Need a 20 page APA paper

profilemahi1432
chapter1editdoc1.docx

Running head: GAMIFICATION FOR SECURITY TRAINING 1

GAMIFICATION FOR SECURITY TRAINING 41

Impact of Gamification on IT Security Training

Cybercrimes cases are increasing at an alarming rate. In the UK, an estimated cost of 3.14 million euros has been spent on cyber breaches (Alotaibi et al., 2016). It has been estimated that the business email compromise scams have cost for more than three billion euros (Alotaibi et al., 2016). Cybercrime affects financially, but it adversely affects the customer's data, which affects the customers. It is estimated that the businesses' losses would be two trillion dollars due to data breaches and cybercrimes in the year 2019 (Kanat et al., 2013). However, large companies are controlling these cyber-attacks, and their number of cases is declining. Still, there is a rise in data breaches and cyber-attacks in small and medium companies, which is alarming for countries that are still developing (Baxter et al., 2016).

Several countries are working on the developments made in information technologies, mobile technologies, communication technologies, and the internet. It has been estimated that about 66% of the world's population has been using the internet regularly because most of the population (Seaborn & Fels, 2015). Almost 39% of the population have preferred online shopping modes using the internet instead of traditional shopping (Alomari et al., 2019). However, significant numbers of people do not understand the significance of cybersecurity to the extent needed to take several security measures.

Several research studies were conducted before for understanding the significance of cybersecurity awareness in different perspectives. The findings of the research studies were based on qualitative and quantitative research methods. The research study results indicated minimal security of information and data ensured on the internet, and the numbers of cybercrimes are getting increased rapidly in recent years. There is no approach used by companies, countries, and institutions to reduce the number of cybercrimes except CERT regulations (Pattabiraman et al., 2018).

Moreover, there are vast numbers of people who have been using the internet daily for performing several types of activities through their smartphones, tablets, iPads, and computer systems like online shopping, online banking, online working, etc. (Mathoosoothenen et al., 2017). However, the increased use of information technology from recent years has increased the knowledge about the effective utilization of technology. Still, people do not have enough knowledge about security awareness. Indeed, the use of antivirus programs, firewalls, and their updates are widespread cybersecurity practices followed by people regularly, but still, people lack to have enough knowledge about the required skills like the methods for creating a strong passwords. (Mathoosoothenen et al., 2017).

Significant growth has been observed in the effective use of technologies. However, people are afraid of increasing cybercriminal attacks and terrorism. They want their data to be contained only by highly responsible companies who would be playing a significant role in improving cybersecurity awareness and supporting the concept using mobile applications to increase awareness regarding cybersecurity (Gonzalez et al., 2017). It has been suggested that one of the best methods for reducing cybercrimes is to raise awareness about best practices of cybersecurity among people, which can be done by providing a significant amount of information and security training (Luh et al., 2020).

It has been revealed that many companies have been very conscious about the security provided to their customers' data and their information for which they are willing to adopt some more effective practices for ensuring the high security of data and devices (Armstrong & Landers, 2017). For this purpose, the companies and governmental institutions can arrange several types of workshops, training sessions, webinars, and seminars with the help of security experts so that required skills and knowledge can be delivered to the targeted audience for spreading cybersecurity awareness (Hart et al., 2020). Therefore, companies must follow multiple types of models, approaches, and methods for providing IT security training so that individuals do not lose their interest and feel boredom in the offered training sessions (Gonzalez et al., 2017).

For this purpose, gamification is one of the most preferred approaches because of several reasons for combating cybercrimes and increasing its related awareness (Baxter et al., 2016). The practice of gamification allows individuals to maintain their interest level and stay engaged with the offered education and training (Erenli, 2013). To use gamification in the training session, the managers and trainers must use gamification techniques according to the goals and objectives (Alomari et al., 2019). Gamification is the practice of increasing participants' engagement and interest by using rewards, acknowledgments, appreciation, scoring systems, and contents of video gaming.

