Raising Employee Cybersecurity Awareness Through Octalysis-Based Gamification: A Pre-Post Assessment Using HAIS-Q at the Ministry of Public Works and Public Housing

Authors

  • Ramadhan Papua Putra Universitas Bina Nusantara
  • Abba Suganda Girsang Universitas Bina Nusantara

DOI:

https://doi.org/10.59261/jequi.v8i3.364

Keywords:

Cybersecurity, Cybersecurity Awareness, Gamification, The Human Aspect of Information Security Questionnaire (HAIS-Q), Game-Based Learning

Abstract

Background: Rapid digital transformation has increased cybersecurity threats, while employee awareness remains a critical vulnerability in many organizations, including government institutions. Strengthening cybersecurity awareness is essential to reduce human-related security risks.

Objective: This study aims to assess employee cybersecurity awareness at the Ministry of Public Works and Housing (Kementerian Pekerjaan Umum dan Perumahan Rakyat [Ministry of PUPR]) using the Human Aspects of Information Security Questionnaire (HAIS-Q) and to evaluate the effectiveness of an Octalysis-based gamification intervention in improving awareness across knowledge, attitude, and behavior dimensions.

Methods: A pre-post quasi-experimental design was applied involving 146 employees. Data were collected using the validated HAIS-Q instrument before and after a four-week web-based gamification intervention. The gamification design implemented two Octalysis core drives: Development & Accomplishment and Empowerment of Creativity & Feedback, through leaderboard, badge, and instant feedback features.

Results: The findings show that overall cybersecurity awareness increased from 75.85% (medium level) to 83.69% (good level), indicating a 10.33% improvement. All seven HAIS-Q focus areas improved, with the most significant gain observed in internet use (58.22% to 69.79%).

Conclusion: The Octalysis-based gamification approach effectively enhanced employee cybersecurity awareness. Integrating gamification with HAIS-Q provides a structured and evidence-based method for improving cybersecurity behavior in government organizations.

Downloads

Download data is not yet available.

References

Aldawood, H., & Skinner, G. (2019). An academic review of current industrial and commercial cyber security social engineering solutions. Proceedings of the 3rd International Conference on Cryptography, Security and Privacy, 110–115.

Alqahtani, H., & Kavakli-Thorne, M. (2020). Design and evaluation of an augmented reality game for cybersecurity awareness (CybAR). Information, 11(2), 121.

Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003.

Aslam, M. M., Kalinaki, K., Tufail, A., Naim, A. G. H., Khan, M. Z., & Ali, S. (2025). Social Engineering Attacks in Industrial Internet of Things and Smart Industry: Detection and Prevention. Emerging Threats and Countermeasures in Cybersecurity, 389–412.

Budi, E., Wira, D., & Infantono, A. (2021). Strategi penguatan cyber security guna mewujudkan keamanan nasional di era society 5.0. Prosiding Seminar Nasional Sains Teknologi Dan Inovasi Indonesia P-ISSN, 2086, 5805.Budi

Chou, T.-S. (2020). A Game-Based Multiplayer System for Cyber Security Training and Awareness. 2020 CIEC.

Chou, Y. (2015). The octalysis framework for gamification & behavioral design. URL: Https://Yukaichou. Com/Gamification-Examples/Octalysis-Complete-Gamification-Framework/[Accessed 2019-11-03].

Deterding, S., Dixon, D., Khaled, R., & Nacke, L. (2011). From game design elements to gamefulness: defining" gamification". Proceedings of the 15th International Academic MindTrek Conference: Envisioning Future Media Environments, 9–15.

Gjertsen, E. G. B., Gjære, E. A., Bartnes, M., & Flores, W. R. (2017). Gamification of Information Security Awareness and Training. ICISSP, 59–70.

Hart, S., Margheri, A., Paci, F., & Sassone, V. (2020). Riskio: A serious game for cyber security awareness and education. Computers & Security, 95, 101827.

Ifinedo, P. (2013). Information systems security policy compliance: An. Psychological Review, 84(2), 191–215.

Inano, M. (2024). Using octalysis framework in the gamification process of a mobile application.

Iskandar, A. S., Hilman, M., & Yazid, S. (2026). Information security awareness assessment for civil servant recruitment committee in Indonesia using HAIS-Q. Information & Computer Security, 34(1), 86–103.

Islam, M. M., Bhuiyan, M. R. I., Islam, S. H., Tabassum, M. N., & Billah, M. (2026). Unlocking the Mediating and Moderating Role of Information Security in Information Systems: A Combined TAM, ISM, and HBM Model. Human Behavior and Emerging Technologies, 2026(1), 5593002.

