Terna Cyber Palace schermata 1
Challenges

What if we turned cybersecurity into a game?

Terna has developed a videogame to raise awareness among its staff about new and emerging cyber threats. To mark European Cybersecurity month, we caught up with the team that came up with the idea.

How do you leave Terna’s offices? By thwarting threats to the company's cybersecurity! This isn’t some secret code, but the plot of Terna's new gamification experiment. Terna Cyber Palace is a new tool created for the employees of the Italian Grid Operator to raise awareness about threats to cybersecurity. It is effectively a virtual escape room centred on cybercrime, and has been developed as part of the Open Italy project (the innovation ecosystem set up within the ELIS Consortium) by Terna’s Cyber Security & Security Platforms and Innovation departments, in collaboration with an Italian start-up.

The initiative coincides with European Cybersecurity month established by the ENISA (European Union Agency for Cybersecurity) and dedicated to promoting IT security among citizens and organisations. This represents yet another opportunity to highlight the cybersecurity best practices explored continuously as part of Terna's “Digital Antibodies” training programme. To learn more about this new gamification project, we spoke to two members of the team that conjured up the game, Luca Tinaburri and Valentina Matturro.

Image019

Third floor: "Ok, let's get started. The countdown has begun. Click on the control panel to enter the floor"

What inspired the project?

«The initiative was created as part of the Cybersecurity Awareness programme aimed at promoting a culture of IT security within the company. As an organisation - comprising our personnel, processes and actions - we have established a specific department responsible for preparing, training, alerting, raising awareness - effectively informing our resources about IT security, or rather the risks associated with the use of IT devices. In fact, the misuse of these kinds of devices can lead to problems that impact the operation of the entire company, threatening its operational continuity. We began to develop this programme in 2021, highlighting how we needed to integrate a gamification-style system into our tool kit. The term “gamification” means using typical game-playing elements, particularly those associated with videogames (points, levels, awards, virtual assets, rankings) to engage users in a certain area of activity. Terna came up with this solution after a meeting with a start-up within the Open Italy system. A working group was set up to design and develop a prototype in 12 weeks, which was then tested and assessed».

Image004

"Click on your selected Avatar", a screenshot of Terna Cyber Palace (photo by Terna)

How was the gameplay developed?

«We began with the idea of creating an escape room because it represented an established form of gameplay used in other fields. We've all heard of escape rooms as a form of entertainment. Next, we began to focus on certain specific aspects of cybersecurity. For example, the main threats include ransomware (one of the topics of European Cybersecurity Month), a type of malicious software that attacks an organisation by encrypting its data, which is mainly transmitted via email. This is the topic we decided to focus on in our videogame storytelling, along with online fraud, transferring them into a context that reflects the company. Which departments are more susceptible to ransomware? Technically all of them, but in a context like the one in which Terna operates, the most vulnerable departments may be those focused more on the operating side of things that handle aspects of our core business. Likewise, the topic of commercial fraud is most relevant to the procurement department, which receives thousands of emails from external sources and consequently could present quite an obvious victim».

And how is this mechanism translated into the gameplay?

«Like in all escape rooms, the aim of Terna Cyber Palace is to escape from the palace in as short a time as possible, taking it in turns to play on the red team, to use computer jargon, which makes the attack, and the blue team, which studies and uses all of the possible moves to defend against the attacks. The game is played in teams but gameplay is asynchronous: the game can be accessed at any time and there is no need for players of the same team to all play at the same time. This means everyone can contribute to the team at any moment».

Image021

Unlock the door: "If the phishing attacks target the CEO, CFO or another senior manager, this is known as..."

How does Terna Cyber Palace work?

«The aim is, quite simply, to escape. We’ve designed the Terna palace, which represents our head offices, across three floors: the players enter the game on the third floor and must work their way down to the ground floor to escape. Users can represent both the defending team (blue team) and the attacking team (red team), so each floor is played out as both teams. The difficulty level doesn't increase; instead, the different levels (or floors) focus on different aspects of cybersecurity. In the game, players enter different rooms which represent Terna’s offices, and each door must be unlocked by answering a question about cybersecurity. For example: “What is phishing?” Once the players enter the room the game begins in earnest, with different scenarios depending on which team they're on. A virtual colleague describes the scenario and the user must play using their cards: these can be intelligence cards or defence/attack cards, depending on the role being played at that moment».

Image024

Your cards: play this card to prepare an attack and increase its effectiveness. Before playing a CYBER-ATTACK card, you must have played two INTELLIGENCE cards

Let's step away from the palace rooms for a minute: based on your experience how are gamification and cybersecurity linked?

«Gamification is a new but very popular approach that enables businesses to introduce colleagues to new information and training in a lighter way. Users are playing a game, but in fact they are learning. The whole concept of training is changing and in this sense it's the perfect example of how innovative methods can be more effective than traditional ones. And when it comes to cybersecurity it's even more useful, because full-immersion approaches are less important than continuous training: we need to stay “on alert” and so our colleagues need to receive constant input. This is what the Terna programme does».

Image020

"Explore the floor using the white arrows. Not sure what to do? Take a break in the staff room"

What is the digital antibody programme and what other initiatives are being implemented throughout the year?

«The programme is based on a series of tools that we use to raise awareness. These include the various notifications posted on our Intranet, such as the alerts about malicious campaigns that are circulating and targeting end users. We've also introduced a training platform to provide continuous input, consisting of bitesize monthly content sent to users that covers a different topic each month: there are 36 topics in total, covered in short 4-5 minute training videos and followed by a questionnaire. As well as the training modules, there is also a section with monthly training capsules in the form of a TV series, with each episode reconstructing a typical cybersecurity incident, often based on real-life events. Each month we publish an internal cybersecurity bulletin with an informal, non-technical tone, which includes more information and interviews».

If you had to summarise the essence of this campaign in one sentence, what would it be?

«Cybersecurity is no longer a topic just for experts. We all need to be more aware of the internet and ready to adopt a correct approach in the use of IT devices. This is one of the most important priorities for companies like Terna. These days it's essential to stay informed to protect not only the organisation but, above all, our own personal domain».