Need a 10 page APA paper
Running head: GAMIFICATION FOR SECURITY TRAINING 1
GAMIFICATION ON SECURITY TRAINING 41
Contents 1 Problem Statement 3 1.1 Model Diagram 4 2 Literature Review 4 2.1 Information Security Compliance 4 2.2 Gamification for Security Training 7 3 State of flow in Gamification for Effective Security Training 16 4 Research Question and Hypothesis 20 4.1 Research Question 20 4.2 Hypothesis 20 4.3 Justification for hypothesis 21 4.4 Motivation for hypothesis 30 4.5 Conclusion 35 5 References 37
Problem Statement
The number of cyber-attacks has been increasing rapidly in organizations. These attacks can bring down the reputation of organizations and can cause a loss of millions of dollars for the organizations. Most vulnerabilities, attacks, risks, and viruses result from a lack of security awareness of employees and users (Seaborn & Fels, 2015).
These risks, vulnerabilities, and attacks can be minimized by improving employees' knowledge and skills in strengthening the company's IT infrastructure. For this purpose, organizations can arrange several types of workshops and training sessions related to cyber-security awareness. Many employees do not show interest and feel boredom in attending those workshops and training sessions. Gamification is considered a practice that can boost the investment and engagement level of employees during security awareness training.
Gamification will positively impact the security training offered to employees by increasing their interest and engagement level. The main problem which is going to be addressed in this research is the understanding of the impact of Gamification on the training session offered to employees for improving the security of IT infrastructure.
The present research study is considered highly useful for finding the impact of Gamification on employees' training sessions for improving the security of IT infrastructure. This study would enable organizations to understand the significance of Gamification, the possible methods that can be utilized for taking advantage of Gamification, and why it is one of the best approaches for increasing the engagement level and involvement of employees in training sessions.
Many employees feel difficulty and face a lack of interest and enthusiasm while attending the workshops and training sessions arranged by their employers and managers (Alotaibi, Furnell, Stengel, & Papadaki, 2016). Hence the use of Gamification can be a highly effective technique available for organizations to increase the interest and engagement level of employees in the offered workshops and training sessions (Baxter, Kip, & Wood, 2016).
Model Diagram
State of Flow
Gamification for Security Training
User Security Compliance
Literature Review
Information Security Compliance
The 21st century has come with technological advancements that have helped organizations flourish and work faster and more efficiently. There are numerous changes that the corporate world undergoes, and for an organization to stay competitive in the market, it must be able to adapt to the changes that are bound to happen (Desai, 2016). Organizations must be able to learn quickly about the business environment. The business principles change over time, and Information Technology is one of those fields that a company must take a keen interest in.
The changing technological advancements mostly include the use of e-commerce, which exposes companies to a higher risk of cybercrime. According to Al-Kalbani (2017), there has been a 38% increase in information technology breaches in a public organization in 2016 compared to 2014. Because of such an increase and the threat of a further surge. Companies must design and operate secure electronic systems that they use for the exchange of information and funds. It is highly fundamental that the security of information that the organizations hold to be kept as high as possible. Companies have noticed the same and have gone on to adopt security practices that include the adoption of an information technology security compliance approach to control the proper use of the information they have (Al-Kalbani, 2017). Showing that a company has taken the necessary precautions to protect the information they have is now considered to be an institutional yardstick (Al-Kalbani et al., 2017; Safa et al., 2016).
For any sort of security of the information, companies, and organizations, including governments, must consider the technical, technological, and non-technical aspects (Al-Kalbani, 2017). As such, the end game is to have a set of rules that must be met to ensure security compliance. In the use of information technology, security compliance refers to the implementation of security practices, policies and standards that work best to protect the information owned or controlled by a particular organization (Al-Kalbani, 2017; Alfawaz et al., 2010). If a company complies with information security, it can improve its security mechanisms that help safeguard information (Siponen et al., 2010). The compliance approach used to information technology helps satisfy the trust that the stakeholders have towards the organization (Al-Kalbani, 2017). Therefore, information technology is essential in the development of e-government and other institutions and organizations as well.
As Dimitriadis (2011) describes, information security is "the preservation of confidentiality, integrity, and availability of information." There is no way that information can be preserved if there is no compliance with the standards that guide its preservation. Over the past decade, there was the notion that information security was a technical thing, and the IT managers were the only ones tasked with the preservation of safety. However, the idea has been changing to include the non-technical part of the organization (Desai, 2016). This has led to the creation of procedures, policies, and awareness programs that help in security compliance. According to Herath and Rao (2009), the failure to prevent security breaches in attacks is a clear sign of a company not complying with the security policies. Research has ascertained that almost half of the security breaches that befall an organization emanate from within the organization (Desai, 2016). This fact places more emphasis on the role that an organization has in stopping security breaches through compliance.
According to Kolkowska and Dhillon (2013), there are two main categories identified concerning information security approaches. The approaches are the approaches that make use of sanctions and the behavioral ones. As such, there are two approaches to security management, which are the individual level and the managerial level of understanding (Flores et al., 2014). This means that the own employees in an organization need proper training and awareness not to misuse information. The employees need to understand the consequences of the guilt of breach of data.
There have been theories that help understand the compliance of organizations to information security. The institution theory (DiMaggio & Powell, 1983) widely provides a better understanding of the pressures that force an institution to comply. The theory states that "organizations must secure legitimacy from its stakeholders by conforming to external expectations" (Appari et al., 2009). The legitimacy that an organization seeks can be gained by making strategic responses to the pressures from external entities (Cavusoglu et al., 2015). It is paramount to note that the organization's external influences and the answer define how the organization is built, run, and how it can be understood and evaluated (Al-Kalbani et al., 2017).
For an organization to follow security compliance, there must be proper external pressures that force it. The influences include normative, mimetic, and coercive pressures (Cavusoglu, 2015). The coercive pressures are the ones that force an organization to adopt the regulations and practices that help in the protection of the security of information. The demands are mainly from government laws and regulations (Al-Kalbani et al., 2017). The normative pressures are those that stem from the expectations that the community has towards the organization (Appari et al., 2009). Finally, the mimetic pressures originate from the company trying to imitate its peers to gain legitimacy (Safa et al., 2016).
The importance of the pressures to the adoption of security compliance is key to ensuring that the organizations. Since many institutions are using Gamification in the training and awareness of the employees, the mimetic pressures play an essential role in increasing the compliance levels of other companies. Bulgurcu (2010) finds out that the implementation of information security awareness even helps to increase the belief of employees towards security awareness. While the government can create rules and regulations that force organizations to raise information security awareness, it is down to the organizations to choose to use Gamification to train the employees.
Gamification for Security Training
Gamification is the method in which the knowledge and experience gained from gaming theory and flow theory have utilized in a non-gaming context. The concept of Gamification was implemented for the first time during the Cold War to improve productivity (Alotaibi, Furnell, Stengel, & Papadaki, 2016). Coonradt in 1984 was the early researcher who applied Gamification in the business context to motivate employees through clear goals, frequent feedback provision, gaming features, and personal choice (Baxter, Kip, & Wood, 2016).
