This isn't an attack on cybersecurity. Every company needs good security. I'm genuinely curious whether other game developers have had similar experiences.
I sometimes wonder if many corporate cybersecurity policies are written with office software, web applications, and enterprise development in mind, without considering how different game development really is.
Game and simulation development is a very different discipline.
I've known simulation and game developers who went through intense vetting simply because they had legitimate development files, tools, SDKs, or assets that weren't on an approved list. Sometimes there wasn't even clear documentation explaining what was allowed or how to get approval. Instead, developers found themselves having to justify normal parts of their workflow and to defend even personal interests after being flagged. A few eventually left those companies and returned to studios where their work was better understood.
Access to information can also become a problem. Many websites are blocked simply because they're categorized as "gaming." But game developers don't visit those sites only to play games. We study gameplay mechanics, level design, UI patterns, AI behavior, balancing, animations, player feedback, technical articles, postmortems, and design discussions. Looking at existing games is part of learning the craft, just as filmmakers watch films, architects study buildings, and engineers study technical standards.
Then there's the day-to-day reality of development. We generate countless EXE files while building and testing. We install SDKs, drivers, graphics libraries, plugins, VR software, debugging tools, hardware utilities, and vendor software. We download EXE, MSI installers, DLLs, sample projects, open-source libraries, and small utilities to solve problems quickly. Some of the most useful development tools are decades old and still happen to be 32-bit. None of this is unusual. it's simply how game and simulation development works.
What becomes frustrating is when these completely normal game development and engineering activities are viewed without context. Instead of being recognized as part of a legitimate development workflow, they can sometimes be treated as suspicious. Developers end up spending more time explaining why they need a tool, a driver, an executable, or administrator access , USB access than actually writing code. For younger developers especially, it can feel intimidating when they don't have enough experience or influence to defend their workflow.
The irony is that many companies encourage innovation while their developers struggle to access the tools, references, and environments needed to build that innovation. Marketing teams are often encouraged to engage with external platforms and vendors, while development teams can face significant hurdles just to obtain legitimate development resources. One company I have known, had directed a simulation developer to format the computer immediately regardless of legitimate file and scanning proved to be all green, clear.
I believe cybersecurity should stop malicious activity. Not make legitimate software downloads, engineering unnecessarily difficult. The best security teams I've worked with understood the technology, documented their policies clearly, and collaborated with developers instead of assuming every exception was a security incident.
So I'm curious:
Have you ever been questioned for having "too many" EXE files?
Have legitimate tools, SDKs, drivers, or plugins been flagged in your workplace?
Have game development websites or reference material been blocked?
Have you struggled to get administrator rights or install software required for your work?
Do you think corporate cybersecurity policies adequately understand the realities of game development, graphics programming, simulation, XR, or embedded development?
I'd really like to hear experiences from game developers, technical artists, engine programmers, graphics programmers, simulation engineers, XR developers, and anyone else working in specialized software development.
Is this a common problem across the industry, or have I just encountered a few unusual environments?