Next Article in Journal
AdaptVote: FPGA-Accelerated Blockchain E-Voting with Age-Invariant Biometric Authentication and Adaptive Cryptography
Previous Article in Journal
QKD-Assisted Secure Transport Framework for Federated Healthcare Systems: A Software Prototype and Baseline Evaluation
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Systematic Review

A Systematic Literature Review on Non-Player Characters Actions and Characteristics in Serious Games for Cyber Security Education

by
Athanasios Manikas
,
Menelaos N. Katsantonis
and
Ioannis Mavridis
*
Department of Applied Informatics, University of Macedonia, 54636 Thessaloniki, Greece
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(5), 155; https://doi.org/10.3390/jcp6050155
Submission received: 27 June 2026 / Revised: 21 August 2026 / Accepted: 31 August 2026 / Published: 3 September 2026
(This article belongs to the Section Security Engineering & Applications)

Abstract

Cyber security has become a growing concern for an increasing number of organizations, many of which are investing significant resources to address the issue. Cyber security education, based on serious games, can enhance learners’ interest, motivation and engagement. Players’ gaming experience, enjoyment and immersion can also be enhanced by the implementation of non-player characters (NPCs) into serious games. The present systematic review was based on the updated PRISMA guidelines and identified 28 papers, each one referring to a different serious game with one or more NPCs. The actions, characteristics, roles and educational benefits NPCs can offer in the context of serious games for cyber security education were examined, as well as the evaluation methods and data collection techniques researchers used. The analysis of the results revealed that NPCs supported players during the game by providing them with feedback, guidance and encouragement primarily through verbal communication and also that NPCs have the potential to increase players’ interest. The evaluation methods and data collection techniques used in serious games for cyber security education involved mostly qualitative and quantitative data collection methods with pre-, in-, and post-game activities, focusing mainly on target users and less on the comparison of the control and experimental groups. The development of a comprehensive classification of NPCs’ actions and characteristics could help fill the gap identified in the literature and could be useful for researchers and designers aiming to implement NPCs into serious games for cyber security education.

1. Introduction

The Cyber Security Breaches Survey [1] revealed that four out of ten businesses in the UK reported experiencing a cyber security breach in 2025. According to the ENISA Threat Landscape 2025 [2], threat actors continue to gain initial access primarily through social engineering tactics, with phishing accounting for around 60% of observed cases and ransomware posing the most significant threat in the EU. The landscape of cyber security remains complex and constantly evolving [3]. An increasing number of organizations are concerned about cyber security risks and are therefore investing a significant amount of their resources to address the issue in the expectation of a corresponding return on investment [4].
Traditionally, cyber security awareness training often relied on videos, lectures and presentations, which tend to be unengaging and lack interactivity [5]. Game-based education and serious games can raise cyber security awareness [6], increase learners’ engagement [7], interest [8] and motivation [9], and are already being used by professionals in the field [10]. In serious games, the characters that are not controlled by the player [11] are called non-player characters (NPCs) and can affect players’ gaming experience [5], enhance players’ immersion [12] and enjoyment [13], foster interactivity [14] and improve players’ intrinsic motivation [13].
In serious games, NPCs have the potential to enhance user engagement [15] by performing actions which cannot be replicated in such a realistic manner through the game’s user interface, like facial expressions that reveal emotions of fear or excitement and replicating human-like movement. In addition, social support provided by NPCs has been found to have a positive impact on the perceived usefulness and the perceived ease of use of the game-based environment [13]. Interaction with NPCs has been found to be beneficial for the participants [16] and also an appealing aspect for them [5]. Finaly, the mentorship provided by NPCs has been shown to improve understanding of the educational material [17].
The aim of this paper is to explore the current state of research on NPCs in serious games for cyber security education and in topics not related to cyber security, and identify their actions and characteristics, the roles they undertake and the educational benefits they can offer.
In order to achieve the above goal, this study addresses four research questions. Initially, (RQ1) explores NPCs’ actions and characteristics in the context of serious games. Next, (RQ2) investigates how NPCs are integrated into serious games. Furthermore, (RQ3) examines how serious games with NPCs for cyber security education have been evaluated. Finally, (RQ4) looks into the educational benefits the integration of NPCs can offer. These research questions provide a methodological blueprint for the systematic mapping of the field by actively guiding the entire process and fostering a purposeful, structured review of the literature.
Although other studies related to NPCs have been conducted, the present study focuses on a range of different NPCs’ aspects like their actions, characteristics, roles and evaluation methods in the context of both cyber security serious games and serious games that are not focused on cyber security education.
The current study results would be useful for both serious game designers, who are interested in exploring different ways of integrating NPCs in their games, and researchers who wish to expand their knowledge regarding the educational benefits that NPCs can offer. Additionally, the present study provides insight into the various evaluation methods employed by other researchers to determine the effectiveness of NPCs’ implementation in the context of serious games.

2. Related Work

Research on NPCs in serious games has grown in recent years and is expected to continue evolving as artificial intelligence (AI) advances and develops. The literature review identified six studies (SLRs and surveys) focusing on NPCs in digital games (Table 1).
The primary objective of [18] study was to conduct a systematic review and provide an overview of the current research development in the field of NPCs and specifically on NPCs’ behavior in games, using evolutionary algorithms. Their work contributes to the literature by identifying the six categories (planning, user interaction, position modification, parameter modification, character state modification, and target assignment strategy) where the evolutionary algorithms play a crucial role. The authors emphasize the considerable progress and ongoing potential in the study of NPC behavior and conclude that incorporating instructional and educational elements can enhance NPC design. Despite stating that incorporating educational and instructional elements could improve NPC design, making NPCs effective as instructors or guides who can provide hints, feedback or challenges tailored to the player’s learning curve, they included a relatively small number of research games compared to other game categories, and none of them focused on cybersecurity.
Ref. [11] survey focuses on the design of personalized NPC companions through adaptation, emphasizing the importance of adaptive systems in improving the player experience. The authors propose a human-centered design framework outlining appropriate game elements for adaptation, suitable data types, techniques for successful adaptation and evaluation methods. The framework comprises three phases—operationalization, the adaptive system and evaluation—and serves as a guide for academics and game designers in designing NPC companions that adapt based on player states. Ref. [11] study emphasizes the importance of adaptive NPC companions. Their work contributes to the existing body of literature on companion characters in video games, providing academics and designers with additional guidance on their integration.
Ref. [19] survey reviews various decision-making methods that are relevant to NPCs in computer games, provides a fundamental summary of them and highlights recent advancements in the field. The authors used a differentiated version of the PRISMA methodology to survey the field, and based on the research results, they categorized the decision-making methods according to three key factors: the target audience (NPCs, their environment, or communities of NPCs); the area of decision-making; and the specific game genre. Their findings suggest that these methods are integral to various functions, such as planning, acting, spatial movement, controlling vehicles or devices, and interacting with players and other NPCs. The main contribution of this study lies in the categorization of decision-making algorithms and their usage in different computer game genres, alongside a discussion of recent advances and methods in the field and the presentation of a taxonomy of the reviewed studies.
Ref. [20] conducted a systematic literature review (SLR) of NPCs design patterns focusing on responsiveness, appearance, communication patterns, emotional aspects, behavioral characteristics and team structures. Their study also explores the learning processes of NPCs in video games and provides a deeper understanding of human-NPC cooperation. The main contribution of the work in [20] is the thematic synthesis conducted, as well as the investigation into the patterns exploited by game developers and designers for building rich social interactions between NPCs and humans. Although their study covered a wide range of topics, including entertainment, education, culture, history, ethics, medicine, health, engineering, sports and tourism, none of the papers addressed cybersecurity education.
Ref. [21] SLR examined the factors involved in creating believable NPCs’ behavior in digital games for entertainment. Their methodology was based on the guidelines provided by [24] for performing SLRs in software engineering, and the results of their study were presented in the form of a short paper. The authors covered a time period of six years (2015–2021) and excluded all papers not related to entertainment games, such as serious games, from their study. Ref. [21] concluded that designers may lose control over NPCs’ responses when deeper algorithmic changes are necessary and that the techniques identified in their study become more efficient when incorporated into frameworks and engines that offer sophisticated mechanisms for managing NPC behavioral responses.
Ref. [22] conducted a literature review exclusively on social agents and social simulations and reviewed in-depth seven academic research projects and two commercial social simulation video games. The authors proposed a taxonomy for social characters with four main categories (communication, flow of knowledge, relationships, emotions) and sub-categories and also managed to identify and classify themes of social state assumptions, models of communication and social relationships and behaviors. The identification of the key similarities and differences between existing social systems and the proposed taxonomy for the different components of social simulation systems constitute the contribution of this study. Finally, despite stating that they had conducted a systematic review of prior research, the authors did not specify the methodology they had relied on.
Ref. [23] investigated whether AI exists in educational games in an attempt to answer the one research question of their study. Their SLR covered the period between 2015 and 2018, and 87 papers were reviewed. According to the authors, their contribution to the literature on educational games and NPCs is based on the information gathered from the studies they reviewed. Their findings suggest that the vast majority of educational games lacked both NPCs and effective learning methods.
Previous studies [18,19,20], reviewed both serious games and games from other categories or focused exclusively on entertainment games, excluding serious games entirely from their research [21]. The present study focused solely on serious games that incorporate NPCs, excluding from the research commercial, entertainment and other game categories which may not incorporate clearly defined educational objectives. Additionally, a considerable difference with the studies mentioned previously is related to the topic of the reviewed games. None of these studies included games with topics related to cyber security, as is the case with our study. Finally, only one of the previous works referred to the evaluation of NPCs in the context of serious games [11]. According to the authors, the evaluation of companion NPCs constitutes the third phase of their proposed framework [11]. However, this framework has not been implemented, which is why the authors presented two case studies for future use. The present study aims to explore the evaluation of NPCs in the context of serious games for cyber security education and attempts to identify the criteria and tools other researchers have proposed using for this purpose.
This study contributes to the growing body of the literature on NPCs and provides information about their actions, characteristics, roles and potential educational benefits of NPCs in the context of serious games for cyber security education and serious games not focusing on cyber security. Additionally, this study summarizes and presents the criteria and tools other researchers used for the evaluation of NPCs in serious games for cyber security education.

