> ## Documentation Index
> Fetch the complete documentation index at: https://stem-docs.intellectualpoint.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Donuts & Dragons wargame

> Build your team's security plan for a donut shop on a limited budget - then defend it against attacks.

## Welcome to Donuts & Dragons

This is the main hands-on activity for Day 3 - and it carries through to Day 4. You and your team will take on the role of the security team for **Donuts & Dragons**, a donut shop and tabletop gaming community hub. Your mission: protect the business from cyberattacks on a limited budget.

<Info>
  Everything you learned this week - security controls, the CIA Triad, defense in depth, threat actors, the kill chain, network architecture, and cloud security - comes together here. This is where theory meets practice.
</Info>

## The scenario

> **At Donuts and Dragons, we're more than just a donut shop - we're a community hub where fresh, handcrafted donuts meet the adventurous spirit of tabletop gaming. Whether you're stopping by for a morning treat or staying for a game night with friends, we offer a welcoming space filled with delicious flavors and fun.**

<Frame caption="Welcome to Donuts and Dragons - your business to protect">
  <img src="https://mintcdn.com/intellectualpoint/Z4o1TCU5ZOWJaHan/images/cyber/donuts-and-dragons-shop.png?fit=max&auto=format&n=Z4o1TCU5ZOWJaHan&q=85&s=725c2ffd43b9b6461f31e87253ab9bd2" alt="Fantasy-themed illustration of the Donuts and Dragons donut shop with customers and D&D gaming atmosphere" width="1200" height="654" data-path="images/cyber/donuts-and-dragons-shop.png" />
</Frame>

### The business

| Detail            | Value                                                                                 |
| ----------------- | ------------------------------------------------------------------------------------- |
| **Business name** | Donuts & Dragons                                                                      |
| **Type**          | Donut shop + tabletop gaming community hub                                            |
| **Hours**         | 6:00 AM - 4:00 PM, 7 days a week                                                      |
| **Staff**         | 1 Manager, 3 Baristas, 1 Baker                                                        |
| **Location**      | Single storefront with a kitchen, a retail counter, a gaming area, and a small office |

### Your goal

You have a **limited budget** assigned by your instructor (typically $10,000-$15,000). Using that budget, purchase security controls that protect the shop's most critical assets. You cannot exceed your budget. Every dollar spent on one control is a dollar you can't spend on another.

On **Day 4**, the instructors (the Red Team) will launch attack scenarios against your defenses. Each security control you purchased that successfully stops an attack earns your team **+1 point**. The team with the most effective defense wins.

<Warning>
  Budget mistakes are permanent. Once you purchase a control, you cannot return it. Plan carefully before spending.
</Warning>

## Assets to protect

These are the assets that Donuts & Dragons relies on to operate. Every asset is a potential target. Your job is to decide which ones are most critical and need the most protection.

| Asset                            | Business use                                                                   | What happens if compromised                                                                     |
| -------------------------------- | ------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------- |
| **Front door & back door**       | Front door for customers, back door for supply deliveries                      | Unauthorized physical access to the building, theft, after-hours break-in                       |
| **Point-of-Sale (POS) computer** | Handles all credit and debit card transactions                                 | Customer payment data stolen, card fraud, PCI-DSS violations, loss of customer trust            |
| **Office computer**              | Employee payroll, HR records, business documents                               | Payroll fraud, employee data leaked, tax documents exposed                                      |
| **Employees**                    | Customer service, donut sales, daily operations                                | Social engineering targets - phishing, impersonation, insider threats                           |
| **Cash drawer**                  | All cash is kept here until bank deposit                                       | Cash theft from employees or intruders                                                          |
| **Walk-in fridge**               | Stores next-day donut inventory and ingredients                                | Inventory tampering, spoilage (loss of product), health code violations                         |
| **Wi-Fi network**                | Supports POS system and customer internet access                               | POS system compromised through the network, customer data intercepted, network used for attacks |
| **Business documents**           | Some stored digitally on the office computer, others stored as physical papers | Contracts leaked, payroll exposed, tax information stolen                                       |

<Tip>
  Not all assets are equally critical. A stolen donut recipe is bad, but stolen customer credit card numbers is a legal and financial disaster. Prioritize based on **impact** - what happens to the business if this asset is compromised?
</Tip>

## Security controls available for purchase

Your instructor will give your team a budget. Review the controls below and decide which ones to buy. Every control has a cost, a type (physical, technical, or both), and a description of what it protects.