Furthermore, gamification should be used in the awareness programs in such a way which can be handled effectively for meeting with the changing needs of the environment, time, and people by considering the lifestyles and cultural practices of participants for keeping it to be more motivating and engaging (Thornton & Francia, 2014). Many studies revealed that whenever employees are provided with some training sessions regarding information technology, they lack interest and feel boredom, which can be handled effectively using Gamification (Adams & Makramalla, 2015).

Research Background

For increasing cybersecurity awareness, companies need to provide required training to all the employees and customers (Buckley & Doyle, 2017). Several types of methods can be used for increasing cybersecurity awareness like education, training sessions, seminars, marketing and promotion, and webinars. However, it is essential to make all these methods more effective for putting a strong positive impact on participants and meeting the goals and objectives (Chen, 2015). The use of the practice of gamification is an effective method for providing a high quality of training to employees. Gamification is the practice of using several types of gaming for providing training and meeting the required goals and objectives (Armstrong & Landers, 2017).

These games are designed for completing a intended purpose instead of for entertainment. These games have been considered a useful tool for bringing significant behavioral changes and providing a high quality of training to employees (Wolfenden, 2019). These methods, which are based on gaming for providing training, are known as a game-based learning approach. These game-based learning approaches are most widely used in schools, colleges, and other educational institutions increasingly adopted by healthcare, advertisement, psychological, behavioral change, and cybersecurity-related training (Redhead & Saunders, 2019). Learning with the help of several types of games is an educational procedure in which participants are asked to play and perform several learning activities using games designed to accomplish particular goals and objectives (Chen, 2015).

These gamification techniques have been proven to be very useful in providing fidelity simulations and problem-solving tasks to improve learners' engagement levels in the activities and motivate them to take an interest (Ruiz-Alba et al., 2019). By considering the scope of these gaming techniques, it has been suggested by the researchers that gamification can be a useful concept for improving the learning skills and capabilities of participants to understand the significance of cybersecurity awareness for organizations (Alotaibi et al., 2016). Several studies found that there is a huge potential for the implementation of gaming technology in several areas.

According to a research study focused on gaming for learning purposes, learning procedures can be highly improved when learners are provided with gaming-based learning education scenarios (Seaborn & Fels, 2015). Gamification can be a useful education tool that can be most widely used and positively affects teaching like puzzle-solving games. Another research study explored mobile phones and other related information technology-based gadgets to improve teaching methods and increase the engagement level of participants (Adams & Makramalla, 2015). There are multiple benefits and advantages offered by gamification to its users, which are hard to neglect and avoid its use.

One of the major benefits of gamification to its users is that it provides an interactive approach for training and educating participants about the program and achieving the target goals and objectives (Alomari et al., 2019). It enables the acquiring of required skills and capabilities in the participants by having fun and learning simultaneously. The nature of gamification is considered very flexible and adaptable, enabling effortless redesigning and reshaping of games according to the situation, background, and training(Erenli, 2013). Therefore, it is very well suited for almost every subject of training.

When a game is designed very effectively, it enables the participants to take a step inside a virtual environment which seem to be similar to the real practical environment and draws a strong connection among the learning of virtual environment and the real-world environment that highly contribute to increasing interest and engagement level of participants in the offered training session (Alotaibi et al., 2016). These game-based learning approaches would be useful for motivating participants to utilize their learning capabilities to understand the concepts being taught and achieve the goal along with required actions and to face the consequences without having any penalties occurred in real life (Baxter et al., 2016).

It has been analyzed that game-based learning methods have been proved to be more useful as compared to traditional methods of learning because these are more engaging, easily able to be customized according to the situation and participants, easily able to be transferable to huge numbers of participants and highly cost-friendly (Armstrong & Landers, 2017). However, significantly fewer research studies were conducted exploring the impact of gamification techniques on IT security training. Therefore, the present paper would be exploring the impact of the gamification-based learning approach on information technology related security training offered to employees.

Problem Statement

In recent years, the number of cybercrimes has been increasing rapidly, which is putting substantial negative impacts on companies' reputation, especially companies dealing with customers' personal and confidential data (Buckley & Doyle, 2017). For handling this kind of situation, the companies are needed to hire highly expert and qualified security experts. They do not hesitate to update their existing knowledge and skills with the changing environment (Chen, 2015).

