A Governance and Architectural Framework for Agentic AI-Driven Gamified Security Awareness
Abstract
: The cybersecurity landscape has evolved from being predominantly technical to becoming a complex socio-technical challenge, where the human element stands as a major attack vector. Traditional Security Education, Training, and Awareness programs often fail due to generalized approaches that neglect individual learner variability, the psychological costs of compliance, and the accelerating volatility of the threat landscape driven by Generative Artificial Intelligence. This work follows a Design Science Research approach, focusing on artifact design and theoretical integration for the proposal of an innovative learning system. By synthesizing topics such as the theory of Nonlinear Dynamic Motivation and the Social Engineering Attack Framework, we present a systematic multi-agent assisted architectural model for cybersecurity awareness training. We acknowledge the important role of Diegetic Connectivity in enhancing training engagement, as it seamlessly embeds learning within a realistic narrative context. As such, we propose leveraging organizational intranet data to derive more convincing and contextually grounded scenarios while reflecting on inherent data privacy concerns.