DIGITAL LIBRARY
A QUANTITATIVE GAME-BASED APPROACH TO SOCIAL ENGINEERING EDUCATION
Iowa State University (UNITED STATES)
About this paper:
Appears in: EDULEARN26 Proceedings
Publication year: 2026
Article: 1158
ISBN: 978-84-09-88444-5
ISSN: 2340-1117
doi: 10.21125/edulearn.2026.1158
Conference name: 18th International Conference on Education and New Learning Technologies
Dates: 29 June-1 July, 2026
Location: Palma, Spain
Abstract:
The past decade has seen a meteoric surge in the number of high-profile cyberattacks and data breaches. Of particular note however, are how cybersecurity threats increasingly exploit human vulnerabilities, with social engineering based attacks emerging as the dominant vector of attack due to user education and awareness not keeping pace with the development of technical countermeasures. This leaves the general population - particularly non-technical users - inadequately equipped to recognize and mitigate such threats.

This study investigates the hypothesis that game-based learning can serve as an effective pedagogical approach to improving cybersecurity awareness and comprehension compared to traditional instructional methods, with a particular focus on social engineering attacks. To evaluate this, a two-pronged methodology is employed. First, a quantitative assessment is conducted to measure baseline knowledge of social engineering concepts and tactics among a broad sample of college students. A survey instrument, carefully designed to be accessible to participants regardless of technical background, captures their baseline knowledge as a comparable numerical score.

Second, the research presents the design, implementation, and evaluation of a prototype serious game aimed at educating users about common social engineering techniques. The game incorporates narrative driven interactions, scenario based decision-making, and targeted minigames to simulate common attacks such as phishing, dumpster diving, and pretexting. Design decisions emphasize accessibility, engagement, extensibility, and the use of a formal design framework to ensure that pedagogical content is tied closely to gameplay mechanics. This enables the developed serious game to function as a standalone learning tool whilst serving as a foundation for future expansion.

To assess the effectiveness of the proposed approach, participants are split into groups that engage either with the game or with conventional educational material. A comparative analysis examines differences in learning outcomes between students in both groups, with the results indicating a measurable improvement in scores for the game condition group as opposed to the group that engaged with conventional educational materials. This would seem to support the viability of serious games as an educational tool.

Beyond these immediate findings, this work also contributes to the broader discourse on security literacy by discussing the lack of standardized approaches for non-technical audiences. It also highlights the need for further research into scalable frameworks for serious game design, as well as expanded studies across diverse populations and contexts. And while the developed prototype is only meant to serve as a proof of concept, its extensible architecture allows for future expansion, including richer narratives, expanded attack scenarios, and the integration of branching narratives for personalized learning.

In conclusion, this study demonstrates that serious games represent a promising and underutilized strategy for addressing the human factor in cybersecurity. By combining quantitative assessment with an interactive design, it provides both empirical evidence and practical guidance for leveraging game-based learning to strengthen security literacy at scale.
Keywords:
serious game, game-based learning, cybersecurity, social engineering, security literacy.