Publication Date
7-27-2026
Abstract
In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life scenarios of four social engineering attacks: phishing, deepfakes, shoulder surfing, and baiting. During a single academic semester pilot study conducted for a local organization, the training program was implemented on ten employees, including cybersecurity professionals, human resources staff, and general employees. The employees were selected based on their prior vulnerability to social engineering attacks. We evaluated the training program using pre-game and post-game surveys, as well as in-game performance metrics, such as scenario-based scores and total game score. Results show a noticeable increase in user engagement and self-reported confidence in identifying and responding to different social engineering attacks. These results provide promising pilot evidence indicating that gamification can be used as a cybersecurity training and education tool, though these results should be tested on a larger scale.
Included in
Cybersecurity Commons, Educational Technology Commons, Game Design Commons, Information Security Commons