Interactive IT Security Training: Comparing an Attacker-Centric IT Security 2D RPG and Text Policy Training
2026Conference / Journal
Research Hub
Hub 5: Human-Centered Security and Privacy
Abstract
Game-based approaches are increasingly used in security awareness and training, yet their impact on recall performance compared to traditional formats remains insufficiently examined, particularly for conveying organizational security policies. Role-playing games (RPGs) offer interactive, narrative-driven experiences, but empirical evidence in organizational contexts is inconclusive.
We address this gap by developing a 2D IT security role-playing serious game designed to convey corporate policies within a fictional organizational scenario. We evaluate this approach in a controlled between-subjects experiment with 168 employees, comparing RPG-based, text-based, and hybrid formats. Outcomes include training experience and free recall of policies.
Our results show that game-based and hybrid formats did not improve overall policy recall compared to text-based training. For two policies, recall is higher in the text condition. Although interactive formats increase engagement, these gains do not translate into improved recall, highlighting the need to critically reassess game-based approaches for policy communication.