Therefore, for this purpose, the company can provide several types of training sessions, arrange webinars and seminars, and provide workshops to improve employees' existing knowledge and skills. The company provides a high quality of security to customers' data and the company devices to avoid significant numbers of cybercrimes and terrorism (Gonzalez et al., 2017).

These training sessions are needed to be in good quality and ensure that all the goals and objectives have been accomplished. It has been observed that many employees do not take interest and feel boredom is taking long duration training sessions regarding IT security, which is needed to be removed and prevented so that all the goals and objectives can be fulfilled (Erenli, 2013). If employees do not take interest and lack engagement in the concepts being taught, they would fail to obtain the required knowledge, skills, and capabilities. For this purpose, the companies are needed to follow several types of tactics, learning models, and approaches, and techniques (Baxter et al., 2016). Gamification is one of the most popular and widely used learning approaches for increasing participants' motivation levels in the concepts being taught (Hart et al., 2020).

Gamification allows managers and trainers to use several types of gaming elements and techniques for increasing the engagement and interest level of participants in the offered training sessions for the sake of appreciation, rewards, scoring board, and acknowledgments. (Kanat et al., 2013). Gamification is being used in several numbers of the industry. Still, the use of it in information technology for tackling cybersecurity is new, which is being started in the previous couple of years (Luh et al., 2020). The present research study's main objective is to evaluate gamification's impact on employees' IT security training sessions for increasing cybersecurity-related awareness.

Purpose of the Research Study

The present research study's primary purpose is to evaluate gamification's impact on employees' IT security training for spreading awareness about cybersecurity. For the current research, all the data would be collected from a mixed research method. Some data would be collected from the qualitative research method, and the remaining data would be collected from the quantitative research method to support the findings of secondary data collection. A survey and an interview would be conducted from the population's selected size for collecting primary data.

In recent years, there is a significant increase in several types of security breaches, vulnerabilities, and flaws that have been contributing to increase cybercrimes and terrorism. Cybercriminals have been taking advantage of those identified security flaws and breaches to attack companies' systems to take out confidential and useful information of customers and companies for putting a substantial negative impact on companies' reputation and getting a financial advantage. Ransomware is one of the most used cybercriminals' practices for negatively impacting the company (Mathoosoothenen et al., 2017).

These significant numbers of vulnerabilities and security breaches have been identified and caused by human beings considered the main real vulnerability in the information technology domain (Pattabiraman et al., 2018). It is highly essential for employees of companies and governmental institutions dealing with confidential data of customers to understand several types of risks and threats that can be regarding the malicious use of their information systems (Ruiz-Alba et al., 2019). Those companies and institutions need to take multiple remedial and preventive steps to reduce security breaches and leakage of data and information to cybercriminals.

For this purpose, the use of security awareness and training sessions is considered one of the critical methods used by companies and institutions to reduce numbers of cybercrimes and terrorism and build a highly competitive position in information technology (Redhead & Saunders, 2019). However, it has been observed that many employees feel unrelaxed, bored, and uninterested in taking long duration training sessions which fails of accomplishment of required goals, objectives, competency, and behaviors in their employees for the prevention of security breaches, vulnerabilities, and cybercrimes (Seaborn & Fels, 2015). To increase participants' motivation, engagement, and interest, companies can use multiple types of practices and approaches in which gamification is one of the highly effective practices (Thornton & Francia, 2014).

The present research study is being conducted to understand the positive and negative impacts of using the gamification technique in the information technology sector to increase awareness about cybersecurity and provide training sessions to employees regarding information technology (Seaborn & Fels, 2015). The idea that would be studied in the current research study would be a long term and continuously used program for making any software application or mobile application based on multiple types of gaming to provide training and spread awareness among employees (Thornton & Francia, 2014). The current research study would also explore the factors that positively contributed to making the gamification approach a highly popular approach for increasing participants' engagement and interest levels.

