Click to edit Master title style
Vera Trubacheva Business Analyst, DLP Research
Kaspersky Lab
How to make people enjoy security
and raise their user awareness via gamification ?
Click to edit Master title style
Page 2
How to raise security?
Click to edit Master title style
Page 3
Humans are the weakest link
Click to edit Master title style
Page 4
Humans are the weakest link
70% of
companies
named humans
as their
greatest
vulnerability
Click to edit Master title style
Page 5
User awareness reduces risks
User awareness is 1 of top 3 security
initiatives for big companies for 2013
Click to edit Master title style
Page 6
“Security training… uhh”
Users
Why traditional training failed?
Click to edit Master title style
Page 7
How to raise security?
1. Gamification can raise user awareness
2. Gamification can raise people’s loyalty
to security policies
Gamification can raise security
Click to edit Master title style
Levels
1. What?
2. Where?
3. How?
Click to edit Master title style
Level 1:
What is gamification?
Click to edit Master title style
Page 10
Click to edit Master title style
Page 11
Gamification is effective
70%
Click to edit Master title style
Page 12
Gamification is effective
50%
Click to edit Master title style
Page 13
Gamification is effective
1. Education
2. Innovation
3. Employees performance
Gartner
Click to edit Master title style
Page 14
Gamification is effective
Pleasure
Dopamine
Click to edit Master title style
Level 2:
Where is gamification used?
Click to edit Master title style
Page 16
Gamification is good for learning
Click to edit Master title style
Page 17
Gamification is good for learning
1. Simulation
2. Stories
Click to edit Master title style
Page 18
Gamification to learn
CyberCIEGE – used to teach network security
by US Navy
Click to edit Master title style
Page 19
Cybersecure: Your Medical Practice used to
teach how to comply with HIPAA
Gamification to learn
Click to edit Master title style
Page 20
Gamification to learn
Anti-Phishing Phil – used by US Airforce and
worldwide
Click to edit Master title style
Page 21
Who does security education via gamification?
Click to edit Master title style
Page 22
Who does security education via gamification?
Security
vendors?
Click to edit Master title style
Level 3:
How can we use gamification?
Click to edit Master title style
Page 24
Gamification at Kaspersky Lab
Click to edit Master title style
Page 25
Gamification to raise user awareness
1. Train in context
2. Tell a story
3. Mock situations
4. Force to make decisions
5. Provide feedback
Click to edit Master title style
Page 26
To raise user awareness
Play game to learn
what phishing is
Click to edit Master title style
Page 27
Gamification to raise user awareness
Integration with training from experts
Click to edit Master title style
Page 28
Gamification to raise user awareness
1. Simulated games - easy
2. Part of real games - challenge
Click to edit Master title style
Page 29
Gamification to raise user awareness
Click to edit Master title style
Page 30
Gamification to comply with policies
Click to edit Master title style
Page 31
Gamification to comply with policies
Security points
Click to edit Master title style
Page 32
Gamification to comply with policies
Building things
Click to edit Master title style
Page 33
Gamification to comply with policies
Click to edit Master title style
Page 34
Gamification to comply with policies
Click to edit Master title style
Page 35
Gamification to comply with policies
Security statuses
Click to edit Master title style
Page 36
Gamification to comply with policies
Security statuses
Good rating Bad rating
Click to edit Master title style
Page 37
Gamification to change behavior
Click to edit Master title style
Page 38
Gamification to change behavior
Click to edit Master title style
Page 39
Summary
1. Gamification can raise user
awareness
2. Gamification can raise people
loyalty to security policies
3. Let’s use gamification in our
products!
Click to edit Master title style
Have fun ;)
How to make people enjoy security and raise their user awareness via gamification?
Vera Trubacheva
Business Analyst, DLP Research
Kaspersky Lab
+7 495 797 8700 x4201