INSIDER — Cybersecurity Game

A multiplayer social-deduction game on floor 4 of Northwind Dynamics. Most players work through an ordinary day; one or two are running an attack chain — tailgating a badge door, dropping a USB stick, swapping a QR poster, changing a supplier’s bank details.

INSIDER — Cybersecurity Game

INSIDER is a free browser-based cybersecurity game. A multiplayer social-deduction game on floor 4 of Northwind Dynamics. Most players work through an ordinary day; one or two are running an attack chain — tailgating a badge door, dropping a USB stick, swapping a QR poster, changing a supplier’s bank details.

Difficulty: Intermediate. Estimated play time: 10 minutes.

Everyone gets a job — Finance, IT, People, Developer, Sales, Reception or Executive — and a badge that opens only some of the fourteen rooms. Everyone also gets a rolling list of ordinary work: print the weekly report, clear the inbox, shred last quarter’s printouts, restock the kitchen. Finished work fills one company-wide workday bar; fill it before the clock runs out and the employees win, provided nobody completed an attack.

The insider gets the same work as cover, plus one or two secret attack chains of four stages each: Front Door Follow, Dropped Drive, Poster Swap, Approval Storm, Supplier Switch, Open Session. Most stages need privacy, a specific room, a stolen item, or an employee to make a mistake — so the attacker is waiting on other people, not on a cooldown.

Every attack and every legitimate request arrives as the same card with the same four answers: do it, say no, check first, or report it. Checking always tells you the truth and is never wrong, but seven of the requests are genuine company business, so blanket refusal costs the company too. Six security categories start at 100 and move with what the floor does; drop the total to 210 out of 600 and the company is compromised.

Once something has been reported and the opening 45 seconds have passed, anyone standing at the meeting-room table can call everyone in: the evidence log, a chat, then a vote. Removing the insider ends the round; removing an innocent colleague damages awareness and buys the insider time. Every match ends with the full attack timeline, who the insiders were, which stages were blocked and by whom, and lessons written against what actually happened.

Single player is not a separate mode — it creates a normal server-side room with seven bots, so it runs exactly the same code as a ten-human match. Bots see only what a player in that seat could see, and only learn whether a request was malicious by spending a check, exactly like you.

What you will learn

  • Challenge someone you do not recognise at a controlled door — it is a five-second question
  • Hand found media to IT, and never connect it, not even “just to see whose it is”
  • Check the domain before typing a password — corporate sign-in has one address
  • Treat a sign-in approval you did not trigger as an incident: deny it and report it
  • Verify unusual requests over a channel you already trust — walk over, or call a known number
  • Lock your screen, and challenge anyone sitting at a desk that is not theirs

How to play

  • Type a name and press “Play now · you and 7 bots”, or “New room” and share the code.
  • W A S D to move, Shift to run, E on anything that lights up in front of you.
  • Requests arrive as a card — press 1–4: do it, say no, check first, report it.
  • Tab is your work list, I your messages, Q the secret plan, R reports something, M the floor plan.
  • Stand at the meeting-room table and press C to call everyone in; talk, then vote.

Platforms and languages

  • Platforms: Desktop, Tablet
  • Languages: English, Română, Français, Deutsch, Nederlands, Italiano, Español, Polski, Українська

Practise with these games

Game screenshots

Start the workday on the open office floor with colleagues, tasks and company safety indicators.
Start the workday on the open office floor with colleagues, tasks and company safety indicators.
A colleague requests a peer check: help them, refuse, check first or report.
A colleague requests a peer check: help them, refuse, check first or report.
Explore the office from the first-person camera.
Explore the office from the first-person camera.
Enter the meeting room and call everyone to the table.
Enter the meeting room and call everyone to the table.
Discuss the evidence and compare colleague accounts in the security meeting.
Discuss the evidence and compare colleague accounts in the security meeting.

Related cybersecurity topics

  • Phishing Awareness Games

    Practise spotting deceptive messages, suspicious sign-in pages and payment requests with free phishing awareness games.

  • QR Phishing Awareness Games

    Learn to check QR-code destinations and recognise quishing. Practise inspecting codes and choosing when to open, ignore or report them.

  • Social Engineering Awareness Games

    Practise responding to impersonation, phone scams, suspicious requests and workplace manipulation in cybersecurity scenarios.

  • Password & Account Security Games

    Learn about unique passwords, password managers, multifactor authentication and fake login pages through interactive security games.

  • Workplace Physical Security Games

    Practise clean-desk decisions, screen locking, badge handling and visitor checks in interactive office security games.

Contact · About