Skip to main content

Advertisement

Log in

A novel SETA-based gamification framework to raise cybersecurity awareness

  • Original Research
  • Published:
International Journal of Information Technology Aims and scope Submit manuscript

Abstract

Information is a critical asset in any organization to achieve its strategic goals. For this, organizations enforce physical, logical, and administrative controls to protect their information from being corrupted, manipulated, or breached. However, an employee with little awareness of cybersecurity threats is an easy target for attackers. Nowadays, companies implement security awareness using policies, procedures, and training sessions, to list a few. Traditional information security awareness sessions have relied heavily on presentation slides and videos. This paper aims to improve the employees’ cybersecurity awareness by developing an interactive video game, a cyber shield game, that includes various embedded threat scenarios. The proposed game consists of four levels. The password complexity level educates players about password threats. The social engineering level aware employees about email attachments and trespass threats. The phishing attack level educates employees about phishing emails and ransomware threats. Finally, the physical security level aware employees about threats to storage and work documents’ disposal. Further, two surveys, pre-game and post-game, are conducted to estimate the players’ knowledge and experience in cybersecurity threats. The proposed security awareness program is applied to ten employees randomly chosen from different organizations. Experimental results indicate that the cyber shield training and awareness program is more interactive than traditional awareness methods. Results also suggest that the proposed awareness program improves the employees’ cybersecurity awareness level by 51.4%.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Fig. 1
Fig. 2
Fig. 3
Fig. 4
Fig. 5
Fig. 6
Fig. 7
Fig. 8
Fig. 9
Fig. 10
Fig. 11

Similar content being viewed by others

References

  1. Hendrix M, Al-Sherbaz A, Bloom V (2016) Game-based cybersecurity training: are serious games suitable for cybersecurity training? Int J Serious Games 3(1):53–61

    Article  Google Scholar 

  2. Gjertsen EGB., Gjære EA, Bartne M, Flores WR (2017) Gamification of information security awareness and training. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy, pp. 59–70.

  3. Boopathi K, Sreejith S, Bithin A (2015) Learning cybersecurity through gamification. Indian J Sci Technol 8(7):642–649

    Article  Google Scholar 

  4. Antonaci A, Klemke R, Stracke C, Specht M (2017) Gamification to empower information security education. GamiFIN Conference, pp. 32–38, Pori, Finland

  5. Scholefield S, Shepherd L (2019) Gamification techniques for raising cybersecurity awareness. 1st International Conference on HCI for Cybersecurity, Privacy and Trust.

  6. Rieff I (2018) Systematically applying gamification to cybersecurity awareness trainings: a framework and case study approach. Delft University of Technology, pp 1–14

    Google Scholar 

  7. Alotaibi F, Furnell S, Stengel I, Papadaki M (2016) A review of using gaming technology for cyber-security awareness. Internat J Inform Security Res. https://doi.org/10.20533/ijisr.2042.4639.2016.0076

    Article  Google Scholar 

  8. Cook A (2016) Using gamification to raise awareness of cyber threats to critical national infrastructure. 4th International Symposium for ICS & SCADA Cyber Security Research, pp. 84–94.

  9. Labuschagne WA, Burke I, Veerasamy N, Eloff MM (2011) Design of cybersecurity awareness game utilizing a social media framework. Conference Information Security South Africa, pp. 1–9.

  10. Alotaibi F (2018) Design and evaluation of mobile games for enhancing cybersecurity awareness. J Internet Technol Secur Trans 6:2

    Google Scholar 

  11. Bada M, Nurse J (2019) Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Inform Comput Sec 27(3):393–410

    Google Scholar 

  12. Khando K, Shang G, Sirajul M.I, Ali S (2021) Enhancing employees information security awareness in private and public organisations: a systematic literature review. Comput Sec 106.

  13. Gjertsen E, Gjære E, Bartnes M, Flores WR (2017) Gamification of information security awareness and training. Science and Technology Publications, pp 59–70

    Google Scholar 

  14. Chau C, Tsui Y, Cheng C (2019) Gamification for internet gaming disorder prevention: evaluation of a wise IT-Use (WIT) Program for Hong Kong Primary Students. Front Psychol.

  15. Kovacevic A, Radaenkovic SD (2020) SAWIT—security awareness improvement tool in the workplace. Appl Sci 10:9

    Google Scholar 

  16. Mario S, Paul BL (2020) Using design-science based gamification to improve organizational security training and compliance. J Manag Inf Syst 37(1):129–161

    Article  Google Scholar 

  17. Zuopeng JZ, Wu H, Wenzhuo L, Mhammed A (2021) Cybersecurity awareness training programs: a cost-benefit analysis framework. Ind Manag Data Syst 121(3):613–636

    Article  Google Scholar 

  18. What is PyCharm? (2020) https://intellipaat.com/blog/what-is-pycharm.

  19. Surwade AU (2020) Phishing email is an increasing menace. Int J Inf Technol 12:611–617. https://doi.org/10.1007/s41870-019-00407-6

    Article  Google Scholar 

  20. Rosa GHD, Roder M, Santos DFS (2021) Enhancing anomaly detection through restricted Boltzmann machine features projection. Internat J Inform Technol 13:49–57. https://doi.org/10.1007/s41870-020-00535-4

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Fadi Abu-Amara.

Rights and permissions

Reprints and permissions

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Abu-Amara, F., Almansoori, R., Alharbi, S. et al. A novel SETA-based gamification framework to raise cybersecurity awareness. Int. j. inf. tecnol. 13, 2371–2380 (2021). https://doi.org/10.1007/s41870-021-00760-5

Download citation

  • Received:

  • Accepted:

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1007/s41870-021-00760-5

Keywords

Navigation