| Security control                  | Type      | Cost    | What it protects                                                                                     |
| --------------------------------- | --------- | ------- | ---------------------------------------------------------------------------------------------------- |
| Deadbolt locks for all entrances  | Physical  | \$800   | Prevents easy forced entry through front and back doors                                              |
| Smart access system (PIN/keypad)  | Physical  | \$1,200 | Controls who can enter the building - each employee gets a unique PIN code                           |
| Interior security cameras         | Physical  | \$2,000 | Records activity inside the store - captures theft, tampering, and incidents on video                |
| Exterior motion lights            | Physical  | \$1,000 | Deters nighttime intrusions by illuminating the perimeter when motion is detected                    |
| Monitored alarm system            | Physical  | \$3,000 | Professional monitoring - alerts police automatically when a break-in is detected                    |
| Lockable cash drawer              | Physical  | \$500   | Prevents casual cash theft at the register - only opens with a key or manager override               |
| POS security suite                | Technical | \$2,000 | Antivirus, anti-skimmer, and encryption for the POS computer - protects customer payment data        |
| Antivirus for office computer     | Technical | \$800   | Detects and blocks ransomware, phishing payloads, and malware on the office PC                       |
| Security awareness training       | Both      | \$1,500 | Trains all employees to recognize phishing emails, social engineering, impersonation, and scams      |
| Separate Wi-Fi for guests         | Technical | \$1,000 | Creates an isolated network for customer internet access - keeps public traffic off internal systems |
| Cloud backup for POS & office PC  | Technical | \$1,200 | Automatic daily backups - restores data if systems are wiped, encrypted by ransomware, or destroyed  |
| Fridge lock & temperature monitor | Physical  | \$400   | Prevents unauthorized access to inventory and alerts staff if temperature rises above safe levels    |
| Fireproof lockbox for documents   | Physical  | \$700   | Protects physical contracts, payroll papers, and tax documents from fire, water damage, and theft    |

<Note>
  Notice the "Type" column. Physical controls protect against physical threats (break-ins, theft). Technical controls protect against cyber threats (malware, hacking). Security awareness training is both - because people are the most common attack vector for both physical and cyber threats.
</Note>

## How to plan your defense

Follow these steps as a team. Your Team Captain leads the discussion, your Budget Specialist tracks spending, and your Report Specialist documents every decision.

<Steps>
  <Step title="Review your budget">
    Your instructor will assign your team a budget. Write it down. Every dollar matters.
  </Step>

  <Step title="Rank your assets by priority">
    Go through the asset table above and decide: which assets, if compromised, would cause the most damage to the business? Consider financial loss, legal consequences, customer trust, and operational impact.

    Ask yourselves:

    * "If the POS system is hacked, what happens to the business?"
    * "If an employee falls for a phishing email, what could the attacker access?"
    * "If the cash drawer is stolen, how much do we lose versus if customer card data is stolen?"
  </Step>

  <Step title="Map controls to assets">
    For each security control, identify which asset(s) it protects. Some controls protect multiple assets - those give you more value per dollar.

    | Control                     | Assets it protects                                |
    | --------------------------- | ------------------------------------------------- |
    | Deadbolt locks              | Front door, back door, building access            |
    | POS security suite          | POS computer, customer payment data               |
    | Security awareness training | Employees, POS, office computer, Wi-Fi            |
    | Separate guest Wi-Fi        | Wi-Fi network, POS computer                       |
    | Cloud backup                | POS computer, office computer, business documents |
  </Step>

  <Step title="Make your purchases">
    Select the controls you want to buy. Add up the costs. If you go over budget, remove something and justify why that control is less important.

    For **every purchase**, your team must answer:

    * **Why this control?** What specific threat does it address?
    * **What does it protect?** Which asset(s) benefit?
    * **What happens if you DON'T buy it?** What risk are you accepting?
  </Step>

  <Step title="Track your spending">
    Use the budget tracker below to record your purchases and remaining funds.
  </Step>

  <Step title="Prepare your defense briefing">
    At the end of the planning phase, your Team Captain will present your team's defense plan to the class. Be ready to explain your strategy and justify your choices.
  </Step>
</Steps>

## Budget tracker

Use this template to track your team's purchases. Copy it to a shared document or use paper.

```text theme={null}
Team Name: ___________________
Total Budget: $_______________

PURCHASES:
# | Control                        | Cost     | Running Total
--|--------------------------------|----------|-------------
1 |                                | $        | $
2 |                                | $        | $
3 |                                | $        | $
4 |                                | $        | $
5 |                                | $        | $
6 |                                | $        | $
7 |                                | $        | $
8 |                                | $        | $

REMAINING BUDGET: $______________
```

## Strategy guide

These tips won't tell you exactly what to buy - that's your team's decision - but they'll help you think like a real security professional.

<AccordionGroup>
  <Accordion title="Think about layered defense" icon="layer-group">
    No single control protects everything. A deadbolt lock doesn't stop a phishing email. Antivirus doesn't stop a physical break-in. The strongest defense plans have **layers** - physical controls, technical controls, and people controls working together.

    Ask yourself: "If this one control fails, what catches the attacker next?"
  </Accordion>

  <Accordion title="Prioritize by impact, not by cost" icon="scale-balanced">
    A $500 lockable cash drawer might seem like a deal, but if there's only $200 in the drawer at any time, is it the best use of your budget? Compare that to the POS security suite at \$2,000 - if the POS is compromised, the business could face thousands in fraud liability and lose customer trust permanently.

    Spend where the impact is highest, not where the price is lowest.
  </Accordion>

  <Accordion title="Don't forget the human factor" icon="user-shield">
    The most expensive security system in the world is useless if an employee holds the door open for a stranger or clicks a phishing link. Security awareness training covers a wide range of threats and protects multiple assets.