Gamification highly helps companies increase their employees' engagement level by utilizing several elements of game designing (Kanat, Siloju, Raghu, & Vinze, 2013). According to some previously conducted research studies, it has suggested that the use of goals, storytelling, rewards, and appreciation are the main aspects of Gamification for increasing the curiosity, interest, engagement level and experiences of challenges of users to boost the engagement level and interest of participants in the offered training sessions and workshops (Seaborn & Fels, 2015).
The use of the gamification technique is one of the most preferred training methodologies which helps the companies to increase innovation, productivity, knowledge, skills, experiences, and learning procedures of their employees and participants (Alomari, Al-Samarraie, & Yousef, 2019). This technique is mainly based on the use of innovative thoughts and gaming techniques in a non-entertainment manner, such as improving education and work skills.
There are vast numbers of benefits offered by Gamification to its users like it enables employees to increase their productivity, provides motivation for improving their engagement and involvement, encourages employees to become more creative for solving the problems and innovatively addressing them, provides strength to the communication procedures (Pattabiraman, Srinivasan, Swaminathan, & Gupta, 2018).
The use of Gamification highly helps employers and managers increase employee engagement by introducing several types of innovative dynamics (Mathoosoothenen, Sundaram, Palanichamy, & Brohi, 2017). It has assumed that the companies who utilize the technique of Gamification in the training sessions offered to their employees can get more successful in improving the particular required skills of their employees through the increased interest and involvement of employees in the provided training sessions and workshops (Erenli, 2013). However, it is also considered a highly useful approach for transmitting a productive and positive corporate image (Alomari, Al-Samarraie, & Yousef, 2019).
Using Gamification more effectively, all the things should be kept simple, engaging, and entertaining to increase the interest and engagement level of employees. The success of Gamification relies mainly on employees' increased involvement, effective gaming techniques, and methods and motivation (Alotaibi, Furnell, Stengel, & Papadaki, 2016). The rewards offered are not considered only pure awards but provide means for inspiring employees to achieve their potential. There are vast numbers of organizations that have to utilize gamification techniques like Google, Starbucks, and Dominos, etc.
When companies use Gamification, they work to make the existing tasks more innovative and fun, like the use of video games. The advancement in information technology has highly contributed to increasing cybercrimes and terrorism that can put strong negative impact not only on the reputation of the company but also on the data and information stored in the servers of the company of their employees, customers, and the organization itself (Baxter, Kip, & Wood, 2016). The increased numbers of attacks, threats, risks, and vulnerabilities demand the IT companies become more innovative, productive, and reliable (Gonzalez, Llamas, & Ordaz, 2017).
For this purpose, companies have needed to provide training sessions and workshops to improve their employees' skills and knowledge. To identify and tackle the various attacks, threats, risks, and vulnerabilities, employees should know about IT security so that they can protect their privacy and data from intruders (Erenli, 2013). Employees should also be able to think from the perspective of intruders and act accordingly.
To identify and address the cyberattacks effectively, quickly, and without any significant loss in terms of finance, customers, and reputation, the employees should have updated knowledge as advancements in technology are taking place at a fast rate (Seaborn & Fels, 2015). Several types of cybercrimes can be occurred and can be proved highly harmful. In 2018, the UK, 79% of companies were posed with the threat of cyberattacks and had to face the consequences of problems that occurred (Alomari, Al-Samarraie, & Yousef, 2019).
Most people, including the employees of any organization, do not show interest in attending workshops related to any topic as the workshops play a significant role in enhancing the knowledge of its attendees to improve their existing experience and skills about the security of IT infrastructure (Luh, Temper, Tjoa, Schrittwieser, & Janicke, 2020). However, a significant problem is faced by a lack of interest and involvement in the offered training and workshops, which can be solved using gamification techniques (Hart, Margheri, Paci, & Sassone, 2020).
Besides, the usage of Gamification for increasing the involvement and engagement level of employees has considered to be very cost-friendly as it can provide a considerable amount of benefits to its users and can save them from major problems like in case of having lack of involvement and engagement level of employees in the offered sessions, all the resources which were utilized by the companies like cost, time, place, etc. would get wasted and of no use (Seaborn & Fels, 2015).
Gamification works on the desire of human beings to get the win, successful, and achieve something. It allows employers to offer several types of rewards like badges, points, leader boards, and the ability to do trading to get a particular kind of prize for deriving high quality of behavior from employees to get engaged in the training sessions (Thornton & Francia, 2014). However, it is also rooted in science, as wining always creates dopamine in human beings' minds. They want to get reached to the next level and be placed on the top of the leader board by doing whatever they can to feel good and have a feeling of pride (Alotaibi, Furnell, Stengel, & Papadaki, 2016).
Besides, there is also the considerable significance of the rules needed to follow for staying in line and to get guided in the decision making. The companies who get successful in implementing and establishing the right standards for the Information Technology Security awareness training sessions and programs can have more opportunities and chances of extending their programs for having long term benefits (Gonzalez, Llamas, & Ordaz, 2017). All the specified rules, regulations, objectives and goals of the training are needed to be clear and straightforward for getting modified and adjusted according to the changing circumstances and situations (Adams & Makramalla, 2015).
Organizations should not move towards the use of Gamification because everyone is using it, and it sounds to be very trending and good. It should be implemented when needed and with a particular purpose (Seaborn & Fels, 2015). All the programs which contain Gamification should have some unique value, and all the participants should be felt to be very special and interested in learning about cybersecurity for securing the IT departments of the companies by having a feeling of winning something (Alomari, Al-Samarraie, & Yousef, 2019).
All the contents of Gamification in the training sessions are needed to be incorporated in a very transparent manner for obtaining a high level of benefits as it can be proved to be very useful and practical for improving the quality of training sessions and achieving a high level of results (Alotaibi, Furnell, Stengel, & Papadaki, 2016). The success of the training based on Gamification relies on the program's accomplishment without being noticed by using Gamification (Gonzalez, Llamas, & Ordaz, 2017).
It has also noticed that the things that work well for one organization are not compulsory and would be sufficient for the other companies (Seaborn & Fels, 2015). Each company seems to have its particular unique organizational culture and training programs designing methods because of having unique traits and knowledge (Alomari, Al-Samarraie, & Yousef, 2019). In each training session, human factors are considered to be the weakest element for IT security as they can make mistakes, and they are also the ones who can make extraordinary efforts to secure the system to a great extent from vulnerabilities, risks, and attacks (Chen, 2015).
There is a considerable significance of information security compliance for improving the quality of operations and services which are being offered to customers. When customers feel that their data is not protected and secured by their company, they hesitate to provide their confidential and personal information (Adams & Makramalla, 2015). There are many cases in which several numbers of organizations have to face a significant loss in terms of customers and finance because of loss of information and data due to several types of vulnerabilities, breaches, and attacks (Alomari, Al-Samarraie, & Yousef, 2019). For example, in 2013, Adobe has to compromise the data of 153 million users, which caused the company to face a $1.1 million legal fee and $1 million to its customers for solving their problems (Swinhoe, 2020).
