Publication Date
8-4-2026
Abstract
Phishing remains one of the most persistent cybersecurity threats facing higher education institutions, where diverse user populations and highly connected digital environments increase exposure to social engineering attacks. Although cybersecurity awareness initiatives are widely implemented, high awareness does not always translate into secure behavior. This study examined phishing awareness, phishing-related practices, phishing susceptibility, and phishing experiences among college students, teaching faculty, and administrative staff in a private higher education institution in the Philippines. Using a quantitative cross-sectional design, data were collected from 553 respondents through a validated survey instrument and analyzed using descriptive statistics, one-way analysis of variance, Tukey's honestly significant difference test, and Pearson correlation. The findings revealed very high phishing awareness across all stakeholder groups but significant differences in cybersecurity practices and phishing susceptibility. Administrative staff demonstrated lower cybersecurity practices and greater susceptibility than students and faculty members. While phishing awareness was positively associated with cybersecurity practices and negatively associated with phishing susceptibility, cybersecurity practices showed the strongest relationship with reduced susceptibility, highlighting the gap between knowing and consistently practicing secure behavior. Based on these findings, the study proposes the Cybersecurity Awareness, Reporting, and Education (C.A.R.E.) Framework, a role-based institutional training framework designed to align established security education strategies with empirically identified behavioral risk profiles. The study contributes evidence that effective phishing resilience in higher education requires targeted, behavior-focused interventions rather than uniform awareness campaigns, providing a practical framework for strengthening institutional cybersecurity.
Included in
Educational Leadership Commons, Higher Education Administration Commons, Information Security Commons, Management Information Systems Commons, Technology and Innovation Commons