Gamifying Security Awareness



Similar documents
Enterprise Gamification

Gamification for Enhanced Sales Performance

Gigya Pricing Proposal

The Sophisticated Attack Myth: Hiding Unsophisticated Security Programs: The Irari Rules of Classifying Sophisticated Attacks

Deeper Customer Engagement Through Gamification and Gift Cards

Using Gamification in Reward and Recognition to improve Employee Engagement

2015 Information Security Awareness Catalogue

PREVENTING ZERO-DAY ATTACKS IN MOBILE DEVICES

April 25-28, 2016 COBO Center Detroit, MI

New Partner: The Ritz-Carlton Participation in Marriott Rewards. Questions & Answers to Respond to Guest Questions

Six Characteristics of Customer centric companies. Rob Rich, MD Insights Research

White Paper on Mobile Digital Wallets For Restaurants and Retailers

State of Mobile Event Technology Annual Report 2014

Gamification: Lessons Learnt. Andrea Pontiggia SDA Bocconi

Credit Card Rewards Consumer Insights

FOUR WAYS TECHNOLOGY IS CHANGING EMPLOYEE BENEFITS

Customer Loyalty in the Restaurant

Conferences Going Mobile: 2012 Trends

photos: Shutterstock.com Page 76 lneonline.com Les Nouvelles Esthétiques & Spa November 2014

Auto Insurance Telematics: Where the Data Meets the Road

It s No Game: Gamification Is Transforming the Call Center

Network Security Testing

Guerilla Marketing Tactics for Retailers

Point of View. Loyalty on the Go: A Look at Travel Loyalty Programs in the Digital Space

Running a successful golf club

5 Reasons Why Your Security Education Program isn t Working (and how to fix it)

Engaging Participants Through Gamification

Moving Members to Action: A Benchmarking Study on Member Referral Programs. October 2010

POST HOLDINGS, INC. VENDOR EXPENSE POLICY (Updated 7/28/2015) Section 1 Expense Reimbursements

Universal Design Toolkit for Customer Engagement Business Case and Overview

Training Employees to Recognise & Avoid Advanced Threats

2015 Customer Success Industry Trends Report

Questions about your U.S. Bank FlexPerks Visa Account Call Cardmember Services

UC Small Farm Program Agritourism Webinar Series. Social Media Kristin York - Instructor June 2, 2016

Company Profile. Leti Arts. Meet the Team. Find out about our products, services and technologies. 0 P a g e

IBS' Loyalty and CRM Offerings. Building profitable customer relationships through innovative loyalty & marketing solutions

Questions about your U.S. Bank FlexPerks Visa Account Call Cardmember Services

What is Text Message Marketing?

How To Sponsor Broadsoft 2015

Accounts. Checking. Name Block Date

The Referral Blueprint

How to optimize your app s monetization? Oct

Manu Marketing. Boutique marketing services. Web Development & SEO Social Media Marketing Video Production Mobile Applications

Gamification 101: An Introduction to Game Dynamics Bridge Pkwy Suite 201 Redwood City, CA 94065

COMMUNITY SCHEME. CORPORATE (Page 5) (Companies with more than 20 local staff who have signed our Corporate Affiliation Agreement)

Gamifcation. Paul Anderson - Classroom Game Design. Our Presentation will begin shortly

THE FUTURE CONTENT PART III: RETHINKING CONTENT CONSUMPTION

REWARDS PUSHING PAST THE TIPPING POINT IN MOBILE PAYMENTS PRESENTED BY: JIM MAROUS MATT WILCOX CARLO CARDILLI

Creating Lasting Value With A Point-of-Sale Cash Program

Exhibit VIII.B.2 Player Database and Loyalty Program

Appendix. Data Tables

2015 Janrain Consumer Research UK, France, and Germany Consumer Identity and Mistargeting. Identity-Driven Marketing

Editor Customer Service Newsletter

AMERICAN EXPRESS LOYALTY PROGRAMS THAT TRANSFORM CUSTOMERS INTO

Marketing Tools s, blasts, phone calls Sections for newsletters and e-blasts Ad space in local magazines, newspapers (Unique) Hall of Fame

5 Reasons Why Your Security Education Program isn t Working (and how to fix it)

White Label Reseller Program

BRP SPECIAL REPORT. Loyalty Programs Rewarding the Customer Experience

The Four Pillars of a Successful Rewards Program

Integrating Travel Into Your Expense Management. Introducing TripLink

Adobe Campaign Guide to Loyalty Marketing in a Digital World

Do CEO s deserve what they earn? As financial careers become more lucrative and as the income gap between the

Key Marketing Trends & Developments in 2015

Listen, Measure, and Engage. Is Social Media part of your CRM strategy? Value Driven

Mobile Application Development Projects

Maximizing Your Customer Experience Management Metrics

AmaZing Cash FAQs. About the Program

Take Advantage of Social Media. Monitoring.