Also, in 2014, eBay has to compromise 145 million users' data, which caused the company to pay hefty fines and some corresponding amount to their customers for addressing the impact which has been faced by them financially (Battaglino, 2019). There are hundreds of examples of smaller, medium and large scale organization which are offering their services by collecting vast types of personal and confidential data of their customers and employees and those companies have to face millions of dollars of loss not only in terms of money but also in their customers and reputation (Alotaibi, Furnell, Stengel, & Papadaki, 2016). If these organizations have put a strong focus on the improvement of their IT infrastructure and implemented robust security compliance, they could have saved themselves from these significant losses.
Security compliance ensures that several security measures have been appropriately taken by the company to protect the IT infrastructure from several types of attacks, risks, vulnerabilities, and breaches. Several IT security regulatory compliance numbers can be followed by organizations (Armstrong & Landers, 2017). This compliance can be effectively implemented if all the relevant employees seem to be aware of these practices. They have relevant skills and updated knowledge that is possible to provide to employees who seem to have problems in these areas through the training sessions.
The offered training sessions can be improved by using the practice of Gamification, which allows employees to take significant interest and involvement in the provided training sessions. These training sessions can help employees understand updated and highly advanced methods to address these vulnerabilities, attacks, and breaches (Baxter, Kip, & Wood, 2016). Employees can be offered advanced knowledge about several types of IT security regulatory compliance like FISMA, HIPPA, SURBANCE OXELY ACT, PCI DSS, etc. All these acts work effectively with the collaboration of IT security agencies and the government to secure the confidential and personal data of customers and employees.
FISMA is a law that was passed in 2002 by the United States Federal, which indicated that the federal agencies should do development, documentation, and implementation of adequate information security and protection programs. It is made for the improvement of the management of e-government. It is considered to be the most significant rules, followed by federal data security standards and guidelines (Gikas, 2010). The primary purpose of it is the reduction of security risks for public information and data.
HIPPA (Health Insurance Portability and Accountability Act) of 1996 was designed to contain comprehensive information about protected health privacy and security. However, confidentiality and security cannot be considered the same but always stays together. The privacy rules mainly focus on the individual's rights for controlling their personal information (Edemekong & Haydel., 2019). According to PHI (Protected Health Information), it is stated that any kind of personal data should not be used or disclosed to any other person without their consent.
SURBANCE Oxley was passed in 2002 by the US Congress for providing help to do protection of investors from several types of fraudulent activities related to finance. It is also called a SOX Act of 2002 and the Corporate Responsibility Act because it brought several substantial reforms about the existing security regulations and introduced new lawbreakers and penalties. The act came in front because of financial scandals that occurred in 2000, like Enron Corporation, World Com, and Tyco International Plc.
PCI DSS is a set of widely accepted policies that are used for optimizing the protection of debit, credit, and cash card transactions and also for the protection of cardholders for avoiding any kind of misuse of personal and confidential data (Ataya, 2010). Both were joined in 2004 by using four significant companies of credit cards: Visa, Discover, Master Card, and American Express. All of these acts work effectively with the collaboration of IT security agencies and the government to secure the confidential and personal data of customers and employees.
The companies which do not follow the guidelines, practices, standards, and policies defined by these agencies and government have to face massive amounts of penalties, punishments, and fines, which can cause them to suffer a major loss in terms of finances and customers. These defined standards help organizations to protect credit card information, email address, bank details, etc. (Chen, 2015) For this purpose, it is suggested that organizations should offer time to time frequent training sessions to their employees so that they can get updated knowledge, skills and get aware of best practices that can be utilized by them for strengthening their IT infrastructure and ensuring IT security compliance (Gonzalez, Llamas, & Ordaz, 2017).
It is suggested that organizations should keep offering short training in their meeting sessions for understanding the effectiveness of existing knowledge of their employees and every three months employees should be provided with some short workshop session for increasing awareness and training sessions should be provided to employees annually or whenever a new employee joins the company for making him/her compatible with the requirements of the company (Gonzalez, Llamas, & Ordaz, 2017).
There are many large-scale organizations which have also been become a victim of these vulnerabilities, breaches, and attacks because of lack of implementation of security compliance. For example, in 2014, there was an attack made on Yahoo which revealed that the companies having the latest technologies could also become vulnerable to these problems and the attacks got successful in stealing the records of more than 500 million accounts (Pattabiraman, Srinivasan, Swaminathan, & Gupta, 2018). Besides, there was also a significant attack made on the Marriott Hotels in which the data of more than 500 million customers was stolen.
Hence, if these companies had implemented strong IT security regulatory compliance and followed the practices and standards specified by the country's IT security agencies and government, they could have saved their millions of dollars along with their reputation and numbers of customers (Thornton & Francia, 2014). The organizations can enhance their data management capabilities, improve the status, and market position of the company. Also, these regulatory compliance helps organizations to promote operational benefits (Gonzalez, Llamas, & Ordaz, 2017).
State of flow in Gamification for Effective Security Training
The theory of flow is considered useful for explaining the procedure in which the use of Gamification can be highly valuable to improve the learning capabilities and skills of individuals. The main reason behind the use of the theory of flow is that most of the games have been designed in such a manner that puts a strong focus on maintaining a balance among the skills and challenges of the learners. However, the individuals who play video games are considered highly efficient as they can learn and find the easiest ways to reach the state of flow to learning something (Luh, Temper, Tjoa, Schrittwieser, & Janicke, 2020). When an employee feels exhausted and bored with the training sessions, the practice of Gamification helps them regain their interest and flow in the offered training session.
Gamification is considered highly useful for allowing individuals to keep working and taking interests in the offered tasks in a flow. A flow helps individuals to work on a particular job in a stream like from the beginner's levels to medium level, and when they get right in all those activities, they are moved to the expert level (Gonzalez, Llamas, & Ordaz, 2017). In the same way, employees are provided with training sessions based on the beginning level knowledge to medium and then expert varying in the offered activities and training. It helps individuals to develop relevant skills, thinking capabilities, and learning attitudes based on their experience (Erenli, 2013).
However, there is a significant role played by intrinsic motivation in the flow theory. The intrinsic motivation usually occurs whenever an individual starts participating in the behavior that seems to be personally rewarding not only because of the pressure that occurred by external assets but also internally by the person (Baxter, Kip, & Wood, 2016). Intrinsic motivation occurs when individuals want to explore or learn something new that is not done by them before and become more curious about the practical experience of those things (Wolfenden, 2019).
