About the model
What the simulation simplifies and why. A model is always a simplification, and anyone who knows where the simplifications sit can trust the rest.
Why a model
The simulation is built to make the trade-offs of preparedness tangible: a limited budget, falling public support and capacity that does not stretch to everything. That requires reality to be boiled down. This page sets out the largest simplifications openly, with a reference to the book Sveriges digitala motståndskraft for the full picture. The book and the simulation share concepts, actors and scenarios; the book owns the depth.
National level, not the organisation's
You govern a country, not an organisation. The reporting deadlines (early warning within 24 hours, incident notification within 72, final report within 30 days), management systems and individual controls are therefore abstracted into national decisions and sector capacity. In the simulation they appear as a line in the event texts; in reality they are the organisation's everyday work. Further reading: chapter 17, on incident handling and reporting.
Four meters
Resilience, economy, trust and geopolitics summarise thousands of real indicators in four numbers, so that the direction of a decision shows immediately. Note that the Resilience meter is the simulation's narrow measure of the ability to function, while the book's title concept is broader: the ability to prevent, withstand, manage, recover and learn. Further reading: chapter 12, on budgets and board communication, and key figures as a basis for decisions.
Capacity is built slowly
Sector capacity moves sluggishly: a budget shift takes years to work through, and a sector at a high level requires continuous funding just to stand still. That is deliberate. Capability is built in years, not in budget lines, and money never replaces people. Further reading: chapter 9, on building a cyber security strategy, and chapter 13 on the road to a management system.
The budget as an annual appropriation
The state budget is set as percentages with a reserve for crises, repair and investment. The real budget process is continuous negotiation; the simulation's is a slider, so that the trade-off between sectors is the whole game. Further reading: chapter 12.
The events are inspired, not reproduced
The crises are built on real incidents but moved in time, place and scale, and the models are set out after each decision and on the page About the simulation. The simulation deliberately names no attacking states; the book describes the categories of actor and their methods. Further reading: chapter 2, on hackers and threat actors, and chapter 24, on the horizon.
The attribution mechanic
For events with an unclear cause, the simulation decides at random, at 55 against 45 in favour of intent, whether the investigation lands on intent or accident. Real attribution is months of technical investigation and intelligence work, not chance. The mechanic portrays the decision maker's dilemma: you have to act before the answer exists. Further reading: chapter 1, section 1.1 on the grey zone, and section 24.5 on hybrid threats.
The shadow account
After every crisis the simulation shows the damage your investments averted. In reality no such account exists: averted damage does not show up in any follow-up, and that is the very reason preparedness is hard to fund. The shadow account is therefore not realism, it is the point. Further reading: chapter 12, on the cost of not investing.
The live response
The real-time responses compress days and weeks of operational incident handling into minutes, so that the difference between built and neglected capability becomes tangible in the hand. The effect of the tools follows sector capacity, research, materiel and cultural layers, not skill with the mouse: anyone who abstains can always leave the response to standing routines. Further reading: chapter 16, on the SOC and the IRT, and chapter 17.
The preparedness mechanics and the book
Four of the simulation's mechanics are built directly from the book's theses:
- Three layers: resilience is built in the layers of technology, organisation and culture, where culture decides and technology can always be circumvented. Attacks aimed at people go around technical protection. Section 1.8.
- Tabletop exercises: a plan that has never been drilled is a hypothesis. Undrilled areas handle their first real crisis worse. Chapters 17.7 and 23.6.
- Threat intelligence sharing: joining MISP-SE gives forewarning ahead of cyberattacks. Low cost, clear benefit, a collective investment. Chapter 22.
- Diversification: the single-vendor strategy is efficient in peacetime and dangerous in a crisis. Diversified dependencies dampen supplier incidents. Chapters 7 and 23.5.
Supply preparedness
The supply part is built on Sweden's national strategy for supply preparedness for the total defence period 2025 to 2030. The strategy's three goals, to maintain flows, to compensate for disruptions and to prioritise in shortage, correspond to the three ways the player can meet a supply crisis: analyse and diversify in advance, stock up endurance to draw on, and finally ration or requisition at a political price.
The simulation simplifies heavily. The strategy's twelve preparedness sectors are folded into the simulation's eight budget sectors, which already carry the budget sliders and the capacity requirements. Seven of them can hold stock: education has no supply dimension in the strategy and therefore gets none. Endurance is measured in whole months and is consumed only by the events that actually break a flow.
Two deviations are worth naming. The emergency stock protects the meters but does not prevent physical destruction of facilities, and it also speeds up repairs in its own sector, because spare parts on the shelf do exactly that. The link between geopolitics and imports affects how hard an externally caused disruption strikes, not how often it occurs, so that chance in the simulation stays comparable between runs.
Rationing and requisition are handled as two levers, while reality requires regulations, agency decisions and long preparation. Repair preparedness shortens the monthly recovery; the direct repair for money in the facility panel is unchanged, and is a simplification in itself. The purpose is to make the trade-offs comprehensible, not to predict outcomes.
The goal is resilience, not invulnerability
The win condition, that society still works when the period is over, is the book's core message in playable form: nobody can guarantee never being hit, and the ability to withstand, adapt and recover is the real goal. Further reading: section 1.8, Resilience, not invulnerability.