BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//talk//7UCFWP
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250924T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:(2) Gotta Contain 'Em All: Collaborative Incident Response Trainin
 g Through Gaming” - Klaus Agnoletti
DTSTART;TZID=Europe/Helsinki:20260924T140000
DTEND;TZID=Europe/Helsinki:20260924T160000
DTSTAMP:20260926T112156Z
UID:pretalx-bsides-tallinn-2026-7UCFWP@pretalx.com
DESCRIPTION:Sign-up form: [**Google forms**](https://docs.google.com/forms
 /d/e/1FAIpQLSc03ePCZyfgYfoK8ScAvfRsEG7t7sdoyw8kU1h9iexZMeaHrA/viewform)\n
 \nIncident response isn't just about knowing your tools - it's about coord
 inating under pressure\, communicating when things go sideways\, and makin
 g calls with incomplete information. Traditional training focuses on isola
 ted techniques\, missing the collaborative reality of actual incidents. An
 d most tabletop exercises? Painfully dull. Participants zone out\, give ch
 eckbox answers\, and leave having learned little.\n\nThis workshop introdu
 ces Malware & Monsters (https://malwareandmonsters.com)\, a framework that
  turns IR training into something people actually enjoy. Think tabletop ro
 le-playing meets creature-collection mechanics\, where teams "hunt and con
 tain" digital threats through story-driven gameplay.\nGame-based learning 
 works - research shows it beats traditional instruction for skill building
  and retention. M&M makes participants actively discover concepts instead 
 of sitting through lectures. Scenarios include organizational pressures\, 
 evolving threats\, and stakeholder drama\, turning abstract security conce
 pts into tangible problems.\n\nYou'll experience the full methodology: lea
 rn the mechanics\, build custom scenarios based on real malware families (
 mapped to MITRE ATT&CK)\, and run live simulations. Participants take spec
 ialized roles - Hunter\, Analyst\, Forensicator\, Communicator\, Coordinat
 or\, or Researcher - experiencing how security functions actually collabor
 ate during incidents.\n\nThe framework includes legacy malmons from malwar
 e history—because history always repeats itself\, and understanding past
  threats reveals patterns in current attacks. The "type effectiveness" sys
 tem teaches strategic thinking about matching defenses to threats. Evoluti
 on mechanics show how attacks escalate when containment fails.\n\nParticip
 ants walk away with ready-to-use materials and facilitation techniques for
  training that actually works.\n\nBest of all? M&M is free to play in most
  cases.
LOCATION:Workshop room (LD2)
URL:https://pretalx.com/bsides-tallinn-2026/talk/7UCFWP/
END:VEVENT
END:VCALENDAR
