European Journal of Information Systems · 2020 · 81 citations · 103 references
EngineeringInformation SecurityUser AwarenessInformation Security EducationCommunicationOsd BehaviourSecurity AwarenessGame DesignGraphic MessagingDigital StorytellingGamificationDesignUser ExperienceData PrivacyInteractive StorytellingOnline Self-disclosureMedia DesignOrganizational CommunicationSocial ComputingGamified Seta ArtefactsDesign ThinkingHuman-computer InteractionArtsOwn Training Adventure
Online self‑disclosure on social networking sites can leave individuals and organisations vulnerable to security threats. The study aimed to design a gamified, choose‑your‑own‑adventure security education artefact in text and visual formats and to deepen understanding of how such artefacts influence human experiences through design science thinking. The artefacts were built to detect trainees’ most vulnerable threats, debrief them, and prompt decision re‑evaluation, and their effectiveness was evaluated in a longitudinal randomized controlled trial against no intervention and standard warning emails, measuring instrumental and experiential outcomes. The study found that the text‑based artefact improved instrumental outcomes while the visual‑based artefact enhanced experiential outcomes, and it yielded design principles, testable propositions, and performance metrics for gamified SETA artefacts, offering practical recommendations for regulating employees’ information security and privacy behaviours.
Online self-disclosure (OSD) on social networking sites can leave individuals and organisations vulnerable to security threats. Following a design science research (DSR) method, we created a gamified, “choose your own adventure” style security education, training, and awareness (SETA) artefact using two formats: text and visual. Both artefacts were designed to identify the security threats that trainees are most susceptible to, debrief them about the threat and its potential consequences, and facilitate behaviour change by letting trainees re-evaluate their decisions. Using a longitudinal randomised controlled experiment, we compared these two artefacts to no intervention and traditional security warning emails by assessing both instrumental (changes in attitudes, intentions, and OSD behaviour) and experiential (memorability and user experience) outcomes. Our survey of 1,718 employees showed that the text-based artefact was better at improving instrumental outcomes, and the visual-based artefact was better at improving experiential outcomes. This study provides a more granular understanding of the linkages between technology artefacts and human experiences through the application of design science thinking. The findings contribute to DSR by developing design principles, testable propositions, and realistic performance evaluation metrics for gamified SETA artefacts, and present practical recommendations for regulating employees’ information security and privacy behaviours inside and outside the workplace.
103