Adaptive Learning Methodology for Cybersecurity Culture through Simulations and Gamification
DOI:
https://doi.org/10.37943/YXUR4896%20Keywords:
risk profiling , cybersecurity culture , security awareness , phishing simulation , gamification , adaptive learning platform , instructional design , Kazakh languageAbstract
People, not technology, are the decisive factor in most information security incidents: phishing and other social-engineering attacks exploit users, not systems. Traditional awareness training — a periodic lecture followed by a test — rarely changes behaviour durably and serves poorly users who differ in age, role and competence, a problem especially acute in Kazakhstan and Central Asia, where digital services are mobile-first and Kazakh-language security education is almost absent. This article develops an adaptive-learning methodology for building a cybersecurity culture across user levels, integrating diagnostic risk profiling, an adaptive trajectory, safety-constrained interactive attack simulations and gamification; a PRISMA-guided bibliometric mapping of 129 works in Web of Science and Scopus grounds the integration gap it addresses. The methodology is formalised as a technical specification and implemented as a deployed, trilingual (Kazakh, English, Russian) web-and-mobile platform whose behaviourally scored simulation logs feed a per-learner risk profile that drives trajectory adaptation. We describe the platform’s core algorithms — action scoring, risk-profile update and weak-spot course recommendation — and report their performance: on the live deployment they execute server-side in under three milliseconds, while authenticated API endpoints respond in roughly 60–85 ms end-to-end. End-to-end operation is verified on a demonstration cohort of 61 learner accounts, 124 course enrolments (34 completed) and 264 graded quiz attempts at a mean score of 76.7%. These results establish feasibility rather than training efficacy, which a randomised controlled trial will measure. The contribution is a reproducible, culture-oriented, Kazakh-inclusive methodology, its technical specification, and a working platform that turns awareness into measurable, adaptive behavioural training.
References
Verizon. (2024). 2024 data breach investigations report. Verizon Business. https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf
Khonji, M., Iraqi, Y., & Jones, A. (2013). Phishing detection: A literature survey. IEEE Communications Surveys & Tutorials, 15(4), 2091–2121. https://doi.org/10.1109/SURV.2013.032213.00009
Kumaraguru, P., Sheng, S., Acquisti, A., Cranor, L. F., & Hong, J. (2010). Teaching Johnny not to fall for phish. ACM Transactions on Internet Technology, 10(2), 1–31. https://doi.org/10.1145/1754393.1754396
Reinheimer, B., Aldag, L., Mayer, P., Mossano, M., Duezguen, R., Lofthouse, B., von Landesberger, T., & Volkamer, M. (2020). An investigation of phishing awareness and education over time: When and how to best remind users. In Proceedings of the 16th Symposium on Usable Privacy and Security (SOUPS 2020) (pp. 259–284). USENIX Association.
Canham, M., Posey, C., Strickland, D., & Constantino, M. (2021). Phishing for long tails: Examining organizational repeat clickers and protective stewards. SAGE Open, 11(1), Article 2158244021990656. https://doi.org/10.1177/2158244021990656
Soylu, D., Medeni, T. D., Andekina, R., Rakhmetova, R., & Ismailova, R. (2021). Identifying the cybercrime awareness of undergraduate and postgraduate students: Example of Kazakhstan. In 2021 IEEE International Conference on Smart Information Systems and Technologies (SIST) (pp. 1–6). IEEE. https://doi.org/10.1109/SIST50301.2021.9465995
Government of the Republic of Kazakhstan. (2023). Concept of digital transformation, development of the information and communication technologies industry and cybersecurity for 2023–2029 (Resolution No. 269, March 28, 2023). Astana, Kazakhstan. https://adilet.zan.kz/rus/docs/P2300000269
Vishwanath, A., Harrison, B., & Ng, Y. J. (2018). Suspicion, cognition, and automaticity model of phishing susceptibility. Communication Research, 45(8), 1146–1166. https://doi.org/10.1177/0093650215627483
Lain, D., Kostiainen, K., & Čapkun, S. (2022). Phishing in organizations: Findings from a large-scale and long-term study. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 842–859). IEEE. https://doi.org/10.1109/SP46214.2022.9833766
Cepeda, N. J., Pashler, H., Vul, E., Wixted, J. T., & Rohrer, D. (2006). Distributed practice in verbal recall tasks: A review and quantitative synthesis. Psychological Bulletin, 132(3), 354–380. https://doi.org/10.1037/0033-2909.132.3.354
Marshall, N., Sturman, D., & Auton, J. C. (2024). Exploring the evidence for email phishing training: A scoping review. Computers & Security, 139, 103695. https://doi.org/10.1016/j.cose.2023.103695
Bitrián, P., Buil, I., Catalán, S., & Merli, D. (2024). Gamification in workforce training: Improving employees’ self-efficacy and information security and data protection behaviours. Journal of Business Research, 179, 114685. https://doi.org/10.1016/j.jbusres.2024.114685
Ryan, R. M., & Deci, E. L. (2000). Self-determination theory and the facilitation of intrinsic motivation, social development, and well-being. American Psychologist, 55(1), 68–78. https://doi.org/10.1037/0003-066X.55.1.68
Amjad, K., Ishaq, K., Nawaz, N. A., Rosdi, F., Dogar, A. B., & Khan, F. A. (2025). Unlocking cybersecurity: A game-changing framework for training and awareness — A systematic review. Human Behavior and Emerging Technologies, 2025(1), Article 9982666. https://doi.org/10.1155/hbe2/9982666
Petersen, K., Vakkalanka, S., & Kuzniarz, L. (2015). Guidelines for conducting systematic mapping studies in software engineering: An update. Information and Software Technology, 64, 1–18. https://doi.org/10.1016/j.infsof.2015.03.007
Kitchenham, B., & Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering (EBSE Technical Report EBSE-2007-01). Keele University and Durham University. https://www.elsevier.com/__data/promis_misc/525444systematicreviewsguide.pdf
Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., McGuinness, L. A., Stewart, L. A., Thomas, J., Tricco, A. C., Welch, V. A., Whiting, P., & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71
Aria, M., & Cuccurullo, C. (2017). bibliometrix: An R-tool for comprehensive science mapping analysis. Journal of Informetrics, 11(4), 959–975. https://doi.org/10.1016/j.joi.2017.08.007
Aidynov, T., Goranin, N., Satybaldina, D., & Nurusheva, A. (2024). A systematic literature review of current trends in electronic voting system protection using modern cryptography. Applied Sciences, 14(7), 2742. https://doi.org/10.3390/app14072742
van Eck, N. J., & Waltman, L. (2010). Software survey: VOSviewer, a computer program for bibliometric mapping. Scientometrics, 84(2), 523–538. https://doi.org/10.1007/s11192-009-0146-3
Sheng, S., Magnien, B., Kumaraguru, P., Acquisti, A., Cranor, L. F., Hong, J., & Nunge, E. (2007). Anti-Phishing Phil: The design and evaluation of a game that teaches people not to fall for phish. In Proceedings of the 3rd Symposium on Usable Privacy and Security (SOUPS 2007) (pp. 88–99). ACM. https://doi.org/10.1145/1280680.1280692
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.