Signify Insights
DiscoverSignify PlaygroundSignify FieldworkSignify LabsSignify KidsSpotlightsAboutSignify SolutionSignify HiveSignify Impact
Signify Playground · Games & self-assessments
A publishing & interactive-learning property · Philadelphia · est. 2019
Play it out

Signify Playground

73 pieces where the decision is yours and the consequence lands before the explanation does. Nothing is locked. Pick by discipline, or by the time you have actually got.

Nothing matches that

Clear the search, or widen the discipline back to All.

A piece serving two disciplines appears in both rows, so the board shows 115 placements across 73 pieces.

Self-AssessmentProfessional Ethics · Programme

How real is your ethics programme?

Twenty questions for a quick read, or fifty for a full programme review — across the eight domains of a working ethics programme: code and policy, ownership, training, speak-up channels, investigation, non-retaliation, third parties, and board oversight. Not a values survey — a check on whether the machinery exists and is used.

Lvl · 6 minOpen
Self-AssessmentCyber · NIST CSF 2.0

How ready are you against NIST CSF 2.0?

Twenty questions for a quick read, or fifty for an outcome-by-outcome deep dive — across the six Functions of CSF 2.0, including Govern, the one most self-assessments skip. Not a Tier rating: a map of which outcomes you could actually evidence tomorrow.

Lvl · 6 minOpen
Self-AssessmentPrivacy · Programme readiness

How ready is your data privacy function?

Twenty questions for a quick read, or fifty for a full programme review — across the eight domains a privacy function has to hold up: governance and roles, records and lawful basis, transparency, individual rights, retention, vendors and transfers, security, and breach response. Scored, with your weakest domain named.

Lvl · 6 minOpen
TournamentProfessional Ethics · Capstone

The Ethics Cup

Five knockout rounds, drawing on all three weeks, so the Final needs what the earlier rounds taught. Each opponent is a temptation rather than a team, every phase has a plausible middle answer as well as a right one, and seven shortcuts across the tournament will get you carded.

Lvl · 13 minOpen
Role-playProfessional Ethics · Feedback

Say It Straight

The comfort trade, in both directions: softening a message until it cannot be acted on, and defending before listening. Two conversations — giving hard feedback, then receiving it when it is partly unfair. No turn has an answer that is free on both axes.

Lvl · 12 minOpen
SimulationProfessional Ethics · Commitments

The Deadline You Can't Make

The late confession: every move that buys silence is cheap on the day you make it and expensive by the end. Five checkpoints across ten days, two axes — the cost you shift onto other people and what the client believes when you speak. Winnable, and only through telling someone before you had proof.

Lvl · 10 minOpen
DrillProfessional Ethics · Commitments

In Scope?

Silent absorption reads as generosity and quietly destroys the record everyone needs when the budget runs out. Twelve unwritten requests where absorbing, recording, raising and declining are four different answers — and refusing everything is wrong three times.

Lvl · 7 minOpen
DrillProfessional Ethics · Authorship

Whose Words Are These?

Attribution is answered by reflex in both directions: citing to avoid owning a claim, and shipping borrowed work because the borrowing felt small. Twelve items where the four answers are genuinely different and one of them stops the work. See your reflex rate.

Lvl · 6 minOpen
DrillProfessional Ethics · AI use

Declare It

One disclosure policy applied to every setting is the mistake, in both directions: declaring everything until nobody reads declarations, and declaring nothing where an undertaking was given. Twelve contexts, four answers, three of which are not about disclosure at all.

Lvl · 5 minOpen
DrillTechnology Strategy · Business case

Run the Number

Implementation cost is compared carefully and run cost arrives after the decision. Twelve technology choices where the deciding number is build, run, exit — or where the two quotes are not for the same thing and the honest answer is that they cannot be compared yet. See your build-cost myopia rate.

Lvl · 7 minOpen
DrillTechnology Strategy · Benefits

Who Banks This?

