Game-based learning vs gamification in security awareness: what changes for the learner?

Compare game-based learning, gamification and branching scenarios in security awareness using one practical objective, research limits and an evaluation worksheet.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Scene from Password Builder.

Expand image

From the CyberPlay Password Builder gallery. Illustrative game scene; any interface text shown is in English.

Game-based learning uses the activity of playing a game to help someone practise a skill or decision. Gamification adds game elements, such as points, badges or progress, to an activity. The distinction is useful, but a label alone says little about what an employee will learn.

For security awareness, the better question is what the learner actually does. Do they merely collect points for finishing content, or must they examine evidence, choose an action and deal with its consequences? This guide compares formats through one workplace objective and provides an original worksheet for inspecting the learning interaction itself.

What you’ll take away

  • Judge the decision, consequence and feedback rather than the format label.
  • Points can support participation without demonstrating security skill.
  • A good branching scenario may be more suitable than a complex game.
  • Combine formats and test a changed scenario before claiming learning transfer.

Use clear working definitions

In this guide, gamification means adding game elements to an existing learning or work activity. A progress bar, badge for completing lessons, or team points competition can be examples. Game-based learning means using a game’s rules and actions as the practice environment. A branching scenario presents choices with different subsequent situations and may sit between these approaches.

The boundaries overlap. A game can award badges; a short lesson can contain a meaningful decision; a branching story can have a complete game structure. Avoid turning the terminology into a ranking. Explain the objective and inspect the experience before deciding whether a particular approach fits the audience.

Compare three approaches to the same objective

Use a single objective: “Verify a changed supplier payment instruction through an established channel.” In a gamified lesson, the learner might read the rule and earn points for answering a question. In a branching scenario, they choose who to call and see how the conversation develops. In a game, they may need to manage several supplier requests while keeping verification and delivery work on track.

Each can be designed well or poorly. The original comparison below describes hypothetical formats, not claims about a specific product. It helps you identify which part of the objective is practised and which part needs a separate discussion or exercise.

Compare three approaches to the same objective
FormatWhat the learner doesWhat to inspect
Lesson with pointsReads the rule and answers a questionDoes feedback explain the verification action?
Branching scenarioChooses a contact route and responseDo branches reflect plausible consequences?
Decision-driven gameBalances requests while applying the ruleCan safe work succeed without relying on reflexes?
Phishing Detective 3D gameplay: reviewing a supplier invoice.

Expand image · Game screenshot · English interface

  1. Compare the changed details

    Check which payment details changed and whether the request matches the expected invoice and work.

  2. Compare with trusted records

    Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Understand what points can and cannot show

Points can make progress visible and create a reason to return. They can also reward the wrong behaviour if speed, repeated guessing or unrelated movement dominates the result. Ask what earns a point and whether that action corresponds to the security objective. A score becomes interpretable only when you understand its rules.

If learners receive points for completion, report participation. If the score combines accuracy and time, separate those elements when discussing performance. Avoid interpreting a leaderboard position as a measure of workplace trustworthiness. People may have different devices, language fluency, motor ability or familiarity with games, none of which should be confused with their willingness to work safely.

Look for a security rule that changes the game

A meaningful mechanic gives the security rule a role in the player’s decisions. If the objective concerns access, granting access without checking should change what can happen next. If the objective concerns verification, an independent check should provide information or enable a safer action. The connection should be understandable to the learner.

A useful inspection technique is to describe the activity without its artwork. What choices remain? What does the player learn from the outcome? If the explanation is “finish an unrelated puzzle, then read a tip”, the security content may need stronger integration. That does not make the puzzle worthless, but it changes the claim you can make about the practice.

Find the Fake Login gameplay: reviewing an application's requested permissions.

Expand image · Game screenshot · English interface

  1. Check the application publisher

    Review the publisher and the intended purpose before treating an application's familiar appearance as trustworthy.

  2. Limit the requested access

    Grant only permissions justified by the task and approved process; pause when broader access needs explanation.

Find the Fake Login gameplay: reviewing an application's requested permissions.

