top of page

Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess

  • phil7672
  • 2 minutes ago
  • 4 min read

It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. 


In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your chance of success in the face of random events.  


The Illusion of Direct Combat: Why Chess Fails the Metaphor


Chess is a game of perfect information. Both players see every piece on the board, understand exactly what moves are legal, and operate in an environment without luck or external chance being a factor, notwithstanding opponent carelessness. If you unintentionally lose a piece in chess, it is because you failed to foresee your opponent’s moves. Chess appeals to us as an analogy for cybersecurity because it implies we have absolute control. However, cyber is not really like this because you never possess perfect information. You might not know, despite threat intelligence efforts, what tactics or tools attackers can deploy. Never mind the attacker, you rarely have a 100% accurate picture of your own situation. 


Backgammon: Strategy in the Face of Uncertainty

Chess is deterministic calculation. Backgammon is stochastic risk management. It is a game of skill, but that skill is executed under the roll of the dice. You can be in a great strategic position, but a sudden, improbable sequence of dice rolls can shatter that, forcing you to adapt. This is very similar to cybersecurity. We have uncertainty of human behavior, software vulnerabilities, supply chain dependencies, and more. 


Backgammon teaches us to not just focus on preventing bad luck entirely but from positioning your pieces on the board so that you can capitalize on favorable outcomes and minimize the damage of disastrous ones.



Mapping Game Strategies to Cyber Operations

To appreciate the parallel let’s look beyond the abstract and get into some backgammon play. 


1. Blots, Anchors, and the Attack Surface

In backgammon, leaving a single checker on a point makes it a blot. If your opponent lands on that exact point, your checker is hit, removed from the board, and sent to the bar, forcing you to expend tempo restarting its journey round the board. To prevent this, you secure the point by placing two or more checkers on it, creating an anchor. An anchor can never be hit or occupied by the adversary, it is a permanent safe zone. In our world, a blot is an exposed vulnerability, a hardcoded API key in a public repository, an unprotected database, or all the other things we have to worry about. Creating an anchor is the necessary defense in depth like identity and access management (IAM) coupled with network segmentation, enforcing multi-factor authentication (MFA) and grouping assets into hardened security zones. This way you ensure that even if an attacker targets a specific point, they cannot "hit" or compromise that because your security cannot be compromised by a single exploit.


2. The Priming Game and Defense-in-Depth

One of backgammon's strongest defensive structures is the prime. This is a continuous wall of anchors built next to each other. A full six-point prime creates an impassable barrier that traps an opponent’s checkers, and they are forced to waste moves while you advance your strategy. This is the board-game equivalent of further defense in depth. A firewall or an isolated endpoint detection and response agent is just one anchor. You construct a "prime", for example, by layering segmented network access, robust endpoint isolation, automated behavior monitoring, and strict data loss prevention. Even if they break past one control, they lack the mobility to move across your infrastructure.


3. The Blitz vs. Ransomware Waves

Conversely, an offensive strategy in backgammon is the blitz. This is an all-out, highly aggressive attack on your opponent's home board. Rather than building a prime, you attack any blots they leave behind, continuously sending them to the bar. The goal is to completely close out your home board before they can establish an anchor, effectively locking them out of the game entirely. This mirrors the operational cadence of automated cyber threats and modern ransomware attacks. Attackers utilizing automation execute a blitz. They hit every exposed blot they can find in a matter of minutes. The objective is to overwhelm the defender’s capabilities, compromising systems and encrypting files.


4. The Doubling Cube and Cyber Risk Management

The most distinct feature of backgammon is the doubling cube. At any point during a match, a player who feels they have an advantage can propose doubling the stakes of the game. The opponent must either concede immediately (forfeiting the current stake) or accept the double, playing on at twice the financial or point value. The doubling cube is a manifestation of risk appetite and business impact assessment. In a cyber incident, executive leadership is constantly forced to play the doubling cube. When a ransomware group steals data and threatens public extortion, they are turning the cube. The organization must calculate its probabilities. Do they pay the ransom (conceding the current stake), or do they refuse to pay and execute a disaster recovery plan, knowing that if they fail, the business damage will double or triple? Managing cyber risk requires an analytical understanding of when to fight and when to cut losses based on a balance of probabilities.


Shifting the Mindset: Resilience Over Perfection


Clinging to the chess myth can create a dangerous culture, the pursuit of flawless, unyielding defense, followed by complete despair when a breach inevitably occurs. But in backgammon, getting hit and sent to the bar is just a part of the game. You re-enter the board, adjust your strategy, and keep playing. By viewing cybersecurity through the lens of backgammon, we embrace the concept of cyber resilience. We accept that bad rolls (zero-days, human errors, vendor breaches) are a mathematical certainty in the long run. The goal is not to play a perfect game, but to architect a system resilient enough to absorb the hits, establish tight anchors, trap the adversary in a well-built prime, and navigate the organization to safety.



Recent Posts

See All
A Coming Incident Crisis?

We’re all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I’ve covered here, we can respond to this in various ways including ramping up speed ac

 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
Subscribe for updates.

Thanks for submitting!

© 2020 Philip Venables. 

bottom of page