Adaptive Learning Methodology for Cybersecurity Culture through Simulations and Gamification

Authors

DOI:

https://doi.org/10.37943/YXUR4896%20

Keywords:

risk profiling , cybersecurity culture , security awareness , phishing simulation , gamification , adaptive learning platform , instructional design , Kazakh language

Abstract

People, not technology, are the decisive factor in most information security incidents: phishing and other social-engineering attacks exploit users, not systems. Traditional awareness training — a periodic lecture followed by a test — rarely changes behaviour durably and serves poorly users who differ in age, role and competence, a problem especially acute in Kazakhstan and Central Asia, where digital services are mobile-first and Kazakh-language security education is almost absent. This article develops an adaptive-learning methodology for building a cybersecurity culture across user levels, integrating diagnostic risk profiling, an adaptive trajectory, safety-constrained interactive attack simulations and gamification; a PRISMA-guided bibliometric mapping of 129 works in Web of Science and Scopus grounds the integration gap it addresses. The methodology is formalised as a technical specification and implemented as a deployed, trilingual (Kazakh, English, Russian) web-and-mobile platform whose behaviourally scored simulation logs feed a per-learner risk profile that drives trajectory adaptation. We describe the platform’s core algorithms — action scoring, risk-profile update and weak-spot course recommendation — and report their performance: on the live deployment they execute server-side in under three milliseconds, while authenticated API endpoints respond in roughly 60–85 ms end-to-end. End-to-end operation is verified on a demonstration cohort of 61 learner accounts, 124 course enrolments (34 completed) and 264 graded quiz attempts at a mean score of 76.7%. These results establish feasibility rather than training efficacy, which a randomised controlled trial will measure. The contribution is a reproducible, culture-oriented, Kazakh-inclusive methodology, its technical specification, and a working platform that turns awareness into measurable, adaptive behavioural training.

References

Verizon. (2024). 2024 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf

Khonji, M., Iraqi, Y., & Jones, A. (2013). Phishing detection: A literature survey. IEEE Communications Surveys & Tutorials, 15(4), 2091–2121. https://doi.org/10.1109/SURV.2013.032213.00009

Kumaraguru, P., Sheng, S., Acquisti, A., Cranor, L. F., & Hong, J. (2010). Teaching Johnny not to fall for phish. ACM Transactions on Internet Technology, 10(2), 1–31. https://doi.org/10.1145/1754393.1754396

Reinheimer, B., Aldag, L., Mayer, P., Mossano, M., Duezguen, R., Lofthouse, B., von Landesberger, T., & Volkamer, M. (2020). An investigation of phishing awareness and education over time: When and how to best remind users. In Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS 2020) (pp. 259–284). USENIX Association.

Canham, M., Posey, C., Strickland, D., & Constantino, M. (2021). Phishing for long tails: Examining organizational repeat clickers and protective stewards. SAGE Open, 11(1), Article 2158244021990656. https://doi.org/10.1177/2158244021990656

Soylu, D., Medeni, T. D., Andekina, R., Rakhmetova, R., & Ismailova, R. (2021). Identifying the cybercrime awareness of undergraduate and postgraduate students: Example of Kazakhstan. In 2021 IEEE International Conference on Smart Information Systems and Technologies (SIST) (pp. 1–6). IEEE. https://doi.org/10.1109/SIST50301.2021.9465995

Government of the Republic of Kazakhstan. (2023). Concept of digital transformation, development of the information and communication technologies industry and cybersecurity for 2023–2029 (Resolution No. 269, March 28, 2023). Astana, Kazakhstan. https://adilet.zan.kz/rus/docs/P2300000269

Vishwanath, A., Harrison, B., & Ng, Y. J. (2018). Suspicion, cognition, and automaticity model of phishing susceptibility. Communication Research, 45(8), 1146–1166. https://doi.org/10.1177/0093650215627483

Lain, D., Kostiainen, K., & Čapkun, S. (2022). Phishing in organizations: Findings from a large-scale and long-term study. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 842–859). IEEE. https://doi.org/10.1109/SP46214.2022.9833766

Cepeda, N. J., Pashler, H., Vul, E., Wixted, J. T., & Rohrer, D. (2006). Distributed practice in verbal recall tasks: A review and quantitative synthesis. Psychological Bulletin, 132(3), 354–380. https://doi.org/10.1037/0033-2909.132.3.354

Marshall, N., Sturman, D., & Auton, J. C. (2024). Exploring the evidence for email phishing training: A scoping review. Computers & Security, 139, 103695. https://doi.org/10.1016/j.cose.2023.103695

Bitrián, P., Buil, I., Catalán, S., & Merli, D. (2024). Gamification in workforce training: Improving employees’ self-efficacy and information security and data protection behaviours. Journal of Business Research, 179, 114685. https://doi.org/10.1016/j.jbusres.2024.114685

Ryan, R. M., & Deci, E. L. (2000). Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being. American Psychologist, 55(1), 68–78. https://doi.org/10.1037/0003-066X.55.1.68

Amjad, K., Ishaq, K., Nawaz, N. A., Rosdi, F., Dogar, A. B., & Khan, F. A. (2025). Unlocking cybersecurity: A game-changing framework for training and awareness — A systematic review. Human Behavior and Emerging Technologies, 2025(1), Article 9982666. https://doi.org/10.1155/hbe2/9982666

Petersen, K., Vakkalanka, S., & Kuzniarz, L. (2015). Guidelines for conducting systematic mapping studies in software engineering: An update. Information and Software Technology, 64, 1–18. https://doi.org/10.1016/j.infsof.2015.03.007

Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University and Durham University. https://www.elsevier.com/__data/promis_misc/525444systematicreviewsguide.pdf

Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., McGuinness, L. A., Stewart, L. A., Thomas, J., Tricco, A. C., Welch, V. A., Whiting, P., & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71

Aria, M., & Cuccurullo, C. (2017). bibliometrix: An R-tool for comprehensive science mapping analysis. Journal of Informetrics, 11(4), 959–975. https://doi.org/10.1016/j.joi.2017.08.007

Aidynov, T., Goranin, N., Satybaldina, D., & Nurusheva, A. (2024). A systematic literature review of current trends in electronic voting system protection using modern cryptography. Applied Sciences, 14(7), 2742. https://doi.org/10.3390/app14072742

van Eck, N. J., & Waltman, L. (2010). Software survey: VOSviewer, a computer program for bibliometric mapping. Scientometrics, 84(2), 523–538. https://doi.org/10.1007/s11192-009-0146-3

Sheng, S., Magnien, B., Kumaraguru, P., Acquisti, A., Cranor, L. F., Hong, J., & Nunge, E. (2007). Anti-Phishing Phil: The design and evaluation of a game that teaches people not to fall for phish. In Proceedings of the 3rd Symposium on Usable Privacy and Security (SOUPS 2007) (pp. 88–99). ACM. https://doi.org/10.1145/1280680.1280692

Downloads

Published

2026-09-30

How to Cite

Radolda, Y., Muratkhan, R., Kydyrali, D., & Nurmashova, M. (2026). Adaptive Learning Methodology for Cybersecurity Culture through Simulations and Gamification. Scientific Journal of Astana IT University, 27(3), 369–383. https://doi.org/10.37943/YXUR4896

Issue

Section

Pedagogy