Kemper, G. (2019). Improving employees’ cyber security awareness. Computer Fraud & Security, 2019(8), 11–14.

Khan, M. A., Merabet, A., Alkaabi, S., & Sayed, H. El. (2022). Game-based learning platform to enhance cybersecurity education. Education and Information Technologies, 27(4), 5153–5177.

Kruger, H. A., & Kearney, W. D. (2006). A prototype for assessing information security awareness. Computers & Security, 25(4), 289–296.

Kusuma, G. P., Suryapranata, L. K. P., Wigati, E. K., & Utomo, Y. (2021). Enhancing historical learning using role-playing game on mobile platform. Procedia Computer Science, 179, 886–893.

Landers, R. N., & Sanchez, D. R. (2022). Game‐based, gamified, and gamefully designed assessments for employee selection: Definitions, distinctions, design, and validation. International Journal of Selection and Assessment, 30(1), 1–13.

Li, T., Dong, F., & Wen, C. (2025). The Security Awareness Adventure: A serious game for security awareness training utilizing a state transition system and a probabilistic model. Computers & Security, 156, 104500.

Marisa, F., Ahmad, S. S. S., Yusoh, Z. I. M., Maukar, A. L., Marcus, R. D., & Widodo, A. A. (2020). Evaluation of student core drives on e-Learning during the covid-19 with octalysis gamification framework. International Journal of Advance Computer Science and Application, 11(11), 104–116.

Mitnick, K. D., & Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.

Ortiz-Garces, I., Gutierrez, R., Guerra, D., Sanchez-Viteri, S., & Villegas-Ch, W. (2023). RETRACTED: Development of a Platform for Learning Cybersecurity Using Capturing the Flag Competitions. Electronics, 12(7), 1753.

Pahlavanpour, O., & Gao, S. (2024). A systematic mapping study on gamification within information security awareness programs. Heliyon, 10(19).

Park, J., Jeon, S., & Han, J. (2026). Motivating employees to engage in extra-role security behaviors: the role of information security climate and leader–member exchange. Journal of Enterprise Information Management, 1–30.

Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., & Zwaans, T. (2017). The human aspects of information security questionnaire (HAIS-Q): two further validation studies. Computers & Security, 66, 40–51.

Pryhodii, M., & Radkevych, O. (2026). Intensification of vocational training for learners via SMART technologies. Professional Pedagogics, 1(32), 3–17.

Qusa, H., & Tarazi, J. (2021). Cyber-hero: A gamification framework for cyber security awareness for high schools students. 2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC), 677–682.

Rahman, D. F., Tobing, F. A. T., & Hassolthine, C. R. (2025). Design and Evaluation of an AI-Driven Gamified Intelligent Tutoring System for Fundamental Programming Using the Octalysis Framework. Ultimatics: Jurnal Teknik Informatika, 17(2), 221–230.

Sarsa, H. (2013). Does Gamification Work? A Literature Review.

Septasari, D. (2023). The Cyber Security and The Challenge of Society 5.0 Era in Indonesia: Cyber Security and The Challenge of Society 5.0 Era in Indonesia. Aisyah Journal Of Informatics and Electrical Engineering (AJIEE), 5(2), 227–233.

Setiawan, P. R., & Yatim, M. H. M. (2026). Systematic Literature Review of HCI Principles in Role–Playing Game Design: Towards a Comprehensive Framework for Enhancing Programming Skills. Sistemasi: Jurnal Sistem Informasi, 15(1), 33–48.

Sutton, A., & Tompson, L. (2025). Towards a cybersecurity culture-behaviour framework: A rapid evidence review. Computers & Security, 148, 104110.

Triantafyllou, S. A., Georgiadis, C., & Sapounidis, T. (2025). Gamification in education and training: A literature review: SA Triantafyllou et al. International Review of Education, 71(3), 483–517.

Wijanarko, A., & Erlansari, A. (2025). Gamification on Cybersecurity Awareness Training for Adolescents: A Systematic Literature Review. Indonesian Journal of Computer Science and Engineering, 2(02), 6–12.

Yang, Y. T., Ge, Y., & Zhu, Q. (2025). Human Risks and Cognition-Inspired Adaptive Cyber Deception. In Foundations of Cyber Deception: Modeling, Analysis, Design, Human Factors, and Their Convergence (pp. 181–200). Springer.

Downloads

Published

2026-08-26