Skip to content

// How to play

Learning game

Firewall Humano

You're the last line of defense.

Close the guard shift without fraud, without leaving a compromised internal account, and without stalling the business so badly that operations grind to a halt. Each person passes a level of the curriculum — Email, Websites, Messaging and social, Artificial intelligence, Social engineering — when their own decisions demonstrated that level's competencies.

Players
1–12 people
Teams
1–4 teams
Duration
26 min (configurable from 20 to 30)
Difficulty
Medium
Devices
Computer or tablet · does not work on phones

La premisa

It's 11:40 PM at Cardal Logística S.A., and the night shift is in charge of the company's shared inbox (guardia@cardal.com.ar). Emails, internal chat messages, texts and voice notes arrive in three waves: legitimate, urgent requests — an invoice due tomorrow, a vendor with a delivery, a coworker who needs a signature — mixed in with phishing, fraud and impersonation attempts. Nobody can classify a message alone: Inbox sees the message the way any employee would, Analyst can inspect the technical layer Inbox can't see, and Context knows the organization — the org chart, who's on vacation, vendors and their registered account, company policy — and can call the registered number to confirm an unusual request.

There's no answer you can memorize: every match draws its messages from a seed, so the second attempt is never the same exam. The team keeps two meters, Security and Operations, and closes the shift in one of six endings depending on how it resolved each message. Reporting everything stalls the business (Operations drops); complying with everything opens the door (Security drops) and, in the most advanced cases, can leave an internal account compromised that keeps sending messages in the following waves — now clean across every technical control.

There are no multiple-choice questions and no screen that says "this is phishing, pick the right answer." Every message gets resolved with a real action under time pressure. A person passes a level of the curriculum when their own decisions — never a bot's — demonstrated that level's key competencies in at least one match.

Los roles

Cada puesto ve una parte distinta. Nadie puede resolverlo solo.

Inbox

Qué ve

Every message the way any employee would: the sender's visible name and address, subject, body, the link's text (not its real destination), the attachment's name (not its real type), the remaining deadline, and whether the message allows verification.

Qué solo puede hacer este puesto

Decide what to do with each message: Comply (do what it asks), Report, Request verification (hands it off to Context and extends the deadline once) or Discard. It's the only role that moves the Security and Operations meters.

Consejos
  • The sender's full address matters more than the name shown on top of the message.
  • Not everything urgent is suspicious — but not everything urgent is trustworthy either. Every wave brings at least one legitimate, urgent request.
  • If something doesn't add up but you're not sure, "Request verification" extends the deadline once and hands the decision to Context without risking the meters.
  • Letting a message expire without a decision penalizes the same as complying with a malicious one: when in doubt, decide.

Analyst

Qué ve

The same as Inbox, plus one technical layer per message that gets revealed on inspection: authentication headers (SPF/DKIM/DMARC and the sender's real address), a link's real destination, a domain's age, and an attachment's real file type.

Qué solo puede hacer este puesto

Inspect a layer — each inspection costs 20 seconds off the message's deadline — and mark the technical signal found.

Consejos
  • A link can say one thing and lead somewhere else. There's no way to know just by looking: you have to inspect it.
  • Every signal lives in a layer: headers, link destination, domain age or attachment type. You have to inspect that layer before you can mark the signal.
  • Every inspection eats into the message's deadline. Pick the most revealing layer first: headers, for email and internal chat.
  • Marking a signal that doesn't apply doesn't penalize the meters, it just gets logged as an error. When in doubt, mark it.

Context

Qué ve

The same as Inbox, plus the full organization, always visible at no cost: the org chart, who's on vacation, vendors with their registered bank account and phone number, and company policy.

Qué solo puede hacer este puesto

Call the registered number when the message allows it — it costs 30 seconds off the deadline — and mark the context signal found.

Consejos
  • If something asks for money or data over a channel that isn't the usual one, Cardal's protocol is simple: hang up and call the number already on file.
  • Share what you see as soon as something doesn't add up — who's on vacation, which vendor doesn't match — don't wait for Inbox to ask.
  • "Calling" counts as evidence even when the result confirms the request was legitimate: what matters is the habit of verifying through another channel.
  • If a message passes every technical control but isn't something that person would ask for at this hour, the signal is in your org chart, not in the inbox.

