HackShield: Raising the Next Generation of Cyber Heroes

Infographic 2026

Find Threat Talks on

HackShield: Raising the Next Generation of Cyber Heroes

 

The hacker who will attack your organization in five years from now is currently sitting in a classroom, and almost nobody is teaching that kid the difference between safe and risky online. That single observation is the reason HackShield exists. In this Threat Talks episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, talks with Tim Murck, co-founder of HackShield, the free serious game that has turned hundreds of thousands of children into “junior cyber agents.”

 

The conversation is not really about kids. It is about human risk. If your defense against a malicious PDF is to train 2,000 employees to never click, you have already lost. Tim explains why fear-based, one-off awareness campaigns fail, and how HackShield’s approach, letting people make the wrong choice safely and learn from it, points to a better way to build a security culture inside any organization.

What you’ll learn

 

  • Why awareness training fails. Telling 2,000 people not to click is not a control.
  • From Zero Trust to Hero Trust. A CISO is part engineer, part campaign manager
  • Security as a positive story. Fear does not motivate change; a better future does.

Your cybersecurity experts

Rob Maas

Lieuwe Jan Koning

Co-founder & CTO
ON2IT

Tim Murck

Tim Murck

 Co-founder
Hero Centered Design™️ & Co-founder of HackShield

Episode details

HackShield started with a simple, uncomfortable premise: the attackers of the next decade are children today, and the education system is not preparing them. Tim Murck and his team responded not as security specialists but as game designers and storytellers, building something that competes with entertainment gaming for a child’s attention. The result is free for every kid and every teacher, sustained by more than thirty private partners, governments, and the Dutch police, plus a commercial workforce program that funds the free layer.

 

The insight for security leaders sits in the middle of the episode. Lieuwe Jan pushes on a familiar failure: a CISO identifies a risk, employees clicking malicious attachments, and answers it with an awareness campaign. Everyone knows the “right” answer when they see the question, so the training scores well and changes almost nothing. Tim’s reframe is that a CISO is not only an engineer of controls, but a campaign manager who has to make an unglamorous topic genuinely engaging. He calls it moving “from Zero Trust to Hero Trust,” a combination of technology that stops the wrong action and a culture that makes people want to act well.

 

The mechanism underneath is worth stealing. HackShield deliberately makes the wrong decision attractive, because a mistake made safely teaches more than a lecture, and it is memorable. Humans learn from their own mistakes, from watching others, and uniquely, from stories about others. That is why gamification and narrative outperform the annual slide deck. The same logic applies whether the learner is nine years old or a senior engineer.

 

For an organization, the takeaway is concrete. Cyber safety is a conversation starter, and children make hard priorities simple: when a kid’s safety is on the line, the debate ends. Companies can put HackShield in front of employees’ children as a corporate social responsibility program, send staff to give guest lectures, and run a workforce awareness track alongside it. The point is not a single tool. It is to stop treating awareness as a compliance checkbox and start treating it as a campaign you actually want people to join.
Infographic 2026

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

5 + 6 =

Christmas Hacker