Make consequences informative and recoverable

A consequence should illuminate the decision, not merely punish the player. Show what evidence was missed, why the selected route was weak, and what another action would establish. Let the learner try again with a changed detail so they can apply the explanation. A dramatic failure screen without a clear lesson adds little.

Handle safe choices with equal care. Explain why verification was useful even when a request turned out to be legitimate. Avoid designing every scenario so that refusal is the winning move. Employees need to complete ordinary work, ask appropriate questions and handle uncertainty. Those are richer objectives than identifying every message as malicious.

Gamification: Progress and rewards surround the activity. Branching scenario: Choices shape the next part of the story. Game-based practice: Rules and consequences require the skill.

Expand image

Three formats, one objective. Objective: verify an unexpected change to payment details. Original CyberPlay explanatory diagram.

Read game research with its limits attached

The What.Hack study reported improved immediate phishing classification in a small student experiment. Its use of repeated test messages and its short evaluation window limit conclusions about retention and workplace transfer. It offers a useful design example, not proof that every game is effective.

A buyer should ask whether an evaluation measures enjoyment, knowledge, an in-game skill, later recall or behaviour in normal work. Those outcomes are related but distinct. If the comparison group receives different content or practice time, the result may also reflect those differences. Keep the study’s actual question attached to any claim made from its findings.

Section sources: What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game

Compare current products without caricatures

SoSafe publicly describes gamified, story-based and role-based training. That illustrates why a vendor cannot be reduced to a single format label. Inspect the selected activity rather than assuming a product offers only passive lessons.

CyberPlay’s catalogue centres on games for security practice. Its educational promise should be assessed through the same lens: which decision is practised, what feedback is provided, and whether the experience fits the learner. Use a demonstration and a pilot to establish the answer. A platform’s general positioning is a starting point, not evidence that every activity meets every objective equally well.

Section sources: Security awareness training

Use an original interaction inspection worksheet

Choose one activity and work through the rows below with a facilitator and an intended learner. Write a concrete observation in each row. “Engaging” is too vague; “the learner inspected the full destination before choosing” is a usable observation. Record an accessibility barrier as a requirement to address, even if other participants enjoyed the activity.

Use an original interaction inspection worksheet
Inspection questionRecord this evidence
What is the consequential choice?The exact action the learner selects
What information can they inspect?Evidence available before deciding
What does the consequence teach?The causal connection explained by the activity
Can legitimate work succeed?A safe route that completes the intended task
Does feedback support another attempt?The rule the learner applies to a changed case
Can the audience participate?Language, device, controls and equivalent alternatives
How does this connect to work?The local procedure or contact used in the debrief

Combine formats around a coherent sequence

A short explanation can introduce the rule, a scenario can demonstrate it, a game can provide practice, and a facilitated discussion can connect it to local procedures. Choose only the parts that serve the objective. More formats do not automatically make a programme better, especially if they repeat the same content without a new task.

NIST SP 800-50r1 includes continuing evaluation and improvement in its learning-programme approach. Use employee questions and observed errors to decide what comes next. If people understand the rule but cannot find the approved contact, the next intervention may be a clearer workflow rather than another module.

Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1

Check the decision after the game is over

Later, present an unfamiliar example with the same underlying objective. Change the supplier name, the communication channel or the reason for urgency. Ask the learner to choose the next action and explain why. This gives more useful evidence than asking them to replay an identical level until they memorise the answer.

Keep the result’s meaning precise. Success in the new exercise supports performance on that task; it still does not prove a reduction in real incidents. Explore CyberPlay’s relevant topic games, select one that fits the objective, and use the worksheet to decide how to facilitate it. The method earns its place when the learner can use the decision principle beyond the original screen.

The Social Engineer gameplay: checking a caller's claimed support role.

Expand image · Game screenshot · English interface

  1. Find the existing directory

    Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.

  2. Do not reuse supplied numbers

    A number supplied by the caller is part of the request and cannot independently verify it.

The Social Engineer gameplay: checking a caller's claimed support role.

Put the decision into practice

Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.

Explore practice games

Sources and further reading

  1. What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game — Cornell University / CHI 2019. Accessed 2026-09-13
  2. Security awareness training — SoSafe. Accessed 2026-09-13
  3. Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13

Keep exploring

All articles

Contact · About