A saving nobody's budget gives up never appears. Twelve business case lines to sort: bankable cash, real capacity that is not cash, activities and milestones that are not benefits at all, and numbers with no baseline underneath them. See whether your case would still reconcile twelve months in.

Lvl · 7 minOpen
DrillTechnology Strategy · Operating model

Who Owns It?

Every box in an operating model has a name in it, which is exactly why the model looks complete and behaves like it has holes. Twelve capabilities to judge: properly owned, named but powerless, split between two so nobody decides, or orphaned outright. Three questions decide each — can they decide, fund it, and refuse.

Lvl · 6 minOpen
DrillTechnology Strategy · Roadmap

Sequence It

A roadmap ordered by appetite fails in month four. Twelve initiatives, each with something specific standing in front of it: a technical prerequisite, a decision nobody has taken, or a team already committed elsewhere — and four that could genuinely start on Monday. See how much of your sequence was wish-order.

Lvl · 7 minOpen
DrillTechnology Strategy · Delivery

The Pilot Trap

A pilot measures its conditions as much as its tool. Twelve that succeeded — some through volunteers, some through support no rollout will reproduce, some with no success criteria at all, and some designed to be believed. See your volunteer-effect blindness before it costs a rollout budget.

Lvl · 6 minOpen
DrillInternal Audit · Independence

Independent Enough?

Independence fails in two directions and only one of them gets talked about. Twelve engagements an in-house function is really offered — work you advised on, a committee seat, a favour for the CFO, a bonus set by the auditee. Take it, safeguard it, hand it to someone else, or say it is not audit's to do; then see whether you were over-cautious or over-comfortable.

Lvl · 6 minOpen
DrillInternal Audit · Scoping

Scope the Audit

A scope that covers everything tests nothing. Thirteen candidate objectives for one procure-to-pay audit — some carrying real risk, some already covered by second line, some impossible to conclude on however important they sound, and some that are procedures rather than objectives. Sort them, then see whether your scope would have spent the budget on the testable or the risky.

Lvl · 7 minOpen
DrillInternal Audit · Root cause

Root or Symptom

An action written from the wrong cause closes and recurs. Twelve findings, each carrying the operating detail that gives the real cause away — a control that cannot work as built, a team with no hours, an incentive pulling the other way, or a task nobody knew was theirs. Assign the family, then see whether you reached for awareness because it is the cheapest action to write.

Lvl · 6 minOpen
DrillInternal Audit · Issue rating

Rate the Issue

Severity inflation is directional and it compounds: every finding rated by how annoying it is devalues every honest rating in the same report. Fifteen findings to rate by exposure, four of which the evidence does not size at all. See your inflation rate, and whether you were willing to say a finding could not be rated yet.

Lvl · 7 minOpen
DrillInternal Audit · Follow-up

Close or Carry

Closing on assertion is invisible — nobody audits the follow-up process. Twelve actions and the evidence offered for each: assertions, partial completions, dashboards without workings, and the case where management did something other than what was agreed. Decide each, then see how green your register would have been.

Lvl · 6 minOpen
DrillGRC · Access review

Grant or Revoke — an access review drill

Twelve rows from an entitlement review: a group identifier with no description, no owner and no last-use data; an undated screenshot supplied by the system owner whose access is under review; a leaver whose user account was disabled and whose service principal still holds a write-capable API key. Approve, revoke, re-scope, or say the evidence does not reach it — then see your rubber-stamp rate, because a review that approves rows it could not have judged still produces evidence that the control operated.

Lvl · 7 minOpen
DrillC-Suite · Decision rights

Whose Call — a decision-rights drill

Twelve decisions and four possible owners: the full board, a committee, management, or the shareholders. Appointing the chief executive, setting an individual package inside an approved policy, choosing a payroll vendor, amending the charter, sequencing a programme the board already approved. Place each one — then see your over-reach rate, because pulling decisions up to the full board feels like diligence and is how a board becomes both overloaded and unable to hold anyone to account.

