Welcome to Donuts & Dragons
This is the main hands-on activity for Day 3 - and it carries through to Day 4. You and your team will take on the role of the security team for Donuts & Dragons, a donut shop and tabletop gaming community hub. Your mission: protect the business from cyberattacks on a limited budget.The scenario
At Donuts and Dragons, we’re more than just a donut shop - we’re a community hub where fresh, handcrafted donuts meet the adventurous spirit of tabletop gaming. Whether you’re stopping by for a morning treat or staying for a game night with friends, we offer a welcoming space filled with delicious flavors and fun.

Welcome to Donuts and Dragons - your business to protect
The business
Your goal
You have a limited budget assigned by your instructor (typically 15,000). Using that budget, purchase security controls that protect the shop’s most critical assets. You cannot exceed your budget. Every dollar spent on one control is a dollar you can’t spend on another. On Day 4, the instructors (the Red Team) will launch attack scenarios against your defenses. Each security control you purchased that successfully stops an attack earns your team +1 point. The team with the most effective defense wins.Assets to protect
These are the assets that Donuts & Dragons relies on to operate. Every asset is a potential target. Your job is to decide which ones are most critical and need the most protection.Security controls available for purchase
Your instructor will give your team a budget. Review the controls below and decide which ones to buy. Every control has a cost, a type (physical, technical, or both), and a description of what it protects.How to plan your defense
Follow these steps as a team. Your Team Captain leads the discussion, your Budget Specialist tracks spending, and your Report Specialist documents every decision.Review your budget
Rank your assets by priority
- “If the POS system is hacked, what happens to the business?”
- “If an employee falls for a phishing email, what could the attacker access?”
- “If the cash drawer is stolen, how much do we lose versus if customer card data is stolen?”
Map controls to assets
Make your purchases
- Why this control? What specific threat does it address?
- What does it protect? Which asset(s) benefit?
- What happens if you DON’T buy it? What risk are you accepting?
Track your spending
Prepare your defense briefing
Budget tracker
Use this template to track your team’s purchases. Copy it to a shared document or use paper.Strategy guide
These tips won’t tell you exactly what to buy - that’s your team’s decision - but they’ll help you think like a real security professional.Think about layered defense
Think about layered defense
Prioritize by impact, not by cost
Prioritize by impact, not by cost
Don't forget the human factor
Don't forget the human factor
Consider what you're NOT buying
Consider what you're NOT buying
Look for controls that cover multiple assets
Look for controls that cover multiple assets

Your team must defend Donuts and Dragons from cyber threats
Scoring and the attack phase
On Day 4, the instructors switch from teaching to attacking. They become the Red Team and launch realistic attack scenarios against every team’s defenses.How scoring works
What attacks look like
Without spoiling Day 4, here are the types of scenarios your defenses might face:Physical attacks
Social engineering
Malware and ransomware
Network attacks
Team discussion questions
Before you finalize your plan, discuss these questions as a team:- What is the single most valuable asset at Donuts & Dragons? Why?
- Which threat is most likely? A physical break-in? A phishing email? A ransomware attack? A disgruntled employee?
- If you could only buy three controls, which three would you choose? Why those three?
- What’s your biggest security gap? What risk are you accepting, and are you comfortable with it?
- How does your plan implement defense in depth? Can an attacker bypass a single control and reach the target, or do they have to get through multiple layers?
Presenting your defense plan
At the end of this activity, each team will present their defense plan to the class. Your presentation should cover:State your budget and total spending
List what you bought
Explain your priorities
Acknowledge your gaps
Defend your strategy
Key takeaways
- Security is about trade-offs. You can’t buy everything, so you have to prioritize based on risk and impact.
- Layered defense means no single point of failure. If one control fails, the next one catches the threat.
- The human element is often the weakest link - training your employees is one of the highest-value investments you can make.
- Every control you don’t buy is a risk you’re accepting. Make sure you’re accepting that risk deliberately, not accidentally.
- The best security plans balance physical controls, technical controls, and people controls to cover the widest range of threats.