3. Objectives

The structural alignment of the study is shown in Table 2, where each research question is directly mapped to its corresponding research objective.

4. Methods

This SLR adapted the steps and items described in the updated PRISMA 2020 guideline for reporting systematic reviews [25]. The completed PRISMA 2020 checklist is available as Supplementary Material.

5. Eligibility Criteria

The inclusion and exclusion criteria were defined prior to conducting the review, in order to prevent bias [26]. The selection of the primary studies was based on these criteria, with studies being included or excluded according to their titles, abstracts and keywords.
Inclusion criteria (IC):
  • IC1: Relevant to research questions (title, abstract, keywords)
  • IC2: Peer-reviewed academic journals
  • IC3: Peer-reviewed conference/symposium proceedings
  • IC4: English language
  • IC5: From 2000 up to and including 2025
Exclusion criteria (EC):
  • EC1: Does not meet inclusion criteria
  • EC2: Without a developed serious game
  • EC3: Without participant evaluation
  • EC4: Papers with different title covering the same research
This review adopts 2000 as the starting year (IC5) to capture the emergence of serious games research, which gained widespread academic recognition in the early 2000s [27], as well as the rapid development in the field of digital game AI, which is also considered to have emerged in the early 2000s [28]. Papers published in peer-reviewed academic journals and peer-reviewed conference/symposium proceedings (IC2, IC3) are considered reliable because their results and methodology are subject to evaluation. Studies that remain solely at a theoretical level (frameworks, game presentations or future works) without a fully developed game and without participants’ evaluation were excluded (EC2, EC3). Participant evaluations can provide empirical data to researchers and allow them to draw useful conclusions regarding the research questions of this study.

6. Information Sources

This study was conducted from December 2025 until February 2026, and the information sources used were: ACM Digital Library, IEEE-Xplore, Scopus, Science Direct, Springer Nature Link and Google Scholar (Table 3). These sources have been used by other researchers to conduct SLRs [18,19,20,21,22] and are recognized within the academic community.

7. Search Strategy

All the above databases (Table 3) were searched, and filters were applied to include publications from the year 2000 up to and including 2025, encompassing peer-reviewed academic journal articles and proceedings and symposium papers written in English. Furthermore, a manual search was conducted through the Google Scholar search engine, using the same keyword combinations (Table 4) to identify any additional relevant papers that may have been overlooked in the initial search results.
The literature search focused mainly on serious games with NPCs for cyber security education and was conducted using various combinations of the keywords and search terms that are listed below.
Some of the search strings used:
  • (“non player character” OR “NPC” OR “agent”) AND (“serious game” OR “educational game” OR “digital game”) AND (“cyber security”)
  • (‘non player character” OR “NPC” OR “intelligent NPC”) AND (“taxonomy” OR “typology” OR “framework”) AND (“serious game” OR “educational game”) AND (“cyber security”)
  • (“non player character” OR “NPC” OR “autonomous character”) AND (“characteristics” OR “actions”)

8. Data Collection Procedures

8.1. Study Selection

Two independent researchers were involved in the initial phase of paper selection. The two researchers had extensive knowledge of the field and experience in conducting SLRs, ensuring a comprehensive understanding of the research topic and relevant literature. Their involvement aimed to minimize bias and enhance the reliability of study identification and inclusion decisions. Before the screening process, the researchers arranged meetings to establish a common understanding of the predefined inclusion and exclusion criteria. Each one independently assessed the titles, abstracts and keywords of the identified studies against the predefined criteria. The resolution of any disagreements that arose between them was achieved through constructive discussion and cooperation, with the aim of achieving a consensus [29]. As Ref. [26] states, the literature analysis phase can also be constructive for the researchers, providing them opportunities for collaboration. Thus, follow-up meetings were also conducted after the screening process to compare decisions.
After searching the databases and conducting the manual search, a total of 4134 papers were found. After removing the duplicate records (18) and screening the rest, a total of 176 records were assessed for eligibility. Based on the inclusion and exclusion criteria described earlier, 148 reports were excluded, and the final 28 papers, each describing a different serious game, are presented below (Figure 1).
Studies of serious games that have not been evaluated or did not have participants (EC3) [30,31,32] and studies describing works in progress or future plans (EC2) [33,34,35,36,37] were excluded from the search results. Similarly, studies describing NPCs’ roles and actions in a non-serious gaming context, as well as non-English papers (EC1) [14,38,39] were also excluded. Zotero 9.0.6 software was used to remove duplicate studies during and after the screening process.

8.2. Data Collection–Data Items

In the data collection process, 28 papers were selected, referring to 28 different serious games with NPCs. Nine of these papers focused on games for cyber security education, while the rest concerned subjects not focusing on cyber security. The outcomes, for which data items were sought from the above papers, were related to the predefined research questions (Table 2) of the current study. In cases where there was no clear information or insufficient data regarding the name of the game, the number of participants, the evaluation process, or the number of NPCs, their role and actions performed by them, it was assumed that this information was not available. Finally, there was no statistical analysis conducted in the current study.

8.3. Risk of Bias Assessment

The studies included in this systematic review were not subject to any risk of bias assessment using a standardized tool. The risk of bias, therefore, may constitute a limitation of this SLR.

8.4. Synthesis of the Results

The results of this study were initially grouped based on the serious game subject. Secondly, the data were tabulated based on the serious game topic, the number of participants, the number of NPCs, the type of game and the year of publication.

8.5. Reporting Bias Assessment and Certainty Bias

Although a statistical analysis was not the focus of this study, the potential for reporting bias should be considered when interpreting the findings of this SLR. Except from selecting only studies originated from peer-reviewed journals and proceedings publications in English, there was no certainty evaluation method used in this study, and this may represent a limitation of this SLR.

9. Results

After the selection process, 28 papers describing 28 different serious games were included in this review. The first nine (Table 5) refer to cyber security-related topics, while the rest (Table 6) concern subjects that are not focused on cyber security.
Recent literature has discussed the use of NPCs in serious games for cyber security education, with these studies being published between 2021 and 2025. Most cyber security serious games topics concerned awareness raising (N = 5), and the type of game in most cases (N = 5) was a Role Playing Game (RPG).
On the other hand, serious games not focusing on cyber security have appeared in the literature since 2007, with most of them published in the last 10 years (between 2016 and 2024). RPGs were also the most common game type (N = 6).

9.1. RQ1: NPCs Actions and Characteristics in Serious Games

The first research question aimed to identify the actions and characteristics of NPCs in serious games for cyber security education and serious games not focused on cyber security.

9.1.1. Cyber Security Serious Games

The systematic review of the literature showed that, in most cases, NPCs in serious games for cyber security education took the form of 2D human characters [5,16,42,43] or 3D human characters [40,45]. In one serious game [5] the NPC displayed a range of emotions and could transition between different states, such as angry, normal, and happy. In other games, NPCs had specific cyber security knowledge and skills and could perform tasks, thus forming a cyber security expertise. These actions included updating antivirus and patching software [40], providing guidance on purchasing defenses [3], communicating in a Caesar cipher [16] or unleashing pretexting attacks to steal confidential data, brute-force attacks to steal credentials or defending against cyber attacks [44]. Regarding object manipulation, in one game the NPC provided a vital lock-picking tool for unlocking a chest [16]. Similarly, with regard to response time and response accuracy, the NPC provided little valid information when being angry, whereas when being happy, it provided vital information [5]. In most cases, the communication between NPCs and players was verbal, with text messaging and written dialog being the most common forms of communication [5,16,40,42,43,45]. NPCs supported players during the game by providing guidance [16], feedback [45], encouragement [16], hints, tips, clues or quizzes [5,16,42], or by presenting to them definitions and various viewpoints [41] simulating real-world circumstances [42]. The majority of the games were RPGs [5,16,40,45], while the rest were a 2D retro platformer [42], a tabletop card game [44] and a dialogue Large Language Model (LLM)-based game [43].

