Free Delivery on orders above $50 for our US and Europe customers

  • Hands-on Security

    Addressing security through physical games

  • Worldwide Shipping

    Breaking through barriers for customers everywhere

  • Fully Custom Games

    For your unique cybersecurity challenges

  • Talk to us!

    We are real people with relevant experience

OWASP® Cornucopia 1.0 Website Edition Threat Modeling Cards

£21.60

Outcome

Identify security work that needs doing earlier in the project lifecycle. Defuse difficult relationships. Build trust. Bring teams together in peace and harmony.

Made by Agile Stationery

Experts in delivering the right kind of conversations. Slick cards in robust boxes. The best there is outside the casinos.

60 cards

The Cyber Security Cornucopia: eCommerce Website Edition card deck is a gamified version of OWASPs Secure Coding Practices Quick Reference Guide. The objective is to help teams perform threat modelling on retail websites in the same way that Elevation of Privilege helps treat model applications in general.

The game features 80 tarot sized cards. Each card describes a common error or anti-pattern that allows systems to be vulnerable to attack. These vulnerabilities are chosen from data gathered by web security experts at OWASP. For more details about the game, click here.

Got Remote teams? Use Croupier to generate random hands for remote players and continue to play using physical cards.

 

How to play?

  • Set the stage

    Before dealing, sketch a simple diagram of the system on a whiteboard, paper, or digital tool, just enough to show key components and data flows.

  • Deal the cards

    Shuffle the deck and deal all the cards to 3-6 players. Each player organizes their hand by suit (but no peeking at your neighbour’s cards!).

  • Let the game begin

    Decide which player starts. The player who starts reads their card and explains how the threat could affect the system.

  • Winning

    Players take turns with the threats in that suit, with the highest card winning the round. The winner leads the next
    round until all cards are played.

Hybrid teams? No problem

Play our threat modeling games remotely
with the power of physical cards!