About the simulation
A national preparedness simulation, and the reality behind it.
What is Resilience?
You govern a Nordic or Baltic country from 2026 to 2040. The choice is between Sweden, Finland, Estonia, Norway and Denmark, each with its own strengths and vulnerabilities. You allocate the state budget across eight sectors of society, repair and harden the infrastructure on the map and handle the crises that interrupt: cyberattacks, sabotage, information influence and extreme weather. Three world situations set the pressure: Stable world, Rising tension and Hybrid war.
Elections are held in 2030, 2034 and 2038, and public support decides whether you get to continue. Three of the eight sectors are visible to voters, five are not. What keeps the country running through the crises is largely what the voters never see.
You do not win by defeating an opponent. You win if society still works when the period is over. A run ends in one of six grades, from Robust down to Kollaps. The grade labels stay in Swedish in every language: they identify a result on the leaderboard and in your profile, and a translated label would look like a different result.
Resilience, not invulnerability
"A decisive insight for anyone taking on information security is that it is not about making yourself invulnerable. No organisation, whatever its size or resources, can guarantee that it will never be attacked. Resilience, meaning the ability to withstand, adapt and recover, is the real goal."
From section 1.8 of the book Sveriges digitala motstÄndskraft (2026), in Swedish.
That is exactly how the simulation is built: you do not win by never being hit, but if society still works when the period is over. The book is the depth, the simulation is the exercise, and events with a counterpart in the book show a chapter reference after each decision.
What the simulation simplifies
A model is always a simplification. The level is national, the meters are four, attribution is settled before the investigation is finished, and the shadow account shows what in reality is never seen. Every major simplification, and why it was made, is set out on the page About the model.
Crises and live response
The register holds 31 major events: cyberattacks, sabotage, information influence, extreme weather and supply crises, plus the occasional offer. On top of that comes a stream of minor incidents that do not pause the run. Some events raise the attribution question: accuse early or wait for the investigation, at the risk of being wrong in either direction.
Many crises play out in real time on the map in a live response mode, where drones, malicious code, physical actors at sea and influence campaigns are met with six tools: air defence, cyber defence, coast guard, fact checking, jamming and isolating a facility. The strength of the tools follows the capacity of the sectors, and anyone who would rather not can always leave the response to standing routines.
Build capability over time
- Research: three tracks (cyber capability, energy resilience, communications) of three steps each, one programme at a time.
- Materiel: two purchasable levels per tool that shorten the reload and strengthen the effect. A third step exists but is unlocked only through a licence agreement later on.
- Deployed defences: four types of unit (air defence battery, patrol boat, close-in protection and jamming mast) that are positioned freely on the map and act automatically during a live response. Two to five positions depending on defence capacity. Upkeep is charged every January. If it does not fit, units are mothballed, and knocked-out equipment can always be repaired.
Exercises
There are 8 curated exercise scenarios with a standardised starting position, a guaranteed crisis and a debrief: Monday Morning as the introduction, then The Care Chain, Blackout, The Deep, The Grid, False Images, Grey Zone, the hardest of them, and The Flow, where two sectors are cut off from supply at once and the stocks are not enough for both. The exercises award their own exercise badges but never count towards the campaign record, the leaderboard or the team list. They exist to teach.
Awards and readiness rank
The simulation quietly notes 27 awards in four categories: Learning, Skill, Exploration and Adversity. Nerves of steel is awarded when you hold back an accusation and the investigation proves you right. Before the storm requires a facility hardened in advance to still be standing when the crisis hits. The whole map sheet awaits anyone who completes the period with all five countries.
The awards, the completed countries and the Robust grades together build your readiness rank: 5 career steps from Case officer through Assistant director, Deputy director and State secretary to National security adviser. 6 of the awards require a certain rank before they can be taken.
The reality behind the crises
The events in the simulation are fictional but built on real incidents. Some of the models:
- NotPetya (2017): malicious code that spread through an update to Ukrainian accounting software and then globally. The shipping company Maersk had to rebuild large parts of its IT estate.
- WannaCry (2017): ransomware that among other things paralysed parts of the British NHS.
- SolarWinds (2020): a backdoor distributed through signed software updates to thousands of organisations, undetected for months.
- The CrowdStrike incident (2024): a faulty content update knocked out millions of Windows systems in a few hours. Airlines, hospitals and government agencies stood still without anyone having attacked.
- The attacks on Ukraine's power grid (2015 and 2016): attackers remotely operated breakers and knocked out the electricity supply for hundreds of thousands of customers.
- Oldsmar, Florida (2021): the dosing of sodium hydroxide at a water treatment plant was raised sharply before an operator intervened. The incident was first described as an intrusion via open remote access, but the investigation later pointed to an operating error.
- Viasat KA-SAT (2022): satellite modems were knocked out across large parts of Europe in the same hour as the invasion of Ukraine began.
- Balticconnector and the Baltic Sea cables (2023 to 2025): damage to a gas pipeline and data cables where the investigations struggled to tell negligence from intent.
- GPS jamming over the Baltic Sea (since 2022): recurring large-scale disruption of satellite navigation that has affected both civil aviation and shipping.
- The election in Slovakia (2023): a manipulated audio recording of a party leader spread in the days before the vote, during the pre-election blackout when it was hardest to answer.
- The forest fires in Sweden (2018): around 25 000 hectares burned and Sweden requested international support through the EU mechanism.
After every crisis the real background is shown. The tone is factual: the simulation wants to show how preparedness works, not to frighten.
The map and data sources
The coastlines come from Natural Earth 1:50m. The place names, lakes and major roads on the map come from Natural Earth 1:10m. All map data is public domain. The world watch notices are drawn from open sources, and their licences are stated on that page.
Technology and account
The simulation runs entirely in your browser, without installation and without tracking. The core is deterministic: leaderboard results are verified by the server by replaying the run from its seed and decision log.
An account is optional and is used for the leaderboard, for teams and to sync awards, readiness rank and exercise badges between devices. You sign in with an email address and a password, and a merge can never lower your rank. If you play without an account, records and awards are stored only locally in your browser. Read more in How we handle your data.
With an account you can also create a team and compete together with others: a crisis management group, a training room or a course. Whoever creates the team invites others with a share link or by email, and you can be in one team at a time. The team's name and member list are public, just like the leaderboard.
Teams are ranked on the average score of the members who have played during the period. A large team therefore gains no advantage from being large, and a team qualifies for the list only once several of its members have played. Beside the average stands the team's readiness rank, the world situation the team plays most often, and what you have gathered together: countries, crisis scenarios, awards and completed runs.
Two of the figures are deliberately counted differently. The readiness rank is counted over all members, because a rank is something you carry with you, while the score is counted only over those who have played during the period: a zero for someone who has not had time to play would turn the list into a measure of diligence instead of skill. And what the team has gathered always counts across all time, whatever period you have chosen, because awards and visited countries do not carry a date.
Publisher
Resilience is an independent product from VER&IT AB. It is not published by, and was not commissioned by, any government agency.