Una partida, paso a paso

  1. Lobby and briefing

    Everyone picks an avatar and a color and marks READY. At the start, the three stations are assigned in secret and the mission is told: it's Cardal Logística's night shift, and the shared inbox doesn't wait until morning.

  2. Wave 1

    3 messages arrive over 7 minutes, spaced out with some breathing room between them. This is the wave for settling into the rhythm: every message carries its own deadline, so Inbox can have more than one open at a time while Analyst and Context dig in.

  3. Wave 2

    4 messages arrive over 8 minutes. If someone complied with a message that compromised an internal account back in Wave 1, this is where its first message shows up — technically clean, passes every control — replacing one of the usual malicious slots.

  4. Wave 3

    4 more messages arrive over 8 minutes, the shift's last chance. If the internal account is still compromised, this wave brings its second message, with a more direct request.

  5. Results and debrief

    The shift closes in one of six endings — Clean shift, Rough shift, Breach contained, Vendor fraud, Account taken over, or Gridlock — depending on the final meters and whether the compromised account escalated. The Game Master's debrief shows which message each person resolved and with what evidence, plus five questions to talk through what would have changed the outcome.

Reglas de oro

Los equipos que ganan hacen casi siempre estas mismas cosas.

  • Nobody classifies a message alone. Inbox sees what any employee would see; the technical truth belongs to Analyst and the organizational truth belongs to Context.
  • Reporting everything costs as much as complying with everything. Every wave brings at least one legitimate, urgent request: stalling it has a cost too.
  • Say what you found, not your conclusion: "SPF fails and the domain is three days old" helps Inbox more than "this is phishing, don't open it."
  • A message that expires without a decision penalizes the same as complying with a malicious one. When in doubt, "Request verification" is almost always better than not deciding.
  • If something asks for money or data over a channel that isn't the usual one, Cardal's protocol is simple: hang up and call the number already on file.
  • Clean technical controls don't mean a message is trustworthy: a compromised internal account passes every control. The tell is whether it's something that person would actually ask for.
  • Marking a signal that doesn't apply doesn't penalize the meters. Inspect, mark, and move on — the real cost is time, not getting a mark wrong.

Errores típicos

Cosas que pasan en casi todas las partidas. Son hechos observables, no juicios sobre nadie.

The team reports any urgent message without checking who sent it or what it's asking for.

Reporting a legitimate request has a cost too: it drops Operations. Every wave has at least one legitimate, urgent message — reading it calmly is part of the game.

Inbox decides before Analyst or Context finish investigating.

Every message's deadline leaves room to inspect and call. If more time is needed, "Request verification" extends it once without risking the meters.

Analyst inspects the same layer twice "just to be sure."

Every inspection costs 20 seconds off the message's deadline and the result doesn't change. Inspecting the right layer once is enough.

Context stays quiet until someone asks directly.

The org chart, vacations and vendors are always visible to Context, at no cost. Share them as soon as something doesn't add up, don't wait for the question.

A message gets waved through because "every technical control came back clean."

A compromised internal account sends messages that pass SPF/DKIM/DMARC because they're real. The only tell is in the context: if it's not something that person would ask for, a clean technical read doesn't matter.

A technical signal gets marked without inspecting the layer it belongs to.

Every technical signal lives in a layer — headers, link destination, domain age, attachment type. You have to inspect that layer before you can mark it.

A message goes unresolved because the team "couldn't quite agree."

A message that expires without a decision penalizes the same as complying with a malicious one. When in doubt, requesting verification is almost always better than not deciding.

