From concept to something tangible
Once the core idea behind Security Architects was clear - a simple, enjoyable game that would allow players to learn about attacks and protections almost incidentally - the next challenge was obvious.
Would it actually work?
An idea can feel solid in theory. Mechanics can make sense on paper. But until players interact with something physical, it remains abstract. The only way forward was to build the simplest possible version and start playing.
There was no polished design. No professional layout. Just scissors, pens and coloured paper.
Learning by building
The first prototype was intentionally rough. Cards were cut by hand. Text was written directly onto paper. Early layout experiments were improvised.
At one stage, a hexagon-based central component was considered. This concept initially seemed attractive because it allowed modular expansion and adjacency mechanics. However, once prototyped physically, it became clear that the additional spatial logic distracted from the core attack–protection tension. The design was simplified not because it lacked interest, but because it introduced friction.
This early “pen and scissors” phase turned out to be more valuable than expected. Because nothing was precious, everything could change. Rules could be adjusted mid-game. Card effects could be rewritten between rounds. New ideas could be tested immediately.
Instead of debating mechanics endlessly, they could observe how the game actually felt.
Simplicity as a constraint
One of the guiding principles from the beginning was accessibility. The game needed to be simple enough to play during a coffee break, and approachable enough that even children could understand it. That constraint influenced every early design decision.
The attack–protection structure became the backbone of the gameplay because it was intuitive. Players could quickly grasp the tension: threats emerge, defences respond. The educational framework (STRIDE) remained present in the background, but it did not dominate the experience.
The aim was not to simulate real-world complexity in full detail. It was to create a playable abstraction that preserved the essence of security thinking without overwhelming the player.
Discovering what actually matters
One of the most valuable outcomes of early prototyping was not mechanical, it was visual.
As the first paper versions were tested, it became clear that players needed guidance directly on the cards. Referring constantly to a rule sheet disrupted the flow and slowed the game down.
That insight led to the introduction of a simple but powerful design feature: six small visual “balloons” placed along the right edge of each card.
The six balloons along the card edge were more than decoration. Originally sketched by hand during the early pen-and-paper phase, they began as a rough experiment in making interactions easier to follow. Over time, they evolved into a deliberate move towards self-documenting mechanics. By embedding interaction rules directly into the card layout, the design reduced cognitive load and preserved game flow, allowing players to understand how cards related to one another without constantly referring back to a rule sheet.
It was a reminder that good game design is not only about mechanics. It is about clarity. The more the rules could live on the card itself, the more accessible the game became.
Interestingly, this visual mechanism emerged not from graphic design software, but from early experimentation with scissors and markers. Without that rough stage, the feature may never have existed.
From sketch to structure
What began as handwritten cards gradually started to stabilise. Rules were refined. Interactions became clearer. The basic rhythm of play began to take shape.
But early playtesting also revealed something important: the game was harder than intended.
That realisation marked the beginning of a new phase - one that moved beyond creativity and into measurement.
In the next article, we’ll explore how balancing Security Architects required stepping back, defining clear metrics, and turning gameplay into something that could be analysed and engineered.