9.1.2. Serious Games Not Focusing on Cyber Security

In serious games that are not focused on cyber security education, NPCs demonstrate various ways of verbal and non-verbal communication with the players and with other NPCs. Specifically, NPCs assign tasks to players using dialog boxes [17], aid learning tasks through human-like conversations [13], provide rewards [55] that are vital for progressing further, or assign quizzes, communicate with players in order to help them learn Amazigh and English vocabulary [15,52], celebrate and congratulate players after successful actions [46], alert the players via the in-game communication system [53] or start a conversation with the players and other NPCs about common topics [59,60,61]. Accordingly, NPCs provide support and feedback when players respond incorrectly or in case of an error [13,53], provide quests [49], information, clues, hints, guidance and advice [13,46,51,52], demonstrate worked examples [50] and offer words of encouragement to the players [13]. Regarding movement, NPCs will chase or follow the player [48,52], move inside the room [50] in random way [48,52], patrol or wander around in the playspace [52,57].

9.2. RQ2: How NPCs Are Integrated into Serious Games?

In the context of serious games, NPCs exhibit a wide variety of different roles, which have been designed to mirror real-world situations and support the overall learning objectives. Each role consists of a set of specific behaviors, which are sequences of actions that NPCs are required to perform within a certain timeframe [52]. Since the roles usually performed by NPCs are generally embodied by humans [62], a NPC must not only take on a role, but also act convincingly in it [63].
In serious games for cyber security education, a variety of different NPCs roles are presented. Specifically, in [43], the LLM-driven NPC, called Aegis, has a distinctive personality and is presented as a guardian of the lab’s knowledge who challenges players to crack its defenses and extract crucial information through adversarial dialog. In [45], NPCs take the role of phishing attack victims who need to be consulted by players regarding cybersecurity threats and phishing attacks. Authors [45] utilized a question generator that uses sample data from spear-phishing datasets and a dialogue generator that relies on an LLM for providing dialogs when the game starts. In SCIPS [3], the NPC acts as a cyber security expert who provides advice and guidance to the players, and in [42] retro platformer game, the NPC appears as an angry troll impersonating a new smartphone user and a data theft victim that kidnaps the protagonist’s friends and takes them to different areas of the jungle. In the Security Awareness Adventure [5], NPCs have different roles and are driven by a state transition model. Depending on their state, NPCs can provide different interactive feedback, and as the authors suggest, they are more likely to reveal valid information when being in a happy state [5]. In VMEET, the NPC impersonating the chief technical officer, a penetration tester or a security lead explained to the player the five ethical principles of cyber security and provided alternative ethical viewpoints [41], and in YellowTraining, NPCs took the role of IT staff, a boss arranging meetings with clients and making deals, a secretary or a hacker impersonating an exterminator [44].
NPCs also appear to have different roles in serious games that are not focused on cyber security education. NPCs on WoM [17] act as quest givers who introduce the initial task to the players and provide them with context and motivation, or as mentors specialized in Wordpress and SEO. In Ref. [13] RPG quest adventure, NPCs can impersonate professors, students, or industry practitioners, aiding learning tasks by engaging in human-like dialog. They can also act as narrative connectors, introducing players to other characters and thereby enhancing the social aspect of the game [13]. In Dungeon Class [50] the NPC acts as an expert in programming, presenting autonomous behavior and a strong visual representation inside the game. In Submarine Electronic Warfare [53], the NPC impersonates the officer of the desk, providing real-time audio feedback to remind players to complete their reporting duties promptly, thereby minimizing the cognitive overlap with the existing visual aspects of the game. In Zion’s Market [60], NPCs take the role of customers, merchants or a mechanic who stand in their own stands and wait for other NPCs to trade items with. Finally, the fox-shaped NPC, in ThrowThingsVR [46] introduces itself and welcomes the players to the game, expresses joy through animations after the players perform successful actions and offers helpful tips after unsuccessful ones. As Ref. [64] states, by employing non-human avatars in serious games, designers could seek to neutralize the gender presentation.

