September 13, 2026
From Nilfgaard to Network Defence (Part 1): The Gwent-Inspired Blueprint for an InfoSec-based…
A common experience that everyone who has worked in a corporate setting goes through is the inevitable message of a cybersecurity awareness…

By Sabari Girish Srinivasan
5 min read
A common experience that everyone who has worked in a corporate setting goes through is the inevitable message of a cybersecurity awareness campaign slide deck that needs to be completed by EOD. How many of us can genuinely raise our hands and say, "Yes, this bit of training was crucial in helping me understand the threats in my work environment, and I paid attention to it"?
If we're being honest, not many of us can say that we found the training valuable. We'd often leave the videos running on the second monitor or in the background while we toil away on our everyday duties, because we know that these videos would be followed by an insultingly easy quiz where every employee knows to pick the option that is the least/most paranoid depending on the type of question. As a result of this, a couple of weeks later, someone inadvertently clicks on a link that says the company has given them a $300 Amazon voucher for their exemplary service to the organisation.
When I started researching interesting topics for my MSc Dissertation, I was looking for something related to Cyber Threat Intelligence and pedagogical methods and observed a fundamental flaw in traditional forms of cyber awareness trainings. They treat security as a checklist of rules to memorise, rather than a living, adversarial system that upgrades and adapts itself quickly. In my previous piece, I explored how the chaotic structure of a Dungeons & Dragons game night forces engineers to think like a Dungeon Master, having to anticipate the chaos and plan so many contingencies that would make Batman shed a tear in pride.
But tabletop RPGs are narrative-focused, slow, and hard to standardise in an efficient training session that does not sacrifice quality and, at the same time, does not need the players to spend an entire week carrying the story forward. What I needed wasn't an open-ended narrative. I needed an idea that was tight, had the opportunity to abstract difficult concepts, and struck the right chord between entertainment and awareness.
Around the same time, I looked at my desktop and booted the first game I saw — The Witcher 3: Wild Hunt. My mind immediately went towards the disgustingly addictive card-based minigame named Gwent. Out of the 200 odd hours I've got on my Steam profile, at least 30 of them would have been spent on Gwent. This game was not entirely based on luck. Luck was a factor, but your victory depends more on reading your opponent's tell, baiting out their higher-value cards, holding onto your own higher-value cards, managing finite resources within rounds and living with the exasperating consequences of having spent a card you should have held onto.
That is when it clicked that threat intelligence and adversarial thinking could be taught through an asymmetric, medieval-themed card duel. This spark turned into Wards & Firewalls.
From my research, the critical flaw I observed in a good amount of cybersecurity awareness training programmes was that they forced everyone to think exclusively like a defender.
While they are sound pieces of operational security, a checklist like "Rotate your passwords every X number of days, don't plug in unfamiliar USB drives, verify email domain names" fails to help the employee understand the operational reality of the person on the other side of the wire. Owing to this, security takes a reactive approach rather than a proactive approach. In a cyber incident, every second counts. Every second a threat actor is present in a network, information is siphoned, files are potentially encrypted and devices get infected. This gaping hole helped me introduce an adversarial thinking aspect in Wards & Firewalls.
My first, non-negotiable rule while designing the game was asymmetry. I was hell-bent over the idea that it had to be a two-player duel between the Castle Guards (Blue team) and the Thieves' Guild (Red team) because the playing field in real-world security is agonisingly uneven. A network security engineer must ensure that the firewall rules are up to date, unwanted ports have been blocked, C2 domains have been blacklisted from reaching employee inboxes and cloud services have been configured securely across thousands of endpoints 24x7x365. All an attacker needs is for an intern to click a big green download button that would 'provide the drivers to the device'.
By forcing the players to think from the Thieves' Guild's perspective, the game strips away complacent behaviour from the defending side. The adversary is not thinking about rules but about how to exploit them. They are focused on the ROI of their attacks and the potential damage they can cause to the Castle Guards. Questions like 'How do I force the Guards to spend their finite resources on upgrade X before I use card Y to siphon 100 Gold from their treasure, forcing them into bankruptcy?' start to swarm in the players' minds.
Wards & Firewalls was designed around semi-open mechanics similar to Gwent. When players track what cards the opponent has drawn, they start to overthink and overplay their hands, eventually falling into unwanted traps. This psychological pressure strongly mirrors real-life scenarios when security engineers must handle a plethora of threats and vulnerabilities with a very limited budget and fortify the network based on their research, anticipating the TTPs and attacks from certain groups.
A major hurdle educational games face is efficiently mapping the abstracted and gamified concepts to realistic behaviour. If a player draws a card that reads 'Implement RFC 2827 Network Ingress Filtering', they would immediately lose whatever semblance of interest they had in the game, and the gamification process fails, rendering the idea to a remodelled version of the same recycled PowerPoint presentation.
To make the concepts intuitive, I had to ensure that the cards designed in the abstracted form had to function as a natural mental model that could subconsciously map real-world defence methodologies and attacks to vivid fantasy medieval concepts.
The Red team deck was engineering around mimicking real-life spray-and-pray techniques to persistent exploitation. Mass phishing was attributed to a Snake Oil Salesman who meets dozens of potential customers/victims each day and sells the 'miracle' cures only to steal their belongings once they are distracted or dazed. On the other hand, an Alehouse Swindler talks to you up at the local tavern, becomes your close 'friend' in a span of a few rounds, and once your guard is down, he swoops in to steal your belongings, mirroring how a targeted spear phishing campaign works. Various other cards were introduced, such as Loosened Castle Walls for a network backdoor (which is self-explanatory), Clatter of Brats for DDoS (nothing can infuriate a guard more than a dozen kids screaming at them and throwing rocks at them) and so on.
A similar concept was applied to the Blue team, mirroring the defence methodologies applied by the SOC and network defence team to keep the organisation safe. The Guild of Watchful Scribes taught the locals how to spot charlatans who befriend you and try to sell you nonsense, acting like the modern-day security awareness training. Other concepts such as The Hidden Borough for Offshore Data Backups and the Walled Districts for Network Segmentation (self-explanatory) were also introduced in such a way that the players could map these abstracted concepts to their real-life counterparts, and having played a few rounds, they could make educated guesses on which defence methodology would work against which cyber attack.
Having a strong, understandable translation layer gave the game its soul, and it was a wonderful starting point. Real-world cybersecurity is far from clean and simple. Security budgets fluctuate unpredictably based on the overall market, the performance of the organisation and, in many cases, political decisions by the government. Defences decay over time if left unmaintained and become obsolete when not trained against updated threats. Worst of all, human vigilance inevitably fades until the next alarm rings.
To turn Wards & Firewalls into an authentic simulation, I had to build these brutal enterprise realities directly into the rulebook and add a pedagogical mechanic that ensured players couldn't just win on lucky card draws. The concept of the game would be lost if luck were the decisive factor of the game.
In the next part, I'll break down the core economic engine of the game, the decay rule applied to the upgrades, and the empirical results from testing the game on non-technical users during my MSc dissertation, where the players' security knowledge jumped by a staggering 92.5%.