Gamification is often suggested as a way to make cybersecurity awareness more engaging. That can be useful, but voluntary activities do not always reach as many people as we hope.
In many organizations, the same motivated participants return to every quiz, challenge or competition. It is tempting to see that pattern as evidence that the activity has failed. I think it tells us something more specific: repeat engagement and broad reach are different outcomes.
Who is the activity actually reaching?
People who enjoy security challenges are often already curious, confident or comfortable asking questions. Their participation is valuable, but it does not automatically tell us how the wider organization experiences security.
Someone who is busy, unsure of their technical knowledge or simply unconvinced that the activity is for them may never join. That person is not necessarily uninterested in security. The invitation, format or timing may not have made participation feel relevant.
A repeat participant can be a sign of genuine value. It is not, by itself, evidence of broad participation.
A broader event can change the pattern
In a previous role, I helped organize an internal Capture the Flag cybersecurity event that attracted more than 100 teams and over 450 participants from engineering and non-engineering backgrounds.
The result was not only about the challenge content. Packaging the activity as a visible, time-bound and team-based event created a clearer reason to join. People could participate with colleagues, learn as they went and see the event as something happening across the organization rather than as a specialist exercise.
That format does not remove every barrier. It does, however, create social momentum and make the invitation easier to understand. A team can also provide a more comfortable entry point for someone who would not take part alone.
What should success mean?
Before launching a gamified activity, I would separate the outcomes we are trying to achieve:
- Depth: did returning participants practise or retain something useful?
- Reach: did people from different roles, teams or experience levels take part?
- Conversation: did the activity create useful discussions about everyday security decisions?
- Follow-through: did the experience lead to a safer action or a question that needed attention?
One activity may be good at depth and another at reach. Treating them as separate measures helps us improve the design instead of judging every event by a single participation number.
Questions I would ask before the next event
- Who is currently participating?Look at the pattern, not only the total count.
- Who is missing?Consider role, confidence, time zone, accessibility and the language used in the invitation.
- What behaviour are we trying to reinforce?A leaderboard is a format, not an objective.
- Could people participate with others?Teams, shared sessions and visible support can lower the barrier to entry.
- What will we learn from the event?Use feedback and participation patterns to shape the next activity.
Gamification will not reach everyone, and it should not be asked to solve every human-risk problem. It can still be useful when we are honest about the audience it attracts and deliberate about designing additional ways for others to participate.
The strongest outcome may not be a perfect leaderboard. It may be a wider group of people feeling that cybersecurity is relevant to the work they already do.