{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:29:09Z","timestamp":1781105349922,"version":"3.54.1"},"reference-count":61,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,4]]},"abstract":"<jats:p>The cyber threat to industrial control systems is an acknowledged security issue, but a qualified dataset to quantify the risk remains largely unavailable. Senior executives of facilities that operate these systems face competing requirements for investment budgets, but without an understanding of the nature of the threat, cyber security may not be a high priority. Education and awareness campaigns are established methods of raising the profile of security issues with stakeholders, but traditional techniques typically deliver generic messages to wide audiences, rather than tailoring the communications to those who understand the impact of organisational risks. This paper explores the use of experiential learning through serious games for senior executives, to develop mental models within which participants can frame the nature of the threat, thereby raising their cyber security awareness, and increasing their motivation to address the issue.<\/jats:p>","DOI":"10.4018\/ijcwt.2017040101","type":"journal-article","created":{"date-parts":[[2017,5,12]],"date-time":"2017-05-12T05:42:44Z","timestamp":1494567764000},"page":"1-15","source":"Crossref","is-referenced-by-count":12,"title":["SCIPS"],"prefix":"10.4018","volume":"7","author":[{"given":"Allan","family":"Cook","sequence":"first","affiliation":[{"name":"De Montfort University, Leicester, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Richard G","family":"Smith","sequence":"additional","affiliation":[{"name":"De Montfort University, Leicester, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5360-9782","authenticated-orcid":true,"given":"Leandros","family":"Maglaras","sequence":"additional","affiliation":[{"name":"De Montfort University, Leicester, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[{"name":"De Montfort University, Leicester, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJCWT.2017040101-0","doi-asserted-by":"publisher","DOI":"10.1111\/j.1559-1816"},{"issue":"3","key":"IJCWT.2017040101-1","doi-asserted-by":"crossref","first-page":"613","DOI":"10.2307\/25750694","article-title":"Practicing safe computing: A multimedia empirical examination of home computer user security behavioral intentions.","volume":"34","author":"C. L.Anderson","year":"2010","journal-title":"Management Information Systems Quarterly"},{"key":"IJCWT.2017040101-2","doi-asserted-by":"crossref","unstructured":"Barford, P., Dacier, M., Dietterich, T. G., Fredrikson, M., & Giffin, J. Jajodia, (2010). Cyber sa: Situational awareness for cyber defense. In Cyber situational awareness (pp. 3\u201313). Springer.","DOI":"10.1007\/978-1-4419-0140-8_1"},{"key":"IJCWT.2017040101-3","author":"M. D.Basil","year":"2013","journal-title":"Effects of social marketing"},{"key":"IJCWT.2017040101-4","doi-asserted-by":"publisher","DOI":"10.3390\/fi4040971"},{"key":"IJCWT.2017040101-5","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2012.31"},{"key":"IJCWT.2017040101-6","author":"B.Burke","year":"2014","journal-title":"Gamify: How gamification motivates people to do extraordinary things"},{"key":"IJCWT.2017040101-7","doi-asserted-by":"publisher","DOI":"10.1049\/ic.2013.0025"},{"key":"IJCWT.2017040101-8","unstructured":"Center, M. I. (2013). Apt1: Exposing one of chinas cyber espionage units. Mandian. com."},{"key":"IJCWT.2017040101-9","author":"E.Cole","year":"2012","journal-title":"Advanced persistent threat: understanding the danger and how to protect your organization"},{"key":"IJCWT.2017040101-10","doi-asserted-by":"publisher","DOI":"10.1016\/j.compedu.2012.03.004"},{"key":"IJCWT.2017040101-11","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2016.12"},{"key":"IJCWT.2017040101-12","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2016.10"},{"key":"IJCWT.2017040101-13","unstructured":"Coventry, L., Briggs, P., Blythe, J., & Tran, M. (2014). Using behavioural insights to improve the publics use of cyber security best practices. Gov.UK report."