Lvl · 6 minOpen
DrillCyber · Cloud & SaaS exposure

Who Can See This — a cloud exposure drill

Twelve cloud and SaaS configurations, one question each: who can actually reach this? A wildcard bucket policy, a dashboard published under a label that says only people with the link, an ACL granting AuthenticatedUsers — which in that provider means any account in the provider, not in your tenant — and a default sharing setting that applied itself to a folder of HR case files. Public, anyone with the link, tenant-wide, or genuinely restricted, then see your false-assurance rate.

Lvl · 7 minOpen
DrillCyber · Vulnerability triage

Patch or Wait — a vulnerability triage drill

Twelve findings competing for one finite queue: a 9.8 remote code execution nobody can reach without credentials, a 6.1 authentication bypass that is internet-facing with a published exploit, a container image that was never deployed, a domain admin account with a 2019 password and no CVE at all. Emergency, next cycle, scheduled or accept — then see your over-escalation rate, because escalating everything is the same as prioritising nothing and it spends the credibility you need the week it is real.

Lvl · 7 minOpen
DrillCyber · Detection engineering

Ship or Tune — a detection-writing drill

Twelve proposed detections and one call on each: a rule keyed to procdump.exe that any rename evades, an alert on every PowerShell execution in the estate, a threat-feed lookup that is stale by construction, and a handful that are genuinely ready to ship. Widen it, narrow it, rewrite it or ship it — then see how often you waved one through, because a rule that matches today's sample and nothing an attacker would do differently tomorrow is carried on the coverage report as though it worked.

Lvl · 8 minOpen
DrillPrivacy · Subject rights

The Request Clock — a subject-access scoping drill

One subject access request and fourteen things the search turned up: an e-mail thread of colleagues' opinions about her, the team's absence spreadsheet, privileged advice, a manager's notebook at home, CCTV with eleven other faces in it. Disclose, redact, withhold under an exemption or rule it out of scope — then see your over-disclosure rate, because handing over a third party's data is a breach you commit while satisfying somebody else's rights.

Lvl · 7 minOpen
DrillPrivacy · Retention

Keep or Kill — a retention and deletion drill

Twelve things your organisation is still holding and one call each: rejected CVs from fourteen months ago, card numbers kept for smoother returns, a leaver's entire mailbox, analytics with full IP addresses on a default nobody chose, a training set with names in the free text. Delete now, keep, legal hold or minimise — then see your over-retention rate, because every extra year is breach surface and discovery risk bought for nothing.

Lvl · 6 minOpen
DrillGRC · Control design

The Control Statement Clinic — make it testable

Twelve control statements lifted from the shape of real catalogues. For each, name which of the seven attributes it fails to pin down — who, what, when, how, evidence, frequency, owner — then choose which of three rewrites a tester could work from. The wrong rewrites are the two real failure modes: longer and more confident but still unfalsifiable, and precise about the wrong activity entirely.

Lvl · 8 minOpen
DrillGRC · Audit evidence

Rely or Reject — an evidence-reliability drill

Eighteen pieces of evidence, each with the provenance you would actually have: an undated screenshot, a client Excel extract, the same extract with the extraction observed and the row count footed, a SOC 2 Type 1 offered for operating effectiveness, a sample drawn from an unvalidated population. Call each one rely, rely with caveats or reject, then name the provenance reason behind it — the completeness-and-accuracy intuition that IPE testing lives on.

Lvl · 7 minOpen
DrillPrivacy · Data scope

Personal, or Not? — a data-scope drill

Twelve things a system holds and one call each: personal data, not personal, or only in context. Hashed e-mail addresses, a dynamic IP, an employee number with no name column, an inference about pregnancy. You are scored on accuracy and on the number that matters more — your false-negative rate, because ruling identifiable data out of scope is the error that ends in a notification.

Lvl · 4 minOpen
DrillAI · Failure modes

Confidently Wrong — naming the AI failure mode

Eight answers from a model that sounds equally sure of all of them: an invented case with a real docket number, a genuine Article cited for content it does not contain, a penalty figure from the draft Regulation, a headcount it has no way to know. Sort each into fabrication, staleness, faulty reasoning or should-have-declined — because each one needs a different control, and “the AI was wrong” is not a finding anyone can act on.