Additionally, the current research study would also discover the reasons which have been contributing to make the use of gaming based learning approach to be more effective in the field of information technology for spreading awareness about cybercrimes and terrorism and how employees can follow multiple types of practices and techniques to avoid security breaches and how they can handle the situations if any kind of vulnerability is identified in the information system (Yang, Asaad, & Dwivedi, 2017). Comment by Jess Schwartz: This in-text citation is improperly formatted. This is how it should be: (Yang et al., 2017). Because you’re using Word (which I strongly suggest against this), it will not allow me to edit the in-text citation.

The present research study would also fill the gap which was existed in the previously conducted research studies. However, there were significantly fewer research studies and identified the impact of gamification on IT security training. Still, there was a significant gap in the literature review, which was identified, and those already conducted research studies in the past.

Significance of the Study

The present research study is considered highly useful and significant for the companies, educational institutions, and governmental organizations that have been handling customers' confidential and sensitive data. Data is regarded as a highly important element for any organization and individual. Most decision-making is based on the company's data, and customers can face several types of problems if their data gets leaked. Therefore, the present research study would be helpful for the companies, educational institutions, and governmental organizations for understanding the significance of IT security training sessions for spreading awareness about cybersecurity and how the interest and engagement level of employees can be maintained during the offered training sessions so that the required goals and objectives can be accomplished by transferring the necessary skills and knowledge to the participants.

Furthermore, there is an enormous scope for the present research study as it can be explored and evaluated from several numbers of perspectives like to understand the significance of gamification in the IT industry, how it is contributing to improving the quality of training sessions offered to employees and why it is getting trendy in the education sector. Moreover, it is also observed that the present research study can be helpful for employees working in companies, governmental sectors, educational institutions, students getting an education for improving their learning skills, and the final year students who would be taking a step inside their practical life and would be joining companies as managers.

However, the present research study would be helpful for educational departments to improving the learning skills of their students so that they can stay motivated during their lectures and teachers can increase engagement and involvement of their students in the lessons being taught to them by using several types of gaming techniques and elements. The present research study results would positively contribute to students' knowledge as they would understand the significance of cybersecurity and what practices and methods can be used by them to reduce the numbers of vulnerabilities and security breaches.

It can help them understand the ways and methods in which employees' interests and engagement levels can be increased in the offered awareness spreading workshops and training sessions. However, it can also help companies understand several types of ways that can be utilized to improve the IT infrastructure's security to strengthen the confidentiality and privacy of data and resources of customers and the organization itself from unauthorized access.

Research Questions

Gamification is getting popular in use in several numbers of areas like education, marketing and promotion, advertisement, and recently in information technology because of several numbers of reasons which would be explored in the present research study by taking help from the literature reviews, secondary data, and primary data of the current research study (Adams & Makramalla, 2015). Using a gaming-based learning approach puts several impacts on participants' learning attitudes according to how it is being used. The present research study would discover the positive and negative implications of using the gaming-based learning approach to IT security training in different environments (Alomari et al., 2019).

Moreover, researchers, educational institutions, and companies use multiple learning-based approaches to provide learning opportunities to employees and students (Alotaibi et al., 2016). Why gamification-based learning is considered one of the highly effective and practical learning approaches used by most companies and individuals would be evaluated in the present research study by considering multiple types of reasoning factors contributing to making it more widespread. The following are the main research questions that would be explored in the present research study.

1. What is the impact of gamification on Information Security Training in the IT industry?

2. How can gamification be an effective learning approach to spread awareness about cybersecurity among IT industry employees?

3. What kind of revelations can be apparent if gamification techniques are introduced into the IT industry?

4. How can techniques of gamification be applied to other industries for increasing its popularity?

In the previously conducted research studies, very few research studies were conducted on exploring the impact of gamification on the IT-related security training sessions(Armstrong & Landers, 2017). However, multiple research studies were conducted regarding the impact of gamification on students' education and the use of gamification in different numbers of areas of industries of life. It was revealed in a research study that gamification is being used in education, advertisement, and healthcare industries most widely for providing training sessions (Alotaibi et al., 2016).

