
CTF365: How Capture the Flag Turned Cybersecurity Training Into an Epic Battle
Cybersecurity training has a motivation problem. The material matters, but traditional methods (lectures, slide decks, dry certification prep) put people to sleep. What if you could train security professionals the way gamers learn raid mechanics: through real competition, real stakes, and real skill progression?
That’s exactly what CTF365 attempted: a persistent, team-based Capture the Flag environment that turned information security training into something people actually wanted to do. Here’s how they used gamification principles to attack one of the most critical skill gaps in tech.
- How CTF365 Applied Security Training Gamification
- The Gamification Challenge in Security Training
- The Gamification Solution
- CTF = Capture the Flag Gamification
- Game Design of CTF365
- Octalysis Analysis: Why CTF365’s Design Worked
- What This Tells Us About Gamification in Professional Training
About Yu-kai Chou: Human-Systems Architect

Yu-kai Chou created the Octalysis Framework after studying gamification since 2003 — years before the term entered mainstream vocabulary. As a Human-Systems Architect & Behavioral Designer, his framework has been applied by LEGO, Microsoft, Porsche, Coca-Cola, Salesforce, and MrBeast, impacting over 1.5 Billion Users.
Chou has taught the Octalysis methodology at Harvard, Stanford, Yale, Tesla, Google, BCG, and IDEO.
His work has been cited by Harvard, Stanford, MIT, Forbes, Wall Street Journal, Wired, US Department of Energy, NIST, NSF, NCBI, US Department of Education, ClinicalTrials.gov, and Google Scholar — with 3,700+ more academic publications. Explore his books here.
How CTF365 Applied Security Training Gamification

I receive tons of emails from around the world regarding gamification, asking me for feedback or to share their story. I read all of them and many of them are interesting, but because of my limited time and full agenda (between my clients, my video show, writing my own content, and writing my book, along with a few startup projects) I’m forced to dig deep into only a few projects.
A few days ago, I received an email from Marius Corici, CEO and Co-founder for the CTF365 startup project, asking me to take a look at what he’s working on. That really caught my attention and I started to do a little research.
We live in a digital, connected world, and security is one of the most critical issues confronting modern society. The scale of cybersecurity threats has grown dramatically. The (ISC)² Cybersecurity Workforce Study has consistently shown a global shortage of millions of security professionals, making effective training more urgent than ever.
The Gamification Challenge in Security Training
Security training is generally dull and boring, but essential.
When it comes to learning information security, there are a few traditional paths: CS faculties (basics), security training companies (dull), or self-taught through forums and blogs (monotonous).
However, somebody has to do it because it is essential.
According to the (ISC)² 2025 Cybersecurity Workforce Study, the global cybersecurity workforce has grown to approximately 5.5 million professionals — yet 95% of organizations still report critical skills gaps, with 88% experiencing at least one significant cybersecurity consequence due to those gaps in the past year. The shortage has shifted from raw headcount to specialized skills in AI security, cloud security, and risk assessment.
When this post was originally written in 2013, Frost & Sullivan projected the workforce would reach 3.2 million that year. The fact that we’ve nearly doubled the workforce and still face critical gaps shows just how fast the threat landscape has evolved.
This is precisely the kind of problem where the Octalysis Framework can diagnose what’s missing from existing training approaches.
The Gamification Solution
What if we could have a method of security training that isn’t dull and boring? A method that is fun, entertaining, challenging, and community driven?
We all know the best way to learn is through application, and that’s where gamification excels with great results in education and training. Learning information security through gamification would increase student and employee engagement, improve retention rates, and speed up the learning process.
CTF = Capture the Flag Gamification
Information Security through Gamification is not a brand new concept. In fact, it’s been around since the early days of the internet. It’s called CTF — Capture The Flag. The DEF CON conference has hosted one of the first CTF competitions, and you can check CTFtime to see where CTF events (within the information security industry) take place worldwide. You’ll find CTFs organized by CS faculties, companies, and even government agencies.
However, there are several problems that many CTF competitions have:
- They Don’t Last — Most CTFs run for only 24 hours to 3 days.
