Abstract
In an increasingly digitised world, the human element continues to be a significant vulnerability
in the cybersecurity landscape. As cyber threats grow in frequency and sophistication, particularly
highlighted during the COVID-19 pandemic, the need to strengthen the ’human firewall’ has become
more pressing. This dissertation introduces "CyberLEAP: Cybersecurity Learning through
Engaging Activities and Play", a novel model designed to promote cybersecurity awareness
through gamification. CyberLEAP aims to offer a structured, engaging, and effective approach to
cybersecurity education, positioning individuals as the first line of defence in the fight against
cyber threats. By harnessing the motivational and immersive qualities of games, the model
advocates for a cultural shift in cybersecurity training, moving away from passive, traditional
methods toward interactive and impactful learning experiences.
A systematic literature review was conducted using methods from the Design Science Research
paradigm to explore existing research on cybersecurity awareness, training, and gamification.
The review revealed a critical gap: despite the abundance of studies on gamified training, there is
a lack of explicit, actionable guidelines to assist in the design of cybersecurity training games.
This absence is particularly challenging for novice designers or educators seeking to develop
engaging cybersecurity awareness tools. Through thematic coding of relevant literature, key
design principles and common components were identified and used to inform the development
of the CyberLEAP model. This model was subsequently validated through the creation and
implementation of a prototype game, which was evaluated against design drivers derived from
the literature.
CyberLEAP is presented as a research artefact and practical model intended to guide both
expert and novice designers in the creation of meaningful, informative, and enjoyable gamified
cybersecurity training experiences. It aims to make the design process more accessible, efficient,
and effective, ultimately contributing to stronger cybersecurity awareness and resilience at the
individual level.