CyberPlay editorial team · Published · Updated · 8 min read
Guide and exercises in English

A useful security awareness game gives an employee a decision worth practising: whether to trust a payment request, approve a sign-in, share a document, or ask for help. The player acts, sees a consequence, receives an explanation, and tries a changed situation. That sequence is the centre of CyberPlay’s approach to education.
Choosing a game therefore starts with the work employees do. A colourful challenge can be enjoyable while teaching little about that work; a modest scenario can be valuable when its choices closely match a real responsibility. This guide helps programme owners choose an appropriate format, run a short pilot, and judge what the experience actually teaches.
What you’ll take away
- Choose one observable security decision before choosing a game.
- Check the feedback, controls and language with representative employees.
- Combine game practice with your organisation’s procedures and a debrief.
- Treat scores as evidence of performance in an activity, not proof of reduced business risk.
Start with a decision employees really make
Replace broad objectives such as “understand cybersecurity” with a sentence you can observe: “Before changing a supplier’s payment details, the learner verifies the request using an established contact.” That objective tells you what the game must allow. A challenge that only asks for the definition of phishing cannot demonstrate that decision.
Speak with the people doing the work before selecting examples. What makes verification difficult: an unavailable manager, an unfamiliar supplier portal, a shared device, or a deadline? Choose a game that exposes a relevant tension and leave time to discuss the parts of the workplace that differ. Your objective should stay stable even when the story, visual style, or difficulty changes.

Expand image · Game screenshot · English interface
- Compare the changed details
Check which payment details changed and whether the request matches the expected invoice and work.
- Compare with trusted records
Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.
Match the format to the learning job
Different formats reveal different things. A knowledge quiz can check whether a term is understood. A branching conversation can rehearse how to respond politely to pressure. A game with several competing tasks can show how a security check fits into an ongoing workflow. A team tabletop can expose missing responsibilities between departments.
Avoid choosing by novelty alone. Technical capture-the-flag exercises may suit specialists but often demand knowledge an ordinary employee does not need. Likewise, an arcade score may reflect movement skill as much as security judgment. Ask the supplier to show the particular decision you care about, including a mistaken choice and the feedback that follows.
| Format | Useful for | Check before choosing |
|---|---|---|
| Quiz with feedback | Checking concepts and misconceptions | Does the explanation teach a next action? |
| Branching scenario | Rehearsing communication and escalation | Can several reasonable routes succeed? |
| Decision-driven game | Practising choices across a changing situation | Does the security rule affect the outcome? |
| Facilitated tabletop | Clarifying team responsibilities | Are decisions and follow-up owners recorded? |
What the research supports
The CHI 2019 What.Hack study found improved phishing classification after a role-playing game in a study of 39 Cornell students. Its immediate post-test reused the pre-test messages. The result supports investigating contextual practice, but does not establish long-term workplace effectiveness or results for CyberPlay.
Use research to ask better evaluation questions. Who participated, what was compared, how was improvement measured, and how long did it last? For your own pilot, describe observations at the same level they were collected: learners explained a safer response, completed a challenge, or remembered a procedure later. A result becomes less useful when its label promises more than the measurement can show.
Section sources: What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game
Look closely at the feedback after a mistake
Good feedback identifies the action, explains the relevant evidence, and gives a usable next step. “Wrong answer” leaves the employee guessing. “The message changes payment instructions; confirm the change through the supplier contact already on file” gives them something to do on Monday morning.
Check whether feedback also handles safe decisions. If the learner rejects every message and still wins, the game may teach blanket avoidance. Include ordinary legitimate work, uncertain requests that need verification, and clear attacks. A strong debrief distinguishes what the player knew from what they inferred. It should explain uncertainty without suggesting that every imperfectly written message is malicious.

