Security awareness games for employees: how to choose and use them

Choose security awareness games that teach useful workplace decisions. Compare formats, run a sample session, and use a practical evaluation checklist.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Scene from Ghost Protocol.

Expand image

From the CyberPlay Ghost Protocol gallery. Illustrative game scene; any interface text shown is in English.

A useful security awareness game gives an employee a decision worth practising: whether to trust a payment request, approve a sign-in, share a document, or ask for help. The player acts, sees a consequence, receives an explanation, and tries a changed situation. That sequence is the centre of CyberPlay’s approach to education.

Choosing a game therefore starts with the work employees do. A colourful challenge can be enjoyable while teaching little about that work; a modest scenario can be valuable when its choices closely match a real responsibility. This guide helps programme owners choose an appropriate format, run a short pilot, and judge what the experience actually teaches.

What you’ll take away

  • Choose one observable security decision before choosing a game.
  • Check the feedback, controls and language with representative employees.
  • Combine game practice with your organisation’s procedures and a debrief.
  • Treat scores as evidence of performance in an activity, not proof of reduced business risk.

Start with a decision employees really make

Replace broad objectives such as “understand cybersecurity” with a sentence you can observe: “Before changing a supplier’s payment details, the learner verifies the request using an established contact.” That objective tells you what the game must allow. A challenge that only asks for the definition of phishing cannot demonstrate that decision.

Speak with the people doing the work before selecting examples. What makes verification difficult: an unavailable manager, an unfamiliar supplier portal, a shared device, or a deadline? Choose a game that exposes a relevant tension and leave time to discuss the parts of the workplace that differ. Your objective should stay stable even when the story, visual style, or difficulty changes.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Expand image · Game screenshot · English interface

  1. Compare the changed details

    Check which payment details changed and whether the request matches the expected invoice and work.

  2. Compare with trusted records

    Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Match the format to the learning job

Different formats reveal different things. A knowledge quiz can check whether a term is understood. A branching conversation can rehearse how to respond politely to pressure. A game with several competing tasks can show how a security check fits into an ongoing workflow. A team tabletop can expose missing responsibilities between departments.

Avoid choosing by novelty alone. Technical capture-the-flag exercises may suit specialists but often demand knowledge an ordinary employee does not need. Likewise, an arcade score may reflect movement skill as much as security judgment. Ask the supplier to show the particular decision you care about, including a mistaken choice and the feedback that follows.

Match the format to the learning job
FormatUseful forCheck before choosing
Quiz with feedbackChecking concepts and misconceptionsDoes the explanation teach a next action?
Branching scenarioRehearsing communication and escalationCan several reasonable routes succeed?
Decision-driven gamePractising choices across a changing situationDoes the security rule affect the outcome?
Facilitated tabletopClarifying team responsibilitiesAre decisions and follow-up owners recorded?

What the research supports

The CHI 2019 What.Hack study found improved phishing classification after a role-playing game in a study of 39 Cornell students. Its immediate post-test reused the pre-test messages. The result supports investigating contextual practice, but does not establish long-term workplace effectiveness or results for CyberPlay.

Use research to ask better evaluation questions. Who participated, what was compared, how was improvement measured, and how long did it last? For your own pilot, describe observations at the same level they were collected: learners explained a safer response, completed a challenge, or remembered a procedure later. A result becomes less useful when its label promises more than the measurement can show.

Section sources: What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game

Look closely at the feedback after a mistake

Good feedback identifies the action, explains the relevant evidence, and gives a usable next step. “Wrong answer” leaves the employee guessing. “The message changes payment instructions; confirm the change through the supplier contact already on file” gives them something to do on Monday morning.

Check whether feedback also handles safe decisions. If the learner rejects every message and still wins, the game may teach blanket avoidance. Include ordinary legitimate work, uncertain requests that need verification, and clear attacks. A strong debrief distinguishes what the player knew from what they inferred. It should explain uncertainty without suggesting that every imperfectly written message is malicious.

The Social Engineer gameplay: checking a caller's claimed support role.

Expand image · Game screenshot · English interface

  1. Find the existing directory

    Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.

  2. Do not reuse supplied numbers

    A number supplied by the caller is part of the request and cannot independently verify it.

The Social Engineer gameplay: checking a caller's claimed support role.