However, the use of a gaming-based learning approach is new for cybersecurity. Still, there was no evidence of its practical usage for providing training sessions to employees to resolve multiple types of security breaches and vulnerabilities (Baxter et al., 2016). In the current research study, gamification on the IT security training sessions offered to employees for spreading awareness regarding cybersecurity and how they can avoid and prevent multiple types of security vulnerabilities and breaches occurred in the information systems would be explored.

It was indicated in a research study that multiple numbers of organizations have been moving towards the use of several types of learning approaches for increasing the engagement and involvement of participants in the concepts that are being taught (Buckley & Doyle, 2017). The use of the gaming-based learning approach is also getting increased day by day as it helps participants to stay motivated and involved in the topics being taught as gamification allows trainers to use multiple types of elements for increasing involvement like storytelling, appreciation, and rewards approach.(Chen, 2015) In the present research study, it would be explored that why gamification is being considered to be one of the best approaches used by trainers for increasing involvement of employees in the training session offered to them for increasing cybersecurity awareness.

There are multiple numbers of reasons which are contributing to making the use of gaming-based learning approach to be more frequently used because it uses video gaming elements for enhancing the interests of participants in the lesson being taught like storytelling, scoreboard, acknowledgment, and level building on the completion of previous activity. (Gonzalez et al., 2017). Gamification is useful for improving the motivation level of participants without getting bored and tired. However, several factors also positively contribute to making it a popular and more effective learning approach than other learning approaches that have not been explored before (Mathoosoothenen et al., 2017). In the current research study, the factors that positively contribute to making gamification-based learning a useful learning approach would be evaluated.

Conceptual Framework Comment by Jess Schwartz: Make this flow chart a picture so that way it can be in line with the text and doesn’t cover over it like it is now.

Impact of Gamification on Security Training

Different types of games can be utilized to increase the engagement level of employees.

It can increase the involvement and interest of employees in the offered training sessions.

Employees can be motivated to participate in the training sessions in return for rewards, gifts, and appreciation, etc.

The increased numbers of cybercrimes and terrorism increased the significance of security training of employees

The gamification technique is considered efficient and effective for stimulating participants' engagement and participation, motivating them to take interest and increasing their dedication in the offered training session for spreading cybersecurity awareness. In the present study, gamification's impact on the IT security training sessions has been evaluated from several perspectives (Kanat et al., 2013). There are several aspects and elements of the gamification technique that information technology managers can utilize to spread cybersecurity awareness among employees.

Gamification can improve the quality of training sessions and workshops offered to the employee

However, gamification is a technique used for education and training purposes, which helps employees to increase their engagement, interest, and involvement in the offered training or learning sessions. Gamification is the practice of using the elements of video games in the offered learning sessions for maintaining their engagement in training (Baxter et al., 2016). The application of gamification concepts in cybersecurity awareness clears that cybersecurity awareness training can be very serious games. It has been observed that there is very little research has been made on the application of gamification concepts and techniques on the cybersecurity awareness context.

In each training session related to cybersecurity awareness, which is offered to employees, the gamification techniques, elements, and concepts are needed to be tailored according to the type of training. It has been suggested that there are a more considerable significance and influence of goals, missions, quest, badges, medals, leader boards, feedbacks, points, rewards, and appreciation in the provision of gamification-based IT security training for spreading awareness about cybersecurity. Gamification concepts and techniques should be selected according to the objectives and goals which are needed to be accomplished by offering the awareness spreading cybersecurity training or workshops to employees.

Definition of Key Terms Comment by Jess Schwartz: There should be many more than two key terms here. Check your lit review for more concepts you can define here.

Gamification. It is the practice followed by managers to improve employees' interest and engagement in the training sessions by utilizing several types of gaming elements (Baxter et al., 2016).

Flow Theory. It addresses how a person engages in an activity that helps improve his or her cognitive skills (Buckley & Doyle, 2017).

Research Assumptions Comment by Jess Schwartz: This goes in chapter 3. Please move.

There were several numbers of assumptions which were identified while working on the present research study. The most identified assumptions are listed below with a brief description.

1. It is ensured that all the participants of the conducted survey or interview would answer all the asked questions to collect primary data authentically, honestly, independently, and candidly.