There are several numbers of research studies that have been conducted to understand the effectiveness of the theory of flow. Still, the researchers do very little work on the evaluation of the efficacy of flow theory on Gamification and how they can be useful to improve the capabilities of employees who are working (Pattabiraman, Srinivasan, Swaminathan, & Gupta, 2018). The flow theory is considered highly helpful in enhancing the efficiency of the activities and tasks performed by using Gamification.
According to Cakmak et al. (2015), flow theory addresses how a person engages in an activity that helps improve his or her cognitive skills. The engagement involves the unique feeling of a sense of control, being entirely concentrated on the operation performed, enjoying the activity, and having the necessary harmony between the skills and the task completed (Cakmak et al., 2015). Csikszentmihalyi (1990) argues that people can achieve happiness by only controlling how they feel in the inner being. An individual can control his life and live the most enjoyable moments of his life by directing his mind to realistic goals and challenges. Therefore, a person who entirely puts his or her focus on the work they do will live the flow experience and will have control over the actions they perform.
According to Csikszentmihalyi (1990), the flow experience is interwoven with positive emotions, intrinsic motivation, high concentration, and a sense of control. It is important to note that individuals mainly experience intrinsic motivation whenever they are doing activities that they are interested in. This intrinsic motivation is a vital feature of the flow experience. Therefore, intrinsic motivation is easily achieved if a person performs an activity out of his or her own free will (Cakmak et al., 2015). There are features of flow experience that are important in determining the flow experience of a person. Eight principles are A challenge activity that requires skills, the merging of action and awareness, clear goals, direct feedback, concentration on the task at hand, the sense of control, the loss of self-consciousness, and the transformation of time (Chen, 2015; Cakmak et al., 2015).
The flow is primarily based on activities and argues that healthy persons enjoy their experience during the business without even realizing it (Cakmak et al., 2015). By accumulating the appropriate events to the purpose of their life, a person can achieve the happiness they wish with a sense of control over the activity they perform. Flow theory has been used before in many fields, including sports, positive psychology, marriage, job performance, and distance education (Cakmak et al., 2015). In playing online games, the creators of the games have mastered the art of ensuring that they achieve the flow experience when playing. This way, video games have infiltrated our daily lives so that every person, young and grown-up, represents video game (Chen, 2015). The ability for game makers to ensure that gamers achieve flow experience is by making sure that there is a balance between the challenges that the game provides and the skills of the person playing (Chen, 2015).
For ensuring IT security compliance, companies are needed to have updated knowledge and skills, which can be achieved by offering several types of training sessions to their workforce. When the employee is asked to get training sessions, they feel boredom and lack of interest which can be improved and increased by following the practice of Gamification in which several types of games and rewards can be offered to employees to learn the concepts more effectively and maintaining a balance among the interest of employees and their leaning capabilities (Baxter, Kip, & Wood, 2016).
Human beings are the key asset for creating most of the vulnerabilities, breaches, and attacks, along with addressing them. Hence, their training is considered highly influential in any organization because they are considered highly responsible for handling data and IT infrastructure (Ruiz-Alba, L., Soares, Rodríguez-Molina, & Banoun., 2019). If employees were offered updated knowledge, practices, and experiences, they would be able to make high-quality decision-making to address the problem more effectively, rapidly, and smartly without getting significant issues for the company.
Gamification is a relatively new approach that takes advantage of the video gaming industry to help in the training and awareness of information security. The era now is full of online forms, which include transfer and storage of information. The internet use to store and transfer information poses a risk of people hacking to get the information they illegally. In some instances, the leakage of information may be unintentional, as Desai (2016) states, almost half of the security breaches that occur an organization emanate from within the organization. Most of the violations are unintentional and are because the users are not aware of the simple ways they can leak information. Therefore, the gamification process uses gaming principles to make training on cybersecurity engaging, entertaining, and informative. This way, the employees get to learn the techniques of stopping leakages, following rules. In a nutshell, following regulations and preventing leakages leads to security compliance.
Information security compliance by the employees means that the whole organization complies and therefore heightened security. There is a strong relationship between the theory of flow, IT security regulatory compliance, and Gamification because organizations are needed to strengthen their IT infrastructure by implementing IT security Compliance (Pattabiraman, Srinivasan, Swaminathan, & Gupta, 2018).
Information security is a top priority for any company an organization. To increase the security of information, the training of employees is essential. If the employees are trained regularly, and through the best possible formats, their awareness will be heightened. Increased awareness of the threats related to information security by the employees, means that they will not be caught flat-footed in case of an attack. The increased use of Gamification increases the willingness of the employees to learn about information security. The increase in awareness means that they will be much more willing to be involved in securing the information of the organization. The use of Gamification increases the relationship between information security compliance and the security of data.
There is a strong impact of Gamification in IT security training. Gamification is a practice of following several types of gaming activities in return for some rewards, acknowledgments, and recognition for increasing the involvement and interests of participants. There is a considerable contribution of Gamification in increasing the engagement level, and the importance of employees in the offered training sessions regarding IT security. The advancement in information technology has highly contributed to growing several types of cybercrimes and terrorism, which also increased the significance of IT security training sessions offered to employees for improving their existing knowledge and experiences.
Research Question and Hypothesis
Research Question
The Impact of Gamification in Security Training for User Security Compliance is moderated by the flow enabled by the game-based training.
Hypothesis
H1: Game-based training leads to higher-level user security compliance
H2: A high state of flow in game-based security training will lead to higher user security compliance.
H3: A low state of flow in game-based security training will lead to lower user security compliance.
Justification for hypothesis
H1:
Silicon and Lowry (2020) conducted a DSR project, which is the Design science research, to improve the problems of the users of organizations. The issues which were discussed in this article included unsuccessful prevention of phishing, ineffective security compliance, and sparse learning of the security training. In this article, A game-based security training system was developed, which focused on two elements: (1) increasing the intrinsic motivation of the employees so that they can develop efficient user security systems (2) improving the learning of these security training and competency.
The vital hypothetical affiliation of this article proposes a speculative kernel theory from the adoption model of the hedonic-system of motivation that can be used to assess the users and employees regarding their motivation level and their coping abilities regarding security and sustainability of the user's security. Four hundred twenty members participated in the six-month field study, which was discussed in this article, shows that fulfilling the coping needs and motivation of the user can make a significant positive difference in the user security compliance through efficient and effective gamified training. A design science research project empirically and theoretically demonstrates that a carefully selected design with information technology artifacts that are gamified can improve the framework of the safety of the organization as well as ensure user security compliance. To be specific, this article shows through a long-term field study that the game-based security training or the incorporation of Gamification can be used to develop a framework that is less of a hindrance to the regular work schedules of the employees, gives the intrinsic motivation to the employees to comply and learn the security training efficiently, and provides the actual efficacy which is necessary for the employees actually to meet and learn. In the same way, this article demonstrates the improvement in the anti-phishing responses which are generated due to the hiring of third-parties. These third parties test the employees and phish them as natural experiments. Furthermore, this article presents a new experimental demonstration of the reasonable significance of the "appropriate challenge" in this unique situation. This article illustrates that a combination of design science research, careful contextual implementation of kernel theory, and long-term analysis in an experimental field setting is a promising way to successfully implement game-based training in the organizations which if adequately learned by the employees, can lead to an efficient user security compliance (Lowry, 2020).
