Design Process

Phishing: Learning Design Solution

The Challenge:

Phishing scams are the “starting point” to many serious cybercrimes including identity theft, financial crimes and ransomware. Phishing has become more sophisticated and harder to recognise. Even with up-to-date devices and security systems, companies and individuals fall victim to phishing scams. Victims and the organisations where they work or study are vulnerable to losses including reputation and consumer trust, financial losses.

The challenge was to design a training and assessment solution to equip staff to recognise and avoid phishing traps, including:

  • Raise awareness of phishing and its repercussions.
  • Encourage staff to understand their role in protecting their and the college’s data security.
  • Build skills for detecting phishing.
  • Ensure staff follow company procedures for managing and reporting phishing emails.
The Solution:

I developed the “Learning Design Plan” using the following steps:

  • Worked with stakeholders to identify the problem and goals.
  • Conducted a performance gap analysis to determine if training was a possible solution.
  • Conducted an audience analysis and personas.
  • Conducted an instructional analysis to identify skills gaps and training outcomes.
  • Created a Phishing infographic – see below
  • Created a summative assessment plan – see below

Example Activity: Phishing Infographic

The Solution:

An interactive phishing infographic highlighting common phishing traps. The infographic allows users to explore key elements and examples of common phishing traps.

The Tools:
  • Genially

Example Activity: Phishing Game

The Solution:

The Phishing Game is an interactive assessment activity to actively promote awareness of phishing scams and importantly, to equip them with skills for identifying phishing attempts. In a training session, staff collaborative to complete the phishing game to detect common attributes of phishing emails. For each attribute they detect, they earn a point and move around the game board. The competitive nature of the game encourages staff to detect all phishing attributes. The collaborative nature of the game encourages staff to work together to see their collective role in protecting data from scams.

The Tools:
  • PowerPoint