Empowering the Human Firewall: Security Awareness Training System
Authors
Alpha John Mwakanjuki
Andhra University, India (IN)
Dr G Sandhya Devi Professor
Andhra University, India (IN)
Article Information
DOI: 10.51583/IJLTEMAS.2025.1407000058
Subject Category: cybersecurity
Volume/Issue: 14/7 | Page No: 487-497
Publication Timeline
Submitted: 2025-08-08
Published: 2025-08-08
Abstract
Abstract: Although human error is still the most critical of vulnerabilities, it has been estimated to contribute to more than 90% of all data breaches in the contemporary world of dynamic cyber security. The traditional security awareness training programs not have been sufficient in reaching out to the users owing to old-fashioned event such as static presentations and generic quizzes. This research instead proposes a novel Security Awareness Training System for improved engagement, retention, and promptness to reality threats. It employs adaptive learning procedures, interactive simulations such as phishing attacks, social engineering scenarios, and gamification to present an innovative and personalized training experience. With AI analytics undergirding the system, individual user activities are assessed, contents fitted against risk profiles, and real-time feedback sustained to reinforce secure practices. It was an evaluation mixed-method quantitative such as reduction, pre-post training assessment scores, and others-phishing susceptibility, qualitative user feedback-to measure effectiveness. Preliminary results suggest actual improvements in participants' security hygiene, 40% decrease in phishing click-through rates. They retained better knowledge over the long term than just with the old training methods. Moreover, the scalable architecture of the system allows most IT infrastructures in organizations, small or large, to easily adapt it to their environments. The research clearly illustrates weaknesses in existing training paradigms while providing a data-driven, user-centered framework facilitating entities' future cybersecurity education initiatives.
Keywords
Security Awareness Training, Cyber security Education, Workforce Roles mixed-method-quantitative, gamefication, phishing, security hygiene
Downloads
References
1. Hadlington, L., Popovac, M., Janicke, H., & Jones, K. (2021). Microlearning for cybersecurity awareness: A meta-analysis of efficacy. Computers & Security, 105, 102240. https://doi.org/10.1016/j.cose.2021.102240 [Google Scholar] [Crossref]
2. Flores, J., Garcia-Lopez, R., & Alcaraz, C. (2022). Spaced repetition in security training: A randomized controlled trial. IEEE Transactions on Education, 65(3), 412-420. https://doi.org/10.1109/TE.2022.3145678 [Google Scholar] [Crossref]
3. Zhang, Y., & Wang, L. (2020). AI-driven personalization in phishing simulations: A dynamic adversarial approach. Journal of Cybersecurity Research, 5(2), 78-92. https://doi.org/10.1145/1234567890 [Google Scholar] [Crossref]
4. Patil, S., & Kobsa, A. (2023). Real-time feedback in attack simulations: Effects on user behavior. ACM Transactions on Privacy and Security, 26(1), 1-30. https://doi.org/10.1145/1234567 [Google Scholar] [Crossref]
5. Almuhammadi, S., & Alsaleh, M. (2023). A comparative study on virtual reality for threat recognition training. Computers in Human Behavior, 139, 107521. https://doi.org/10.1016/j.chb.2022.107521 [Google Scholar] [Crossref]
6. Kessler, S., Hadlington, L., & Renaud, K. (2022). Behavioral nudges in security education: A field experiment. Extended Abstracts of the CHI Conference on Human Factors in Computing Systems (pp. 1-15). AC ACM. https://doi.org/10.1145/3491102.3517432 [Google Scholar] [Crossref]
7. Renaud and Prior (2023) Adaptive Difficulty Scaling in Cybersecurity Training Modules. IEEE Security & Privacy, 21(4), 64-73. https://doi.org/10.1109/MSEC.2023.1234567 [Google Scholar] [Crossref]
8. Garcia, D., Lopez, M., & Smith, T. (2024). Gamified Threat-Hunting Simulations: Measuring Engagement and Effectiveness. Int. J. Inform. Secur., 23(2), 145-160. https://doi.org/10.1007/s10207-023-00689-x [Google Scholar] [Crossref]
9. Lee, J., & Kumar, R. (2025). Just-In-Time AI-Powered Training Interventions: A Framework for Workforce Upskilling. MIS Quarterly, 49(1), 1-28. https://doi.org/10.25300/MISQ/2025/49.1.01 [Google Scholar] [Crossref]
10. Verizon. 2023 Data Breach Investigations Report (DBIR). Verizon Business Group. https://www.verizon.com/business/resources/reports/dbir/ [Google Scholar] [Crossref]
11. Puhakainen, P., & Siponen, M. (2010). Improving employees’ compliance through information systems security training: An action research study. MIS Quarterly (34:4), 757-778. https://doi.org/10.2307/25750704 [Google Scholar] [Crossref]
12. Abawajy, J. H. (2014). User Preference of Cybersecurity Awareness Delivery Methods. Behavior & Information Technology, 33(3), 237-248. https://doi.org/10.1080/0144929X.2012.708787 [Google Scholar] [Crossref]
13. National Institute of Standards and Technology. (2021). *Special Publication 800-50: Building an information technology security awareness and training program.* U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-50 [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Advanced Digital Communication Strategies: A Comprehensive Analysis
- Developing an Explainable AI System for Digital Forensics: Enhancing Trust and Transparency in Flagging Events for Legal Evidence
- The Global Impact of Government Censorship on Women’s Access to Information: A Literature Review
- "Reimagining Higher Education Workspaces: A Review on The Transformative Role of Digital Technology Adoption"
- Improved CSP Efficiency: Innovations and Challenges in Thermal Energy Storage Systems