This article supports our hypothesis. The design science research techniques and hedonic-motivation system, if correctly applied and efficiently implemented, can lead to higher-level user security compliance. The design science research and the hedonic-motivation systems are the basics of the gamification security literature. Hence, (Lowry, 2020) by their long-term field study experiment in which they incorporated the core kernel theory, the hedonic-motivation system, and the design science research, proved that game-based training leads to higher-level user security compliance.
Baxter et al. (2016) gave evidence from the lab and field and applied the basic game-based techniques to information technology compliance training. This article addressed the main problems of these security training. Organizations rely on internal controls to secure the integrity and security of the data of their users. Data privacy training and information technology security are the primary controls to protect the organization's data. Often, it is seen that employees do not like such kinds of training, however, which may indicate a lack of internal control, a lack of attention, thus leading to a lack of success. To improve the experience of these training, organizations adhere to game-based techniques in the training modules of the employees, which is known as Gamification. In this article, an information technology field study was conducted for security training, and a lab study was done for the data privacy settings. The field study was conducted on bank employees. This article examined and compared whether a non-traditional game-based training module increased the satisfaction and learning of the employees as compared to the traditional non-game-based training techniques. The article discovered that Gamification or the incorporation of the game-based training system brings higher levels of satisfaction in the field and lab and thus leads to higher user security compliance. Still, so far, there has not been a significant increase in learning. Plus, these learning upgrades were rare and quite small, like 1 percent to 3 percent. Furthermore, this article concluded that gamers, i.e., individuals who are interested in gaming individually learned more about game-based training than non-gamers, even though the gamers had a less satisfaction level from the gamification training (Baxter, Kip, & Wood, 2016).
This article supports our hypothesis that game-based techniques can lead to a higher level of user security compliance but further addresses the need for implementing some modifications to these gamified training. First of all, the training should not be this much long that can hinder the coping and learning abilities of the users. Secondly, these game-based training should be given in simple language rather than the IT language, so that a gamer or a non-gamer; everyone can understand the training quickly. Thirdly, the gamified training should be conducted in a calculated period when the employees can spare time for these training easily and not feel hectic after the course. All of these modifications that the article addresses, including keeping up with the motivation of the user, filling the gap in the learning of gamers and non-gamers, and keeping the gamified training course short and comprehensive are the efficient way of implementing the gamified trainings. Hence, (Baxter, Kip, & Wood, 2016) findings support our hypothesis that if correctly implemented, game-based training can lead to higher levels of user security compliance.
H2:
Yoo et al. (2018) explored the influence of psychological ownership and flow on training, security education, security compliance, and awareness effectiveness. The purpose of this article and the problems that this article addressed include the investigation of the psychological ownership and the effects of higher flow on SETA, which is the security education, awareness, and training, security compliance intention, effectiveness, and self-efficacy. The experience of flow at security education, awareness, and training has been introduced as a pivotal precursor to the expectation of security compliance intention, effectiveness, and self-efficacy. To achieve these goals, this article proposes a hypothesis structure and break down the survey information to test the hypotheses. The components of flow in security education, awareness, and training are extended for this study, and the elements like feedback, challenge, immersion, autonomy, and social interactions are included.
The results of this article represent that the flow at security education, awareness, and training encounters significant associations with the psychological ownership and effectiveness of security education, awareness, and training, which thus positively and directly influence the intention of security compliance. Some managerial implications and theoretical framework are also discussed in this article. This article proposes a hypothesis and proves it with the help of field surveys that an immersive flow in the security education, awareness, and training leads to the user security compliance intention. The hypothesis model or the conceptual model of this article states that factors like feedback, challenge, autonomy, social interaction, immersion, feeling in control, an intrinsic interest of the employees in the activity, focused attention of the user on the activity and a feeling of curiosity in the user regarding the activity leads to an immersive flow. This immersive flow gives rise to psychological ownership and security education, awareness, and training simultaneously. Security education, awareness, and training lead to self-efficacy. This self-efficacy and psychological ownership combined lead to user security compliance intention.
The findings of the investigations of this article make many contributions to information security literature. One significant contribution includes that the investigation found that the flow in security education, awareness, and training has a positive impact on data security in an association. The investigation of this article found that an immersive increase in the flow of security education, awareness, and training leads to user security compliance intention. There is a remarkable link between the user security compliance intention and the immersive flow at security education awareness and training. This investigation also showed that the employees who have high SETA effectiveness are more likely to comply and agree with the security policies of the organization (Chul Woo Yoo, 2018).
From all the investigations and results of this article mentioned above, it is evident that the investigations of this article are in support of our hypothesis. Our hypothesis states that a higher flow in the game-based training leads to higher user security compliance, which was proved in the article provided by (Chul Woo Yoo, 2018). According to (Chul Woo Yoo, 2018), the link between the high flow or immersive flow and user security compliance intention is complex as a higher user security compliance is achieved after the implementation of many steps. But this is a direct link, and through psychological ownership and self-efficacy, higher flow in the game-based training leads to a higher level of user security compliance intention in the employees.
Nakamura and Csikszentmihalyi (2009) researched the flow theory. They stated in their article, flow is the complete immersion of an individual in a task or an activity, and this flow leads to positive psychology, which in other words can be described as the psychological ownership. This psychological ownership, as illustrated by (Chul Woo Yoo, 2018), leads to higher user security compliance intention (Jeanne Nakamura, 2009).
Brühlmann (2013) wrote an article on game-based training methods from the perspective of flow and self-determination. This article stated that in the collaboration of humans and computers, the game-based training or the gamification trend is a piece of the initiative of primary interest, ranging from facilitating all-encompassing procedures to the user experience approach. This article addresses Gamification as the use of game components in a non-game setting. It is gradually and increasingly used in learning, sports, health care, sustainability, crowdsourcing. Higher expectations are placed regarding the positive impacts of Gamification as consumer loyalty is low in today's internet.
This article discusses the Gamification from the viewpoint of the motivational theories. Extensive research on the reward strategies and investigations in the field of computer games makes the self-efficacy and self-determination theory a possible starting point. Similarly, the idea of flow has features when it comes to designing usability and optimal user security compliance. Following the self-determination theory, the potential effects of individual, situational, and logical variables are examined in this study. The article addresses that intrinsic motivation in a task leads to higher flow, and a higher flow leads to higher self-determination. This higher self-determination state leads to better user security compliance. The factors mentioned in this article, which contribute towards a higher state of flow, include challenge-skill base, action-awareness merging, clear goals, and concentration on hand at task. The results of the article's investigation conclude that flow has a practical approach. Aspects like the sense of control, action-awareness, and concentration lead to higher flow and ultimately increases the usability and user security compliance (Florian Brühlmann. E Mekler, 2013).
