From Awareness to Practice: Domain-Specific Information Security Awareness as a Predictor of Self-Reported Cybersecurity Practices among University Personnel
By: Noli B. Lucila
References
- EDUCAUSE. “Top 10 IT Issues, 2022: The Higher Education We Deserve”. Available at: https://er.edu-cause.edu/articles/2021/11/top-10-it-issues-2022-the-higher-education-we-deserve (Accessed on date: 15 January 2026). EDUCAUSE Review.
- Verizon. “Data breach investigations report”. Available at https://www.verizon.com/business/resources/reports/dbir/(Accessed on date: 15 January 2026).
- S.S. Iyer & B. Raji. Cybersecurity culture and organizational resilience: A human-centered approach to digital risk management. American Journal of Industrial and Business Management, 15(5), 748–766, 2025.
- M. Nieles, K. Dempsey & V.Y. Pillitteri. “An introduction to information security (NIST Special Publication 800-12 Rev. 1)”. National Institute of Standards and Technology. Available at: https://csrc.nist.gov/pubs/sp/800/12/r1/final. (Accessed on date: 15 January 2026).
- C. Herley. So long, and no thanks for the externalities: the rational rejection of security advice by users. Proceedings of the 2009 Workshop on New Security Paradigms Workshop, 133–144, 2009.
- K. Parsons, D. Calic, M. Pattinson, M. Butavicius, A. McCormac & T. Zwaans. The human aspects of information security questionnaire (HAIS-Q): Two further validation studies. Computers & Security, 66, 40–51, 2017.
- M.S. Tsauri. Human Vulnerabilities to Social Engineering Attacks: A Systematic Literature Review for Building a Human Firewall. Journal of Applied Informatics and Computing, 9(4), 1127–1136, 2025.
- A.K. Gwenhure & F.S. Rahayu. Gamification of cybersecurity awareness for non-IT professionals: A systematic literature review. International. Journal of Serious Games, 11(1), 83–99, 2024.
- M. Bada, A.M. Sasse & J.R.C. Nurse. “Cyber security awareness campaigns: Why do they fail to change behaviour?” Available at: https://arxiv.org/abs/1901.02672 (Accessed on date: 15 January 2026).
- K. Khadka & A.B. Ullah. Human factors in cybersecurity: an interdisciplinary review and framework proposal. International Journal of Information, 24(3), 119, 2025.
- S. Oh, H. Baek, J.H. Huh, T. Kim, W. Jeon, I. Oakley & H. Kim. Understanding and improving user adoption and security awareness in password checkup services. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, 1–32, 2025.
- P. Ifinedo. Information systems security policy compliance: An empirical study of the effects of socialisation, influence, and cognition. Information & Management, 51(1), 69–79, 2014.
- K. Parsons, E. Young, M. Butavicius, A. McCormac, M. Pattinson & C. Jerram. The influence of organisational information security culture on cybersecurity decision making. Journal of Cognitive Engineering and Decision Making, 9(2), 117–129, 2015.
- N.C. Edeh. Cybersecurity and human factors: A literature review. Cybersecurity for Decision Makers (pp. 45–56), 2023.
- M. G. Ali, Cybersecurity Governance and Policy Development in Higher Education Institutions: A Strategic Framework for Resilience and Compliance, Education Resources Information Center (ERIC), Report ED675147, 2025. Available at: https://eric.ed.gov/?id=ED675147 (Accessed on date: 15 January 2026).
- The Jamovi Project, jamovi, Version 2.6, Jamovi.org, 2024. Available at: https://jamovi.org. (Accessed on date: 15 January 2026).
- R Core Team. R: A Language and Environment for Statistical Computing, Version 4.4. R Foundation for Statistical Computing, 2024. Available at: https://www.R-project.org/ (Accessed on date: 15 January 2026).
Language: English
Page range: 173 - 190
Published on: Jul 8, 2026
Published by: Cerebration Science Publishing Co., Limited
In partnership with: Paradigm Publishing Services
Publication frequency: 6 issues per year
Keywords:
Related subjects:
© 2026 Noli B. Lucila, published by Cerebration Science Publishing Co., Limited
This work is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 License.