Photo by Carlos Cram on Unsplash

Cybersecurity is Like Playing Dungeons & Dragons

How our security operations mirror the fantasy tabletop role-playing game

Seth Goldhammer
4 min readSep 8, 2020

--

In our current security operations’ workflows, qualifying threats, understanding the threat’s scope, and determining root cause closely resemble how players interact with their Dungeon Master (DM). With each alert, analysts must determine which ‘paths’ to investigate. There isn’t sufficient time to explore each and everything path. This means that if an analyst doesn’t ask the right question or interpret the response correctly, they find themselves going down the wrong path all too easily.

Take this example from a group playing Dungeons and Dragons
(based on http://hackslashmaster.blogspot.com/2012/05/on-missed-treasure.html):

http://justinyun.blogspot.com/

If this story seems familiar it’s because it happens far too often in security. If we retell the story as a threat investigation, it goes something like this:

https://www.deviantart.com/aaronmiller/art/Map-Check-498444550

Similar to D&D, there are multiple paths for the security analysts. However, the security analyst does not have the luxury of time. Its not always intuitive which path to investigate, even when guided by prior experiences and playbooks. While playing D&D and exploring multiple paths is enjoyable, it’s highly stressful to rely on guesswork to perform security investigations. There are too many paths to investigate with dead ends that reach inconclusive results.

It is time technology began to work more intelligently to guide us down the right path. Note, this isn’t a playbook for how to investigate, but a mechanism to tell us what to investigate. This looks like technology evaluating investigation paths on the security analysts’ behalf to determine which provides the clearest evidence that qualifies the threat indicator and shines details on its root cause and the threat’s scope.

--

--

Seth Goldhammer

20+ years in cybersecurity bringing products to market at TippingPoint, HP, and LogRhythm. Currently VP of Marketing @SpyderbatInc.