Raising Employee Cybersecurity Awareness Through Octalysis-Based Gamification: A Pre-Post Assessment Using HAIS-Q at the Ministry of Public Works and Public Housing
DOI:
https://doi.org/10.59261/jequi.v8i3.364Keywords:
Cybersecurity, Cybersecurity Awareness, Gamification, The Human Aspect of Information Security Questionnaire (HAIS-Q), Game-Based LearningAbstract
Background: Rapid digital transformation has increased cybersecurity threats, while employee awareness remains a critical vulnerability in many organizations, including government institutions. Strengthening cybersecurity awareness is essential to reduce human-related security risks.
Objective: This study aims to assess employee cybersecurity awareness at the Ministry of Public Works and Housing (Kementerian Pekerjaan Umum dan Perumahan Rakyat [Ministry of PUPR]) using the Human Aspects of Information Security Questionnaire (HAIS-Q) and to evaluate the effectiveness of an Octalysis-based gamification intervention in improving awareness across knowledge, attitude, and behavior dimensions.
Methods: A pre-post quasi-experimental design was applied involving 146 employees. Data were collected using the validated HAIS-Q instrument before and after a four-week web-based gamification intervention. The gamification design implemented two Octalysis core drives: Development & Accomplishment and Empowerment of Creativity & Feedback, through leaderboard, badge, and instant feedback features.
Results: The findings show that overall cybersecurity awareness increased from 75.85% (medium level) to 83.69% (good level), indicating a 10.33% improvement. All seven HAIS-Q focus areas improved, with the most significant gain observed in internet use (58.22% to 69.79%).
Conclusion: The Octalysis-based gamification approach effectively enhanced employee cybersecurity awareness. Integrating gamification with HAIS-Q provides a structured and evidence-based method for improving cybersecurity behavior in government organizations.
Downloads
References
Aldawood, H., & Skinner, G. (2019). An academic review of current industrial and commercial cyber security social engineering solutions. Proceedings of the 3rd International Conference on Cryptography, Security and Privacy, 110–115.
Alqahtani, H., & Kavakli-Thorne, M. (2020). Design and evaluation of an augmented reality game for cybersecurity awareness (CybAR). Information, 11(2), 121.
Alshaikh, M. (2020). Developing cybersecurity culture to influence employee behavior: A practice perspective. Computers & Security, 98, 102003.
Aslam, M. M., Kalinaki, K., Tufail, A., Naim, A. G. H., Khan, M. Z., & Ali, S. (2025). Social Engineering Attacks in Industrial Internet of Things and Smart Industry: Detection and Prevention. Emerging Threats and Countermeasures in Cybersecurity, 389–412.
Budi, E., Wira, D., & Infantono, A. (2021). Strategi penguatan cyber security guna mewujudkan keamanan nasional di era society 5.0. Prosiding Seminar Nasional Sains Teknologi Dan Inovasi Indonesia P-ISSN, 2086, 5805.Budi
Chou, T.-S. (2020). A Game-Based Multiplayer System for Cyber Security Training and Awareness. 2020 CIEC.
Chou, Y. (2015). The octalysis framework for gamification & behavioral design. URL: Https://Yukaichou. Com/Gamification-Examples/Octalysis-Complete-Gamification-Framework/[Accessed 2019-11-03].
Deterding, S., Dixon, D., Khaled, R., & Nacke, L. (2011). From game design elements to gamefulness: defining" gamification". Proceedings of the 15th International Academic MindTrek Conference: Envisioning Future Media Environments, 9–15.
Gjertsen, E. G. B., Gjære, E. A., Bartnes, M., & Flores, W. R. (2017). Gamification of Information Security Awareness and Training. ICISSP, 59–70.
Hart, S., Margheri, A., Paci, F., & Sassone, V. (2020). Riskio: A serious game for cyber security awareness and education. Computers & Security, 95, 101827.
Ifinedo, P. (2013). Information systems security policy compliance: An. Psychological Review, 84(2), 191–215.
Inano, M. (2024). Using octalysis framework in the gamification process of a mobile application.
Iskandar, A. S., Hilman, M., & Yazid, S. (2026). Information security awareness assessment for civil servant recruitment committee in Indonesia using HAIS-Q. Information & Computer Security, 34(1), 86–103.
Islam, M. M., Bhuiyan, M. R. I., Islam, S. H., Tabassum, M. N., & Billah, M. (2026). Unlocking the Mediating and Moderating Role of Information Security in Information Systems: A Combined TAM, ISM, and HBM Model. Human Behavior and Emerging Technologies, 2026(1), 5593002.
