From Awareness to Practice: Domain-Specific Information Security Awareness as a Predictor of Self-Reported Cybersecurity Practices among University Personnel
Abstract
This study examined information security awareness as a predictor of self-reported cybersecurity practices among 160 personnel of a state university in the Philippines. Awareness was measured across six domains: password security, phishing, device security, data protection, security policy, and social engineering. Results showed moderate to high awareness and reported practices, with uneven domain patterns. Multiple regression indicated that awareness domains explained 55.8% of the variance in reported practices. Password security, phishing, and social engineering awareness were significant predictors, while security policy, data protection, and device security were not. However, these findings should be understood in the context of self-reported cybersecurity practices, which may differ from actual behavior.
© 2026 Noli B. Lucila, published by Cerebration Science Publishing Co., Limited
This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 License.