Game Cards
Attack Example using Spoofing Attack
Cyber Criminals – “Attacker gathered information from corporate website and used this to create emails to target employees in a phishing attack”.
Cyber Criminals – “Attacker gathered information from corporate website and used this to create emails to target employees in a spear phishing attack. The employees click on the link and installs a key logger enabling the attacker to gather user names and passwords”
Games Master role to explain perfect attack has: Threat Actor (Cyber Criminals); How they gathered information; Target of attack; Method in attack; and motive (Gather usernames and passwords).
Defence Example
Three different examples of defence to spear phishing attack.
Card 3 Secure Configuration: “Configure the Email server to verify the IP Address of the incoming email domain and put in spam folder where does not match”.
Card 7 Security Training: “Strategy to detect spear phishing emails by training staff how to spot spoofed emails and implement a intranet based training solution for staff to test their skills”
Card 3 Secure Configuration: “Install a behavioural based end point detection system and if user does click on spear phishing email the system will automatically prevent any data loss or malware being installed”
Information Example
The Games Master can select this card to helps players understand that poor configuration choices create vulnerabilities even when good technology is in place.
“Weak secure configuration means systems are set up in a way that makes them easier to attack — for example, default passwords, unnecessary services enabled, outdated settings, or misconfigured permissions. Even strong security tools fail if the configuration behind them is weak.”
Alternative Games Master can use this information card to act as the attacker.