Sebastian Pape, Dennis-Kenji Kipker

Case Study: Checking a Serious Security-Awareness Game for its Legal Adequacy


It is generally accepted that the management of a company has a legal obligation to maintain and operate IT security measures as part of the company’s own compliance – this includes training employees with regard to social engineering attacks. On the other hand, the question arises whether and how the employee must tolerate associated measures, as for example social engineering penetration testing can be very intrusive.