},{"key":"IJCWT.2017040101-14","doi-asserted-by":"publisher","DOI":"10.1177\/1046878110390784"},{"key":"IJCWT.2017040101-15","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2010.06.023"},{"key":"IJCWT.2017040101-16","doi-asserted-by":"publisher","DOI":"10.1002\/9781118789353"},{"key":"IJCWT.2017040101-17","doi-asserted-by":"publisher","DOI":"10.1109\/ENABL.2004.11"},{"key":"IJCWT.2017040101-18","unstructured":"FireEye. (2014). Fire eye advanced threat report: 2013. http:\/\/www2.fireeye.com\/rs\/fireye\/images\/fireeye-advanced-threat-report-2013.pdf"},{"key":"IJCWT.2017040101-19","unstructured":"Fishbein, M., & Ajzen, I. (1977). Belief, attitude, intention, and behavior: An introduction to theory and research."},{"key":"IJCWT.2017040101-20","unstructured":"GAO. (2004, March). Critical infrastructure protection: Challenges and efforts to secure control systems. Report to Congressional Requesters."},{"issue":"1","key":"IJCWT.2017040101-21","first-page":"37","article-title":"On cyber attacks and signature based intrusion detection for modbus based industrial control systems. Journal of Digital Forensics","volume":"9","author":"W.Gao","year":"2014","journal-title":"Security and Law"},{"key":"IJCWT.2017040101-22","doi-asserted-by":"publisher","DOI":"10.1109\/FIE.2011.6142778"},{"key":"IJCWT.2017040101-23","doi-asserted-by":"crossref","unstructured":"Gundu, T., & Flowerday, S. V. (2012). The enemy within: A behavioural intention model and an information security awareness process. In 2012 information security for South Africa (pp. 1\u20138).","DOI":"10.1109\/ISSA.2012.6320437"},{"key":"IJCWT.2017040101-24","author":"Z.Hiwiller","year":"2015","journal-title":"Players making decisions: Game design essentials and the art of understanding your players"},{"key":"IJCWT.2017040101-25","first-page":"80","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains.","volume":"1","author":"E. M.Hutchins","year":"2011","journal-title":"Leading Issues in Information Warfare & Security Research"},{"key":"IJCWT.2017040101-26","unstructured":"ICS-CERT. (2011). ICS-CERT incident response summary report 2009-2011."},{"key":"IJCWT.2017040101-27","unstructured":"ICS-CERT. (2012). ICS-CERT year in review - 2012. Online. Retrieved from https:\/\/ics-cert.us-cert.gov\/ICS-CERT-Year-Review-2012"},{"key":"IJCWT.2017040101-28","unstructured":"ICS-CERT. (2013). ICS-CERT monitor october, november, december 2013."},{"key":"IJCWT.2017040101-29","unstructured":"ICS-CERT. (2016, January). Ics-cert monitor november\/december 2015. Retrieved from https:\/\/ics-cert.us-cert.gov\/sites\/default\/files\/Monitors\/ICS-CERT"},{"key":"IJCWT.2017040101-30","unstructured":"Kahn, M. N. (2010). Sentiment market analysis. FTPress Delivers."},{"key":"IJCWT.2017040101-31","doi-asserted-by":"publisher","DOI":"10.1111\/j.1539-6924.1981.tb01350.x"},{"key":"IJCWT.2017040101-32","unstructured":"Kaspersky. (2014). Cyberthreats to ICS systems - you don\u2019t have to be a target to become a victim."},{"key":"IJCWT.2017040101-33","doi-asserted-by":"publisher","DOI":"10.1086\/209461"},{"key":"IJCWT.2017040101-34","author":"D. A.Kolb","year":"1984","journal-title":"Experiential learning: Experience as the source of learning and development"},{"key":"IJCWT.2017040101-35","author":"R.Langner","year":"2013","journal-title":"To kill a centrifuge"},{"key":"IJCWT.2017040101-36","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.03.013"},{"key":"IJCWT.2017040101-37","author":"J.Menkes","year":"2009","journal-title":"Executive intelligence"},{"key":"IJCWT.2017040101-38","unstructured":"Merrick, J., Leclerc, P., Trenkov, H., & Olsen, R. (2015). Outthinking the terrorists. Breakthroughs in Decision Science and Risk Analysis, 287."