Expand image · Game screenshot · English interface
- Find the existing directory
Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.
- Do not reuse supplied numbers
A number supplied by the caller is part of the request and cannot independently verify it.
Run this original 15-minute sample session
Use the exercise below with fictional details and no live email. Allow two minutes to read, three minutes for individual choices, five minutes for discussion, and five minutes to connect the lesson to your procedure. These timings are facilitation suggestions, not a scientifically established optimum. Ask people to write their reason before seeing the answer so one confident colleague does not set the room’s response.
Test access before inviting the whole organisation
Run the experience on the devices employees actually use, including a smaller screen if mobile access matters. Check readable text, zoom, keyboard operation, clear focus, audio alternatives, motion, timing pressure, and whether colour is the only signal. A learner who cannot control the game cannot meaningfully demonstrate the security decision.
Offer an equivalent discussion or text exercise when the selected game creates a barrier. Equivalent means practising the same objective and receiving the same feedback; it does not require reproducing every animation. Verify the language inside the game, including instructions and error messages, rather than assuming the catalogue’s translated navigation proves the entire experience is translated.
Use a pilot evaluation sheet
Invite employees from the intended audience and watch where they need assistance. Separate a misunderstood security rule from a confusing button or difficult control. Record concrete observations while the session is fresh, then decide whether to use the activity, adapt its facilitation, or choose a different format. Do not average a serious access barrier away inside a high overall satisfaction score.
| Criterion | Evidence to collect | Decision |
|---|---|---|
| Relevant objective | Learner describes the work decision in their own words | Use / revise / replace |
| Meaningful choice | A safe and unsafe action have explainable consequences | Use / revise / replace |
| Useful feedback | Learner can state a better next action after a mistake | Use / revise / replace |
| Accessible participation | Intended users can read, operate and finish with suitable alternatives | Ready / remedy required |
| Operational fit | Learner can find the real reporting or verification route | Ready / process gap |
| Reporting clarity | Administrator distinguishes activity records from learning claims | Ready / clarify |
Make games part of a continuing programme
NIST SP 800-50r1 treats cybersecurity learning as a programme that is evaluated and updated as needs change. Use a game within that wider cycle: explain the local rule, practise it, discuss obstacles, and revisit it after people have returned to normal work.
For example, begin with supplier verification, later change the channel to a phone call, and eventually introduce a request from a known but potentially compromised account. Keep the verification principle consistent while changing the surface clues. New starters may need the basic process first; experienced staff may benefit more from an exception scenario. A calendar should reflect those differences.
Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1
Measure a useful outcome without overclaiming
Record participation separately from performance. A completed game shows that an activity was completed under its own rules. A correct answer with an explanation gives different evidence. A later, unfamiliar scenario can explore retention. An observed workplace report concerns behaviour in a different setting. Keep these labels separate in your programme report.
For phishing exercises, NIST’s Phish Scale helps contextualise detection difficulty. A lower click rate on an easier message should not automatically be credited to training. Keep the audience, task and challenge difficulty in view when comparing sessions; also track whether employees know how to report uncertainty promptly.
Section sources: Phishing With a Net: The NIST Phish Scale and Cybersecurity Awareness
Choose the first game and prepare the debrief
Start with one audience and one decision. Explore CyberPlay’s topic collections, read the game details, and play through the chosen challenge yourself before assigning it. Prepare three debrief prompts: what evidence mattered, what action was available, and how the same choice works here.
After the session, choose one practical improvement. It might be a clearer reporting bookmark, a supplier verification contact, or a reminder for managers to support pauses under pressure. That improvement connects the experience to working conditions. Games can give employees a place to practise; the programme must also make safer decisions possible when the game is closed.

Expand image · Game screenshot · English interface
- Connect the available evidence
Compare clues from different sources and explain which details support the decision you are considering.
- Separate facts from assumptions
Record what you observed, what someone claims, and what still needs confirmation before drawing conclusions.
Put the decision into practice
Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.
Explore practice gamesSources and further reading
- What.Hack: Engaging Anti-Phishing Training Through a Role-playing Phishing Simulation Game — Cornell University / CHI 2019. Accessed 2026-09-13
- Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13
- Phishing With a Net: The NIST Phish Scale and Cybersecurity Awareness — NIST. Accessed 2026-09-13
Keep exploring
- Phishing training games: practise the decisions behind a suspicious message
Use phishing training games to rehearse inspection, independent verification and reporting. Includes a fictional supplier message and a practical session plan.
EN · 8 min read - Game-based learning vs gamification in security awareness: what changes for the learner?
Compare game-based learning, gamification and branching scenarios in security awareness using one practical objective, research limits and an evaluation worksheet.
EN · 8 min read - Security awareness training metrics: measure more than completion
Measure security awareness with a practical metric dictionary covering participation, decisions, retention and reporting, plus fair comparisons and clear limits.
EN · 8 min read - Human risk management: how organisations turn evidence into action
Learn what human risk management means, how it helps organisations and where CyberSense learning insights fit. A practical guide with examples and an exercise.
EN · 7 min read - Microlearning for security awareness: design a short practice session
Design a short security awareness session around one workplace decision, meaningful feedback and a later revisit. Includes a complete facilitator-ready storyboard.
EN · 8 min read - Human risk management metrics: turn CyberSense into a coaching plan
Read coverage, CyberSense and learning priorities by department. Use a worked example to choose employee coaching, assign practice and review the evidence.
EN · 7 min read