Cyber security awareness works best when people can see how an attacker thinks. That is why we have launched a new set of interactive Cybersecurity Games designed to help businesses test staff awareness in a practical, low-pressure way.
The games are available online at game.39d.uk/game/ and are designed for staff training, team discussions and awareness sessions. Rather than another long presentation, the aim is to give people a short challenge that makes common cyber risks feel real.
Why we built cyber security games for staff
Most employees do not need to become cyber security specialists. They do, however, make security decisions every working day: opening an email, approving a payment request, choosing a password, signing into Microsoft 365, sharing a file or deciding whether a message looks genuine.
Traditional awareness training can explain the rules, but interactive exercises make those rules easier to remember. A game creates a simple question: what would I do in this situation? That makes it easier to identify habits that could expose the business to phishing, account takeover, impersonation or password attacks.
Launching with password and social-engineering awareness
One of the first exercises looks at password habits and how much useful information an attacker can obtain from predictable patterns. It explores behaviours such as using names, family references, pets, hobbies, company names, locations, important years, familiar number patterns and similar passwords across several services.
The exercise does not need a member of staff to type in their real password. Instead, it tests the habits around how passwords are created and reused, then explains the kinds of patterns a targeted attacker may try.
This is important because a password can look complicated while still being predictable. Adding a year, an exclamation mark or a number to a familiar word does not automatically make it strong if the underlying pattern can be guessed.
What should your team learn from the games?
The objective is not to catch people out. It is to create useful conversations and show where small changes can reduce risk. Staff should come away with a clearer understanding of practical controls such as:
- using a unique password for every account;
- using a password manager rather than inventing memorable variations;
- enabling multi-factor authentication or passkeys wherever possible;
- avoiding passwords based on information that may be visible on social media or company websites;
- reporting suspicious emails, login prompts and payment requests quickly;
- checking unusual requests using a second, trusted method of communication.
A useful way to test cyber security awareness in your business
You can use the games as a quick exercise during a team meeting, induction session or cyber security awareness week. A simple approach is:
- Send the game link to the team. Give staff a few minutes to complete the exercise individually.
- Discuss the result rather than individual scores. Focus on the risky habits the game highlights.
- Ask what would happen in the real business. For example, who would a member of staff contact if they received a suspicious Microsoft 365 login prompt or an urgent request to change bank details?
- Turn the discussion into actions. This might include rolling out a password manager, enabling MFA, changing a payment-verification process or arranging additional phishing awareness training.
- Repeat the exercise later. Security awareness is more effective when it becomes part of normal business behaviour rather than a once-a-year compliance task.
Games are a starting point, not the whole security programme
Staff awareness is one layer of cyber security. It should sit alongside technical controls such as advanced email filtering, endpoint detection and response, secure backups, managed firewalls, vulnerability management and well-configured Microsoft 365 security.
A well-trained employee may spot a suspicious email, but the business should still have technology and processes that reduce the chance of that email reaching them in the first place. Equally, good technology still benefits from staff who know how to recognise and report unusual behaviour.
Use the games alongside phishing simulations and awareness training
For businesses that want to go further, 39Security provides managed security awareness and phishing simulations. This allows awareness activity to become an ongoing programme with regular testing, reporting, new-starter training and follow-up support rather than a single annual exercise.
We also run practical cyber security training days for business owners, directors, managers and internal IT contacts across Essex, Kent and Hertfordshire. These sessions cover phishing, payment fraud, passwords, MFA, Microsoft 365, Windows security, backups, incident response and Cyber Essentials.
Try the new Cybersecurity Games
The games are available now. Try them yourself, share them with your staff and use the results to start a practical conversation about the behaviours that could put your business at risk.
Launch the Cybersecurity Games and test your awareness →
If the exercise identifies gaps in your organisation, you can also complete our free cyber security assessment or speak to 39Security about a managed staff-awareness programme.