•  
  •  
 

Publication Date

7-21-2026

Abstract

This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established instrument. Among implementation-based interventions such as labs, ranges, and CTFs, only 22.5% provided publicly accessible artifacts for reuse. Overall, the findings indicate that the field prioritizes intervention development over empirical evaluation. As cybersecurity education continues to mature, stronger assessment practices and greater accessibility of educational artifacts can help identify effective interventions, support broader adoption, and provide clearer evidence of cybersecurity skill development.

Share

COinS