- Geographic Limitations: Often you have to be physically present in a specific room or building.
- They Are Scattered: Events happen worldwide but are fragmented and short, which means almost all of them are small too.
- They Don’t Count — Because of the problems above, HR departments don’t give much weight to high-achievers in these games.
That’s why the team behind CTF365 decided to change the way Capture the Flag is designed and held, bringing a brand new approach to push security gamification to a bigger scale.
Game Design of CTF365
Team-Based Competition
The game is team-based, which means it improves and strengthens communication skills as teams are forced to work together under pressure, developing critical attributes for enterprise security teams, especially Red Teams, CERT, and CSIRT groups.
Global Teams
At the time of this writing, there were over 8,500 registered users and more than 590 teams waiting for launch.
The team built an internet within the Internet. A place where security professionals, security students, system administrators, and programmers can play and get continuous training in information security.
How Does CTF365 Work?
CTF365 is a game where “Players” build their own Fortress/VPS (virtual private server) and defend them while attacking other servers. It mirrors what happens in real life when your server or computer networks are under attack by hackers.
Below are some questions I asked Marius Corici, the CEO:
Define CTF365 in one sentence.
“World of Warcraft for Hackers.” As a “Player,” the awesome magic moves and fighting techniques are represented by your ability to write powerful scripts to hack.
(For more on how WoW mechanics create engagement, see my World of Warcraft gamification analysis.)
How did CTF365 get 8,500 registered users before launch?
Marius shared the strategies they used when marketing budget was close to none:
- Word of Mouth: This got them to the top of Hacker News, driving over 12,500 unique visits in one day and over 1,000 registered users.
- Referral Campaigns (Core Drive 6: Scarcity): Bring 5, 10, or 15 Players and get access to the Private Alpha, Private Beta, as well as premium accounts for testing.
- Strategic Partnerships: Free access for not-for-profit Information Security Conferences, which helped them get featured on The Hacker News.
Octalysis Analysis: Why CTF365’s Design Worked
When I asked Marius why he thought CTF365 would catch players’ attention, he surprised me by referencing the Octalysis Framework. He identified 4 Core Drives active in the design from launch:
Core Drive 1: Epic Meaning & Calling — Learning, training, and improving security skills. For every player, CTF365 is a haven where security professionals and aspiring hackers can do things that are normally forbidden: attacking and hacking other systems without worrying about legality. They’re protecting the digital world by getting better at understanding threats.
Core Drive 4: Ownership & Possession — Players build their bases from scratch, own virtual goods (servers, routers, etc.), and speed up their learning curve while improving retention rate.
Core Drive 3: Empowerment of Creativity & Feedback — Using different techniques, players unlock milestones while having real-time control over their servers and receiving instant feedback on their attacks and defenses.
Core Drive 2: Development & Accomplishment — Nothing makes players happier than being on the “Hall of Fame” leaderboard, winning prizes, and collecting points and badges for their real skills.
CTF365’s Ambitions
Marius outlined three goals for the project:
- Become a prerequisite for the InfoSec industry. A security professional certificate is important, but what you can actually do hands-on matters more.
- Become the World of Warcraft for the ITC industry. Using specific hacking tools is one thing; writing powerful scripts as a programmer is even cooler. Programmers can team up with ethical hackers to boost their teams.
- Become LinkedIn on steroids for HR departments hiring security professionals, where verified skills matter more than paper credentials.
What This Tells Us About Gamification in Professional Training
CTF365 is a strong example of how gamification can transform even the most technical, traditionally dry training into something engaging. The core insight? When people can practice real skills in a competitive, social environment with clear feedback loops, learning retention and motivation increase dramatically.
This is why the Octalysis Framework emphasizes that Core Drive 3 (Empowerment of Creativity & Feedback) is the most sustainable long-term motivator. It’s the drive that keeps players coming back not for points or badges, but because the activity itself is intrinsically rewarding.
For more on how gamification transforms education, see our guide on Top 10 Education Gamification Examples and our deep dive on What is Gamification.