9.3. RQ3: Evaluation of Cyber Security Serious Games with NPCs

SCIPS [3] is an experiential serious game, based on the COFELET [65] framework, that encourages participants to make informed decisions about cyber security. SCIPS uses intelligent scaffolding in the form of a unique guidance mechanic that acts as an agent, advising players on the best choice by analyzing their role and decisions. Four different groups of participants provided feedback after completing a session of the game. The authors noted that participants from the groups were better able to work together as a team and against a similar team. They were also better able to make decisions under pressure, implement the necessary defenses and discover how a cyber attack progresses and how to defend against one. Notably, participants’ ability to correctly identify ICS-related risks increased by 84.48% between the pre- and post-game tasks. Additionally, 90.6% of participants reported an improvement in their understanding of cyber threats to ICS and operational technology.
Ref. [40] collected answers from the pre and post-game questions, and gathered statistical data during the game regarding the total time spent playing AWATO (Figure 2) and the time needed to classify threats and read the manual. The authors also observed the 19 participants while playing the game through the teleconference screen-sharing utility and talked to some of them after the game. The 15-item post questionnaire focused on the participants’ perceptions of the game experience, and according to the authors, it was evaluated by Split-Half Reliability. Regarding likeability, 90% of participants enjoyed playing, 89% found the game more engaging than a traditional lecture, and 79% would recommend it to other people. As for learnability, 84% replied that the game presented the concepts in a more interesting and playful way, and 74% answered that the game allowed them to learn faster. Regarding usability, 79% of the participants indicated that the visual feedback in the classification system helped them understand incorrect classifications. AWATO evaluation focused primarily on issues related to the game’s likeability, learnability, and usability, with all the post-test questions referring to the actions performed by the players. Finally, the authors conclude that in order to be able to respond to players’ decisions and make their game more exciting, NPCs should exhibit a wider range of characteristics and behaviors.
VMEET [41] game aimed to provide ethical training and sensitize cyber security professionals to the cyber security ethical principles using intelligent virtual agents who act as NPCs (Figure 3). Two of the three research questions the researchers sought to answer through their study were related to agents. All the data were gathered with pre- and post-game surveys. The collected data were about demographics, players’ basic ethical knowledge and NPCs personality. Particularly in the debriefing survey, players were asked to rate one of the three NPCs’ personality on the Five-Factor TIPI scale, as well as its ethical priorities for every principle. Regarding participants’ allocation, the 304 participants were randomly divided into two groups and received the same game scenarios in different orders. The total number of players that fully completed the game was 149, and 68 players completed at least the first scenario, but their data were still analyzed. The authors concluded that by engaging in these scenarios, players realized that numerous ethical issues can arise in cyber security contexts and that they did not know as much about these issues as they had previously thought. Additionally, it was found that players’ moral sensitivity was increased by playing the game and the NPCs were generally successful in conveying their personalities to players, but not their ethical principles [41]. Although the study reports the methodology used and discusses the outcomes, it does not acknowledge potential risks of bias.
Cyber Adventure game [16] evaluation focused on the game’s usability, educational aspects and overall user experience. The study was conducted in two phases, each involving the completion of a questionnaire by the target user group, consisting of five users. The results of the analysis of qualitative and quantitative data from the first phase, collected from five participants, indicated that all five participants felt engaged while playing. Four participants felt their understanding of cyber security concepts improved after playing the game. All participants expressed a preference for the game over other traditional methods. Three participants found the game narrative helpful in clarifying cyber security concepts, and four participants found the game objectives clear. The same five participants also took part in the second phase. The results from this phase indicated an improvement in the overall gaming experience. Three of the participants found that interacting with NPCs (Figure 4) and game objects was more helpful, showcasing an enhanced directive experience. Participants emphasized that the game had successfully ignited their curiosity and improved their retention of concepts. According to the authors, the game’s non-replayable design is a limitation, as once the cyber security content has been understood, revisiting it is not very motivating for players. Another limitation of this study is its small sample size (N = 5), which may restrict the generalizability of the findings. Finally, as the authors suggest, their study did not include the intended target population due to the inability to obtain ethics approval for recruiting them.
In Ref. [42] retro-themed RPG, players are requested to help the NPCs with their smartphone issues by answering their questions (Figure 5). The game was available in two versions, one tailored to the user’s motivational orientation and one not. In order to address the four research questions in their study, the authors used the Protection Motivation Theory (pre- and post- study) to measure players’ intention to protect themselves from smartphone security and privacy threats. Additionally, they used the Intrinsic Motivation Inventory to measure the player’s intrinsic motivation in relation to the persuasive game, the Smartphone Security Behavior Scale (pre- and post- study) to measure smartphone security behavior across two factors (technical and social) and the Permission Scenario and Regulatory Focus Questionnaire to identify the player’s motivation orientation (promotion focus or prevention focus). The authors found strong evidence that the game was effective in improving users’ intentions to behave securely with their smartphones, based on the pre- and post-questionnaires completed by 102 participants, and the qualitative and quantitative analysis. Although the results showed that player experience did not differ significantly between the two game versions and that the two game versions were equally effective in promoting secure smartphone behavior, players preferred the tailored version of the game and showed significantly greater improvement in their intentions to behave securely with their smartphones than those who played the non-tailored version. Moreover, according to the authors, the overall player experience scores indicated that the game was highly persuasive, and this is also supported by the feedback collected from user interviews. Finally, the authors suggest that one limitation of their study may be connected to the fact that all the survey data was self-reported by the participants.
In Cracking Aegis dialog-based game [43], players were tasked with convincing the NPC Aegis (Figure 6) that they were someone else and persuading it to reveal passwords, locations or other confidential information. The game was run on the researchers’ computer, and the screen was shared with the participants, prompting players to recognize vulnerabilities in real life, encouraging them to reflect on their control over personal data and motivating them to adopt privacy-conscious behaviors. To address the three research questions, brief interviews after each scenario and semi-structured interviews after the game captured the participants’ reactions and experiences. While the sample size of 22 participants was adequate for qualitative analysis, it was insufficient for a robust quantitative analysis. The analysis revealed that the game heightened players’ concerns about the security of their personal information. In addition to highlighting potential biases regarding inconsistent feedback generated by LLMs, the authors discussed other limitations as well. These included the lack of participant diversity (primarily Chinese speakers), which may limit the generalizability of the findings to other racial or ethnic groups; the fact that all participants experienced the same game conditions, which restricted the opportunity to observe the game’s effects through a comparative lens; and finally, the variability in game implementation through prompt engineering.
YellowTraining [44] is a collaborative tabletop serious game, based on the tCOFELET framework, that aims to raise awareness of cyber security. The game promotes safe cyber practices and good ‘hygiene’, improving learners’ ability to identify and mitigate cyberattacks. Eleven postgraduate students took part in two game sessions led by a lecturer and two researchers in order to address the core research question of the study. The participants assumed the roles of company employees and worked together to protect their company assets (Figure 7) from cyber threats and ensure its success. To overcome the potential inaccuracy of the participants’ responses due to reliance on memory and self-reporting, the researchers employed a non-participatory observation approach, recording qualitative data in real time throughout the two game sessions. The qualitative data analysis provided evidence that key elements of a Community of Practice (joint enterprise, mutual engagement, joint tasks, shared communal resources) are facilitated by YellowTraining. The pilot study also showed that all participants were fully engaged, demonstrating high levels of interest and motivation throughout the game sessions.
Ref. [45] game was designed to test players’ decision-making skills. Through multiple-choice questions and dialogs with NPCs, players can demonstrate their understanding. The 28 participants were divided equally into a control group and an experimental group. While the control group only took the pre-survey, the experimental group took the pre- and post-surveys and played the game. Both groups took a standardized Google phishing quiz featuring all three types of phishing attack. The results revealed variations in confidence levels, behavior, and quiz scores between the control and experimental groups. On average, participants experienced a 30% increase in confidence after playing the game, which significantly improved their confidence levels. A total of 78% of participants in the experimental group indicated their willingness to change their online security behaviors. However, 53.57% lacked confidence in identifying phishing attempts. Over 90% of the experimental group could correctly answer at least 75% of the quiz questions. By contrast, only 28.57% of the control group managed to achieve this result. According to the post-survey results, 85% of players reported a deeper understanding of phishing. The game also motivated 75% of players to adopt better security practices in their daily lives, such as verifying email authenticity and avoiding suspicious links. On average, players’ awareness increased by 24%. To address the potential for selection bias, the authors recruited participants from social media platforms, university and community centers. The authors also suggest that guaranteed anonymity and confidentiality could prevent participants from feeling influenced by social pressure and exaggerating their level of vigilance. Finally, in order to maintain data integrity, researchers analyzed only the initial response from each participant.
In Security Awareness Adventure [5], the players must interact with NPCs at the right time and in the right way. On average, players visited 21 out of the 23 available NPCs. Due to ethical and moral issues, the experiment lacked a control group, with all 41 participants using the same serious game. The four evaluation goals proposed by the authors were based on the Technology Acceptance Model that is used to explain and predict how users may accept new technologies. Firstly, the participants took a security awareness exam, then they played the serious game, after which they were asked to export the game data and write an attack report. Finally, they took another security awareness exam and completed a user experience questionnaire. Next, they participated in a semi-structured interview. Through their interviews, the authors discovered that the participants considered the experiment to be effective in improving their security awareness and also found that it was far livelier and more interesting than text- or lecture-based training methods. Authors also conducted two hypothesis tests. First, they tested for significant differences in the scores for each item before and after the experiment and then, they tested for significant differences in the scores of all 41 participants. Data analysis revealed that the game provides a useful and easy-to-use gaming experience and effectively improves participants’ security awareness (85.4% of participants demonstrated an increase in security awareness). The authors also found that participants became more adept at identifying security vulnerabilities in diverse scenarios after engaging with the serious game. Additionally, 69% of students found the NPC dialog in the game to be very interesting. Finally, the authors suggest that the standardized answers to the test questions were determined by two independent experts. This small number could pose a threat to the validity of the answers, as their personal experiences or biases could affect their generalizability.
The SLR identified a combination of both qualitative and quantitative data collection methods with pre-, in-, and post-game activities. Methods such as questionnaires, surveys, interviews, direct observation and in-game data analysis were employed. The majority of the studies were focused exclusively on target users and less on comparisons of the control and experimental groups (Table 7).

9.4. RQ4: Educational Benefits of NPCs in Serious Games

The review of the literature revealed no studies with cyber security serious games in which participants were divided into control and experimental groups, with one group playing the game with NPCs and the other playing the same game without NPCs. Although in one study [45] participants were divided into control and experimental groups, while both groups completed the pre-survey and phishing quiz, only the experimental group played the game and completed the post-survey. In another study [41], participants were randomly divided into two separate groups, which played the same game with the only difference being the order in which each scenario appeared.
On the other hand, in the game Dungeon Class [50], designed to teach elementary school students programming, researchers used two different versions of the same game. In the first version, participants were supported by an NPC, while in the second version, text was used. The 291 participants were divided into two groups according to the type of support they received. The data collected during the game were used to draw conclusions that showed that students with prior programming experience performed better with in-game support provided by NPCs than with textual support. Similarly, the SEW-AT [53] was used to train 68 U.S. Navy electronic warfare operators. Two versions of SEW-AT were used during the training: one without an NPC Office of the Desk (OOD), and one with an NPC OOD. The SEW-AT version with the NPC OOD assessed trainee performance in real time and provided verbal prompts based on this assessment. Firstly, the NPC OOD alerted trainees to high-priority errors they had just made, and secondly, to whether their reports were submitted in a timely manner. The participants were divided into two groups (T1 and T2), who played respective versions of the SEW-AT game, one with the NPC OOD and one without. The authors found that those who trained in SEW-AT with the NPC OOD (T2) displayed greater improvements in their overall scenario score than those who trained without the NPC OOD (T1). Likewise, in ThrowThingsVR [46], a game designed to promote upper-limb motor stimulation through intuitive throwing gestures, the 12 participants were divided into two groups. The first group (Blue) chose to play, initially, the game with the NPC, while the other (Red) chose the version without the NPC. All players played both versions of the game, but they chose which to start with and which to play later. The authors used the Intrinsic Motivation Inventory questionnaire to evaluate the players’ experience and created a custom 5-question questionnaire to evaluate NPC impact. One group (Red) reported that the NPC hindered their performance by appearing directly in front of them during the session; however, they still preferred the version of the game with the NPC. Most players reported that the NPC did not directly improve their scores, but the majority still preferred the version of the game in which the NPC was present.
Participants in two cyber security serious games were asked to complete questionnaires that included questions related to NPCs in the game. In Cyber Adventure [16], the authors investigated how many participants found the interaction with NPCs helpful. After analyzing the collected data, it appeared that four out of five participants found these interactions helpful. In Security Awareness Adventure [5], the number of interactions with each of the game’s 23 NPCs were recorded, and it appeared that, on average, participants interacted with 21 of the 23 NPCs. The post-survey for this game included a question asking participants which of the serious game designs they found more appealing. Twenty-six of the 41 participants chose the dialog with NPCs from the available answers.
In addition to cyber security serious games, researchers have identified educational benefits from incorporating NPCs in other topics as well. In WoM [17], a serious game for SEO, OOP and Web development education, participants were asked to evaluate the effectiveness of NPCs’ guidance in understanding educational material. From the total of 61 participants, 38 found NPCs’ guidance very effective and 23 found it moderately effective, while nobody chose the option ‘It wasn’t effective’. According to their findings, thee authors concluded that NPCs’ mentorship significantly contributes to students’ understanding of the learning material, thereby enhancing the effectiveness of the gamified approach in improving learning outcomes [17]. Two hundred university students participated in the financial technology game by [13] (Liew et al., 2024). The questionnaire completed by the participants included five questions related to the social support provided by NPCs. After analyzing the collected data, the researchers confirmed their initial hypothesis and concluded that social support provided by NPCs enhances both the perceived usefulness and the perceived ease of use of the digital game-based learning (DGBL) environment. The creators of Turtle Trainer [15], a game designed for English language and grammar education, analyzed the data collected from 27 participants and concluded that NPCs can increase user interest in educational games. Finally, Ref. [47] concluded that NPCs created using their believable agent architecture are considered more believable than those created using the Finite State Machine technique.

