← Latest papers
💻 computer science

Introducing and Interfacing with Cybersecurity -- A Cards Approach

This paper proposes and evaluates a playing card-based interface grounded in the National Cyber Security Centre's CyBOK, which successfully helps novices acquire introductory cybersecurity knowledge and facilitates discussions linking attacks, vulnerabilities, and defenses.

Original authors: Ryan Shah, Manuel Maarek, Shenando Stals, Lynne Baillie, Sheung Chi Chan, Robert Stewart, Hans-Wolfgang Loidl, Olga Chatzifoti

Published 2026-02-25
📖 4 min read☕ Coffee break read

Original authors: Ryan Shah, Manuel Maarek, Shenando Stals, Lynne Baillie, Sheung Chi Chan, Robert Stewart, Hans-Wolfgang Loidl, Olga Chatzifoti

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine cybersecurity as a massive, terrifying library. Inside, there are over 1,000 pages of dense, technical manuals explaining how hackers break into systems, how to fix the holes, and how to build better locks. This library is called CyBOK (Cybersecurity Body of Knowledge). It's an amazing resource, but for a beginner, it's like trying to read a dictionary to learn how to speak a new language. It's too heavy, too complex, and you don't know where to start.

The authors of this paper asked: "How do we get regular people to understand this library without drowning them in pages?"

Their answer? Turn the library into a deck of playing cards.

Here is the story of how they did it, explained simply:

1. The Problem: The "Wall of Text"

Cybersecurity is often seen as a subject only for geniuses with special degrees. But 95% of security breaches happen because regular people make simple mistakes (like using "password123"). The existing guides are too hard to read, so people ignore them. We need a way to make these concepts "click" for everyone, from 10-year-olds to university students.

2. The Solution: The "Cybersecurity Card Game"

The team created a deck of cards that acts like a portable, interactive map of the massive CyBOK library. Instead of reading a chapter, you pick up a card.

Think of the deck as a Lego set for security. You have three main types of bricks:

  • Red Cards (Attacks): These are the bad guys. They represent things like "Hacking" or "Stealing Data."
  • Diagonal Cards (Vulnerabilities): These are the broken windows in your house. They represent the weak spots, like "Leaving a door unlocked" or "Bad code."
  • Shield Cards (Defences): These are the solutions. They represent "Locking the door" or "Installing a firewall."

The Magic Trick:
In the first version of the cards, they used tiny codes (like A_1 or V_2) to connect the cards. It was like a treasure hunt where you had to match the codes to see how a specific attack (Red) exploits a specific weakness (Diagonal) and how a specific shield (Shield) stops it.

3. The Experiment: Two Workshops

The team tested this idea in two different "playgrounds":

  • Workshop 1: University students (ages 22–35) who knew a little about computers but were new to security.
  • Workshop 2: Primary and middle school kids (ages 10–15) who barely knew what a computer virus was.

They gave them the cards and asked them to build stories: "Show me how a hacker steals a password and how we stop them."

4. What Happened? (The Results)

The results were surprisingly good!

  • 80% of people said the cards gave them a basic understanding of cybersecurity.
  • 70% of people said the cards helped them talk about security and connect the dots between problems and solutions.

The "Aha!" Moment:
The kids and the adults both realized that security isn't just about magic computers; it's about a chain reaction: Bad Code (Vulnerability) + Hacker (Attack) = Disaster, unless you have a Fix (Defence).

5. The "Version 2" Upgrade

After the first test, the team realized the deck was a bit too heavy.

  • The Issue: There were 124 cards. It was like trying to play a card game with a whole encyclopedia. People felt overwhelmed.
  • The Fix: They cut the deck down to 70 cards. They removed the "General" cards (which were just labels) and replaced them with a simple Glossary (a cheat sheet).
  • The Visuals: They made the red color lighter so it wasn't so aggressive, and they swapped the confusing tiny codes for big, clear icons (like a skull for an attack, a shield for defense). It became easier to see the connections at a glance.

6. Why This Matters

This paper proves that you don't need to be a computer wizard to understand cybersecurity. By turning complex knowledge into a tactile, visual game, they made it possible for:

  • Students to learn the basics without getting bored.
  • Developers to understand the risks of their code.
  • Everyone to have a conversation about security without needing a dictionary.

The Bottom Line:
Just as you wouldn't teach a child to drive by handing them a 500-page engineering manual, you shouldn't teach cybersecurity with a 1,000-page textbook. Give them a deck of cards, let them play, and suddenly, the scary world of cyber threats becomes a game they can understand, discuss, and master.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →