3–7 players · 45–75 minutes · no preparation required
You are a security team. Some time ago — you are about to find out how long — someone got in. They are still here.
The uncomfortable part is that you already made most of the decisions that determine how this goes. You chose which controls to fund. You are now going to find out what those choices bought you.
BLAST RADIUS is played with two decks drawn from real security frameworks. The techniques the adversary uses come from MITRE ATT&CK. The controls you defend with come from NIST SP 800-53. Crucially, the relationship between them is not invented for the game — when a control detects a technique, it is because MITRE's Center for Threat-Informed Defense maps that control to that technique. The game cannot teach you something the frameworks disagree with.
Optional: the ATLAS expansion, for incidents involving AI systems.
One player is the Scenario Lead. You hold the hidden information, you narrate, and you adjudicate. You are not playing against the team — you are running the incident for them. Your job is to make the outcome legible, not to win.
Everyone else is a Responder. You act as one team, by consensus. There are no individual turns and no hidden hands between you. If you cannot agree, you do not act, and the clock still runs. That is deliberate.
The Scenario Lead draws one objective card and keeps it hidden. It sets the chain length, the impact ceiling, and any special rule for this game.
The Lead then builds the attack chain: one technique card from each stage pile, in order.
| Stage | What it represents |
|---|---|
| 1 — Entry | How they got in |
| 2 — Foothold | How they stayed |
| 3 — Elevation | How they gained power and hid |
| 4 — Expansion | How they spread |
| 5 — Objective | What they came for |
Draw at random for a fair game, or choose deliberately to build a scenario that matches something your organisation actually worries about. The chain stays face down in a row where everyone can see the five empty slots.
Some objective cards skip a stage or add one. Follow the card.
Deal twelve control cards face up. This is the market.
The Responders have a budget of 14 Control Points and buy control cards from the market together. Each card shows its cost. Refill the market as cards are taken. Unspent points are lost.
You must all agree on every purchase.
Everything that follows is downstream of this step. Do not rush it. The argument about whether to spend five points on one foundational control or five points on five narrow ones is the argument your organisation has every budget cycle, compressed into ten minutes. Let it run.
Note the tension built into the deck: broad controls cost more and detect weakly; narrow controls cost little and detect sharply. A foundational control like continuous monitoring applies to hundreds of techniques at +2. A tightly scoped one might apply to four techniques at +6. Neither is the right answer.
Set the dwell counter to 0 and the impact track to 0. Unless the objective card says otherwise, the impact ceiling is 10.
The Scenario Lead narrates the opening. Establish the organisation, the business context, and the first symptom — something odd that got escalated. Do not name a technique, and do not describe anything from a hidden card directly.
Example opening: "You are a mid-sized logistics firm. Three hundred staff, two warehouses, most things in the cloud, one very old scheduling system nobody will let you turn off. This morning, finance called the service desk because a supplier says an invoice was paid to the wrong account. The service desk closed it as a finance problem. Finance called back."
Each round, the Responders take one action as a team. Then the clock advances. Repeat until someone wins.
Name one control card you hold, and one stage you are probing.
Roll d20 and add that control's Signal. Compare to the Stealth DC of the hidden technique in that stage — the Lead knows it, you do not.
If your control is listed on that technique's card, you need to meet the Stealth DC. The control was built for this.
If your control is not listed, you need to beat the Stealth DC by 5. You are looking with the wrong instrument. It is not impossible — people do trip over things — but you are working against the tool rather than with it.
You will not know in advance which case you are in. That is the whole problem.
Either way, the control goes on cooldown for two rounds and cannot be used again until then. Investigation is not free.
Natural 1: draw a complication. Natural 20: the technique is revealed regardless of mapping. The Lead must explain how it surfaced — a tip-off, a coincidence, someone being nosy on a quiet afternoon. These things do happen.
Name a revealed technique and a control you hold.
Roll d20 + Signal against that technique's Stealth DC + 2, and + 5 more if your control is not listed on it. Containment is harder than detection.
On success, the technique is contained. Lay it sideways. It no longer contributes to impact and cannot come back.
Once per game only. You take no other action this round. Instead:
This is standing up a formal incident bridge and getting the right people on it. It costs you time, which is the point.
After every action, add 1 to the dwell counter.
