Level of Cybersecurity Awareness of Btech Employees: Basis for Proposing Cybersecurity Training

Level of Cybersecurity Awareness of Btech Employees: Basis for Proposing Cybersecurity Training

Article Fingerprint

ReserarchID

52Y7L

Level of Cybersecurity Awareness of Btech Employees: Basis for Proposing Cybersecurity Training Banner

AI TAKEAWAY

Connecting with the Eternal Ground
  • English
  • Afrikaans
  • Albanian
  • Amharic
  • Arabic
  • Armenian
  • Azerbaijani
  • Basque
  • Belarusian
  • Bengali
  • Bosnian
  • Bulgarian
  • Catalan
  • Cebuano
  • Chichewa
  • Chinese (Simplified)
  • Chinese (Traditional)
  • Corsican
  • Croatian
  • Czech
  • Danish
  • Dutch
  • Esperanto
  • Estonian
  • Filipino
  • Finnish
  • French
  • Frisian
  • Galician
  • Georgian
  • German
  • Greek
  • Gujarati
  • Haitian Creole
  • Hausa
  • Hawaiian
  • Hebrew
  • Hindi
  • Hmong
  • Hungarian
  • Icelandic
  • Igbo
  • Indonesian
  • Irish
  • Italian
  • Japanese
  • Javanese
  • Kannada
  • Kazakh
  • Khmer
  • Korean
  • Kurdish (Kurmanji)
  • Kyrgyz
  • Lao
  • Latin
  • Latvian
  • Lithuanian
  • Luxembourgish
  • Macedonian
  • Malagasy
  • Malay
  • Malayalam
  • Maltese
  • Maori
  • Marathi
  • Mongolian
  • Myanmar (Burmese)
  • Nepali
  • Norwegian
  • Pashto
  • Persian
  • Polish
  • Portuguese
  • Punjabi
  • Romanian
  • Russian
  • Samoan
  • Scots Gaelic
  • Serbian
  • Sesotho
  • Shona
  • Sindhi
  • Sinhala
  • Slovak
  • Slovenian
  • Somali
  • Spanish
  • Sundanese
  • Swahili
  • Swedish
  • Tajik
  • Tamil
  • Telugu
  • Thai
  • Turkish
  • Ukrainian
  • Urdu
  • Uzbek
  • Vietnamese
  • Welsh
  • Xhosa
  • Yiddish
  • Yoruba
  • Zulu
Font Type
Font Size
Font Size
Bedground

Abstract

Cybersecurity threats pose serious risks to the world, particularly in many educational institutions wherein they were handling, managing, and controlling large volume of sensitive data. Human errors remain a leading cause of data breaches, highlighting the importance of assessing the employees’ level of cybersecurity awareness. This study aimed to determine the level of cybersecurity awareness of BTECH employees in terms of knowledge, skills, and attitude, and to examine whether there are significant difference and relationship among selected variables.

Descriptive-quantitative research design with comparative and correlational components was utilized in this study. Data were collected from 190 teaching and nonteaching employees using a purposive sampling method. Gathering of data was accomplished through an adopted-modified and validated survey questionnaire. To analyze the data, percentage, frequency, weighted/composite mean, t-test, one-way ANOVA, and Pearson Product-Moment Correlation were used as statistical tools.

Findings revealed a moderate level of cybersecurity awareness, with skills ranking highest (WM = 3.88), followed by attitude (WM = 3.47) and knowledge (WM = 3.29). A significant positive relationship was observed between knowledge, skills, attitude, and overall cybersecurity awareness. No significant differences were found across most demographic variables except for position.

To significantly enhance and strengthen the cybersecurity knowledge, skills, and attitude of BTECH employees, this study concludes that proposing a cybersecurity training program is essential to improve cybersecurity awareness and reduce institutional vulnerability to cyberattacks.

Introduction

Technology plays a significant role in modern organizations, like educational institutions as it enhances the efficiency of communication, efficiency, and data management. While facing the advantages and reliance of educational institutions into digital systems, it also exposes institutions to cyberattacks such as phishing, ransomware, and unauthorized access.

Huge amounts of confidential information such as documents, records, and data were controlled and managed by educational institutions. Because of factors mentioned, educational institutions become frequent targets of cyberattacks. Studies and reports indicate that human error is one of the primary causes of data breaches, emphasizing the importance of employee awareness and cybersecurity practices.