    In real-world breaches, **human error** is the #1 cause. The 2023 Verizon Data Breach Investigations Report found that 74% of breaches involved the human element.
  </Accordion>

  <Accordion title="Consider what you're NOT buying" icon="circle-xmark">
    For every control you skip, you're accepting the risk that the threat it protects against will happen. That's called **risk acceptance**, and it's a legitimate strategy - but only if you've thought about it deliberately.

    Before finalizing your plan, go through the controls you didn't buy and ask: "What happens if the attack this control would have stopped actually happens?"
  </Accordion>

  <Accordion title="Look for controls that cover multiple assets" icon="bullseye">
    Some controls are force multipliers. Security awareness training protects employees against phishing, social engineering, and scams - threats that can compromise the POS, the office computer, and the cash drawer. Cloud backup protects both the POS and office computer against ransomware, hardware failure, and data corruption.

    Controls that cover multiple assets give you more defense per dollar.
  </Accordion>
</AccordionGroup>

<Frame caption="Your team must defend Donuts and Dragons from cyber threats">
  <img src="https://mintcdn.com/intellectualpoint/Z4o1TCU5ZOWJaHan/images/cyber/donuts-and-dragons-cyber.png?fit=max&auto=format&n=Z4o1TCU5ZOWJaHan&q=85&s=c5a05ee9b47491a696e4a0fa08652129" alt="Donuts and Dragons shop with a cyber guardian scanning for threats" width="1200" height="654" data-path="images/cyber/donuts-and-dragons-cyber.png" />
</Frame>

## Scoring and the attack phase

On **Day 4**, the instructors switch from teaching to attacking. They become the **Red Team** and launch realistic attack scenarios against every team's defenses.

### How scoring works

| Outcome                                                                          | Points                                            |
| -------------------------------------------------------------------------------- | ------------------------------------------------- |
| Your purchased control **successfully blocks** the attack                        | **+1 point**                                      |
| Your team **did not purchase** a control that would have stopped the attack      | **0 points** (and you suffer the consequences)    |
| Your team can **explain why** they accepted a risk and what their backup plan is | **Partial credit** at the instructor's discretion |

The team with the highest total score wins the Donuts & Dragons Cyber Defense Challenge.

### What attacks look like

Without spoiling Day 4, here are the *types* of scenarios your defenses might face:

<CardGroup cols={2}>
  <Card title="Physical attacks" icon="door-open">
    Break-in attempts, tailgating, theft, physical access to systems
  </Card>

  <Card title="Social engineering" icon="mail">
    Phishing emails, impersonation, pretexting, baiting
  </Card>

  <Card title="Malware and ransomware" icon="lock">
    Malicious software delivered via email, USB, or network access
  </Card>

  <Card title="Network attacks" icon="wifi">
    Wi-Fi exploitation, network sniffing, man-in-the-middle
  </Card>
</CardGroup>

<Tip>
  Think about which of these attack categories your current defense plan covers. If your plan only addresses physical threats, you're wide open to cyber attacks - and vice versa. The best plans cover both.
</Tip>

## Team discussion questions

Before you finalize your plan, discuss these questions as a team:

1. **What is the single most valuable asset at Donuts & Dragons?** Why?
2. **Which threat is most likely?** A physical break-in? A phishing email? A ransomware attack? A disgruntled employee?
3. **If you could only buy three controls, which three would you choose?** Why those three?
4. **What's your biggest security gap?** What risk are you accepting, and are you comfortable with it?
5. **How does your plan implement defense in depth?** Can an attacker bypass a single control and reach the target, or do they have to get through multiple layers?

## Presenting your defense plan

At the end of this activity, each team will present their defense plan to the class. Your presentation should cover:

<Steps>
  <Step title="State your budget and total spending">
    How much was your budget? How much did you spend? How much is left over?
  </Step>

  <Step title="List what you bought">
    Go through each purchased control and briefly explain why you chose it.
  </Step>

  <Step title="Explain your priorities">
    Which assets did you prioritize and why? What was your strategy?
  </Step>

  <Step title="Acknowledge your gaps">
    What did you NOT buy? What risk are you accepting? Do you have a backup plan?
  </Step>

  <Step title="Defend your strategy">
    Be ready for questions from the instructors and other teams. Why did you spend $3,000 on an alarm system instead of $2,000 on POS security? Justify your reasoning.
  </Step>
</Steps>

<Warning>
  The attack phase on Day 4 will test every team's plan. There is no perfect defense - but the teams that thought carefully about layered defense, prioritized by impact, and covered multiple attack categories will score the highest.
</Warning>

## Key takeaways

* Security is about **trade-offs**. You can't buy everything, so you have to prioritize based on risk and impact.
* **Layered defense** means no single point of failure. If one control fails, the next one catches the threat.
* The **human element** is often the weakest link - training your employees is one of the highest-value investments you can make.
* Every control you don't buy is a **risk you're accepting**. Make sure you're accepting that risk deliberately, not accidentally.
* The best security plans balance **physical controls**, **technical controls**, and **people controls** to cover the widest range of threats.