10. Discussion

The present SLR reviewed 28 papers, each one referring to a different serious game. All games were categorized based on their topic (nine cyber security and 19 not focused on cyber security). For every category, a detailed list was created containing the authors, year of publication, game type, the number of participants and NPCs (Table 5 and Table 6). The evaluation methods and data collection techniques regarding the evaluation of cyber security serious games were also recorded (Table 7).
Our SLR findings showed that the most common game type was RPG, in contrast to other studies in which RPG was the least common game type [19]. This difference may be due to the fact that the present study focused exclusively on serious games and did not include any commercial games or games from other categories. Especially in cyber security education, RPGs allow the participants to adopt the perspectives of both attackers and defenders, encouraging active learning and helping them to develop an understanding of adversaries’ mindset and tactics [66]. Our findings also revealed that in most cyber security serious games NPCs appeared as 2D or 3D human characters and took the roles of attackers and defenders, demonstrating expertise in cyber security, by carrying out tasks that require specific cyber security skills and knowledge.
Regarding the support provided to the players by NPCs in cyber security serious games, our findings showed that guidance, feedback and encouragement were provided mostly through verbal communication based on text and written dialogs. Other researchers also concluded that communication is a key factor in effective interaction between players and NPCs, and engaging conversations referencing real-world situations and experiences are more effective in terms of player engagement and enjoyment [20]. Recent progress in AI and LLMs has provided game developers the opportunity to incorporate these new technologies for enhancing NPCs’ communication capabilities, and AI-enhanced NPCs appear to have a positive influence on students’ intrinsic motivation and interest [67].
The evaluation of cyber security serious games with NPCs was conducted mainly with pre- and post-questionnaires and by collecting and analyzing in-game data. As evidenced by our SLR, cyber security serious games evaluation focused more on collecting statistical data and on issues related to likeability, learnability, usability, user experience, and players’ ethical sensitivity [16,40,41] and less on NPCs’ educational benefits and effectiveness. On the other hand, the evaluation of serious games not focusing on cyber security, focused on NPCs’ perceived intelligence, believability [13,47], user experience [46], movement [48] and on the educational benefits they can offer [15,17,50,53].
Regarding participants’ allocation, in cyber security serious games, there was only one study in which the 28 participants were divided into control and experimental groups of an equal size [45]. Ref. [5] suggests that participants may not be divided into groups due to ethical and moral issues that arise when only certain students are allowed to use the serious game while others use different educational materials. Finally, it was not specified in all studies whether participants were selected randomly or whether their level of knowledge was equivalent. All the above factors could introduce bias into the results of this SLR.
In contrast to other SLRs, this study focused mainly on NPCs’ actions, characteristics, roles and their educational benefits in the context of serious games. In the future, a comprehensive classification of those and other actions and characteristics of NPCs in the context of cyber security serious games could be carried out. This classification could be useful for researchers and designers seeking a comprehensive understanding of how NPCs could be implemented into serious games for cyber security education. Finally, the review of the literature did not appear to identify any standardized tool or questionnaire for the comprehensive evaluation of NPCs in the context of serious games for cyber security education. The creation of such a tool could contribute to the evaluation of NPCs and provide useful insights for their improvement.

11. Limitations

The present study is subject to various limitations. In the initial phase of the research, all studies conducted in languages other than English were excluded, along with those that were not peer-reviewed journal papers or conference/symposium proceedings. Despite conducting searches across multiple databases and utilizing various keywords in the search query, it is possible that some relevant studies may not be identified and included in the current review. Not all NPCs’ actions and characteristics of the reviewed serious games could be analyzed since these games were not all publicly available. Additionally, no formal risk of bias assessment, based on standardized tools, was conducted for every individual study. Finally, reporting bias was not formally assessed, therefore the possibility of missing results remains, and lastly, the certainty of evidence was not assessed with a structured framework, which may affect the robustness of the findings.

12. Conclusions

This SLR has identified and summarized the findings of 28 studies, following the Prisma 2020 updated guidelines [25]. In response to RQ1, NPCs in serious games for cyber security education and serious games not focused on cyber security took the form of human characters, demonstrating cyber security expertise by performing tasks and actions related to cyber security, manipulating objects, moving in the playspace (chase, follow, random, patrol, wander) providing support (feedback, help, information, advice, guidance, encouragement, hints, tips, clues, quests, various viewpoints), responding (instant, accurately) and communicating with players in various forms (verbal, non-verbal). Regarding RQ2, NPCs took various roles in serious games, impersonating mentors, quest givers, guardians, customers, IT employees, phishing attack victims and data theft victims, receptionists and other company related roles. In relation to RQ3, the evaluation of cyber security serious games was conducted mainly with pre- and post-questionnaires, in-game data gathering and analysis, observation and surveys. Most of the games were evaluated by target group users only, and the division into control and experimental groups was relatively rare. Finally, concerning RQ4, preliminary evidence suggests that educational benefits have been identified in serious games when it comes to NPCs. Participants found the interaction with NPCs helpful, and the guidance provided by NPCs was found to be either very or moderately effective. Additionally, NPCs’ mentorship helped participants understand the learning material, and the provided social support enhanced participants’ perceived ease of use and perceived usefulness of the DGBL environment. Overall, it was found that NPCs have the potential to increase participants’ interest in the context of serious games.
Although this SLR provided a transparent analysis and summary of the actions, characteristics, roles and educational benefits of NPCs in the context of serious games, the various limitations outlined in the previous sections should be taken into consideration when interpreting the presented findings. Future research should address the limitations of this SLR and also the gaps identified, concerning the inclusion of non-English publications, where feasible, to enhance the comprehensiveness and generalizability of the findings, the absence of a thorough classification of NPCs’ actions and characteristics in the context of serious games for cyber security education, and the lack of comprehensive tools for the evaluation of NPCs’ effectiveness in the context of serious games for cyber security education.

Supplementary Materials

The following supporting information can be downloaded at: https://www.mdpi.com/article/10.3390/jcp6050155/s1, PRISMA 2020 Checklist.

Author Contributions

Conceptualization, A.M., M.N.K. and I.M.; methodology, A.M., M.N.K. and I.M.; validation, A.M., M.N.K. and I.M.; data curation, A.M., M.N.K. and I.M.; writing—original draft preparation, A.M. and M.N.K.; writing—review and editing, A.M., M.N.K. and I.M.; visualization, A.M. and M.N.K.; supervision, I.M. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

A list of excluded studies based on the exclusion criteria and summarized data extracted from the included studies are available upon request.

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
AIArtificial Intelligence
DGBLdigital Game-Based Learning
ECExclusion Criteria
ICInclusion Criteria
LLMLarge Language Model
NPCNon-Player Character
RPGRole Playing Game
RQResearch Question
SEOSearch Engine Optimization
SLRSystematic Literature Review

