Microlearning for security awareness: design a short practice session

Design a short security awareness session around one workplace decision, meaningful feedback and a later revisit. Includes a complete facilitator-ready storyboard.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Scene from Data Dash.

Expand image

From the CyberPlay Data Dash gallery. Illustrative game scene; any interface text shown is in English.

Microlearning for security awareness is a short learning activity focused on a narrow objective. Its value depends on what the learner does in the time available. A brief video can introduce a rule; a short scenario can ask someone to apply it. Neither becomes effective simply by lasting five minutes. The useful design question is whether the session gives a person a clear decision, enough context and feedback they can use at work.

This guide provides an original session about an unexpected sign-in approval, including preparation, suggested timing, discussion prompts and a changed follow-up. The timing is an illustrative facilitation plan. Adapt it to the audience, language and device; there is no universal duration that guarantees learning or safe behaviour.

What you’ll take away

  • Choose one observable decision for each short session.
  • Include time for the learner to act and explain their reasoning.
  • Use feedback that gives a practical next step.
  • Revisit the same principle later with a different situation.

1. Define the scope before the duration

Start with an outcome small enough to practise coherently: when an unexpected sign-in approval appears, the employee will reject it and use the established reporting route. That outcome fits a short scenario. Covering password creation, identity theft, phishing, backups and incident response in one tiny module leaves too little room for a meaningful decision about any of them.

Write what the session will assess and what belongs elsewhere. A sign-in approval exercise can ask about context and reporting. It does not need to explain every authentication protocol. If learners lack the prerequisite knowledge, add a short explanation or schedule a separate foundation session before expecting an independent response.

2. Use learning research with care

Roediger and Karpicke’s 2006 experiments found that retrieval practice improved delayed recall of studied prose compared with repeated study under the tested conditions. That supports considering a later recall opportunity. It does not establish an ideal cybersecurity module length, prove transfer to workplace incidents or demonstrate an outcome for CyberPlay.

The practical implication for this design is deliberately modest: let people attempt a decision, explain it, then return to the principle later. Measure what they can do on the task you present. A claim about real-world reporting or fewer incidents would require separate evidence. Short sessions are a design option, not a substitute for evaluating the learning programme.

Section sources: Test-enhanced learning: taking memory tests improves long-term retention

3. Prepare the local process and the example

Confirm how employees should handle an unexpected approval request using the organisation’s approved sign-in and reporting procedures. Find the legitimate help contact and a fallback if the normal channel is unavailable. Make sure the facilitator can explain both. Do not teach an employee to call a number supplied by an unverified requester.

Create a fictional screen in plain text or an accessible visual. State that the employee has not started a sign-in. Keep personal accounts and real credentials out of the exercise. CISA’s reference includes multifactor authentication among its basic protective actions; this activity adds the practical question of what to do when an approval is unexpected.

Find the Fake Login gameplay: examining a sign-in page.

Expand image · Game screenshot · English interface

  1. Inspect the registrable domain

    Read the registrable domain carefully; familiar words elsewhere in an address do not establish its owner.

  2. Use your known portal

    Reach the service through a known portal and consider the context from your approved password manager.

Find the Fake Login gameplay: examining a sign-in page.

Section sources: Four Easy Ways to Stay Safe Online

4. Follow this complete session storyboard

The following eight-minute plan is an example, not a deadline for learners. Allow more time for reading, assistive technology or a useful question. For a group discussion, give participants a quiet moment to choose before hearing colleagues. Otherwise the first confident answer can hide the decisions other people would have made.

4. Follow this complete session storyboard
Suggested timeFacilitator actionLearner action
Minute 0–1State the role and objective: no sign-in has been started.Read the context and locate the relevant information.
Minutes 1–3Present the approval request and withhold the answer.Choose an action and briefly explain why.
Minutes 3–5Explain the consequences and the local approved response.Compare the feedback with the original reasoning.
Minutes 5–7Introduce a caller who claims the approval is needed for a repair.Apply the same verification principle to the changed request.
Minute 7–8Show the legitimate report route and invite a remaining question.Name where help would come from and one detail to report.
Context: Introduce one recognisable situation. Choice: Let the learner decide before explaining. Feedback: Show the evidence behind the safer action. Later revisit: Change the example and ask again.

Expand image

One short session, one decision. Timing is a design choice; keep space for meaningful feedback. Original CyberPlay explanatory diagram.

