00
Days
00
Hrs
00
Min
00
Sec
Submit Your Paper

Empowering the Human Firewall: Security Awareness Training System

Authors

Alpha John Mwakanjuki

Andhra University, India (IN)

Dr G Sandhya Devi Professor

Andhra University, India (IN)

Article Information

DOI: 10.51583/IJLTEMAS.2025.1407000058

Subject Category: cybersecurity

Volume/Issue: 14/7 | Page No: 487-497

Publication Timeline

Submitted: 2025-08-08

Published: 2025-08-08

Abstract

Abstract: Although human error is still the most critical of vulnerabilities, it has been estimated to contribute to more than 90% of all data breaches in the contemporary world of dynamic cyber security. The traditional security awareness training programs not have been sufficient in reaching out to the users owing to old-fashioned event such as static presentations and generic quizzes. This research instead proposes a novel Security Awareness Training System for improved engagement, retention, and promptness to reality threats. It employs adaptive learning procedures, interactive simulations such as phishing attacks, social engineering scenarios, and gamification to present an innovative and personalized training experience. With AI analytics undergirding the system, individual user activities are assessed, contents fitted against risk profiles, and real-time feedback sustained to reinforce secure practices. It was an evaluation mixed-method quantitative such as reduction, pre-post training assessment scores, and others-phishing susceptibility, qualitative user feedback-to measure effectiveness. Preliminary results suggest actual improvements in participants' security hygiene, 40% decrease in phishing click-through rates. They retained better knowledge over the long term than just with the old training methods. Moreover, the scalable architecture of the system allows most IT infrastructures in organizations, small or large, to easily adapt it to their environments. The research clearly illustrates weaknesses in existing training paradigms while providing a data-driven, user-centered framework facilitating entities' future cybersecurity education initiatives.  

Keywords

Security Awareness Training, Cyber security Education, Workforce Roles mixed-method-quantitative, gamefication, phishing, security hygiene

Downloads

References

1. Hadlington, L., Popovac, M., Janicke, H., & Jones, K. (2021). Microlearning for cybersecurity awareness: A meta-analysis of efficacy. Computers & Security, 105, 102240. https://doi.org/10.1016/j.cose.2021.102240 [Google Scholar] [Crossref]

2. Flores, J., Garcia-Lopez, R., & Alcaraz, C. (2022). Spaced repetition in security training: A randomized controlled trial. IEEE Transactions on Education, 65(3), 412-420. https://doi.org/10.1109/TE.2022.3145678 [Google Scholar] [Crossref]

3. Zhang, Y., & Wang, L. (2020). AI-driven personalization in phishing simulations: A dynamic adversarial approach. Journal of Cybersecurity Research, 5(2), 78-92. https://doi.org/10.1145/1234567890 [Google Scholar] [Crossref]

4. Patil, S., & Kobsa, A. (2023). Real-time feedback in attack simulations: Effects on user behavior. ACM Transactions on Privacy and Security, 26(1), 1-30. https://doi.org/10.1145/1234567 [Google Scholar] [Crossref]

5. Almuhammadi, S., & Alsaleh, M. (2023). A comparative study on virtual reality for threat recognition training. Computers in Human Behavior, 139, 107521. https://doi.org/10.1016/j.chb.2022.107521 [Google Scholar] [Crossref]

6. Kessler, S., Hadlington, L., & Renaud, K. (2022). Behavioral nudges in security education: A field experiment. Extended Abstracts of the CHI Conference on Human Factors in Computing Systems (pp. 1-15). AC ACM. https://doi.org/10.1145/3491102.3517432 [Google Scholar] [Crossref]

7. Renaud and Prior (2023) Adaptive Difficulty Scaling in Cybersecurity Training Modules. IEEE Security & Privacy, 21(4), 64-73. https://doi.org/10.1109/MSEC.2023.1234567 [Google Scholar] [Crossref]

8. Garcia, D., Lopez, M., & Smith, T. (2024). Gamified Threat-Hunting Simulations: Measuring Engagement and Effectiveness. Int. J. Inform. Secur., 23(2), 145-160. https://doi.org/10.1007/s10207-023-00689-x [Google Scholar] [Crossref]

9. Lee, J., & Kumar, R. (2025). Just-In-Time AI-Powered Training Interventions: A Framework for Workforce Upskilling. MIS Quarterly, 49(1), 1-28. https://doi.org/10.25300/MISQ/2025/49.1.01 [Google Scholar] [Crossref]

10. Verizon. 2023 Data Breach Investigations Report (DBIR). Verizon Business Group. https://www.verizon.com/business/resources/reports/dbir/ [Google Scholar] [Crossref]

11. Puhakainen, P., & Siponen, M. (2010). Improving employees’ compliance through information systems security training: An action research study. MIS Quarterly (34:4), 757-778. https://doi.org/10.2307/25750704 [Google Scholar] [Crossref]

12. Abawajy, J. H. (2014). User Preference of Cybersecurity Awareness Delivery Methods. Behavior & Information Technology, 33(3), 237-248. https://doi.org/10.1080/0144929X.2012.708787 [Google Scholar] [Crossref]

13. National Institute of Standards and Technology. (2021). *Special Publication 800-50: Building an information technology security awareness and training program.* U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-50 [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles

© 2026 IJLTEMAS · RSIS International. All rights reserved. ISSN 2278-2540.