References

  1. DSIT Cyber Security Breaches Survey 2025. Available online: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025 (accessed on 17 March 2026).
  2. ENISA. ENISA Threat Landscape 2025. Available online: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 (accessed on 17 March 2026).
  3. O’Connor, S.; Hasshu, S.; Bielby, J.; Colreavy-Donnelly, S.; Kuhn, S.; Caraffini, F.; Smith, R. SCIPS: A Serious Game Using a Guidance Mechanic to Scaffold Effective Training for Cyber Security. Inf. Sci. 2021, 580, 524–540. [Google Scholar] [CrossRef] [Scilit]
  4. Li, L.; He, W.; Xu, L.; Ash, I.; Anwar, M.; Yuan, X. Investigating the Impact of Cybersecurity Policy Awareness on Employees’ Cybersecurity Behavior. Int. J. Inf. Manag. 2019, 45, 13–24. [Google Scholar] [CrossRef] [Scilit]
  5. Li, T.; Dong, F.; Wen, C. The Security Awareness Adventure: A Serious Game for Security Awareness Training Utilizing a State Transition System and a Probabilistic Model. Comput. Secur. 2025, 156, 104500. [Google Scholar] [CrossRef] [Scilit]
  6. Triplett, W.J. Addressing Cybersecurity Challenges in Education. Int. J. STEM Educ. Sustain. 2023, 3, 47–67. [Google Scholar] [CrossRef] [Scilit]
  7. Hill, W.; Fanuel, M.; Yuan, X. Comparing Serious Games for Cyber Security Education. In Proceedings of the 2020 ASEE Southeastern Section Conference, Auburn, AL, USA, 8–10 March 2020. [Google Scholar]
  8. Hu, S.; Hsu, C.; Zhou, Z. Security Education, Training, and Awareness Programs: Literature Review. J. Comput. Inf. Syst. 2022, 62, 752–764. [Google Scholar] [CrossRef] [Scilit]
  9. Wang, J.; Hodgson, R.; Cristea, A. MEMORABLE: A Multi-playEr custoMisable seriOus Game fRAmework for cyBer-Security Learning. In Proceedings of the 18th International Conference on Intelligent Tutoring Systems (ITS 2022), Bucharest, Romania, 29 June–1 July 2022; pp. 313–322. [Google Scholar]
  10. Hendrix, M.; Al-Sherbaz, A.; Bloom, V. Game Based Cyber Security Training: Are Serious Games Suitable for Cyber Security Training? Int. J. Serious Games 2016, 3, 53–61. [Google Scholar] [CrossRef] [Scilit]
  11. Pretty, E.J.; Fayek, H.M.; Zambetta, F. A Case for Personalized Non-Player Character Companion Design. Int. J. Hum. Comput. Interact. 2024, 40, 3051–3070. [Google Scholar] [CrossRef] [Scilit]
  12. Belle, S.; Gittens, C.; Nicholas Graham, T.C. A Framework for Creating Non-Player Characters That Make Psychologically-Driven Decisions. In Proceedings of the 2022 IEEE International Conference on Consumer Electronics (ICCE), Las Vegas, NV, USA, 7–9 January 2022; pp. 1–7. [Google Scholar]
  13. Liew, T.W.; Siradj, Y.; Tan, S.-M.; Roedavan, R.; Khan, M.T.I.; Pudjoatmodjo, B. Game-Changer NPCs: Leveling-Up Technology Acceptance and Flow in a Digital Learning Quest. Int. J. Hum. Comput. Interact. 2024, 41, 3994–4014. [Google Scholar] [CrossRef] [Scilit]
  14. Siswoko, T.M.; Haryanto, H.; Hastuti, K.; Kadiasti, R. Non-Playable Character (NPC) based on Behaviour Tree for Enhanced Immersive Experience in the Serious Game “Warik’s Adventure.”. JAIC 2023, 7, 284–290. [Google Scholar] [CrossRef] [Scilit]
  15. Yunanto, A.A.; Herumurti, D.; Rochimah, S.; Kuswardayan, I. English Education Game Using Non-Player Character Based on Natural Language Processing. Procedia Comput. Sci. 2019, 161, 502–508. [Google Scholar] [CrossRef] [Scilit]
  16. Deshmukh, S. Cyber Adventure-An Education 2D RPG Game to Teach Cybersecurity Concepts. In Proceedings of the Wellington Faculty of Engineering Symposium, Wellington, New Zealand, 10 October 2023. [Google Scholar]
  17. Sotirov, M.; Petrova, V.; Nikolova-Sotirova, D. Learning through Gamification: A Case Study on the Development and Integration of a University Educational Serious Game. In Proceedings of the 2024 International Conference Automatics and Informatics (ICAI), Varna, Bulgaria, 10–12 October 2024; pp. 313–318. [Google Scholar]
  18. Armanto, H.; Rosyid, H.A.; Muladi; Gunawan. Improved Non-Player Character (NPC) Behavior Using Evolutionary Algorithm—A Systematic Review. Entertain. Comput. 2025, 52, 100875. [Google Scholar] [CrossRef] [Scilit]
  19. Uludağlı, M.Ç.; Oğuz, K. Non-Player Character Decision-Making in Computer Games. Artif. Intell. Rev. 2023, 56, 14159–14191. [Google Scholar] [CrossRef] [Scilit]
  20. Wittmann, M.; Morschheuser, B. What Do Games Teach Us About Designing Effective Human-AI Cooperation? A Systematic Literature Review and Thematic Synthesis on Design Patterns of Non-Player Characters. In Proceedings of the 6th International GamiFIN Conference 2022, Tampere, Finland, 26–29 April 2022; pp. 95–104. [Google Scholar]
  21. da Silva, G.A.; Ribeiro, M.W.d.S. Development of Non-Player Character with Believable Behavior: A Systematic Literature Review. In Proceedings of the Simpósio Brasileiro de Jogos e Entretenimento Digital (SBGames), Gramado, Brazil, 18–21 October 2021; pp. 319–323. [Google Scholar]
  22. Azad, S.; Martens, C. Little Computer People: A Survey and Taxonomy of Simulated Models of Social Interaction. Proc. ACM Hum.-Comput. Interact. 2021, 5, 245. [Google Scholar]
  23. Yunanto, A.A.; Herumurti, D.; Rochimah, S.; Arifiani, S. A Literature Review for Non-Player Character Existence in Educational Game. In Cyber Physical, Computer and Automation System: A Study of New Technologies; Joelianto, E., Turnip, A., Widyotriatmo, A., Eds.; Springer: Singapore, 2021; pp. 235–244. ISBN 978-981-334-062-6. [Google Scholar]
  24. Kitchenham, B.; Charters, S. Guidelines for Performing Systematic Literature Reviews in Software Engineering; EBSE Technical Report, EBSE-2007-01; Keele University and University of Durham: Keele, UK, 2007. [Google Scholar]
  25. Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 Statement: An Updated Guideline for Reporting Systematic Reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [Scilit]
  26. Carrera-Rivera, A.; Ochoa, W.; Larrinaga, F.; Lasa, G. How-to Conduct a Systematic Literature Review: A Quick Guide for Computer Science Research. MethodsX 2022, 9, 101895. [Google Scholar] [CrossRef] [Scilit]
  27. Wilkinson, P. A Brief History of Serious Games. In Entertainment Computing and Serious Games: International GI-Dagstuhl Seminar 15283, Dagstuhl Castle, Germany, 5–10 July 2015, Revised Selected Papers; Dörner, R., Göbel, S., Kickmeier-Rust, M., Masuch, M., Zweig, K., Eds.; Springer International Publishing: Cham, Switzerland, 2016; pp. 17–41. ISBN 978-3-319-46152-6. [Google Scholar]
  28. Yannakakis, G.N.; Togelius, J. Artificial Intelligence and Games; Springer International Publishing: Cham, Switzerland, 2018; ISBN 978-3-319-63518-7. [Google Scholar]
  29. Aromataris, E.; Pearson, A. The Systematic Review: An Overview. Am. J. Nurs. 2014, 114, 53–58. [Google Scholar] [CrossRef] [Scilit]
  30. Jansen, P.; Fischbach, F. The Social Engineer: An Immersive Virtual Reality Educational Game to Raise Social Engineering Awareness. In Proceedings of the Extended Abstracts of the 2020 Annual Symposium on Computer-Human Interaction in Play, Online, 2–4 November 2020; pp. 59–63. [Google Scholar]
  31. Krylov, B.; Abramov, M.; Khlobystova, A. Automated Player Activity Analysis for a Serious Game About Social Engineering. In Recent Research in Control Engineering and Decision Making; Dolinina, O., Bessmertny, I., Brovko, A., Kreinovich, V., Pechenkin, V., Lvov, A., Zhmud, V., Eds.; Springer International Publishing: Cham, Switzerland, 2021; pp. 587–599. [Google Scholar]
  32. Tioh, J.-N.; Mina, M.; Jacobson, D.W. Cyber Security Social Engineers An Extensible Teaching Tool for Social Engineering Education and Awareness. In Proceedings of the 2019 IEEE Frontiers in Education Conference (FIE), Covington, KY, USA, 16–19 October 2019; pp. 1–5. [Google Scholar]
  33. Cullinane, I.; Huang, C.; Sharkey, T.; Moussavi, S. Cyber Security Education through Gaming Cybersecurity Games Can Be Interactive, Fun, Educational and Engaging. J. Comput. Sci. Coll. 2015, 30, 75–81. [Google Scholar]
  34. Jian, N.; Kamsin, I. Cybersecurity Awareness Among the Youngs in Malaysia by Gamification. In Proceedings of the 3rd International Conference on Integrated Intelligent Computing Communication & Security (ICIIC 2021), Bangalore, India, 13 September 2021. [Google Scholar]
