Ruhr-Uni-Bochum

Interactive IT Security Training: Comparing an Attacker-Centric IT Security 2D RPG and Text Policy Training

2026

Konferenz / Journal

Research Hub

Hub 5: Human-Centered Security and Privacy

Abstract

Game-based approaches are increasingly used in security awareness and training, yet their impact on recall performance compared to traditional formats remains insufficiently examined, particularly for conveying organizational security policies. Role-playing games (RPGs) offer interactive, narrative-driven experiences, but empirical evidence in organizational contexts is inconclusive.

We address this gap by developing a 2D IT security role-playing serious game designed to convey corporate policies within a fictional organizational scenario. We evaluate this approach in a controlled between-subjects experiment with 168 employees, comparing RPG-based, text-based, and hybrid formats. Outcomes include training experience and free recall of policies.

Our results show that game-based and hybrid formats did not improve overall policy recall compared to text-based training. For two policies, recall is higher in the text condition. Although interactive formats increase engagement, these gains do not translate into improved recall, highlighting the need to critically reassess game-based approaches for policy communication.

Tags

Human Factors in Security & Privacy: Groups
Human Factors in Security & Privacy: Individuals