Serious game · Application Security · DevSecOps

Every decision has consequences.

Codes & Consequences is a board game that turns secure software development into a practical experience of strategy, risk and collaboration.

Sessions, workshops and licensing are arranged directly. Ask about availability.

The Game

Your team knows the theory. Let them face the consequences.

C&C simulates the development of a digital product inside a company. Teams have to ship a system while balancing delivery speed, security investment, business requirements, architecture, quality, cost and risk.

Save on security and you may ship faster — and inherit vulnerabilities, incidents and lost trust. Over-invest in controls without business context and you may protect a product that arrives too late to matter.

There is no perfect line. That is the point.

Security does not happen in isolation. It is decided in architecture, in requirements, in deadlines, in budgets and in the conversations a team either has or avoids.

Your Mission

Build a hospital management system. Don't break the hospital.

Players take responsibility for a digital product in healthcare — web and mobile applications, APIs, patient data, authentication, integrations, administrative features and the infrastructure underneath.

The setting raises the stakes. Consequences do not land on a scoreboard; they land on people.

  • Patient privacy
  • Data integrity
  • Service availability
  • Hospital operations
  • User trust
  • Business continuity

You are not collecting points. You are building a system that has to work, ship, and stay safe — without running the company into the ground or losing the client along the way.

Decisions

Security is easy when time and money are unlimited. Here, they are not.

  • Release now, or fix the vulnerability?

  • Invest in security, or build another feature?

  • Accept the risk, or delay the product?

  • Protect the architecture, or reduce costs?

  • Inform the client, or contain the incident quietly?

  • What would your team sacrifice to meet the deadline?

Every answer costs something. The table finds out how much.

Inside the Game

One product. Limited resources. Countless consequences.

Requirement cards

Functional, non-functional, security, architectural, regulatory and operational demands — all competing for the same budget.

Threat cards

Credential theft, data leaks, broken authentication, exposed APIs, vulnerable dependencies, supply chain attacks, insider threat, ransomware.

Surprise cards

Budget cuts, shifting priorities, a key person leaving, an audit, a vendor failure, a production incident, a critical vulnerability found late.

Security investments

Threat modeling, code review, SAST, DAST, SCA, secrets management, logging, hardening, API security, training, Security Champions, incident response.

The board, the rules and the full decks are revealed at the table. Ask about a session →

What Teams Learn

Learn security by making decisions.

Security requires prioritization

Not every risk can be treated now. Teams practice choosing where limited resources go, and defending that choice.

Technical decisions are business decisions

Architecture, shortcuts and technical debt reappear as budget, reputation and customer trust.

Risk stops being abstract

Participants argue about accepting, treating and transferring risk — then live with what they chose.

Timing matters

A control applied late costs more than the same control applied at the right moment. The game makes that visible.

Communication prevents consequences

Security, engineering, product and leadership have to actually talk. Most damage is predictable in hindsight.

Judgement under uncertainty

Real decisions rarely wait for complete information. Neither do these.

Who Is It For

Built for the people who have to live with the decision.

Participants do not need to be security experts. Mixed tables work best — that is where the argument is.

Engineering

Developers, software architects, tech leads, engineering managers

Security

Application Security, DevSecOps, Security Champions, risk analysts

Product & Leadership

Product Owners, delivery leads, technology leadership

Education & Community

Students, professors, universities, conferences, technology communities

Use Cases

Turn AppSec into an experience.

Corporate workshops

A facilitated session inside your company: context, rules, a game played together, and a debrief that connects the table back to your real backlog.

Security Champions programs

Give champions a shared experience for reasoning about risk with the teams they support.

Training

Fits Secure Software Development, AppSec, DevSecOps, Threat Modeling, risk management and security culture programs.

Universities

Supports software engineering, information security, project management, architecture and risk management courses.

Conferences & events

Run it as a hands-on workshop, a village activity, a competition or a community session alongside the main agenda.

Corporate licensing

Licensing and subscription models for internal programs and recurring training. Talk to us about licensing.

Why C&C

Your shortcuts have consequences. So does your training.

  • Built by an AppSec practitioner

    Grounded in real work with application security, software engineering, DevSecOps and corporate programs.

  • Security inside business context

    Participants balance security against deadline, budget, quality and customer satisfaction — the way it actually happens.

  • Consequences you can see

    Every choice changes the state of the game. Nothing is theoretical for long.

  • Collaborative by design

    The game rewards debate, negotiation and teams that talk to each other.

  • Works at any maturity level

    Usable with students, experienced developers, security professionals and leadership.

  • Adaptable

    Facilitation adjusts to the audience, the time available, the objectives and the context of the event or company.

  • Memorable

    Participants experience the problem instead of listening to a description of it.

  • Risk-driven discussion

    Decisions are argued on impact, likelihood, context and the resources actually available.

About the Creator

Cássio Batista Pereira

Application Security specialist, professor, writer, podcaster and speaker, with around two decades in technology and security — and a background in software development and architecture before that.

He works across Application Security, Secure Software Development, DevSecOps, Threat Modeling, Security Champions programs, vulnerability management, and security education and awareness. He builds training, initiatives and products that pull security, engineering and business closer together.

C&C comes out of that practice. The game is built on decisions he has watched teams get right — and get wrong.

FAQ

Questions before the first move.

Is Codes & Consequences a technical game?

It covers technical and strategic decisions, but participants do not need to be security experts. The discussion is the content.

Who can play?

Developers, security professionals, architects, Product Owners, managers, students and other technology professionals. Mixed groups tend to get the most out of it.

How many people can participate?

The format varies according to the workshop, the event and the game configuration used. Contact us for details.

How long does a session take?

Duration depends on the number of participants, the depth of the discussion and the format selected. Contact us for details.

Can the game be used in corporate training?

Yes. It suits workshops, internal security programs, Security Champions initiatives and secure development training.

Can it be used at events?

Yes. It can run as a workshop, a competition, a village activity or an interactive community session.

Is the game available for licensing?

Licensing and subscription models may be offered to companies and partners. Talk to us about licensing.

Is the game customizable?

Sessions and facilitation may be adapted to different audiences and business contexts. Ask us what you have in mind.

Get in touch

Ready to face the consequences?

Bring C&C to your team, your program or your event. Sessions, workshops and licensing are arranged directly with the creator.

[email protected]

You make the decisions. The game delivers the consequences.