Lvl · 4 minOpen
SimulationCyber · Identity & access

Blast Radius — an identity attack-path sim

A service-desk account got phished and has no admin rights of its own. Walk the path it can actually take through the identity graph, then cut exactly three edges. Disabling the breached account reduces the reach by nothing — group nesting and a service account nobody owns built all of it.

Lvl · 11 minOpen
GameCyber · Detection & response

The Alert Queue — 40 alerts, one analyst

One shift, forty alerts, twelve alert shapes — and every real alert paired with a near-identical benign twin whose severity rating is no help at all. At the end you get the number nobody measures: how your accuracy on the final ten compared with your first ten.

Lvl · 8 minOpen
SimulationInternal Audit · Annual planning

Plan the Year — an audit-plan allocation sim

1,800 audit hours, fourteen auditable entities and no way to cover them all in depth. Set the depth on each one, then the year delivers its eight surprises. Half the mark is what you caught — the other half is whether the plan was defensible before you knew any of it.

Lvl · 11 minOpen
Self-AssessmentGRC · Third-party risk

How managed is your third-party risk?

Twenty checks for a quick read, or fifty for a full portfolio review, across the eight domains of a managed third-party programme — governance, inventory and tiering, due diligence, contracts, monitoring, concentration and exit, the fourth-party chain, and incidents. Scored, with your gaps named.

Lvl · 6 minOpen
GameCyber · Build & Defend

Starting XI — pick your cyber line-up

Your security stack is a football team. Choose a formation, fill the eleven from a transfer budget, then watch the attack play down the pitch and see which channels get breached.

Lvl · 9 minOpen
TournamentMulti-domain · Knockout

Road to the Final — a knockout tournament

Pick one of five sides — cyber, audit, AI governance, resilience or privacy — and go from the Round of 32 to the Final. Every tie is a real decision under pressure: win the matches, mind your discipline, and lift the trophy.

Lvl · 13 minOpen
GameInternal Audit · Forensic

Tie-Out — a forensic deduction

Management hands you a binder and a story. Tie every claim to the evidence — corroborate, contradict, or flag it unsupported — then follow the contradictions to the truth.

Lvl · 14 minOpen
GameC-Suite · Proxy contest

The Coalition Vote — 5-day vote-whip simulation

Five business days to the annual meeting. Eight named institutional holders own 41% of the float; ISS and Glass Lewis route most of the rest. You have ten moves to land. Pick the ones that move the holders you can actually move — and skip the ones that look like work but are not.

Lvl · 12 minOpen
GameC-Suite · M&A diligence

The Acquisition Dossier — 7-day M&A diligence sim

$1.4B target. Seven business days of diligence before the LOI lapses. Ten possible review actions; seven hidden red flags buried across the target. The board recommendation you write today is the document the minutes record two years from now — when one of those flags becomes a 10-K item or a class-action complaint.

Lvl · 13 minOpen
GameC-Suite · SEC enforcement

The Regulator’s Interview — SEC enforcement deposition sim

You are seated in the SEC enforcement field office for a “voluntary” interview. Counsel is present. Ten questions across friendly openers, memory probes, restating, impeachment, and the concession trap. The traps are rarely in the hostile questions. Three scores moving silently: cooperation, accuracy, discipline.

Lvl · 11 minOpen
GameC-Suite · SOX 404

The Material-Weakness Memo — SOX 404 disclosure sim

Three weeks to the 10-K. The auditor calls: material weakness in revenue cut-off. Seven rounds across investigative scope, Item 9A clause assembly, restatement, NT-10K, market sequencing, and the audit-committee meeting. Three hidden scores: SOX 404 conclusion, investor confidence, class-action probability.

