Security Tower Defense — Cybersecurity Game

Attacks walk across your office floor toward the CORE DATA VAULT. Put the right protection in their way — no single one stops everything. Fifteen security controls, twelve attack types and eighteen build slots on one floor, fifteen authored rounds, then procedurally generated ones forever.

Security Tower Defense — Cybersecurity Game

Security Tower Defense is a free browser-based cybersecurity game. Attacks walk across your office floor toward the CORE DATA VAULT. Put the right protection in their way — no single one stops everything. Fifteen security controls, twelve attack types and eighteen build slots on one floor, fifteen authored rounds, then procedurally generated ones forever.

Difficulty: Intermediate. Estimated play time: 20 minutes.

One office floor, seen from above. Five routes run from the internet gateway through the DMZ, the web and mail servers, identity, the workstations and the server room to the CORE DATA VAULT, and every attack walks one of them — two of those routes start inside, at the workstations and at production, because an insider never crosses the perimeter. Eighteen build slots sit beside the routes and fifteen controls compete for them: MFA Gateway, Email Security, EDR, Patch Management, Firewall, Network Segmentation, SIEM, SOC Team, Backup System, Web Application Firewall, Security Awareness, Privileged Access, Traffic Protection, Decoys and Data Exit Checks. Each has its own cost, range, cooldown, unlock round and two upgrade tiers, and each is sold back for half of what you put into it.

Twelve attack types, each one built to break an assumption the earlier rounds let you form. Stolen passwords are real passwords, so the login page cannot tell. Malware only matters after delivery. Ransomware spreads to a second machine when the network is flat. A compromised supplier arrives trusted and turns hostile 38% of the way in. From round 11 the botnet flood adds up to +220% to the cooldown of every control it walks past, the zero-day gets nothing from patching, the fileless attack re-hides every 7 seconds unless monitoring keeps revealing it, data exfiltration walks the route backwards from the vault to the exit, and round 15 is a boss that heals 7 health a second when nothing is hitting it, cloaks, and sends a new payload ahead of it every 5.5 seconds.

Fifteen authored rounds, then generated ones forever. Modifiers start at round 8 and are guaranteed in endless: Fast movers (+30% speed), Hardened (+38% health), In numbers (55% more attackers, each weaker), Quiet approach (everything arrives hidden), Reduced visibility (every control reaches 32% less far, bigger bonus), Pay per stop (double money per kill, no round bonus) and Relentless (attackers regenerate). Endless health compounds at 1.27× a round, a boss lands every fifth endless round, and clearing a campaign round without a single leak repairs 6% company health. Your deepest round is saved between runs.

A single objective card always names the next step, pins it in the world, and offers a hint if you stall for twelve seconds; finishing one plays a short lesson card explaining why it worked. The run ends in an after-action report: a score out of 100, attacks stopped, small incidents, serious breaches, budget left, a grade for each of logins, computers, network, monitoring and recovery, and three lessons written from the board you actually built. Everything is in all nine platform languages — English, Romanian, French, German, Dutch, Italian, Spanish, Polish and Ukrainian — the company name you type is used throughout, and the game ships no binary assets — every texture is drawn onto a canvas at runtime and the audio is synthesised with the Web Audio API.

What you will learn

  • Explain defence in depth from a board you built: identity, endpoint, network, monitoring and recovery each cover a different failure
  • Match a control to the attack it actually stops instead of buying the most expensive one
  • Recognise what a perimeter cannot see — insiders, stealthed traffic and data on its way out
  • Say why a second check at login stops a stolen password that looks legitimate
  • Say why backups and internal segmentation decide how bad a ransomware day gets
  • Spend a fixed budget across a whole attack sequence rather than on one wall

How to play

  • Pick your language from the nine on the start screen, type your company name, and set sound and graphics.
  • Click a glowing spot on the floor to place a protection; the blue lines are the routes attacks take.
  • Pick the protection that beats that attack, not the strongest one — the briefing lists what helps most.
  • Press Space or Start round when you are ready, then watch which attacks get through.
  • Click an attacker mid-round to see what stops it and what it ignores, then upgrade or re-layer between rounds.

Platforms and languages

  • Platforms: Desktop, Tablet
  • Languages: English, Română, Français, Deutsch, Nederlands, Italiano, Español, Polski, Українська

Practise with these games

Game screenshots

Hold the line as a late-game firefight closes in on the vault.
Hold the line as a late-game firefight closes in on the vault.
Install a security operations center and watch the defense come online.
Install a security operations center and watch the defense come online.
Meet Lockjaw: a ransomware attacker with a personality of its own.
Meet Lockjaw: a ransomware attacker with a personality of its own.
Meet the Overlord: a formidable advanced threat.
Meet the Overlord: a formidable advanced threat.
The boss takes fire as the room erupts into a decisive battle.
The boss takes fire as the room erupts into a decisive battle.

Related cybersecurity topics

Contact · About