CyberPlay editorial team · Published · Updated · 8 min read
Guide and exercises in English

Game-based learning uses the activity of playing a game to help someone practise a skill or decision. Gamification adds game elements, such as points, badges or progress, to an activity. The distinction is useful, but a label alone says little about what an employee will learn.
For security awareness, the better question is what the learner actually does. Do they merely collect points for finishing content, or must they examine evidence, choose an action and deal with its consequences? This guide compares formats through one workplace objective and provides an original worksheet for inspecting the learning interaction itself.
What you’ll take away
- Judge the decision, consequence and feedback rather than the format label.
- Points can support participation without demonstrating security skill.
- A good branching scenario may be more suitable than a complex game.
- Combine formats and test a changed scenario before claiming learning transfer.
Use clear working definitions
In this guide, gamification means adding game elements to an existing learning or work activity. A progress bar, badge for completing lessons, or team points competition can be examples. Game-based learning means using a game’s rules and actions as the practice environment. A branching scenario presents choices with different subsequent situations and may sit between these approaches.
The boundaries overlap. A game can award badges; a short lesson can contain a meaningful decision; a branching story can have a complete game structure. Avoid turning the terminology into a ranking. Explain the objective and inspect the experience before deciding whether a particular approach fits the audience.
Compare three approaches to the same objective
Use a single objective: “Verify a changed supplier payment instruction through an established channel.” In a gamified lesson, the learner might read the rule and earn points for answering a question. In a branching scenario, they choose who to call and see how the conversation develops. In a game, they may need to manage several supplier requests while keeping verification and delivery work on track.
Each can be designed well or poorly. The original comparison below describes hypothetical formats, not claims about a specific product. It helps you identify which part of the objective is practised and which part needs a separate discussion or exercise.
| Format | What the learner does | What to inspect |
|---|---|---|
| Lesson with points | Reads the rule and answers a question | Does feedback explain the verification action? |
| Branching scenario | Chooses a contact route and response | Do branches reflect plausible consequences? |
| Decision-driven game | Balances requests while applying the rule | Can safe work succeed without relying on reflexes? |

Expand image · Game screenshot · English interface
- Compare the changed details
Check which payment details changed and whether the request matches the expected invoice and work.
- Compare with trusted records
Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.
Understand what points can and cannot show
Points can make progress visible and create a reason to return. They can also reward the wrong behaviour if speed, repeated guessing or unrelated movement dominates the result. Ask what earns a point and whether that action corresponds to the security objective. A score becomes interpretable only when you understand its rules.
If learners receive points for completion, report participation. If the score combines accuracy and time, separate those elements when discussing performance. Avoid interpreting a leaderboard position as a measure of workplace trustworthiness. People may have different devices, language fluency, motor ability or familiarity with games, none of which should be confused with their willingness to work safely.
Look for a security rule that changes the game
A meaningful mechanic gives the security rule a role in the player’s decisions. If the objective concerns access, granting access without checking should change what can happen next. If the objective concerns verification, an independent check should provide information or enable a safer action. The connection should be understandable to the learner.
A useful inspection technique is to describe the activity without its artwork. What choices remain? What does the player learn from the outcome? If the explanation is “finish an unrelated puzzle, then read a tip”, the security content may need stronger integration. That does not make the puzzle worthless, but it changes the claim you can make about the practice.

