[Paper Review] Engaging Users with Educational Games: The Case of Phishing
This study investigates how to effectively engage users with educational games targeting phishing awareness, conducting workshops with 9 younger adults to explore design preferences. It finds that both casual and serious gamers prioritize enjoyable gameplay over information delivery, with casual players favoring humor and simplicity, while serious gamers prefer narrative-driven mechanics—highlighting that educational games must be fun above all to succeed in cybersecurity training.
Phishing continues to be a difficult problem for individuals and organisations. Educational games and simulations have been increasingly acknowledged as enormous and powerful teaching tools, yet little work has examined how to engage users with these games. We explore this problem by conducting workshops with 9 younger adults and reporting on their expectations for cybersecurity educational games. We find a disconnect between casual and serious gamers, where casual gamers prefer simple games incorporating humour while serious gamers demand a congruent narrative or storyline. Importantly, both demographics agree that educational games should prioritise gameplay over information provision - i.e. the game should be a game with educational content. We discuss the implications for educational games developers.
Motivation & Objective
- To explore user engagement strategies in educational games focused on phishing awareness.
- To identify differences in design preferences between casual and serious gamers in the context of cybersecurity education.
- To understand how gameplay quality influences user engagement in educational games.
- To inform game developers on effective design principles for cybersecurity training games.
Proposed method
- Conducted user workshops with 9 younger adult participants to explore expectations for phishing-related educational games.
- Collected qualitative feedback on game design, humor, narrative, and interactivity preferences.
- Analyzed user responses to identify divergent preferences between casual and serious gamers.
- Categorized game elements into gameplay, narrative, humor, and educational content to assess user priorities.
- Used thematic analysis to extract key design principles from participant feedback.
- Emphasized the importance of treating the game as a primary experience, with education as a secondary outcome.
Experimental results
Research questions
- RQ1How do casual and serious gamers differ in their expectations for educational games on phishing?
- RQ2What role does humor play in engaging casual gamers with cybersecurity educational games?
- RQ3To what extent should narrative or storyline influence the design of serious educational games for phishing?
- RQ4How do users prioritize gameplay versus information delivery in educational games?
- RQ5What design principles can maximize user engagement in phishing-awareness educational games?
Key findings
- Casual gamers preferred simple, humorous games that felt more like entertainment than education.
- Serious gamers valued a coherent narrative or storyline, indicating a need for deeper engagement mechanisms.
- Both user groups agreed that gameplay quality was more important than the amount of educational content provided.
- Educational games should be designed primarily as games, with learning embedded naturally within gameplay.
- There is a significant disconnect between user expectations and current educational game designs, which often prioritize content delivery over fun.
- The study concludes that successful phishing-awareness games must prioritize enjoyable, engaging gameplay to achieve long-term user engagement.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.