5. Present the decision before the explanation

Do not highlight the correct answer with a warning colour or label the screen as a scam before the learner chooses. Give the facts they need, then allow an authentic choice. The objective is to understand the decision, not to catch someone out with missing information. If several responses could be valid under your policy, acknowledge that and refine the prompt.

The Social Engineer gameplay: deciding how to handle an MFA prompt.

Expand image · Game screenshot · English interface

  1. Reject an uninitiated request

    Deny a sign-in approval you did not initiate, even if another message urges you to accept.

  2. Report through official support

    Contact the established helpdesk or security team and explain when the unexpected approval requests appeared.

The Social Engineer gameplay: deciding how to handle an MFA prompt.

6. Explain the consequence of each choice

For the approval choice, explain that an approval is part of granting account access and must correspond to an action the user intended. For the same-channel confirmation, explain why another message from the requester is not an independent check. For rejection and reporting, explain what a useful report contains: approximate time, affected service and what the person observed.

Keep the language calm and specific. A learner who chose incorrectly needs a usable alternative, not a dramatic prediction of catastrophe. Let them attempt a second version immediately after the explanation. Record the first attempt separately if you are evaluating the session; an improved retry and an independent first response answer different questions.

7. Choose an appropriate game segment

A short game activity fits when its mechanics expose the target decision clearly and its controls do not consume the whole session. Pilot the full path, including loading, instructions and any result screen. Read the actual game description and test the interaction before describing its duration to employees. Different learners may take different amounts of time.

Use the account-security topic directory to find relevant CyberPlay practice. After playing, ask the learner to connect one decision to the organisation’s sign-in procedure. Treat the game as a practice environment with its own rules. The facilitator’s job is to explain where those rules correspond to work and where local procedures add detail.

8. Schedule a changed follow-up

At a later session, change the story while preserving the principle. For example, a caller asks the employee to read out an account recovery code to keep a meeting service working. Ask the learner to identify the requested action, select a trusted check and name the reporting route without first displaying the previous answer.

Choose a practical interval and record it so results remain interpretable. If the employee can repeat the original answer but struggles with the changed request, use that as a cue for more varied practice. Do not assume the first session failed entirely or that a successful follow-up guarantees behaviour under every real-world condition.

The Social Engineer gameplay: checking a caller's claimed support role.

Expand image · Game screenshot · English interface

  1. Find the existing directory

    Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.

  2. Do not reuse supplied numbers

    A number supplied by the caller is part of the request and cannot independently verify it.

The Social Engineer gameplay: checking a caller's claimed support role.

9. Design for employees’ actual working time

Offer an equivalent text version when the format relies on sound, rapid mouse movement or a device unavailable to part of the workforce. Support pause and rereading. For facilitated groups, make sure quieter participants have time to form their own answer. For shift teams, schedule the activity when staff can take part without compromising operational responsibilities.

Avoid using short sessions as an excuse to interrupt work constantly. A predictable slot with a clear purpose is easier to explain and manage. NIST’s programme guidance treats learning as a maintained organisational activity. Assign someone to check that the content, reporting route and supporting policy remain current as the organisation changes.

Section sources: Building a Cybersecurity and Privacy Learning Program, SP 800-50 Rev. 1

10. Evaluate the session with a small design review

Use the checklist below after the pilot and the first delivery. The most useful improvement may be clearer context, a more plausible choice or a simpler reporting route. Keep observations about the interface separate from observations about the security decision. An employee who could not operate a control has not necessarily demonstrated a knowledge gap.

  • Can the objective be stated as one observable action?
  • Does the learner have enough information to make the decision?
  • Does feedback explain why each plausible action matters?
  • Can the employee perform the safe action using a real local process?
  • Is there enough time for access needs, reflection and questions?
  • Does the later scenario change the story while keeping the same principle?
  • Are reported outcomes limited to the evidence actually collected?

Put the decision into practice

Try an account-security scenario and identify one decision to connect to your own sign-in and reporting procedures.

Explore passwords games

Sources and further reading

  1. Test-enhanced learning: taking memory tests improves long-term retention — Roediger and Karpicke, Psychological Science; PubMed record. Accessed 2026-09-13
  2. Four Easy Ways to Stay Safe Online — CISA. Accessed 2026-09-13
  3. Building a Cybersecurity and Privacy Learning Program, SP 800-50 Rev. 1 — NIST. Accessed 2026-09-13

Keep exploring

All articles

Contact · About