2. It is ensured that all the participants of the primary data collection method are selected on the criteria that they are relevant to the topic of the present research study directly or indirectly so that highly useful and reliable data can be collected for doing effective decision making.

3. It is ensured that all the selected participants in collecting primary data have a sincere interest in participating in the present research study so that significant results can be produced, which would be useful for playing its role in society and community. They do not have any other kind of intends and motives like getting higher positions in the selected company or getting in good books of their boss.

4. It was ensured that all the secondary data for the present research study had been collected from highly reliable resources so that any kind of authentic and accurate data can be collected and added in the current research study.

Research Limitations Comment by Jess Schwartz: This goes in chapter 3. Please move.

Multiple types of limitations were identified while working on the present research study that was needed to be handled very intelligently and smartly. Some of the main limitations faced while working on the current research study are briefly described in the following.

1. Participants were hesitated in answering the questions asked in the questionnaires designed for interviews and surveys to collect primary data because they were afraid their names would be disclosed in any part of the research study or to their superiors, which can cause any kind of problems.

2. The selected sampling size for collecting primary data was significantly smaller, which was considered very difficult for doing the high quality of accurate and reliable decision-making about the study's topic.

3. The allocated time for completing the research study was a significant limitation while working on the present study.

4. The availability of highly accurate, authentic, and reliable information and data regarding the topic of the present research study was also another major limitation because there was a massive amount of data available about gamification but not in the context of cybersecurity.

Scope of the Research Study

The current research study is considered highly effective and vital for companies, managers, employees, and owners of large-scale technology-related organizations to understand the contribution of gamification and the significance of training sessions offered to employees to boost the security and update their existing knowledge and skills. This research study would help managers of the companies improve the quality of training provided to employees.

It can help them understand the ways and methods in which employees' interests and engagement levels can be increased in the offered awareness spreading workshops and training sessions. However, it can also help companies understand several types of ways that can be utilized to improve the IT infrastructure's security to strengthen the confidentiality and privacy of data and resources of customers and the organization itself from unauthorized access. This research study would help improve the quality of training sessions offered to employees. All the required knowledge can be easily transferred to employees, and employees can obtain the required skills and capabilities.

Summary and Conclusion

Cybersecurity awareness can be explained as the people who seem to be aware of several types of cybersecurity threats that can be faced by their networks, systems, and devices (Alomari et al. 2019). End users are considered the weakest element and the primary vulnerability point in the network for allowing several cyberattacks to get inside. Hence, it is considered highly significant for end-users to stay aware of cybersecurity (Moore, 2019). Several types of methods can be utilized for spreading awareness about cybersecurity like training sessions can be conducted by using classroom course, e-learning, presentations, and webinars.

It has been observed that spreading awareness about cybersecurity is not considered an easy task ever because there are multiple training techniques. Still, none of them provided highly effective results (Pattabiraman et al., 2018). Hence, it is considered highly significant to do tailoring in the existing used training practices to provide useful information and increase the interest of participants in cybersecurity (Alotaibi et al., 2016). There is a huge significance in maintaining employee engagement and involvement in the offered training sessions because otherwise, all the applied resources and costs would be useless and wasted.

It has also been evidenced that the companies who utilize gamification techniques in their offered training session to their employees for spreading cybersecurity awareness seem to improve the learning of their employees to the 70% as compared to other traditional training sessions (Luh et al., 2020). There are vast numbers of benefits offered by gamification to the participants of offered training like it enables employees to increase their productivity, provides motivation for improving their engagement and involvement, encourages employees to become more creative for solving the problems and innovatively addressing them, provides strength to the communication procedures (Gonzalez et al., 2017).

When companies use gamification, they work to make the existing tasks more innovative and fun, like video games. The success of the training based on gamification relies on the program's accomplishment without being noticed by using gamification. Security compliance ensures that several security measures have been appropriately taken by the company to protect the IT infrastructure from several types of attacks, risks, vulnerabilities, and breaches (Hart et al., 2020). The companies are needed to ensure IT security compliance for strengthening and securing the IT departments from several types of attacks, vulnerabilities, and risks (Rieff, 2018).