Lvl · 14 minOpen
GameC-Suite · Ransomware

The Ransom Decision — a 7-phase ransomware sim

2:14am. The actor wants $14M in BTC within 72 hours. Seven phases, seven commitments — and every phase locks in a decision before the truth that matters most is visible. OFAC, insurance, backups, the payment itself. The mechanic is the lesson.

Lvl · 13 minOpen
SimulationAI governance · Incident response

The Model Did Something — an AI incident under uncertainty

An AI claims model may be harming people and nobody knows why. Eight phases, scarce attention, four advisors who are each reliable about one thing and wrong about another, and a debrief that scores your judgement rather than your luck.

Lvl · 20 minOpen
GameC-Suite · SEC Item 1.05

The Disclosure Window — SEC Item 1.05 simulation

3:47am, the CISO calls. The SEC’s four-business-day clock just started. Twelve checkpoints across ninety-six hours. Facts arrive, decisions lock paths, the room shrinks. Two scores move all night — regulatory exposure and stakeholder trust.

Lvl · 12 minOpen
GameC-Suite · Activism timeline

The Activist Letter — a 14-day proxy timeline

An activist letter dropped this morning with four demands. Top holders are reading it; proxy advisors are circling. Fourteen days, four parallel stakeholder tracks, one move per day. Some moves close the door behind them — read carefully.

Lvl · 14 minOpen
GameC-Suite · AI committee

The Use-Case Gate — an AI governance committee sim

Eight AI proposals on the committee’s agenda. Approve, reject, or conditional with the right conditions — not the conditions that just sound governance-flavoured. Two scores move in opposite directions all day; the easy way out in either direction is the trap.

Lvl · 12 minOpen
GameC-Suite · Investor relations

The Earnings Hot Seat — Reg FD under live Q&A

Eight named analysts — friendly, hostile, naive, sharp. Three answers each, four metrics moving at once. Some questions reward rich specificity; others are Reg FD traps where the same kind of answer ends careers.

Lvl · 10 minOpen
GameAI · Internal Audit

The Prompt Lab — prompting for internal auditors

Seven real audit tasks, four prompts each. Pick the one a careful auditor would actually send — the tempting answers are the wrong ones. A genuinely hard one.

Lvl · 8 minOpen
GameAll domains · Memory

Term Match — a terminology memory game

Flip cards to pair each term with its definition across cybersecurity, GRC, internal audit and strategy — and reveal a fact with every match.

Lvl · 5 minOpen
GameStrategy Execution · Change

Mind the Gap — a transformation-sequencing game

Get a change program across the valley between vision and value. Sequence the moves, mind your momentum, and don’t let the big bets fire before their foundations.

Lvl · 9 minOpen
GameCompetitive Strategy · Game Theory

Five Moves Ahead — a competitive-strategy war-game

Out-think an adaptive rival across five moves. Read its temperament, refuse the price war, and compound value — or watch it read you first.

Lvl · 11 minOpen
SimulationOperational Resilience · DORA

The War Room — an incident-command sim

Take command of a major outage and move a finite team across recovery, customers, the regulator clock and staff — round by round, before something breaks.

Lvl · 9 minOpen
Role-playInternal Audit · Negotiation

Agree the Finding — an audit negotiation

Present a real finding to a department head who pushes back. Hold your credibility without losing the room — every reply moves two meters.

Lvl · 8 minOpen
SimulationCyber · Build & Defend

Build & Defend — design a control set, then get attacked

Spend a finite budget on the controls you choose, then watch a real attack sequence test your design — and see what held and what got through.

Lvl · 7 minOpen
GameAI Governance · EU AI Act

Classify the Use Case — EU AI Act Sorter

Sort real AI systems into prohibited, high-risk, limited and minimal — then see where the Act actually puts each one, and the Article that decides it.

Lvl · 6 minOpen
DrillGRC · Risk

Which Is Riskier? — a calibration drill

Pairwise calls on residual risk. Find out where your instinct is sound and where the scary words are skewing your judgment.

Lvl · 5 minOpen
SimulationCyber · Board & C-Suite

The Breach Room — a C-suite tabletop

Run a massive US data breach as the board. Drag the right decisions onto the table and learn, round by round, where boards hold the line.

