

Spent some time looking for ideas on how to do a security training (compliance requirement) that didn’t suck. Cribbing from some reddit posts, I think I’m going to give everyone a notecard with something like “Is Bob Bobson a client here”, have them pair up, and do a little phone conversation roleplay where one person is a visher trying to trick the other into revealing the piece of information, while the other person gets practice saying “No.” Seemed like a good way to let the staff dip a toe into thinking like an attacker.




If you don’t want to do a one-shot, I still recommend keeping it short. 3-5 sessions perhaps. Just to dip a toe in and even out the kinks, and be able to feel good that you completed something. Decide if you want to commit to a big sprawling campaign after the first little demo campaign.