Aktuelles
Cybersecurity Awareness Training for Industrial Software Developers via a Serious Game for Code Review
Software developers must not only be capable of producing secure code, but must also possess the ability to identify security vulnerabilities when evaluating their peers’ work. The necessary awareness of this is crucial in indus- trial environments that handle critical infrastructure. The present work explores a method to empower software developers on the topic of secure coding, through the practice of code review. We propose a serious game, called the “DuckDebugger”, specifically designed for use in industrial settings and to address the needs of software developers, and implement it across 13 events together with over 200 industrial developers.