Requirement cards
Functional, non-functional, security, architectural, regulatory and operational demands — all competing for the same budget.
Serious game · Application Security · DevSecOps
Codes & Consequences is a board game that turns secure software development into a practical experience of strategy, risk and collaboration.
Sessions, workshops and licensing are arranged directly. Ask about availability.
The Game
C&C simulates the development of a digital product inside a company. Teams have to ship a system while balancing delivery speed, security investment, business requirements, architecture, quality, cost and risk.
Save on security and you may ship faster — and inherit vulnerabilities, incidents and lost trust. Over-invest in controls without business context and you may protect a product that arrives too late to matter.
There is no perfect line. That is the point.
Security does not happen in isolation. It is decided in architecture, in requirements, in deadlines, in budgets and in the conversations a team either has or avoids.
Your Mission
Players take responsibility for a digital product in healthcare — web and mobile applications, APIs, patient data, authentication, integrations, administrative features and the infrastructure underneath.
The setting raises the stakes. Consequences do not land on a scoreboard; they land on people.
You are not collecting points. You are building a system that has to work, ship, and stay safe — without running the company into the ground or losing the client along the way.
Decisions
Release now, or fix the vulnerability?
Invest in security, or build another feature?
Accept the risk, or delay the product?
Protect the architecture, or reduce costs?
Inform the client, or contain the incident quietly?
What would your team sacrifice to meet the deadline?
Every answer costs something. The table finds out how much.
Inside the Game
Functional, non-functional, security, architectural, regulatory and operational demands — all competing for the same budget.
Credential theft, data leaks, broken authentication, exposed APIs, vulnerable dependencies, supply chain attacks, insider threat, ransomware.
Budget cuts, shifting priorities, a key person leaving, an audit, a vendor failure, a production incident, a critical vulnerability found late.
Threat modeling, code review, SAST, DAST, SCA, secrets management, logging, hardening, API security, training, Security Champions, incident response.
The board, the rules and the full decks are revealed at the table. Ask about a session →
What Teams Learn
Not every risk can be treated now. Teams practice choosing where limited resources go, and defending that choice.
Architecture, shortcuts and technical debt reappear as budget, reputation and customer trust.
Participants argue about accepting, treating and transferring risk — then live with what they chose.
A control applied late costs more than the same control applied at the right moment. The game makes that visible.
Security, engineering, product and leadership have to actually talk. Most damage is predictable in hindsight.
Real decisions rarely wait for complete information. Neither do these.
Who Is It For
Participants do not need to be security experts. Mixed tables work best — that is where the argument is.
Developers, software architects, tech leads, engineering managers
Application Security, DevSecOps, Security Champions, risk analysts
Product Owners, delivery leads, technology leadership
Students, professors, universities, conferences, technology communities
Use Cases
A facilitated session inside your company: context, rules, a game played together, and a debrief that connects the table back to your real backlog.
Give champions a shared experience for reasoning about risk with the teams they support.
Fits Secure Software Development, AppSec, DevSecOps, Threat Modeling, risk management and security culture programs.
Supports software engineering, information security, project management, architecture and risk management courses.
Run it as a hands-on workshop, a village activity, a competition or a community session alongside the main agenda.
Licensing and subscription models for internal programs and recurring training. Talk to us about licensing.
Why C&C
Grounded in real work with application security, software engineering, DevSecOps and corporate programs.
Participants balance security against deadline, budget, quality and customer satisfaction — the way it actually happens.
Every choice changes the state of the game. Nothing is theoretical for long.
The game rewards debate, negotiation and teams that talk to each other.
Usable with students, experienced developers, security professionals and leadership.
Facilitation adjusts to the audience, the time available, the objectives and the context of the event or company.
Participants experience the problem instead of listening to a description of it.
Decisions are argued on impact, likelihood, context and the resources actually available.
About the Creator
Application Security specialist, professor, writer, podcaster and speaker, with around two decades in technology and security — and a background in software development and architecture before that.
He works across Application Security, Secure Software Development, DevSecOps, Threat Modeling, Security Champions programs, vulnerability management, and security education and awareness. He builds training, initiatives and products that pull security, engineering and business closer together.
C&C comes out of that practice. The game is built on decisions he has watched teams get right — and get wrong.
FAQ
It covers technical and strategic decisions, but participants do not need to be security experts. The discussion is the content.
Developers, security professionals, architects, Product Owners, managers, students and other technology professionals. Mixed groups tend to get the most out of it.
The format varies according to the workshop, the event and the game configuration used. Contact us for details.
Duration depends on the number of participants, the depth of the discussion and the format selected. Contact us for details.
Yes. It suits workshops, internal security programs, Security Champions initiatives and secure development training.
Yes. It can run as a workshop, a competition, a village activity or an interactive community session.
Licensing and subscription models may be offered to companies and partners. Talk to us about licensing.
Sessions and facilitation may be adapted to different audiences and business contexts. Ask us what you have in mind.
Get in touch
Bring C&C to your team, your program or your event. Sessions, workshops and licensing are arranged directly with the creator.
You make the decisions. The game delivers the consequences.