The most costly mistakes in business rarely appear to be mistakes at the time the decision is made. Cutting stock improves working capital, consolidating infrastructure reduces costs, and automation reduces labour intensity. The problem only becomes apparent later, when a decision that seems rational in isolation triggers a chain of consequences in other parts of the organisation.
It is precisely this mechanism that well-designed strategic games and business simulations bring to light. Their significance does not lie in ‘gamifying’ work. It is about the ability to observe a system in which a decision has a cost, a delay, unintended consequences and influences the behaviour of other participants.
The need for this way of thinking grows in line with the complexity of organisations. In a 2026 PwC survey of 4,454 CEOs from 95 countries, only 30 per cent expressed high confidence in revenue growth over the next 12 months. At the same time, 56 per cent of companies have not yet seen either a rise in revenue or a reduction in costs thanks to AI. Cyber threats are already recognised as a significant risk by 31 per cent of CEOs. Management teams must therefore simultaneously invest in technology, control costs and manage risks, the sources of which often lie beyond the boundaries of a single department.
A classic example is the Beer Distribution Game developed at MIT. Participants manage four links in the supply chain: the shop, the wholesaler, the distributor and the manufacturer. A slight change in demand can trigger sharp fluctuations in orders and stock levels throughout the system. This is a model of the bullwhip effect, one of the best-documented problems in logistics.
John Sterman’s experiments reveal something more interesting than the forecasting problem itself. Even when demand is constant and known to the participants, excessive orders and destabilisation of the chain still occur. The root of the problem lies in people’s behaviour and their reactions to delays and the decisions of other participants in the system. MIT also describes experiments in which managers of large companies did not achieve significantly better results in this game than much less experienced participants.
A similar mechanism occurs in cybersecurity. A study published in *The Journal of Strategic Information Systems* analysed 1,479 simulation rounds concerning the development of cybersecurity capabilities. Experienced specialists did not perform any better than the control group when it came to assessing the delays between investing in security measures and achieving actual resilience. However, they demonstrated a greater ability to learn in subsequent rounds that actions must be taken before an incident occurs. Professional experience alone did not, therefore, compensate for errors in understanding the dynamic system.
This model has now moved beyond the training rooms. AWS recommends regular ‘game days’, during which teams simulate failures whilst simultaneously testing technology, procedures, communication and individual accountability. AWS documentation explicitly states that these exercises should also involve business owners, and one of the typical mistakes organisations make is having procedures that have never been tested in practice.
Capital One conducts such exercises every month. The company has moved from quarterly cross-region switchover tests to regular experiments using chaos engineering. Combined with service recovery automation and dependency management tools, this has reduced system recovery times from hours to minutes and cut the number of critical-severity incidents by 80–90 per cent. This is not the result of the game itself, but an example of an organisation that has replaced the assumption of resilience with regular testing.
The European DORA introduces a similar approach. Financial institutions are required to maintain a digital operational resilience testing programme and to subject systems supporting critical or significant functions to appropriate tests at least once a year. The regulation explicitly mentions scenario-based testing alongside penetration, performance and end-to-end testing.
Strategic simulations therefore become important where an organisation’s knowledge of individual components is insufficient. AI, the cloud, cybersecurity and the supply chain are all interdependent systems. One may be familiar with each of their components and still fail to predict the behaviour of the whole system accurately. Simulation allows one to identify this error before the market, a customer or a real-world incident does.