This article is also in support of our hypothesis. It is proved by the investigations of this article that clear goals, feedback, sense of control if incorporated in the gamification system can lead to higher flow. This higher flow can cause higher user security compliance intention, as the hypothesis of this paper proposes.
H3:
Hamari and Koivisto (2014) measured the flow in Gamification by the dispositional flow scale in their article. This paper assesses the flow of the game-based training and studies the psychological properties of the Dispositional Flow Scale-2. This paper uses information collected from clients of an exercise of Gamification (N = 200). The psychometric examination and of this article suggested that the flow components are based on the related divisions of the flow, which are similarly gradually seen in relation to game-based training. These include a balance of challenge and skill, feedback, clear goals, control, and autotelic experience. The article suggests that the possible outcomes of a lower level of flow can be loss of sense of time, loss of concentration, merging of action and awareness, and loss of self-consciousness.
The article reveals from the psychometric analysis that the flow in the context of game-based trainings should be seen as a division between different settings of the conditions to reach the complete flow state and its consequences which result from achieving the whole flow state rather than fully observing the nine dimensions including concentration, time, autotelic experience, clear goals, feedback, challenge-skill balance, loss of self-consciousness, control, and merging action-awareness, as a total view of the flow (Juho hamari, 2014).
The investigations of this article support the third hypothesis of this paper that a lower level of flow leads to lower user security compliance. The article proves that the nine dimensions of flow are nine separate things, and lower efficacy of any of the nine aspects lead to a lower level of learning, motivation, self-determination, and self-efficacy. And as (Chul Woo Yoo, 2018) illustrates that self-efficacy is directly linked with the user security compliance intention; it is proven that a lower state of flow in the game-based training leads to a lower level of user security compliance.
Chan and Ahern (1999) suggested that modifying the components of the flow theory can lead to the likelihood of an increase or decrease in the learning experiences of the students. The article states that while some scientists suggest the activity content to increase the learning experiences, for example, the flow experience, challenge, and clear goals, others estimate that the flow upgrades through interactive presentation and vividness. This article explores the relationship of the presentation, the activity content, and the flow experience in the teaching process. The results suggest that the activity content factors like inducing clear goals and inducing flow experience have a significant effect on the motivational levels of the students. However, the introduction is a double-edged blade. The presentations of Hypermedia and the induction of flow can motivate the students if they are appropriately used. At this point, when the hypermedia presentations are new, and the flow components are new to the students, elaborate introductions can take a distracting turn. Therefore, when the difficulties are severe and the students are new to the flow understanding, the components of Hypermedia should be used sparingly to start the learning experience. As the exercise progresses, and students are capable of fully understanding the flow components, the learning experience will increase (Tom S. Chan, 1999).
This article indirectly supports our hypothesis. The article states an indirect link of flow with user security compliance. The article proves a direct link of flow with learning and motivation. And learning and motivation are indirectly related to the self-efficacy of the employees, which further leads to user security compliance. Now, this article by YY illustrates that lower induction of flow experiences complicated hypermedia presentations lead to lower learning and motivation experiences, and this hypothesis ultimately leads to the theory that a small state of flow in game-based security training will lead to lower user security compliance.
García-Jurado et al. (2018) evaluated the role of flow and Gamification in the e-commerce industry. The article works on three principled goals. In the first place, it looks at the effects of game-based training on behavioral intention towards an e-commerce website. Second, this paper analyzes the impacts of the state of the flow on the usage of e-commerce sites. Ultimately, the investigation intends to identify and separate the contradictions between millennia and Generation X. In this study, data was collected from Amazon users. Gamification in Millennials has positive and critical roundabout impacts on conduct goals through the stream state. On account of the Generation X, it has been identified that stream meddles in its impression of usability. The social aim of utilizing the Web page is straightforwardly related to the buy expectation. Organizations should offer a pleasant interface to Millennials and a situation simpler to use to Generation X, for Gamification to be effective. The incorporation of game-based training in Millennials has positive and critical roundabout impacts on conducting and achieving the goal through the complete flow state. On account of Generation X, it has been identified that flow meddles in its impression of usability. The social aim of utilizing the Web page is straightforwardly related to user security. Organizations should offer a pleasant interface to Millennials and a situation simpler to use to the Generation X, for Gamification to be useful as dull interfaces do not help to achieve any of the dimensions of the flow like less time for the consumers to buy the products. These flat interfaces lead to a lower state of flow, and the lower state of flow leads to less user security of purchasing the goods.
This article illustrates that the lower the flow, the lower is the enjoyment of the user. And the fun is quite essential for the users to revisit the page. Millennials who don't encounter a stream, Gamification can have negative results on the behavior intention of those users. On the off chance that they are most certainly not getting a charge out of the Web or suitably focused, a symptom of lower flow, the game-based training can bore or distract them, which makes a feeling of dismissal. On account of Generation X, the Gamification additionally doesn't influence the expectation to utilize, and, similarly, as with the Millennials, a higher flow state is required to create constructive outcomes. This article supports the hypothesis and illustrates that with a lower flow, the Gamification can produce no significant results (Alejandro García-Jurado, 2018).
Motivation for hypothesis
H1: Game-based training leads to higher-level user security compliance.
For the first hypotheses, which states that the Gamification or the incorporation of the game-based training techniques in the workplaces leads to an increased level of user security compliance, two articles were chosen in support of this hypothesis. The two articles supporting the hypothesis are (Baxter, Kip, & Wood, 2016) and (Lowry 2020). The hypothesis of this paper states that if the game-based techniques are incorporated in the training of the employees, it can inevitably lead to a higher confirmation and assurance of the security of the users. The elements of gameplay like competition, rules of play, point-scoring are the essential elements of applying game-based techniques in a non-game context. If asked to a training session, these elements can motivate the employees to work harder and focus on their duties while competing with other employees, scoring points, and proving that they are capable of what their job requirement is. The competition with other employees in the training sessions lead to an appropriate challenge phase. This appropriate challenge then leads to employees' motivation to do better for the organization and the users.
Now it is understandable that implementing the gamification techniques in the training sessions is an important task, but it is not an impossible thing to do. Many organizations have started conducting such training sessions for their employees, and they were successful. Lowry and Silic, in their article, stated that specific designs with specific information technology artifacts for particular kinds of employees could be a key to the success of applying game-based techniques in the training sessions. This article supported the hypothesis in many ways. The hypotheses state that game-based techniques can lead to higher user security compliance, which was proven in this article. Game-based technologies like the Kernel theory, hedonic motivation system, and design science research were studied, analyzed, and experimented in. The results of the article proved that long-term research on the specificity of the requirements of the employees, the organization and the type of game-based techniques which can work best on the situation, the successful implementation of the kernel theory and a careful selection of design science research could surely lead to the success of the gamified training session.