References

Adams, M., & Makramalla, M. (2015). Cybersecurity skills training: an attacker-centric gamified approach. Technology Innovation Management Review. Alomari, I., Al-Samarraie, H., & Yousef, R. (2019). The role of gamification techniques in promoting student learning: A review and synthesis. Journal of Information Technology Education: Research, 395-417. Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A Review of Using Gaming Technology for Cyber-Security Awareness. International Journal for Information Security Research, 660-666. Armstrong, M. B., & Landers, R. N. (2017). An evaluation of gamified training: Using narrative to improve reactions and learning. Simulation & Gaming, 513-538. Baxter, R. J., Kip, H. J., & Wood, D. A. (2016). Applying Basic Gamification Techniques to IT Compliance Training: Evidence from the Lab and Field. Journal of Information Systems, 119-133. Buckley & Doyle, E. (2017). Individualizing gamification: An investigation of the impact of learning styles and personality traits on the efficacy of gamification using a prediction market. Computers & Education, 43-55. Buckley, P., & Doyle, E. (2017). Individualizing gamification: An investigation of the impact of learning styles and personality traits on the efficacy of gamification using a prediction market. Computers & Education, 43-55. Chen, E. T. (2015). Gamification as a resourceful tool to improve work performance. In Gamification in education and business, 473-488. Erenli. (2013). The impact of gamification-recommending education scenario. International Journal of Emerging Technologies in Learning. Gonzalez, H., Llamas, R., & Ordaz, F. (2017). Cybersecurity Teaching through Gamification: Aligning Training Resources to our Syllabus. Research in Computing Science, 35-43. Hart, S., Margheri, A., Paci, F., & Sassone, V. (2020). Risk: A Serious Game for Cyber Security Awareness and Education. Computers & Security. Kanat, I. E., Siloju, S., Raghu, T. S., & Vinze, A. S. (2013). Gamification of emergency response training: A public health example. IEEE (pp. 134-136). Luh, R., Temper, M., Tjoa, S., Schrittwieser, S., & Janicke, H. (2020). PenQuest: a gamified attacker/defender meta-model for cybersecurity assessment and education. Journal of Computer Virology and Hacking Techniques, 19-61. Mathoosoothenen, V. N., Sundaram, J. S., Palanichamy, R. A., & Brohi, S. N. (2017). An Integrated Real-Time Simulated Ethical Hacking Toolkit with Interactive Gamification Capabilities and Cyber Security Educational Platform. In Proceedings of the 2017 International Conference on Computer Science, (pp. 199-202). Moore, M. (2019). Gamification: A winning strategy for cybersecurity training. Retrieved from https://www.scmagazine.com/home/opinion/executive-insight/gamification-a-winning-strategy-for-cybersecurity-training/ Pattabiraman, A., Srinivasan, S., Swaminathan, K., & Gupta, M. (2018). Fortifying corporate human wall: A Literature review of security awareness and training. In Information Technology Risk Management and Compliance in Modern Organizations, 142-175. Redhead, A., & Saunders, J. (2019). Gamification and Simulation. In Serious Games for Enhancing Law Enforcement Agencies, 83-98. Rieff, I. (2018). Systematically Applying Gamification to Cyber Security Awareness Trainings. The Netherlands. Ruiz-Alba, L., J., Soares, A., Rodríguez-Molina, M. A., & Banoun., A. (2019). Gamification and entrepreneurial intentions. Journal of Small Business and Enterprise Development. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action. International Journal for Information Security Research. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action: A survey. International Journal of human-computer studies, 14-31. Thornton, D., & Francia, G. (2014). Gamification of information systems and security training: Issues and case studies. Information Security Education Journal, 15-24. Wolfenden, B. (2019). Gamification as a winning cybersecurity strategy. Computer Fraud & Security, 9-12. Yang, Y., Asaad, Y., & Dwivedi, Y. (2017). Examining the impact of gamification on the intention of engagement and brand attitude in the marketing context. Computers in Human Behavior, 459-469.