Glosario

Inbox
The role that decides. Sees every message the way any employee would, and it's the only one that moves the Security and Operations meters.
Headers (SPF/DKIM/DMARC)
The technical mechanisms that verify whether an email really came from the domain it claims to. Analyst checks these by inspecting the "Headers" layer.
Homoglyph
A character that looks like another one (for example, a Latin letter mimicking a Cyrillic one) used to build a domain almost identical to the real one. It's an advanced-level signal.
Recently registered domain
A domain that's only a few days old. Real vendors almost never switch domains overnight; Analyst checks this in the "Domain age" layer.
Vendor fraud (BEC)
Business Email Compromise: a message posing as a vendor or an executive to get a transfer authorized or a bank account changed.
Compromised account
When someone falls for a message that compromises a real internal account, that account keeps sending messages in the following waves — technically clean, because they're real. Only Context can notice something's off.
Out-of-band verification
Confirming an unusual request by calling a number already on file, instead of replying over the same channel the request arrived on. It's Context's action.
Request verification
One of Inbox's four decisions: extends the message's deadline once and hands it off to Context, without moving the meters yet.
Security meter
0 to 100. Drops when a malicious message is complied with, or when a message expires without a decision; rises when one is reported correctly.
Operations meter
0 to 100. Drops when a legitimate message is reported or discarded; rises when one is complied with on time. If it drops below 40, the shift ends in Gridlock.
Level
Beginner, Basic, Intermediate or Advanced. Each level unlocks new signals on top of the previous ones, and sets which competencies need to be demonstrated to pass it.
Focus
Email, Messaging and social, or AI and deepfakes. Changes which channels show up more often, not which levels or signals are available.

Preguntas frecuentes

Why can't Inbox see the technical address or the headers?

Because nobody classifies a message alone — that's the game's mechanic. Inbox sees exactly what any employee would see, and needs what Analyst and Context find to make a grounded decision.

What happens if I report a legitimate message just in case?

The Operations meter drops: over-reporting has a cost too, because it stalls real business requests. The "report everything as phishing" strategy loses just as much as "comply with everything."

How does someone pass a level of the curriculum?

Every level of every module defines key competencies (for example, "report a phishing email" or "verify a link's real destination"). It's passed once one person's decisions — never a bot's — demonstrated them in at least one match.

What do the focuses change?

The focus (Email, Messaging and social, or AI and deepfakes) changes which channels show up more often in the inbox. It doesn't change which levels or signals are available — that's set by the level.

Can you play solo?

Yes. In solo mode, the recommended pick is Inbox — it's where you learn the most — while bots cover Analyst and Context. You can also pick any other station: there's always a human making the final call.

What makes this different from a phishing quiz?

There are no multiple-choice questions and no "correct answer" to memorize: every match draws its messages from a seed, with real costs for getting it wrong in either direction. What gets evaluated are decisions made under time pressure, not a pick among four options.

What happens if someone on the team falls for a malicious message?

It depends on the message: some just drop Security with no further consequence, and the more serious ones — the ones that compromise an internal account — trigger a chain that keeps sending messages in the following waves. None of this ends the match: it gets talked through in the debrief, without singling anyone out.

What if there are more than three of us? Which station repeats?

The team cycles back to Inbox. And up to 4 teams can play the same scenario in parallel, each with its own seed, if you need to cover a larger group.

Jugar en solitario

In "Play solo" you take one of the three stations and bots cover the rest. The recommended pick is Inbox: it's the station that decides, and where you learn the most about the game. The match starts once you mark READY, with no Game Master.

Rookie

Investigates slowly and sometimes forgets to share what it found. Good for getting to know all three stations without pressure.

Skilled

Inspects and calls without being asked, and shares findings over the team chat. This is the recommended level for a first shift.

Expert

Prioritizes the message with the least time left and explains its reasoning as soon as it acts. Good for practicing under real time pressure.

  • A bot never makes a decision for you that you could make yourself: it proposes it over chat ("I'd report this one: the domain is three days old") and waits. If you're playing Inbox, the final call is always yours.
  • If you play Analyst or Context, the bot Inbox decides with whatever the team found before the deadline — a shift never gets stuck for lack of people.
  • Inspecting a layer isn't a decision, so bots always execute it, even solo: you won't waste time waiting on a bot to check something you can already see yourself.
  • Only your own decisions generate competency evidence. Whatever a bot does doesn't count toward your level approval — which is why it's worth taking the station you most want to practice.