This study aims to deal with the long-standing disparity in conventional cybersecurity training and effective behavioral alteration by creating and testing a Reward-Driven Bloom’s Taxonomy Framework. The framework by incorporating the elements of gamification and the principle of cognitive learning contributes to improving cybersecurity awareness, knowledge retention and security-conscious behaviour in organizations.
The mixed-methods quasi-experimental design were used through three stages: expert validation of the pre-implementation (n = 18), the implementation of the training through Proofpoint Learning Management System (LMS) (n = 414 enrolled, 100% completion rate) and the evaluation of the post-implementation (n = 100). The elements of gamification such as badges, certificates, leaderboards and tiered challenges were combined with the six levels of cognition introduced by Bloom. T-tests, ANOVA and chi-square were used as quantitative analysis and thematic analysis as the qualitative data were analyzed using the framework by Braun and Clarke (2006).
The findings indicate statistically significant gains in knowledge retention of cybersecurity (18.4% increase, p = 0.01), motivation (27% increase of gamified competition participants, p = 0.013) and self-reported behavioral intent (33.5% increase in positive acceptable use policy (AUP) compliance responses). The chi-square tests proved that there were significant correlations between competition participation and motivation (χ² = 22.51, p = 0.001). ANOVA noted that there existed a significant difference between the departmental differences (p = 0.045) and there was also a difference in age in terms of risk perception (F(2,93) = 3.176, p = 0.017). The sizes of the effects were small to medium (Cohen d = 0.34–0.58). Applied practice was found to be the most prevailing reason for knowledge retention (62% of participants).
The single-organization type of design in the context of Saudi Arabia restricts generalizability. This is because lack of a control group limits causal inference but pre- post comparisons and triangulation enhance validity. The self-reported behavioral measures will have to be validated by the objective indicators in future like the phishing performance. Future research would involve longitudinal evaluation of behaviour persistence and not just in the aftermath of post-training.
The research is an original contribution, as it will systematically combine the application of Bloom-cognitive taxonomy with the theory of gamification based on the framework proposed by Deterding et al. (2011). Compared to previous studies that have concentrated on either cognitive progression or gamified interaction as an independent variable, this framework shows the synergistic impact of a particular game feature (points, badges, leaderboards, certificates) and a particular level of cognitive performance (Remember through Create) on attitudinal and behavioral outcomes. The study provides a tested framework that fills the gap between educational psychology and incentive-based learning, promoting sustainable cybersecurity behavior change. While the research was conducted within a single organization in Saudi Arabia, the framework offers a scalable model that can be adapted to other organizational contexts for broader implementation.
