The Second KC7 Cybersecurity Camp Uses Game Immersion to Increase Student Engagement
In June 2024, KC7’s second cybersecurity summer camp welcomed nearly 50 young participants in Central Kentucky, continuing our mission to cultivate an investigative mindset essential for the future of cybersecurity.
Through immersive role-playing and practical exercises, campers learned to analyze and respond to cybersecurity intrusions from a holistic perspective. We created an interactive, game-like environment which fostered not only technical skills as students took on real-world job roles while developing critical soft skills such as teamwork, communication, and problem-solving.
In the capstone activity, students responded to a simulated ransomware attack against a hospital. In order to recover from the attack, students learned to:
- Write database (Kusto) queries to analyze intrusion data and identify the hackers’ techniques, tactics, and procedures.
- Analyze open source intelligence artifacts (social media, etc..) to identify the hackers involved based on evidence.
- Manage the business activities associated with cybersecurity. E.g. earn revenue to fund incident response activities for their teams, compute and pay taxes on earned revenues, and make risk-based decisions to maximize profits.
- Present their findings in a professional format to a panel of judges, demonstrating a remarkable depth of understanding and application.
Key takeaways:
- Students in our camp came from diverse backgrounds in terms of gender, race, and socio-economic status. Their high engagement shows that the lack of diversity in cybersecurity is due to limited opportunities, not a lack of interest or ability.
- By minimizing formal instruction and encouraging learning through gameplay and exploration, we found that students were more engaged and showed a deeper understanding of the subject matter.
- By redefining cybersecurity "fundamentals" as highly transferable, cross-disciplinary skills that teach students to think, reason, and communicate, we can reshape their perspectives on cybersecurity and capture the interest of students who might otherwise dismiss it as a career option.
The camp’s philosophy encourages resilience, collaboration, and continuous learning —qualities that align with the KC7 Foundation’s broader goal of preparing a diverse, well-equipped future cybersecurity workforce.
Welcome back to cybersecurity camp!
This year, we are excited to welcome back almost 50 campers, all of whom come from Title I schools in Fayette County! Though the field of cyber security is fairly male dominated, 34% of our campers this year were female, giving us hope that access to opportunities like this at a younger age will enable more diversity in the future. As with last year, our focus is on helping students improve their investigative mindset. After all, cybersecurity is all about asking the right questions and analyzing data to discover what hackers are doing.
On day one, we explored a quick introduction to data analysis and helped students ask better questions. We started with last year's museum heist mystery—a fan favorite. During this exercise, the students had to figure out who stole an artifact (a Benin Bronze) from the African Art Museum. The students took turns interviewing six witnesses of the crime, developed a greater understanding of the heist, pieced together the disjointed clues, and built a case to argue for who they believed committed the crime.
Just like last year, we were impressed by the improvement in the quality of the questions that students were asking. Over the course of the exercise, the students learned how to ask more pointed questions and consider competing hypotheses (we threw in a bit of trickery there). This year, we were particularly blown away by the quality of the final reports presented by the students. One group, in particular, provided such a clean and concise analysis of the heist that it bested even our own answer guide.
In the afternoon, we began a data analysis investigation to help a Kung Fu fighter named Po figure out why he was defeated by his arch-nemesis. The students learned how to write basic Kusto queries and how to identify the correct database to investigate. Amazingly, the only instruction for using the query language was embedded in the module itself, so students were learning and applying this knowledge simultaneously. On day two, additional layers were added to the investigation.
On the walls, we placed artifacts including Tweets, licenses, text messages, and photographs that were crucial to the attribution element of the investigation. Students were introduced to the following roles:
- Case Manager - compiled all known information on the case and helped groups organize their findings
- Investigator - searched the room for evidence that would allow their team to build a solid case to convict the perpetrator
- Analyst - used KQL to sort through the data to understand the progression of the cyber attack
Each student was able to get a feel for the responsibilities of each role in order to determine where their particular interests lie. This level of choice is where the camp finds its success. As students found their areas of expertise, they were encouraged to take notes, converse with their teams, and piece together an attribution sheet that models a real-world report of the investigation.