Run this original 15-minute sample session

Use the exercise below with fictional details and no live email. Allow two minutes to read, three minutes for individual choices, five minutes for discussion, and five minutes to connect the lesson to your procedure. These timings are facilitation suggestions, not a scientifically established optimum. Ask people to write their reason before seeing the answer so one confident colleague does not set the room’s response.

Notice: Identify the request and the situation. Decide: Choose what to inspect, verify or report. Understand: Explain why the outcome followed. Revisit: Apply the rule to a changed example.

Expand image

A decision is the learning unit. Practise a choice, understand the consequence, then try a new context. Original CyberPlay explanatory diagram.

Test access before inviting the whole organisation

Run the experience on the devices employees actually use, including a smaller screen if mobile access matters. Check readable text, zoom, keyboard operation, clear focus, audio alternatives, motion, timing pressure, and whether colour is the only signal. A learner who cannot control the game cannot meaningfully demonstrate the security decision.

Offer an equivalent discussion or text exercise when the selected game creates a barrier. Equivalent means practising the same objective and receiving the same feedback; it does not require reproducing every animation. Verify the language inside the game, including instructions and error messages, rather than assuming the catalogue’s translated navigation proves the entire experience is translated.

Use a pilot evaluation sheet

Invite employees from the intended audience and watch where they need assistance. Separate a misunderstood security rule from a confusing button or difficult control. Record concrete observations while the session is fresh, then decide whether to use the activity, adapt its facilitation, or choose a different format. Do not average a serious access barrier away inside a high overall satisfaction score.

Use a pilot evaluation sheet
CriterionEvidence to collectDecision
Relevant objectiveLearner describes the work decision in their own wordsUse / revise / replace
Meaningful choiceA safe and unsafe action have explainable consequencesUse / revise / replace
Useful feedbackLearner can state a better next action after a mistakeUse / revise / replace
Accessible participationIntended users can read, operate and finish with suitable alternativesReady / remedy required
Operational fitLearner can find the real reporting or verification routeReady / process gap
Reporting clarityAdministrator distinguishes activity records from learning claimsReady / clarify

Make games part of a continuing programme

NIST SP 800-50r1 treats cybersecurity learning as a programme that is evaluated and updated as needs change. Use a game within that wider cycle: explain the local rule, practise it, discuss obstacles, and revisit it after people have returned to normal work.

For example, begin with supplier verification, later change the channel to a phone call, and eventually introduce a request from a known but potentially compromised account. Keep the verification principle consistent while changing the surface clues. New starters may need the basic process first; experienced staff may benefit more from an exception scenario. A calendar should reflect those differences.

Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1

Measure a useful outcome without overclaiming

Record participation separately from performance. A completed game shows that an activity was completed under its own rules. A correct answer with an explanation gives different evidence. A later, unfamiliar scenario can explore retention. An observed workplace report concerns behaviour in a different setting. Keep these labels separate in your programme report.

For phishing exercises, NIST’s Phish Scale helps contextualise detection difficulty. A lower click rate on an easier message should not automatically be credited to training. Keep the audience, task and challenge difficulty in view when comparing sessions; also track whether employees know how to report uncertainty promptly.

Section sources: Phishing With a Net: The NIST Phish Scale and Cybersecurity Awareness

Choose the first game and prepare the debrief

Start with one audience and one decision. Explore CyberPlay’s topic collections, read the game details, and play through the chosen challenge yourself before assigning it. Prepare three debrief prompts: what evidence mattered, what action was available, and how the same choice works here.

After the session, choose one practical improvement. It might be a clearer reporting bookmark, a supplier verification contact, or a reminder for managers to support pauses under pressure. That improvement connects the experience to working conditions. Games can give employees a place to practise; the programme must also make safer decisions possible when the game is closed.

Phishing Detective 3D gameplay: connecting clues on an evidence board.

Expand image · Game screenshot · English interface

  1. Connect the available evidence

    Compare clues from different sources and explain which details support the decision you are considering.

  2. Separate facts from assumptions

    Record what you observed, what someone claims, and what still needs confirmation before drawing conclusions.

Phishing Detective 3D gameplay: connecting clues on an evidence board.

Put the decision into practice

Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.

Explore practice games

Sources and further reading

  1. What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game — Cornell University / CHI 2019. Accessed 2026-09-13
  2. Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13
  3. Phishing With a Net: The NIST Phish Scale and Cybersecurity Awareness — NIST. Accessed 2026-09-13

Keep exploring

All articles

Contact · About