In another article by Ryan J. Baxter, it is stated and proved through a field study that game-based techniques are successful in increasing and assuring the security compliance at the user end. The only need is to implement these gamified training sessions properly. The hypothesis can surely be correct and work in the field if the game-based training sessions are not too long that can bore the employees, not executed on the wrong time or after a long day job that can make the employees feel hectic and not interested in the training and the training should be in simple language that an already gamer or a non-gamer, both can easily understand.
Once a training session is successful, the employees are more focused, motivated, and knowledgeable. The employees can then understand their tasks and work better for the security and the demands of the users. This will ultimately lead to a safer organization and safer user security.
H2: A high state of flow in game-based security training will lead to higher user security compliance.
This is the second hypothesis of this paper. For this hypothesis, which states that flow is an essential element for the successful implementation of the Gamification and an immersive or high state of flow will result in an increased rate of user security compliance, three articles were chosen. The articles in support of this hypothesis include (Florian Brühlmann. E Mekler, 2013), (Chul Woo Yoo, 2018) and (Jeanne Nakamura, 2009). The second positive hypothesis states that a high state of flow or an immersive flow is the key to the success of a gamified training and the success of a gamified training leads to a higher assurance of the security of the users. Flow elements are the most important things to consider while we are talking about flow in the gamification context. The hypothesis is correct, as illustrated by Chul Woo Yoo, that the SETA effectiveness can lead to higher psychological ownership, and higher psychological ownership is proved in this article that it ensures a higher user security compliance intention. If we focus on the elements of the flow, there are nine elements, and each aspect, if successfully undertaken, results in a higher user security compliance intention. Chul Woo Yoo proves in his article that an immersive flow directly links with the higher user security compliance intention.
The immersive flow is initiated by the elements of flow, including feedback, challenge, clear goals, social interaction, immersion, feeling in control, and autonomy. The immersive flow or a higher state of flow when initiated, lead to effective security education, awareness, and training. This further leads to the employees' focused attention on the user and results in psychological ownership (Chul Woo Yoo, 2018). Jeanne Nakamura states the same thing and proves that this hypothesis is correct by addressing that the flow is the cause of a psychological ownership state, and this psychological ownership combined with self-efficacy leads to a higher user security compliance (Jeanne Nakamura, 2009). The second hypothesis of this paper is correct and is proven in another field study driven by Florian Brühlmann. Brühlmann proved this hypothesis is right through the self-determination element of the immersive flow (Florian Brühlmann. E Mekler, 2013). Self-determination and other aspects of flow like the sense of immersion, action-awareness, concentration, and focus leads to an increase in usability. This usability of the employees is proved to enhance user security compliance intention. All of the keys which can prove this hypothesis true is already present in the literature.
Understanding this hypothesis is as simple as understanding the basics of flow. Immersive flow by Jeanne Namakura is a state of complete immersion of an individual in any activity (Jeanne Nakamura, 2009). Now, suppose, if an employee who is dealing with users, is completely motivated, focused, and immersed in his job, he will be sure to complete his task with full satisfaction. This is what the hypothesis proposes. Successful enactment of the factors of flow by an employee, like challenge-skill base, concentration on hand at task, clear goals, and action-awareness merging leads to an immersive flow and an immersive flow leads to higher self-efficacy, self-determination, and psychological ownership. The psychological ownership and self-efficacy combined lead to a higher state of user security compliance.
H3: A low state of flow in game-based security training will lead to lower user security compliance.
For the third hypothesis, which states that flow and user security compliance are again directly linked, and the low state of flow in game-based security training leads to lower user security compliance, three articles were chosen. The articles in support of this hypothesis include (Alejandro García-Jurado, 2018) (Juho hamari, 2014) and (Tom S. Chan, 1999). Juho Hamari supported this hypothesis by stating that each of the flow dimensions are separate things (Juho hamari, 2014). An absence of any of the dimensions of flow leads to an overall lower state of flow or a lower efficacy of any dimension leads to lower state of flow. This lower state of flow results in a lower level of motivation, learning, self-efficacy, and self-determination.
Other than the lower state of flow of an employee by himself/herself, the failed induction of flow through training sessions can also lead to a lower state of flow. Now, suppose, if the employees are already not motivated and a gamified security training session also gives no results due to the newness of the components of flow, this will ultimately lead to a state where employees are more confused and complexed. In this state, they would not be able to conduct their job efficiently. They will have less knowledge, lower levels of concentration, and a confused mind regarding how to perform their tasks of the security of their users. All of this will create aa a mess. Ultimately, the result will be a less safe and up-to-the-mark organization with less knowledgeable employees and compromised user security compliance.
To conclude, all three hypotheses are positive hypotheses that present that Gamification increases user security compliance, and, in the Gamification, flow is directly related to user security compliance. If the flow state is higher, the user security compliance is higher, and if the flow state is lower, the user security compliance is more moderate. All the components of flow and user security compliance are like a circle. If the loop breaks, the results get distorted. The flow theory provides enough proof on this topic. All three hypotheses are proven right from the above-discussed literature. For a better understanding, the flow theory is helpful enough, which states that the flow is achieved through feedback, challenge, action-awareness, clear goals, immersion, feeling in control, and autonomy. Once the flow is achieved, it gives rise to self-efficacy and psychological ownership. These two combined leads to user security compliance intention. This is the whole process of how the higher or lower flow leads to a more upper or lower state of user security compliance. Hence, the three hypotheses are accurate based on the review literature and the investigations enacted in that literature.
Conclusion
To conclude, the three hypotheses of this paper are justified by the articles mentioned above. It is proved from the above review of literature that Game-based training leads to higher-level user security compliance, A high state of flow in game-based security training will lead to higher user security compliance and A low state of flow in game-based security training will lead to lower user security compliance. Yet, there is a need for further research in the field of gamified security training to find solutions for the successful induction of flow based on achieving a flow of all nine dimensions individually. Furthermore, merely including a few gamification components to a current framework is not the best methodology. Equivalently, the rewards don't make an exhausting purchase enjoyable over the long haul, game-based training does not fix a terrible design. To know the kind of motivation and flow, an employee needs to undertake an efficient user security compliance might be the optimal design of the game-based training.
