Working title · Pre-alpha

Exploit Margin

Can you grow a technology company while professional adversaries work to break in?

Exploit Margin is a business simulation about pressure. AI adversaries study your people, shop dark markets for tooling, and chain 16 attack techniques toward whichever prize pays: your data, your money, or your machines.

Pre-alpha. No public build yet. Playtesters get in first and shape the design.

16 attack techniques 17 security controls 4 adversary objectives

Grow under pressure

Ship features, hire, and win customers quarter by quarter. Every system you add opens new ground an adversary can probe. The market rewards speed and quietly bills you for it later.

time →
Growth and exposure move together.

Meet your adversaries

AI adversaries run campaigns of their own, with budgets, skills, and patience. They scrape your org chart, buy password dumps and zero-days on underground markets, and pick from 4 objectives: steal your data, ransom your systems, spy on you, or mine crypto on your servers.

  1. day 12 · recon · employee directory scraped
  2. day 19 · market · credential dump acquired
  3. day 26 · phish · finance inbox targeted
  4. day 33 · intrusion · CRM session hijacked
  5. day 41 · objective · exfiltration channel opened
Interface concept, pre-alpha.

Make whole attacks impossible

Patching one flaw closes one door. A security invariant removes the hallway: a machine-enforced property of your infrastructure that blocks a required attack step, for every flaw behind it, current and future. Lay that foundation early and attacks die halfway through.

Attack path left open

  1. 01 Vulnerable service
  2. 02 External payload requested
  3. 03 Payload reaches the system
  4. 04 Compromise spreads

Default-deny egress invariant

  1. 01 Vulnerable service
  2. 02 External payload requested
  3. 03 Outbound path blocked
  4. 04 Attack chain stops

Answer the breach

Detection arrives late and certainty arrives later. When an incident lands, you choose among 5 responses with real costs in cash, staff, and downtime. A wrong call turns a bad week into a board meeting.

day 41 · incident detected

Choose your response

  • Ride it out risk
  • Isolate the system downtime
  • Rebuild from backup downtime · staff
  • Forensic analysis cash · staff
  • Call in outside help cash
Interface concept, pre-alpha.

Every run asks a different question.

Outgrow them?

Scale your platform and perfect product market fit while rivals burn quarters on cleanup.

Outbuild them?

Spend early on foundations that make whole classes of attack impossible, then scale in peace.

Play it darker?

Adversaries take tips. A well-placed lead about a competitor's weakness could clear the market for you.

The simulation runs today. The public experience is still being earned.

Company building, infrastructure, adversaries, detection, and incident response are playable in the development build; current work is shaping them into a scenario a new player can read without help.

Current development build
Standalone simulation against AI companies and adversaries; not publicly available
In development
Scenario pacing, onboarding, balance, and an explanatory end-of-run report
Not promised yet
Public demo date, multiplayer, or a crowdfunding launch

Security advice is fragile. Security invariants change the system.

The project grew from studying why sound advice loses to deadlines and budgets. Invariants turn key protections into properties of the infrastructure itself, and the game makes their cost, and the delayed cost of skipping them, something you feel.

Read the research behind the game
“Attackers need one open door. The company has to decide which doors never exist.” Project design principle

Want in? Playtest invites go to this list first.

Get development milestones that matter and first notice when private playtests open. Substance over frequency.

π