  35. Mittal, A.; Gupta, M.P.; Chaturvedi, M.; Chansarkar, S.R.; Gupta, S. Cybersecurity Enhancement through Blockchain Training (CEBT)—A Serious Game Approach. Int. J. Inf. Manag. Data Insights 2021, 1, 100001. [Google Scholar] [CrossRef] [Scilit]
  36. Ryan, M.; McEwan, M.; Sansare, V.; Formosa, P.; Richards, D.; Hitchens, M. Design of a Serious Game for Cybersecurity Ethics Training. In Proceedings of the DiGRA 2022 Conference: Bringing Worlds Together, Krakow, Poland, 1 January 2022. [Google Scholar]
  37. Dörringer, A.; Klopp, M.; Rossmann, R. Digital Storytelling in Serious Games: Empirical Research on the Impact of Narrative in 3D Learning Worlds. In Proceedings of the 6th European Conference on Software Engineering Education, Seeon, Germany, 2–4 June 2025; pp. 96–105. [Google Scholar]
  38. Cui, L.; Zhu, C.; Hare, R.; Tang, Y. MetaEdu: A New Framework for Future Education. Discov. Artif. Intell. 2023, 3, 10. [Google Scholar] [CrossRef] [Scilit]
  39. Pamungkas, M.D.; Hidayat, S.; Prayudi, Y. Serious game: Learning digital forensic acquisition techniques to increase community awareness. J. Tek. Inform. 2022, 3, 1757–1764. [Google Scholar] [CrossRef] [Scilit]
  40. Fu, J.; Lu, Y.; Yang, Z.; Nah, F.; Lc, R. Cracking Aegis: An Adversarial LLM-Based Game for Raising Awareness of Vulnerabilities in Privacy Protection. In Proceedings of the 2025 ACM Designing Interactive Systems Conference, New York, NY, USA, 4 April 2025; pp. 639–662. [Google Scholar]
  41. Ganesh, A.; Ndulue, C.; Orji, R. Tailoring a Persuasive Game to Promote Secure Smartphone Behaviour. In Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems, Hamburg, Germany, 23–28 April 2023; pp. 1–18. [Google Scholar]
  42. Ferro, L.S.; Marrella, A.; Catarci, T.; Sapio, F.; Parenti, A.; De Santis, M. AWATO: A Serious Game to Improve Cybersecurity Awareness. In HCI in Games; Fang, X., Ed.; Springer International Publishing: Cham, Switzerland, 2022; pp. 508–529. [Google Scholar]
  43. Rahartomo, A.; Ghaleb, A.T.A.; Ghafari, M. Phishing Awareness via Game-Based Learning. In Proceedings of the 2025 IEEE/ACM 37th International Conference on Software Engineering Education and Training (CSEE&T), Ottawa, ON, Canada, 29 April 2025; pp. 287–291. [Google Scholar]
  44. Katsantonis, M.N.; Manikas, A.; Partarakis, N.; Mavridis, I. Yellow Training: A Collaborative tCOFELET Tabletop Serious Game for Cybersecurity Awareness and Training. Int. J. Inf. Secur. 2025, 24, 171. [Google Scholar] [CrossRef] [Scilit]
  45. Bajwa, M.H.A.; Richards, D.; Formosa, P. VMEET: A Serious Game for Teaching Ethical Viewpoints to Cybersecurity Professionals. In Proceedings of the Australasian Conference on Information Systems (ACIS 2024), Canberra, Australia, 4–6 December 2024. [Google Scholar]
  46. Papadimitriou, S.; Chrysafiadi, K.; Virvou, M. FuzzEG: Fuzzy Logic for Adaptive Scenarios in an Educational Adventure Game. Multimed. Tools Appl. 2019, 78, 32023–32053. [Google Scholar] [CrossRef] [Scilit]
  47. Tazouti, Y.; Boulaknadel, S.; Fakhri, Y. Design and Implementation of ImALeG Serious Game: Behavior of Non-Playable Characters (NPC). In Advances on Smart and Soft Computing; Saeed, F., Al-Hadhrami, T., Mohammed, E., Al-Sarem, M., Eds.; Springer: Singapore, 2022; pp. 69–77. [Google Scholar]
  48. Lêu, M.O.; Nunes, F.L.S.; Peres, F.; Teixeira, J.M. Impact of a Non-Playable Character on Player Experience and Performance in VR Games. In Proceedings of the 2025 27th Symposium on Virtual and Augmented Reality (SVR), Salvador, Brazil, 30 September–3 October 2025; pp. 342–351. [Google Scholar]
  49. Schroeder, B.L.; Fraulini, N.W.; Van Buskirk, W.L.; Johnson, C.I. Using a Non-Player Character to Improve Training Outcomes for Submarine Electronic Warfare Operators. In Adaptive Instructional Systems; Sottilare, R.A., Schwarz, J., Eds.; Springer International Publishing: Cham, Switzerland, 2020; pp. 531–542. [Google Scholar]
  50. Afonso, N.; Prada, R. Agents That Relate: Improving the Social Believability of Non-Player Characters in Role-Playing Games. In Entertainment Computing-ICEC 2008; Stevens, S.M., Saldamarco, S.J., Eds.; Springer: Berlin/Heidelberg, Germany, 2008; pp. 34–45. [Google Scholar]
  51. Chowanda, A.; Blanchfield, P.; Flintham, M.; Valstar, M. ERiSA: Building Emotionally Realistic Social Game-Agents Companions. In Intelligent Virtual Agents; Bickmore, T., Marsella, S., Sidner, C., Eds.; Springer International Publishing: Cham, Switzerland, 2014; pp. 134–143. [Google Scholar]
  52. Go, C.A.L.; Lee, W.-H. Digital Game-Based Learning: An Agent Approach. In Universal Access in Human-Computer Interaction. Applications and Services; Stephanidis, C., Ed.; Springer: Berlin/Heidelberg, Germany, 2007; pp. 588–597. [Google Scholar]
  53. Haryanto, H.; Gamayanto, I.; Kardianawati, A.; Rosyidah, U.; Mulyanto, E.; Sutojo, T. Improvement of Imaginative Immersion in Role Playing Serious Game Using Appreciative Game Activity. In Proceedings of the 2023 International Conference on Electrical and Information Technology (IEIT), Malang, Indonesia, 14–15 September 2023; pp. 191–195. [Google Scholar]
  54. González-Arroyo, R.U.; Arámburo-Lizárraga, J. Serious Game Design Using Good Video Game-Based Learning Principles and the Knowledge Generation Model for Visual Analytics. IEEE Rev. Iberoam. Tecnol. Del Aprendiz. 2022, 17, 21–30. [Google Scholar] [CrossRef] [Scilit]
  55. Toukiloglou, P.; Xinogalos, S. Ingame Worked Examples Support as an Alternative to Textual Instructions in Serious Games About Programming. J. Educ. Comput. Res. 2022, 60, 1615–1636. [Google Scholar] [CrossRef] [Scilit]
  56. Refnaldi, I.A.A. Design an Enemy Non-Player Character in Maze Game Using Finite State Machine Algorithm. J. Comput. Eng. 2023, 2, 70–79. [Google Scholar] [CrossRef] [Scilit]
  57. Headleand, C.J.; Jackson, J.; Williams, B.; Priday, L.; Teahan, W.J.; Ap Cenydd, L. How the Perceived Identity of a NPC Companion Influences Player Behavior. In Transactions on Computational Science XXVIII: Special Issue on Cyberworlds and Cybersecurity; Gavrilova, M.L., Tan, C.J.K., Sourin, A., Eds.; Springer: Berlin/Heidelberg, Germany, 2016; pp. 88–107. ISBN 978-3-662-53090-0. [Google Scholar]
  58. Inyang, S.; Sweetser, P.; Ozdowska, A. Mental State Modelling: A Philosophy of Mind Approach to Emergent Believable Behaviour in Non-Player Characters. In Proceedings of the 36th Australasian Conference on Human-Computer Interaction, Brisbane, Australia, 30 November–4 December 2024; pp. 1–12. [Google Scholar]
  59. Dever, D.A.; Azevedo, R. Autonomy and Types of Informational Text Presentations in Game-Based Learning Environments. In Artificial Intelligence in Education; Isotani, S., Millán, E., Ogan, A., Hastings, P., McLaren, B., Luckin, R., Eds.; Springer International Publishing: Cham, Switzerland, 2019; pp. 110–120. [Google Scholar]
  60. Jalbert, J.; Rank, S. Exit 53: Physiological Data for Improving Non-Player Character Interaction. In Interactive Storytelling; Nack, F., Gordon, A.S., Eds.; Springer International Publishing: Cham, Switzerland, 2016; pp. 25–36. [Google Scholar]
  61. Sales, R.; Clua, E.; de Oliveira, D.; Paes, A.; Chaimowicz, L.; Nunes, M.A.S.N. Evaluation between Humans and Affective NPC in Digital Gaming Scenario. In Proceedings of the 2014 IEEE 3rd International Conference on Serious Games and Applications for Health (SeGAH), Rio de Janeiro, Brazil, 14–16 May 2014; pp. 1–8. [Google Scholar]
  62. Ochs, M.; Sabouret, N.; Corruble, V. Simulation of the Dynamics of Nonplayer Characters’ Emotions and Social Relations in Games. IEEE Trans. Comput. Intell. AI Games 2009, 1, 281–297. [Google Scholar] [CrossRef] [Scilit]
  63. Aljammaz, R.; Wardrip-Fruin, N.; Mateas, M. Towards an Understanding of Character Believability. In Proceedings of the 18th International Conference on the Foundations of Digital Games, Lisboa, Portugal, 12–14 April 2023; pp. 1–9. [Google Scholar]
  64. Kirna, C.; Lorenz, B. Societal Responsibility in Educational Game Making: Gender Presentation in Cyber Security Games. In Learning and Collaboration Technologies; Smith, B.K., Borge, M., Eds.; Springer: Cham, Switzerland, 2025; pp. 27–40. [Google Scholar]