References
Adams, M., & Makramalla, M. (2015). Cybersecurity skills training: an attacker-centric gamified approach. Technology Innovation Management Review, 5(1), 1-21 Alomari, I., Al-Samarraie, H., & Yousef, R. (2019). The role of gamification techniques in promoting student learning: A review and synthesis. Journal of Information Technology Education: Research, 395-417. Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A Review of Using Gaming Technology for Cyber-Security Awareness. International Journal for Information Security Research, 660-666. Armstrong, M. B., & Landers, R. N. (2017). An evaluation of gamified training: Using narrative to improve reactions and learning. Simulation & Gaming, 513-538. Ataya, G. (2010). PCI DSS audit and compliance. Information security technical report, 138-144. AlKalbani, A., Deng, H., & Kam, B. (2015, July). Organisational Security Culture and Information Security Compliance for E-Government Development: The Moderating Effect of Social Pressure. In PACIS (p. 65). Al-Kalbani, A. (2017). A Compliance Based Framework for Information Security in E-Government in Oman. https://pdfs.semanticscholar.org/85ae/23222e1a34c2a4e4408a00f047b160ca1c6f.pdf AlKalbani, A., Deng, H., Kam, B., & Zhang, X. (2017). Information Security compliance in organizations: an institutional perspective. Data and Information Management, 1(2), 104-114. Appari, A., Johnson, M. E., & Anthony, D. L. (2009). HIPAA Compliance: An Institutional Theory Perspective, Proceedings of the American Conference on Information Systems, 252. Battaglino, J. (2019, 4 14). 7 Hidden Benefits of IT Security Compliance for Your Business. Retrieved from https://www.cherwell.com/library/blog/it-security-compliance/ Baxter, R. J., Kip, H. J., & Wood, D. A. (2016). Applying Basic Gamification Techniques to IT Compliance Training: Evidence from the Lab and Field. Journal of Information Systems, 119-133. Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: An empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523-548. Brühlmann, F., Mekler, E., & Opwis, K. (2013). Gamification from the perspective of self-determination theory and flow. University of Basel. Chen, E. T. (2015). Gamification as a resourceful tool to improve work performance. In Gamification in education and business, 473-488. Cavusoglu, H., Cavusoglu, H., Son, J.-Y., & Benbasat, I. (2015). Institutional pressures in security management: Direct and indirect influences on organizational investment in information security control resources. Information & Management, 52(4), 385-400. Csikszentmihalyi, M. (1990). Flow: The psychology of optimal experience. New York, NY: Harper and Row Chan, T. S., & Ahern, T. C. (1999). Targeting motivation—adapting flow theory to instructional design. Journal of Educational computing research, 21(2), 151-163. Desai, M. (2016). An integrated approach for information security compliance in a financial services organization. http://etd.cput.ac.za/bitstream/handle/20.500.11838/2396/205219500-Desai-MR-Mtech-IT-FID-2016.pdf?sequence=1&isAllowed=y DiMaggio, P., & Powell, W. W. (1983). The Iron Cage Revisited: Collective Rationality and Institutional Isomorphism in Organizational Fields, American Sociological Review 48(2), 147-160. Dimitriadis, C. (2011). Information Security from a Business Perspective. ISACA Journal 1(1):43-48. Edwards, J. R., Mason, D. S., & Washington, M. (2009). Institutional pressures, government funding and provincial sport organizations. International Journal of Sport Management and Marketing, 6(2), 128-149. Edemekong, P. F., & Haydel., M. J. (2019). Health Insurance Portability and Accountability Act (HIPAA). Erenli. (2013). The impact of gamification-recommending education scenario. International Journal of Emerging Technologies in Learning. Gikas, C. (2010). A general comparison of fisma, hipaa, iso 27000 and pci-dss standards. Information Security Journal: A Global Perspective, 132-141. Gonzalez, H., Llamas, R., & Ordaz, F. (2017). Cybersecurity Teaching through Gamification: Aligning Training Resources to our Syllabus. Research in Computing Science, 35-43. García-Jurado, A., Castro-González, P., Torres-Jiménez, M., & Leal-Rodríguez, A. L. (2019). Evaluating the role of gamification and flow in e-consumers: millennials versus generation X. Kybernetes. Hart, S., Margheri, A., Paci, F., & Sassone, V. (2020). Riskio: A Serious Game for Cyber Security Awareness and Education. Computers & Security. Herath, T., & Rao, H. R. (2009). Encouraging information security behaviors in organizations: Role of penalties, pressures, and perceived effectiveness. Decision Support Systems, 47(2), 154–165. Kanat, I. E., Siloju, S., Raghu, T. S., & Vinze, A. S. (2013). Gamification of emergency response training: A public health example. IEEE, (pp. 134-136). Hamari, J., & Koivisto, J. (2014). Measuring flow in Gamification: Dispositional flow scale-2. Computers in Human Behavior, 40, 133-143. Ke, W., & Wei, K. K. (2008). Organizational culture and leadership in ERP implementation. Decision Support Systems, 45(2), 208-218. Kirsch, L. J., & Boss, S. R. (2007). The Last Line of Defense: Motivating Employees to Follow Corporate Security Guidelines. International Conference on Information Systems, Icis 2007, 103. Kolkowska, E., & Dhillon, G. (2012). Organizational power and information security rule compliance. Computers & Security, 33, pp.3-11 Luh, R., Temper, M., Tjoa, S., Schrittwieser, S., & Janicke, H. (2020). PenQuest: a gamified attacker/defender meta-model for cybersecurity assessment and education. Journal of Computer Virology and Hacking Techniques, 19-61. Mathoosoothenen, V. N., Sundaram, J. S., Palanichamy, R. A., & Brohi, S. N. (2017). An Integrated Real-Time Simulated Ethical Hacking Toolkit with Interactive Gamification Capabilities and Cyber Security Educational Platform. In Proceedings of the 2017 International Conference on Computer Science, (pp. 199-202). Nakamura, J., & Csikszentmihalyi, M. (2009). Flow theory and research. Handbook of positive psychology, 195-206. Pattabiraman, A., Srinivasan, S., Swaminathan, K., & Gupta, M. (2018). Fortifying corporate human wall: A Literature review of security awareness and training. In Information Technology Risk Management and Compliance in Modern Organizations, 142-175. Redhead, A., & Saunders, J. (2019). Gamification and Simulation. In Serious Games for Enhancing Law Enforcement Agencies, 83-98. Ruiz-Alba, L., J., Soares, A., Rodríguez-Molina, M. A., & Banoun., A. (2019). Gamification and entrepreneurial intentions. Journal of Small Business and Enterprise Development. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action. International Journal for Information Security Research. Seaborn, K., & Fels, D. I. (2015). Gamification in theory and action: A survey. International Journal of human-computer studies, 14-31. Safa, N.S., Von Solms, R. & Furnell, S., (2016). Information Security Policy Compliance Model in Organizations, Computers & Security, 56, 70-82. Swinhoe, D. (2020, 4 17). The 15 biggest data breaches of the 21st century. Retrieved from https://www.csoonline.com/article/2130877/the-biggest-data-breaches-of-the-21st-century.html Silic, M., & Lowry, P. B. (2020). Using design-science based Gamification to improve organizational security training and compliance. Journal of Management Information Systems, 37(1), 129-161. Thornton, D., & Francia, G. (2014). Gamification of information systems and security training: Issues and case studies. Information Security Education Journal, 15-24. Yoo, C. W., Sanders, G. L., & Cerveny, R. P. (2018). Exploring the influence of flow and psychological ownership on security education, training and awareness effectiveness and security compliance. Decision Support Systems, 108(1), 107-118. Wolfenden, B. (2019). Gamification as a winning cybersecurity strategy. Computer Fraud & Security, 9-12.