Then, later in the day, the third case that would continue for the duration of the camp was introduced. Students were shown a video from the hacking group, Lockbyte, demanding a two million dollar ransom for the release of a hospital’s patient records. Mimicking a real-world ransomware attack, the hackers were able to shut down the hospitals IT services leaving campers to figure out not only what was happening and why, but also to restore their services, negotiate with the hackers, handle their financials, and piece together the case while completing bounties to hopefully lock up the members of the group.
On day three, students were introduced to a new role:
- Chief Financial Officer (CFO) - maintained a record of expenses and fines, paid taxes, and acted as their team’s intermediary with the bank
If you think teaching a group of students ages 9-12 how to pay their taxes seems impossible, hold on to your socks. Teams were able to get a feel for managing their money so they could keep their businesses afloat; they kept track of expenses to avoid fines at each hourly tax periods, paid to restore their IT services and restore their hospital’s data, and even handled the income received by their investigators for collecting bounties and solving puzzles.
Throughout the rest of the week, students worked diligently to complete the investigation, restore all 7 of their IT services, and come out on top with the most money earned. On Friday, each group presented their findings to the judges that included both security analysts and actual hospital employees. It was remarkable how detailed these reports were considering that the campers were working with tables of data on a computer and close to 50 physical artifacts hidden around the room. Students were able to detail the process of the investigation, identify all 10 members of the hacking group, and recount the story of the leader who betrayed a team of hackers and left them penniless.
Our Approach
Every morning students were welcomed into the room with excitement and high fives before being asked to repeat the five tenets of the KC7 philosophy:
- I will try my best every day
- When I fail, I will learn from it and try again
- I will challenge myself to learn new things
- I will learn from my peers, and help them learn from me
- I will use what I learn to make the world a better place
The beauty of KC7’s approach isn’t simply that it teaches students about cyber security, but that it allows students the choice to work and learn as a team where all students’ skills are utilized. Looking around the room, it might seem chaotic, but all students were finding their place and feeling valued for their contributions. Analysts worked away learning query language and sorting through data with ADX while Investigators moved around the room piecing together evidence for criminal referrals or decrypting puzzles to earn some extra income. CFOs, some of whom didn’t even know how many zeroes went into a million at the beginning of camp, calculated expenses while Case Managers compiled information and provided guidance to their teams.
To be very clear, most of the attendees were unsure of the camp’s purpose or even what cyber security meant when they walked in on day 1. Getting students engaged from the start took a bit of work but they quickly found our excitement to be contagious. Through the enthusiasm of our facilitators and student workers as well as the approach to the work, the shift in student attitude was clear on the morning of day 2 as students ran in ready to high five and get to work.
By gamifying the experience and using project-based learning, students were constantly learning with only a minimal amount of direct instruction. Learning actively in real time, students were able to impress not only the camp facilitators but themselves as they discovered skills they weren’t aware of having. Students learned communication skills and how to work collaboratively. They encouraged their team members to be confident during presentations. When given breaks, students could be heard grumbling about having to stop the investigation. One student even shouted, “How can they force us to take breaks? I want to work!” While technology and tools will change over time, the flexibility, adaptability, and eagerness to learn that students demonstrated during this camp will always be in demand.
About the KC7 Foundation
The KC7 Foundation is a 501(c)(3) nonprofit organization whose mission is to empower everyone to succeed in tomorrow’s diverse cybersecurity workforce. We realize this mission by developing cybersecurity training and educational content that is accessible to everyone. The KC7 Foundation aims primarily to provide equitable training to several key groups: K-12 students, post-secondary students, transitioning professionals looking to reskill into cyber roles, and current cybersecurity professionals looking to upskill.
The KC7 Foundation considers K-12 cybersecurity education to be one of its key focus areas. To ensure that we build the next generation of cybersecurity leaders, we must provide engaging and accessible opportunities that will help young students build interest in and excitement about cybersecurity. Then, we must support and nurture that curiosity by providing dynamic and comprehensive learning opportunities for all grade levels. In order to do that, we must bring together industry professionals with K-12 educators to provide students hands-on, real-world training that will teach them the foundations of cybersecurity and help spark an interest in this career field.
Funds obtained from donations, grants, and sponsors support our mission and are used to provide cybersecurity training and workshops at no cost to underserved communities and populations.