Kemper, G. (2019). Improving employees’ cyber security awareness. Computer Fraud & Security, 2019(8), 11–14.
Khan, M. A., Merabet, A., Alkaabi, S., & Sayed, H. El. (2022). Game-based learning platform to enhance cybersecurity education. Education and Information Technologies, 27(4), 5153–5177.
Kruger, H. A., & Kearney, W. D. (2006). A prototype for assessing information security awareness. Computers & Security, 25(4), 289–296.
Kusuma, G. P., Suryapranata, L. K. P., Wigati, E. K., & Utomo, Y. (2021). Enhancing historical learning using role-playing game on mobile platform. Procedia Computer Science, 179, 886–893.
Landers, R. N., & Sanchez, D. R. (2022). Game‐based, gamified, and gamefully designed assessments for employee selection: Definitions, distinctions, design, and validation. International Journal of Selection and Assessment, 30(1), 1–13.
Li, T., Dong, F., & Wen, C. (2025). The Security Awareness Adventure: A serious game for security awareness training utilizing a state transition system and a probabilistic model. Computers & Security, 156, 104500.
Marisa, F., Ahmad, S. S. S., Yusoh, Z. I. M., Maukar, A. L., Marcus, R. D., & Widodo, A. A. (2020). Evaluation of student core drives on e-Learning during the covid-19 with octalysis gamification framework. International Journal of Advance Computer Science and Application, 11(11), 104–116.
Mitnick, K. D., & Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.
Ortiz-Garces, I., Gutierrez, R., Guerra, D., Sanchez-Viteri, S., & Villegas-Ch, W. (2023). RETRACTED: Development of a Platform for Learning Cybersecurity Using Capturing the Flag Competitions. Electronics, 12(7), 1753.
Pahlavanpour, O., & Gao, S. (2024). A systematic mapping study on gamification within information security awareness programs. Heliyon, 10(19).
Park, J., Jeon, S., & Han, J. (2026). Motivating employees to engage in extra-role security behaviors: the role of information security climate and leader–member exchange. Journal of Enterprise Information Management, 1–30.
Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., & Zwaans, T. (2017). The human aspects of information security questionnaire (HAIS-Q): two further validation studies. Computers & Security, 66, 40–51.
Pryhodii, M., & Radkevych, O. (2026). Intensification of vocational training for learners via SMART technologies. Professional Pedagogics, 1(32), 3–17.
Qusa, H., & Tarazi, J. (2021). Cyber-hero: A gamification framework for cyber security awareness for high schools students. 2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC), 677–682.
Rahman, D. F., Tobing, F. A. T., & Hassolthine, C. R. (2025). Design and Evaluation of an AI-Driven Gamified Intelligent Tutoring System for Fundamental Programming Using the Octalysis Framework. Ultimatics: Jurnal Teknik Informatika, 17(2), 221–230.
Sarsa, H. (2013). Does Gamification Work? A Literature Review.
Septasari, D. (2023). The Cyber Security and The Challenge of Society 5.0 Era in Indonesia: Cyber Security and The Challenge of Society 5.0 Era in Indonesia. Aisyah Journal Of Informatics and Electrical Engineering (AJIEE), 5(2), 227–233.
Setiawan, P. R., & Yatim, M. H. M. (2026). Systematic Literature Review of HCI Principles in Role–Playing Game Design: Towards a Comprehensive Framework for Enhancing Programming Skills. Sistemasi: Jurnal Sistem Informasi, 15(1), 33–48.
Sutton, A., & Tompson, L. (2025). Towards a cybersecurity culture-behaviour framework: A rapid evidence review. Computers & Security, 148, 104110.
Triantafyllou, S. A., Georgiadis, C., & Sapounidis, T. (2025). Gamification in education and training: A literature review: SA Triantafyllou et al. International Review of Education, 71(3), 483–517.
Wijanarko, A., & Erlansari, A. (2025). Gamification on Cybersecurity Awareness Training for Adolescents: A Systematic Literature Review. Indonesian Journal of Computer Science and Engineering, 2(02), 6–12.
Yang, Y. T., Ge, Y., & Zhu, Q. (2025). Human Risks and Cognition-Inspired Adaptive Cyber Deception. In Foundations of Cyber Deception: Modeling, Analysis, Design, Human Factors, and Their Convergence (pp. 181–200). Springer.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ramadhan Papua Putra, Abba Suganda Girsang

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