  65. Katsantonis, M.; Mavridis, I. Ontology-Based Modelling for Cyber Security E-Learning and Training. In Advances in Web-Based Learning–ICWL 2019; Herzog, M.A., Kubincová, Z., Han, P., Temperini, M., Eds.; Springer International Publishing: Cham, Switzerland, 2019; pp. 15–27. [Google Scholar]
  66. Hart, S.; Margheri, A.; Paci, F.; Sassone, V. Riskio: A Serious Game for Cyber Security Awareness and Education. Comput. Secur. 2020, 95, 101827. [Google Scholar] [CrossRef] [Scilit]
  67. Xiao, Y.; Li, D.; Guo, K. Using ChatGPT to Bring Non-Player Characters to Life: Effects on Students’ Storyline-Driven Game-Based Writing Learning. Comput. Educ. 2025, 238, 105414. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Studies selection process (PRISMA flowchart).
Figure 1. Studies selection process (PRISMA flowchart).
Jcp 06 00155 g001
Figure 2. AWATO starting interview with survey questions. Reprinted from Ref. [40].
Figure 2. AWATO starting interview with survey questions. Reprinted from Ref. [40].
Jcp 06 00155 g002
Figure 3. Player discussing with other NPCs. Reprinted from Ref. [41].
Figure 3. Player discussing with other NPCs. Reprinted from Ref. [41].
Jcp 06 00155 g003
Figure 4. Player interaction with NPC in Caesar Cipher. Reprinted from Ref. [16].
Figure 4. Player interaction with NPC in Caesar Cipher. Reprinted from Ref. [16].
Jcp 06 00155 g004
Figure 5. A friendly NPC waiting for the player’s help. Reprinted from Ref. [42].
Figure 5. A friendly NPC waiting for the player’s help. Reprinted from Ref. [42].
Jcp 06 00155 g005
Figure 6. Cracking Aegis dialog-based game UI. Reprinted from Ref. [43].
Figure 6. Cracking Aegis dialog-based game UI. Reprinted from Ref. [43].
Jcp 06 00155 g006
Figure 7. Yellow Training board with company assets. Reprinted from Ref. [44].
Figure 7. Yellow Training board with company assets. Reprinted from Ref. [44].
Jcp 06 00155 g007
Table 1. Studies on NPCs in digital games.
Table 1. Studies on NPCs in digital games.
AuthorsYearPublication TypeReviewed PapersResearch TypeTime PeriodResearch Topic
[18]2025JournalN/ASLR2008–2024NPCs behavior
[11]2024JournalN/ASurveyN/ANPCs Companion Design
[19]2023Journal106Survey1979–2023NPCs decision-making
[20]2022Conference174SLRN/ANPC design patterns for effective human–AI cooperation
[21]2021Symposium 18SLR2015–2021NPCs behavior
[22]2021Conference9SurveyN/ANPCs and models of social interaction
[23]2021Conference87SLR2015–2018AI existence (NPC) in educational games
N/A = Not available.
Table 2. Research questions and objectives.
Table 2. Research questions and objectives.
Research Questions (RQs)Objectives
RQ1: How are NPCs’ characteristics and actions described in the literature on serious games?To identify the actions and characteristics of NPCs in serious games.
RQ2: How are NPCs integrated into serious games?To identify the roles of NPCs in the context of serious games.
RQ3: How have serious games with NPCs for cyber security education been evaluated?To identify the criteria and tools used for the evaluation of NPCs in serious games for cyber security education.
RQ4: What educational benefits does the integration of NPCs have to offer?To identify the educational advantages of NPCs in comparison to other educational tools and game mechanics used in serious games.
Table 3. Search results from databases and search engines.
Table 3. Search results from databases and search engines.
Database/Search EngineSearch Results
ACM Digital Library368
IEEE-Xplore1492
Scopus588
Science Direct442
Springer Nature Link69
Google Scholar1173
Table 4. Search terms and keywords.
Table 4. Search terms and keywords.
SubjectSearch Terms and Keywords
Non-Player CharactersNon player character, NPC, autonomous agent, intelligent NPC, autonomous character
ClassificationTypology, taxonomy, classification, framework, characteristics, actions
Serious gamesSerious game, learning game, educational game, video game,
digital game, computer game, game-based learning
Cyber securityCyber security, cyber security education, cyber security awareness raising, cyber security training
Table 5. Cyber security serious games with NPCs.
Table 5. Cyber security serious games with NPCs.
AuthorsYearGame NameGame TypeTopic (Cybersecurity Related)Number of ParticipantsNumber of NPCs
[3]2021SCIPSSimulationProvide effective cyber security training.571
[40]2022Another Week at the Office (AWATO)RPGIdentify and classify threats based on STRIDE-HF model.19>1
[41]2024VMEETRPGCyber security ethics principles.3043
[16]2023Cyber AdventureRPGCyber security concepts.53
[42]2023N/A2D Retro PlatformerImprove user
awareness about smartphone security and privacy.
102>1
[43]2025Cracking AegisDialog-based gameRaising awareness of privacy protection.221
[44]2025YellowTrainingTabletop card gameCyber security awareness raising.11>3
[45]2025N/ARPGRaising awareness about phishing attacks.28>1
[5]2025Security Awareness AdventureRPGSecurity awareness training.4123
Table 6. Serious games with NPCs not focusing on cyber security.
Table 6. Serious games with NPCs not focusing on cyber security.
AuthorsYearGame NameGame TypeTopic (Not Focusing on Cyber Security)Number of ParticipantsNumber of NPCs
[46]2025ThrowThingsVRVirtual RealityUpper-limb motor stimulation121
[17]2024World of Mindcraft (Wom)RPGSEO, OOP, Web development618
[13]2024N/ARPG quest adventureFinancial technology200>12
[47]2024Occult IslandSimulationMental State Modeling (MSM) evaluation18>1
[48]2023Game Maze CleanerMaze gameNPC movement10>2
[49]2023The TruthRPGEnglish vocabulary
learning
10N/A
[50]2022Dungeon ClassBlock based gameProgramming2911
[51]2022AlainPlatformerDevelop number sense1N/A
[52]2022ImALeG3D Virtual worldAmazigh language learningN/A18
[53]2020Submarine EW Adaptive Trainer (SEW-AT)SimulationSubmarine Electronic Warfare681
[54]2019Crystal IslandN/ADevelop scientific reasoning skills902
[15]2019Turtle TrainerBattle gameEnglish language and grammar27N/A
[55]2019FuzzEGEducational adventure gameHTML Programming60>6
[56]2016Exit 53RPGPhysiological data driving NPC behavior163
[57]2016Web war2D top down gamePlayer’s behavior depending on NPC identity173>3
[58]2014N/AMemory gameNPC effect on fun factor51
[59]2014The
Smile Game
Social gameERiSA evaluation262
[60]2008Zion’s MarketRPGNPCs social behavior impact on game experience206
[61]2007N/ARPGBDI NPC evaluation103
Table 7. Evaluation methods and data collection techniques.
Table 7. Evaluation methods and data collection techniques.
AuthorsYearGame NameEvaluation-Data Collection
[3]2021SCIPSPR, POS, TRG
[40]2022Another Week at the Office (AWATO)PR, POS, TRG, QUES, ING, OBS
[41]2024VMEETPR, POS, TRG, ING, SRV
[16]2023Cyber AdventurePR, POS, TRG, QUES
[42]2023N/APR, POS, TRG, QUES, INTR
[43]2025Cracking AegisPOS, TRG, ING, INTR
[44]2025YellowTrainingOBS
[45]2025N/APR, POS, C&E, SRV, QUES
[5]2025Security Awareness AdventurePR, POS, TRG, ING, SRV, INTR
PR = Pre-game, POS = post-game, QUES = questionnaire, ING = in game data gather/analysis, OBS = observation, SRV = survey, INTR = interview, C&E = control and experimental group, TRG = target users only.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Manikas, A.; Katsantonis, M.N.; Mavridis, I. A Systematic Literature Review on Non-Player Characters Actions and Characteristics in Serious Games for Cyber Security Education. J. Cybersecur. Priv. 2026, 6, 155. https://doi.org/10.3390/jcp6050155

AMA Style

Manikas A, Katsantonis MN, Mavridis I. A Systematic Literature Review on Non-Player Characters Actions and Characteristics in Serious Games for Cyber Security Education. Journal of Cybersecurity and Privacy. 2026; 6(5):155. https://doi.org/10.3390/jcp6050155

Chicago/Turabian Style

Manikas, Athanasios, Menelaos N. Katsantonis, and Ioannis Mavridis. 2026. "A Systematic Literature Review on Non-Player Characters Actions and Characteristics in Serious Games for Cyber Security Education" Journal of Cybersecurity and Privacy 6, no. 5: 155. https://doi.org/10.3390/jcp6050155

APA Style

Manikas, A., Katsantonis, M. N., & Mavridis, I. (2026). A Systematic Literature Review on Non-Player Characters Actions and Characteristics in Serious Games for Cyber Security Education. Journal of Cybersecurity and Privacy, 6(5), 155. https://doi.org/10.3390/jcp6050155

Article Metrics

Back to TopTop