},{"key":"IJCWT.2017040101-39","author":"H.Mills","year":"2000","journal-title":"Artful persuasion: How to command attention, change minds, and influence people"},{"issue":"4","key":"IJCWT.2017040101-40","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1145\/2542049","article-title":"A survey of intrusion detection techniques for cyber-physical systems.","volume":"46","author":"R.Mitchell","year":"2014","journal-title":"ACM Computing Surveys"},{"key":"IJCWT.2017040101-41","doi-asserted-by":"crossref","unstructured":"Miyazaki, A. D., & Fernandez, A. (2001). Consumer perceptions of privacy and security risks for online shopping.The Journal of Consumer Affairs, 35(1), 27\u201344.","DOI":"10.1111\/j.1745-6606.2001.tb00101.x"},{"key":"IJCWT.2017040101-42","unstructured":"NERC. (2010, November). High-impact, low-frequency event risk to the North American bulk power system. A Jointly-Commissioned Summary Report of the North American Electric Reliability Corporation and the U.S. Department of Energy Workshop."},{"key":"IJCWT.2017040101-43","doi-asserted-by":"crossref","unstructured":"O\u2019Reilly, K., Goode, S., & Hart, D. (2010). Exploring mobile commerce intention: Evidence from Australia. In 2010 10th international symposium on communications and information technologies.","DOI":"10.1109\/ISCIT.2010.5665155"},{"key":"IJCWT.2017040101-44","author":"C.Office","year":"2011","journal-title":"The uk cyber security strategy\u2013protecting and promoting the UK in a digital world"},{"key":"IJCWT.2017040101-45","doi-asserted-by":"publisher","DOI":"10.1007\/BF02300540"},{"key":"IJCWT.2017040101-46","doi-asserted-by":"publisher","DOI":"10.1080\/00223980.1975.9915803"},{"key":"IJCWT.2017040101-47","doi-asserted-by":"crossref","unstructured":"Schwartz, B. (2004). The paradox of choice.","DOI":"10.1037\/e597322010-001"},{"key":"IJCWT.2017040101-48","unstructured":"SCIPS Evaluation Workshop. (2015a, 15th May). De Montfort University. SCIPS Evaluation Workshop. (2015b, 29th June). Imperial College, London. SCIPS Evaluation Workshop. (2016, 23rd August). Queen\u2019s University, Belfast."},{"key":"IJCWT.2017040101-49","unstructured":"Stouffer, K., Falco, J., & Scarfone, K. (2011). Guide to industrial control systems (ICS) security. NIST special publication (800\u201382)."},{"key":"IJCWT.2017040101-50","unstructured":"The White House. (2013, February). Executive order - improving critical infrastructure cybersecurity."},{"key":"IJCWT.2017040101-51","doi-asserted-by":"publisher","DOI":"10.4018\/ijgbl.2015040104"},{"key":"IJCWT.2017040101-52","doi-asserted-by":"publisher","DOI":"10.1109\/MIPRO.2015.7160480"},{"key":"IJCWT.2017040101-53","author":"S.Weinschenk","year":"2013","journal-title":"How to get people to do stuff: Master the art and science of persuasion and motivation"},{"key":"IJCWT.2017040101-54","doi-asserted-by":"publisher","DOI":"10.1016\/j.jsr.2003.11.007"},{"key":"IJCWT.2017040101-55","doi-asserted-by":"publisher","DOI":"10.1177\/1046878108321866"},{"key":"IJCWT.2017040101-56","doi-asserted-by":"publisher","DOI":"10.1080\/03637759209376276"},{"key":"IJCWT.2017040101-57","unstructured":"Witte, K. (1998). Fear as motivator, fear as inhibitor: Using the extended parallel process model to explain fear appeal successes and failures."},{"key":"IJCWT.2017040101-58","doi-asserted-by":"crossref","unstructured":"Wu, D., Lowry, P. B., & Zhang, D. (2015). Patient compliance behavior in a mobile healthcare system: An integration of theories of rational choice and planned behavior. Proceedings of the 2015 48th Hawaii international conference on System sciences (HICSS) (pp. 2976\u20132984).","DOI":"10.1109\/HICSS.2015.360"},{"key":"IJCWT.2017040101-59","author":"C.Wueest","year":"2014","journal-title":"Targeted attacks against the energy sector"},{"key":"IJCWT.2017040101-60","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2005.297"}],"container-title":["International Journal of Cyber Warfare and Terrorism"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=181790","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,5]],"date-time":"2022-05-05T20:10:27Z","timestamp":1651781427000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJCWT.2017040101"}},"subtitle":["Using Experiential Learning to Raise Cyber Situational Awareness in Industrial Control System"],"short-title":[],"issued":{"date-parts":[[2017,4]]},"references-count":61,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/ijcwt.2017040101","relation":{},"ISSN":["1947-3435","1947-3443"],"issn-type":[{"value":"1947-3435","type":"print"},{"value":"1947-3443","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,4]]}}}