Pedagogical perspectives on cyber security exercises - A rationale and literature overview

Authors:

  • Fredrik Söderström

Publish date: 2025-01-27

Report number: FOI-R--5575--SE

Pages: 45

Written in: Swedish

Keywords:

  • cybersecurity
  • cybersecurity exercise
  • learning
  • pedagogy

Abstract

Cybersecurity exercises are a well-established way of practicing skills and ability to deal with threats in the cyber domain. This type of exercises are carried out in a controlled, simulated and realistic environment, where the participants are expected to develop their ability to deal with different kinds of threats and attacks. However, in practice and research, this area has received primarily a technical focus, resulting in taking the participants' knowledge development and learning, related to the exercise more or less for granted. Within research and practice, there is a clear need for more cross-border and holistic perspectives on cybersecurity exercises. Above all, a clear need to integrate perspectives on learning and pedagogy in the field is described. Without pedagogical perspectives on cybersecurity exercises, ensuring that the participants develop the learning and ability sought is difficult. This report presents the results of a literature overview focusing on pedagogical perspectives on cybersecurity exercises. In summary, this research area is driven by increasing cybersecurity needs, is relatively newly established, and requires further research. Current research presents several good ideas and well-motivated arguments, but approaches and methodologies where pedagogy is a well-integrated part throughout the exercise life cycle is missing. Pedagogical perspectives on cybersecurity exercises is a sub-area needing further studies and knowledge development. This report is a step towards further motivating and developing this research perspective on cybersecurity exercises at the Swedish Defence Research Agency (FOI).