Expand image · Game screenshot · English interface
- Check the application publisher
Review the publisher and the intended purpose before treating an application's familiar appearance as trustworthy.
- Limit the requested access
Grant only permissions justified by the task and approved process; pause when broader access needs explanation.
Make consequences informative and recoverable
A consequence should illuminate the decision, not merely punish the player. Show what evidence was missed, why the selected route was weak, and what another action would establish. Let the learner try again with a changed detail so they can apply the explanation. A dramatic failure screen without a clear lesson adds little.
Handle safe choices with equal care. Explain why verification was useful even when a request turned out to be legitimate. Avoid designing every scenario so that refusal is the winning move. Employees need to complete ordinary work, ask appropriate questions and handle uncertainty. Those are richer objectives than identifying every message as malicious.
Read game research with its limits attached
The What.Hack study reported improved immediate phishing classification in a small student experiment. Its use of repeated test messages and its short evaluation window limit conclusions about retention and workplace transfer. It offers a useful design example, not proof that every game is effective.
A buyer should ask whether an evaluation measures enjoyment, knowledge, an in-game skill, later recall or behaviour in normal work. Those outcomes are related but distinct. If the comparison group receives different content or practice time, the result may also reflect those differences. Keep the study’s actual question attached to any claim made from its findings.
Section sources: What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game
Compare current products without caricatures
SoSafe publicly describes gamified, story-based and role-based training. That illustrates why a vendor cannot be reduced to a single format label. Inspect the selected activity rather than assuming a product offers only passive lessons.
CyberPlay’s catalogue centres on games for security practice. Its educational promise should be assessed through the same lens: which decision is practised, what feedback is provided, and whether the experience fits the learner. Use a demonstration and a pilot to establish the answer. A platform’s general positioning is a starting point, not evidence that every activity meets every objective equally well.
Section sources: Security awareness training
Use an original interaction inspection worksheet
Choose one activity and work through the rows below with a facilitator and an intended learner. Write a concrete observation in each row. “Engaging” is too vague; “the learner inspected the full destination before choosing” is a usable observation. Record an accessibility barrier as a requirement to address, even if other participants enjoyed the activity.
| Inspection question | Record this evidence |
|---|---|
| What is the consequential choice? | The exact action the learner selects |
| What information can they inspect? | Evidence available before deciding |
| What does the consequence teach? | The causal connection explained by the activity |
| Can legitimate work succeed? | A safe route that completes the intended task |
| Does feedback support another attempt? | The rule the learner applies to a changed case |
| Can the audience participate? | Language, device, controls and equivalent alternatives |
| How does this connect to work? | The local procedure or contact used in the debrief |
Combine formats around a coherent sequence
A short explanation can introduce the rule, a scenario can demonstrate it, a game can provide practice, and a facilitated discussion can connect it to local procedures. Choose only the parts that serve the objective. More formats do not automatically make a programme better, especially if they repeat the same content without a new task.
NIST SP 800-50r1 includes continuing evaluation and improvement in its learning-programme approach. Use employee questions and observed errors to decide what comes next. If people understand the rule but cannot find the approved contact, the next intervention may be a clearer workflow rather than another module.
Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1
Check the decision after the game is over
Later, present an unfamiliar example with the same underlying objective. Change the supplier name, the communication channel or the reason for urgency. Ask the learner to choose the next action and explain why. This gives more useful evidence than asking them to replay an identical level until they memorise the answer.
Keep the result’s meaning precise. Success in the new exercise supports performance on that task; it still does not prove a reduction in real incidents. Explore CyberPlay’s relevant topic games, select one that fits the objective, and use the worksheet to decide how to facilitate it. The method earns its place when the learner can use the decision principle beyond the original screen.

Expand image · Game screenshot · English interface
- Find the existing directory
Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.
- Do not reuse supplied numbers
A number supplied by the caller is part of the request and cannot independently verify it.
Put the decision into practice
Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.
Explore practice gamesSources and further reading
- What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game — Cornell University / CHI 2019. Accessed 2026-09-13
- Security awareness training — SoSafe. Accessed 2026-09-13
- Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13
Keep exploring
- Security awareness games for employees: how to choose and use them
Choose security awareness games that teach useful workplace decisions. Compare formats, run a sample session, and use a practical evaluation checklist.
EN · 8 min read - Microlearning for security awareness: design a short practice session
Design a short security awareness session around one workplace decision, meaningful feedback and a later revisit. Includes a complete facilitator-ready storyboard.
EN · 8 min read - Security awareness training metrics: measure more than completion
Measure security awareness with a practical metric dictionary covering participation, decisions, retention and reporting, plus fair comparisons and clear limits.
EN · 8 min read - Phishing training games: practise the decisions behind a suspicious message
Use phishing training games to rehearse inspection, independent verification and reporting. Includes a fictional supplier message and a practical session plan.
EN · 8 min read - Human risk management metrics: turn CyberSense into a coaching plan
Read coverage, CyberSense and learning priorities by department. Use a worked example to choose employee coaching, assign practice and review the evidence.
EN · 7 min read - NIS2 security awareness training: a practical programme and evidence checklist
Plan NIS2 security awareness training by role, connect activities to risks, and keep useful evidence. Includes management and employee training distinctions.
EN · 8 min read