On rounds 4, 7, 10 and 13, the adversary advances. Add to the impact track:
A Prevent control you hold reduces the advance by 1 if it is listed on a revealed technique. Minimum 1 per advance regardless.
So at round 4 with nothing found, that is 5 impact. Find two by round 4 and it is 3 + 1 = 4. Find nothing at all and the second advance finishes you.
The maths is unforgiving in one specific way, and it is the right way: what kills you is not being wrong, it is being slow. A team that reveals steadily survives even if it never contains anything. A team that spends four rounds debating loses before it learns anything.
You win when every technique in the chain has been revealed and the stage 5 technique has been contained, before the impact track reaches its ceiling.
You lose the moment the impact track reaches the ceiling.
There is no turn limit. A team making progress is never arbitrarily cut off, and a team that is losing can see exactly why.
Do not skip this. It is fifteen minutes and it is the reason the exercise exists.
If any complication card came up, read its debrief prompt aloud and answer it honestly. Those questions are the ones that tend to sting.
If your organisation is assessed against the NCSC Cyber Assessment Framework
— NIS-regulated, CNI, or in scope for GovAssure — the debrief sheet in
data/authored/caf_debrief.json maps what just happened onto CAF's four
objectives and fourteen principles.
Each principle carries a prompt tied to something the game actually produced: how many rounds until the first reveal (C1 Security monitoring), whether anyone drafted a Recover control (B5 Resilient networks and systems), whether the team could name a supplier's contractual response time (A4 Supply chain). Score each as not achieved, partially achieved, achieved, or not exercised — that last one matters, and you should use it rather than guessing.
There is a pleasing circularity here: the GovAssure CAF profiles were built by modelling attacks against ATT&CK and identifying which indicators of good practice would mitigate them. This game runs that logic backwards, from technique to control to outcome.
This is not a CAF assessment. It produces conversation and a list of things to go and check properly. Do not put these scores in a GovAssure return.
Narrate outcomes, do not just report them. "You fail" is a dead end. "You pull the logs and there is nothing obviously wrong, which is either good news or the worst news" keeps the room in the fiction.
Ask why before you resolve. When the team nominates a control, ask what they expect to find. It takes ten seconds and it converts a die roll into reasoning. It also lets you narrate a failure that makes sense.
Let the blind-control result land. When a check succeeds but the control does not map, resist the urge to soften it. Sit with it for a moment. That silence is the lesson.
Adjust openly. If the team is drowning, say so and give them a break — a free reveal, a reduced DC. If they are coasting, bring the advances forward. Announce that you are doing it. Nobody learns anything from a Lead secretly steering the outcome.
On rules disputes: you decide, immediately, and you move on. Write it down and argue about it afterwards.
Running it for a mixed audience. With non-technical players in the room, have a technical player read the technique description aloud and translate it into one plain sentence before anyone rolls. The translation is often more valuable than the game.
Solo or pairs. Play the objective card face up and the chain face down. You are optimising your posture against a known adversary goal, which is a different and quieter exercise.
Your actual estate. Before setup, remove every control card your organisation does not have. Do not replace them. Play with what is left. This is the most uncomfortable version and by far the most useful.
Your actual budget. Run the posture draft alone, twice: once with this year's budget, once with next year's proposed number. The difference between the two postures is a slide your CFO will understand.
AI incident. Use the ATLAS expansion for the Entry and Foothold stages. Be aware that ATLAS carries no 800-53 control mapping, so those cards use authored difficulty rather than derived, and are flagged accordingly.
Technique cards reproduce content from MITRE ATT&CK v19.1 and MITRE ATLAS. Control cards derive from NIST SP 800-53 Rev 5, which is a work of the US Government and in the public domain — so card text is written to fit the card, with the control identifier printed on every card so you can look up the full wording. The control-to-technique mapping comes from MITRE's Center for Threat-Informed Defense under the Apache 2.0 licence. The optional debrief scoring sheet uses the NCSC Cyber Assessment Framework v4.0 under the Open Government Licence.
BLAST RADIUS is not affiliated with, sponsored by, or endorsed by The MITRE Corporation, MITRE Engenuity, NIST, or the NCSC.
See ATTRIBUTION.md for the full notices, including why an earlier build based on the Secure Controls Framework was withdrawn.
← Back to overview