Nothing Like the Real Thing! A Randomized Field Experiment of Quasi-Mixed Reality Gamified Phishing Training

Jong Seok Lee, William J. Kettinger, Chen Zhang · ACM SIGMIS Database the DATABASE for Advances in Information Systems · 2025

In recent years, organizations have been incorporating gamification elements and techniques into security compliance training, and research has shown positive outcomes resulting from using gamification in security compliance training. However, research has focused on training using game elements within one-time (or periodic) dedicated training sessions, where training occurs outside an employee's regular work context. Consequently, even if gamified, this ''away from the actual job'' approach may limit the ability to readily draw on earlier training and stay vigilant against phishing attacks once he/she returns to normal job duties. Contrasted with the approach used in prior research, this study proposes mixing gamified security training with the reality of day-to-day work activities, which we call quasi-mixed reality in gamified security training. Specifically, the security training proposed in this study is a several-week-long program that takes place in employees' regular work context while they perform their everyday job tasks. In a randomized field experiment, we find that employees who were randomly assigned to experience quasi-mixed reality in gamified phishing training performed better in detecting and avoiding phishing attacks than those who were assigned to a control group. In addition, we propose and articulate mindfulness of phishing as a psychological mechanism and develop a path model based on mindfulness of phishing to provide insights into how the quasi-mixed reality gamified phishing training improves employee behavior regarding phishing detection and avoidance.

Read the paper · More papers on PaperTik