UX Research · University of Brighton · IDM04 · 4 months
Led the research pipeline for a gamified cybersecurity escape room: a 29-question survey, binary coding of 98 responses, five in-depth interviews, and personas that shaped the game design.
[ 01 · The brief ]
The gap is not awareness. It is behaviour.
The team was asked to address a real problem: cybersecurity training is widely described as uninspiring and repetitive, producing low engagement and low retention. Our hypothesis was that the failure was motivational, not informational.
My scope was the research infrastructure: designing the instrument, coding the data, and turning it into personas the design team could build a game around.
[ 02 · Process ]
What I did
- Designed a 29-question survey targeting stated knowledge against reported behaviour
- Binary-coded 98 responses to isolate the knowledge-behaviour gap
- Ran five in-depth interviews to explain the gap the survey exposed
- Synthesised personas that the wider team used to drive the escape room narrative
“Working professionals know the risks — and ignore them anyway.”
Headline finding, 98 coded responses
[ 03 · Findings ]
What the evidence said
78% reported skipping password updates. 51.5% reported using public Wi-Fi without a VPN. Yet 62% rated those same threats at the top of the risk scale.
People are not under-informed. They are trading security against friction, in the moment, and losing. That reframed the design target from teaching facts to changing the moment of decision.
[ 04 · Outcome ]
What changed
The research framework fed directly into a gamified escape room built by the wider team, which is live and publicly playable. My contribution was phases one and two: the instrument, the coding and the personas.
When stated belief and reported behaviour diverge this sharply, the design problem is friction, not education.
Reflection