rather than intuition?
- Which procedures did we choose too early, too late, or not at all?
- How did the bonuses related to established procedures influence our strategy?
- What did we learn about our ability to prioritise when an unforeseen event occurs?
- What information should we have shared more clearly within the team?
- If this incident were to happen for real tomorrow, what would be our first concrete improvement?