Greenify: Fostering Sustainable Communities Via Gamification

Theme Parks: Riding the Social Media Rollercoaster

Does Your Course Have Game? Umer Noor, Lynda Hausman Faculty, SMS & IT

Transcription:

Gamifying Security Awareness SESSION ID: HUM-T07A Ira Winkler President Secure Mentem @IraWinkler Samantha Manke Executive Vice President Secure Mentem @SamanthaManke

Verifying Awareness Training Compliance 2

Traditional Security Awareness Programs Typically pushes information to users Videos, posters, newsletters, etc. Little tracking of usage Forces users to take training Only metrics are Pass/Fail Focuses on topics Great for some environments 3

What is Gamification? The application of game principles to business problems Encouragement of participatory engagement and voluntarily seeking out additional information Not limited to business problems Getting wide use in fitness, training and marketing 4

Common Gamification in the Real World Airline frequent flier programs LinkedIn participation TripAdvisor and Yelp badges Hotel frequent traveler programs Grocery store rewards programs Gas rewards, discounts only to club members Nike+ Starbucks app 5

What They All Strive to Do Create brand loyalty Reward for extra purchases Encourages more of the desired behaviors Completely voluntary 6

What is Gamification of Security Awareness? A long-term, ongoing awareness program Focuses on behaviors Proactively rewards good security behaviors Encourages employees to seek out awareness training and opportunities Gets employees to pull awareness materials Reverses the awareness program paradigm 7

What Is NOT Gamification? An actual game A one-time effort Video based training Phishing simulations If you force users to take the gamified training, it is not gamification! 8

Principles of Gamification 1. Clearly defined goals 2. Rules/limitations 3. Ongoing feedback 4. Voluntary participation 9

Clearly Defined Goals Clearly identified goals Clearly identified rewards for hitting the goals Goals are achievable Rewards are desirable 10

Rules Define how participants attain the goals Creates limitations for achieving goals Limitations make it engaging Think carrying the ball in golf or soccer 11

Feedback Participants know how they are doing towards achieving their goal Organization knows which employees deserve rewards Feedback mechanism can entice further participation 12

Voluntary Participation No one is forced to participate in program Rewards encourage participation With most gamification programs the challenge is the reward Think golf 13

How Do You Create a Gamification Program? Assess your culture Examine your business drivers Identify a theme to create the program around Set up system to record points Create awareness of your program 14

Culture Determines Reward Structure What will incentivize your employees to participate in your program? What will upper management allow you to give? Gift cards, acknowledgment, free lunch, gifts, days off Tiering the reward structure Easy for basic rewards Attainable for advanced rewards Requires work for ultimate reward 15

Business Drivers Determines Point Structure What behaviors do you reward? What activities do you reward? How many points for each? For example, if stopping tailgaters is a big priority for your organization, you should award more points for that than reading an article 16

Sample Point Structure Behavior Points Awarded Read article 50 Forward phishing message 50 Attend lunch and learn 100 Stop tailgater 100 Report social engineering attempt 100 Find security vulnerability 200 Give presentation 250 17

Sample Reward Structure Level Points Reward Beginner 100 Badge, T-shirt Apprentice 500 Badge, gift card, certificate Group Expert 1,000 Badge, executive acknowledgement, bigger gift, advisor status Expert 2,000 Badge, C-level acknowledgment, more money, more shwag Guru 3,000 Badge, promotion, day off Make it worth it! 18

Conclusions Gamification is better for some environments than others Tech people with more autonomy tend to respond better to gamification Not everyone needs to participate You can have multiple programs Culture drives reward structure and rewards Business drivers and security concerns drive points Reverses the security awareness program paradigm 19

Questions?

For More Information Ira@securementem.com +1-443-603-0200www.facebook.com/ira.winkler @irawinkler www.linkedin.com/in/irawinkler Samantha@securementem.com +1-651-325-5902 @samanthamanke http://www.linkedin.com/pub/samanth a-manke/21/34/779 21