I. Introduction
Information security has become one of the main priorities for governmental and private institutions. It has been shown in several occasions that a big amount of all security incidents is caused by human errors such as system misconfigurations, security policy breaches and careless systems administration. Since these actions were not done on purpose, most of them could have been avoided by improving the information security education of managers, the training of the system administrators and the general awareness of end users. Simulation systems are of great help for this task since they allow hands-on experience and user interaction. This sentence, attributed to Confucius, and also mentioned in [1], is self explanatory: “I see and I forget, I hear and I remember, I do and I understand”.