BLAST·RADIUS
Cooperative tabletop incident response

BLAST RADIUS

You are a security team. Someone got in a while ago and is still here. The uncomfortable part is that you already made the decisions that determine how this goes.

Most tabletop exercises start when the alert fires. This one starts a budget cycle earlier — you draft your control posture first, then live with it.

3–7 players
45–75 minutes
No preparation
Read the rules Design document GitHub

The idea

When a control reveals a technique in this game, it is not because a designer decided it should. It is because MITRE's Center for Threat-Informed Defense maps that NIST 800-53 control to that ATT&CK technique. The game cannot teach you something the frameworks disagree with.

The corollary is the interesting part. When a check succeeds and reveals nothing, it is because the control you bought does not cover that stage of the attack — and that gap is real too. Teams normally discover it at 3am.

Status: rules complete, decks regenerating. The game was originally built on the Secure Controls Framework and that build was withdrawn — the SCF's licence permits reproducing its control text but not redistributing its ATT&CK mapping, which is the mechanic the whole game rests on. The control layer has moved to NIST SP 800-53 with MITRE's Apache-licensed mappings. The reasoning is written up in full on the attribution page.

Posture draft

Spend a fixed budget on controls before the incident starts. Broad controls cost more and detect weakly; narrow ones cost little and detect sharply.

Derived difficulty

A technique's stealth rating comes from how many controls map to it. Nothing is hand-tuned for drama.

Dwell, not turns

You do not run out of time. Impact accumulates while the chain stays hidden. What kills you is being slow, not being wrong.

CAF debrief

Optional scoring against NCSC CAF v4.0 objectives, so a UK regulated organisation leaves with a gap list rather than an anecdote.

The decks

DeckCardsSource
Technique cardspendingMITRE ATT&CK v19.1
Control cardspendingNIST SP 800-53 Rev 5
Complication cards24Original
Objective cards8Original

Plus a 103-card MITRE ATLAS expansion for incidents involving AI systems.

Built on

SourceLicenceUsed for
MITRE ATT&CK v19.1MITRE terms of useTechnique cards
MITRE ATLASPublic releaseAI expansion
NIST SP 800-53 Rev 5Public domainControl cards
CTID 800-53 → ATT&CK mappingsApache 2.0The detection mechanic
NCSC CAF v4.0Open Government Licence v3.0Debrief scoring

Every source permits redistribution. Full notices.