Lvl · 12 minOpen
BuilderBusiness Analysis · CoE

Build a Business Analysis CoE

Pick a 20-question quick scan or a 50-question deep dive across the eight domains of a high-performing Business Analysis CoE — scored, with a strong-practice blueprint for where to invest next.

Lvl · 6 minOpen
Self-AssessmentAI Governance

How governed is your AI & automation?

Pick a 20-question quick scan or a 50-question deep dive across the eight domains a real AI risk assessment must reach — mapped to recognized frameworks. Get a maturity score, a radar chart and exactly where your gaps are.

Lvl · 6 minPlay
GameRisk assessment

Rate the Risk

Read the context for each area, then set the risk level — Low to Critical. The scary ones are often fine; the boring ones are sometimes on fire. Rate the residual risk.

Lvl · 9 minPlay
Self-AssessmentEU AI Act · Regulatory

Are you EU AI Act-ready?

Pick a 20-question quick scan or a 50-question deep dive mapped to the EU AI Act — risk classification, prohibited practices, the high-risk obligations, transparency, GPAI duties, conformity and post-market monitoring. Scored, with exactly where your gaps are.

Lvl · 7 minPlay
Word gameGRC · Risk · Audit · Security

The Practitioner's Scramble

Read the clue, then tap the ringed letters in order to spell the term. Four packs across governance, risk, audit and security — forty terms in all.

Lvl · 7 minOpen
CrosswordCyber · GRC · Audit

The Practitioner's Crossword

Four full puzzles from the language of cyber, GRC and internal audit. Fill the grid, check yourself, then come back for a different set of answers.

Lvl · 10 minOpen
Self-AssessmentEnterprise GRC

GRC Maturity Assessment

Pick a 20-question quick scan or a 50-question deep dive across the eight domains of a mature GRC program — scored, benchmarked, and pointed at your biggest gaps.

Lvl · 4 minPlay
Self-AssessmentDORA · Operational resilience

Are You Actually DORA-Ready?

Pick a 20-question quick scan or a 50-question deep dive across the eight domains of DORA readiness — governance, ICT risk, incident reporting, resilience testing and third-party risk. Scored, with exactly where your gaps are.

Lvl · 5 minPlay
SimulationInternal Audit · AI

Auditing the Machine

Take the lead auditor’s chair on an AI loan-decisioning model. Scope it, risk-rank it, test it for real, and defend your opinion to the board.

Lvl · 12 minPlay
SimulationCyber · IR

Tabletop: Friday-Night Ransomware

You're the incident commander. Branching decisions, a nervous board, and a debrief that scores your calls.

Lvl · 10 minPlay
SimulationFintech · GDPR

Remediation Board: GDPR

A fintech DPO sim across three difficulty levels: triage eight live GDPR findings, build a risk-led plan under budget, then survive the quarter’s real-world events.

Lvl · 10 minPlay
SimulationFintech · CCPA/CPRA

Remediation Board: US Privacy

The fintech remediation board for US privacy: triage eight live CCPA/CPRA findings across three levels, then survive the quarter’s enforcement events.

Lvl · 10 minPlay
SimulationFintech · Saudi PDPL

Remediation Board: Saudi PDPL

The fintech remediation board for Saudi PDPL: triage eight live findings across three levels, then survive the quarter’s SDAIA-driven events.

Lvl · 10 minPlay
SimulationSAP S/4HANA

S/4HANA Cutover Sim

Run the final week before go-live and keep the controls intact under pressure.

Lvl · 9 minPlay
GameCybersecurity

Phishing Triage: 60 Seconds

Six inboxes, a ticking clock. Quarantine, escalate or release — and watch your false-positive rate.

Lvl · 6 minPlay
GameCybersecurity · AI

Inbox Under Siege

The flagship. A working email client, the hour before a payment run, and eight messages — some written by an AI adversary. Inspect, verify, and decide what to trust.

Lvl · 10 minPlay