In the Philippine context, rapid digitalization in education has further increased exposure to cyber risks. Despite technological advancements, gaps in employee awareness and training remain a concern. Therefore, assessing cybersecurity awareness is essential to identify vulnerabilities and develop effective training programs.

Cybersecurity awareness in this study is viewed as a multidimensional construct consisting of knowledge, skills, and attitude, while demographic variables serve as possible influencing factors. Additionally, selected demographic variables may serve as intervening factors that can influence the level of cybersecurity awareness of employees.

Human error plays a critical role in cyberattacks, often due to negligent employee actions that lead to data breaches. Research, including AlKuwari (2024), emphasizes inadequate training and awareness as major contributors to these threats, particularly concerning social engineering tactics like phishing. The National Privacy Commission of the Philippines identifies human error as a primary cause of data breaches in sectors like education, highlighting the necessity for institutions to implement protective measures and comply with the Data Privacy Act of 2012 (RA 10173). Furthermore, Martínez-Peláez et al. (2024) demonstrate that improved cybersecurity training can reduce employee susceptibility to attacks, stressing the importance of integrating cybersecurity education into regular operations.

Moreover, the research highlights that understanding human factors is essential, as employees can be both an organization’s greatest asset and its weakest link in terms of cybersecurity. Nonum et al. (2025) argue that organizations often overlook the importance of employee behavior and decision-making in cybersecurity, leading to vulnerabilities that attackers exploit through trust and authority.

Despite advancements in technical safeguards, human error, particularly in phishing attacks, remains a critical concern, as noted by Alqahtani and Alshahrani (2021). Phishing is a prevalent method of cyberattacks, exploiting cognitive biases and a lack of awareness among employees, which can lead to severe consequences such as data theft and ransomware. This highlights the necessity for organizations to adopt a human-centered cybersecurity strategy that encompasses behavioral science to effectively complement existing technical defenses.

In recent incidents of data breaches involving educational institutions, the University of the Philippines Tacloban College (UPTC) experienced a breach of its Learning Management System, compromising over 1,600 student records. UPTC has implemented preventive actions with guidance from UP Diliman, while the UP System introduced privacy guidelines. Pamantasan ng Lungsod ng Maynila’s official Facebook page was hacked due to phishing, prompting alerts from the Manila City Government. Romblon State University reported a breach leaking sensitive information, leading to collaborations with law enforcement and cybersecurity strategies. Similarly, BTECH’s Facebook Admissions page faced unauthorized access, and Ifugao State University experienced hacking incidents, calling for improved cybersecurity measures. The Department of Education’s Ilocos Norte Division reported a breach affecting three million records, stressing the need for enhanced cybersecurity training in educational institutions.

Ongoing training and simulations are crucial for reducing phishing risks and enhancing cybersecurity awareness among employees. A study by Toth (2025) found that continuous training can reduce phishing attacks by 50 % within six months. Customized training targeting specific departments is also essential, as evidenced by Alenzi and Rusho (2024), which indicated that tailored training can reduce human error incidents by 45 % 65 % , particularly in non-technical departments lacking cybersecurity knowledge.

Further research by Roy and Francis (2023) highlighted that persistent training diminishes data breaches by addressing human-related factors. Additionally, structured awareness training significantly influences employee behavior, leading to fewer phishing and data mishandling incidents, as noted by Hadlington and Parsons (2021). Creating a supportive training environment that considers cultural factors and using engaging simulation exercises can enhance employee alignment with cybersecurity principles while making learning enjoyable.

Statement of the Problem

This study aims to determine the level of cybersecurity awareness among teaching and non-teaching BTECH employees and to examine whether significant differences and relationships exist among selected variables. The study was specifically designed to address the questions listed below:

  1. What is the profile of BTECH employees in terms of:

    1. Age

    2. Sex

    3. Position

    4. Nature of work

    5. Employment status, and

    6. Length of service?

  2. What is the level of cybersecurity awareness of employees in terms of:

    1. Knowledge

    2. Skills, and

    3. Attitude?

  3. Is there a significant difference in the level of cybersecurity awareness of employees when grouped according to selected demographic variables such as age, sex, position, nature of work, employment status or length of service?

  4. Is there a significant relationship among employees’ cybersecurity knowledge, skills, and attitudes with their overall level of cybersecurity awareness?

  5. What cybersecurity training programs may be proposed to address the needs of BTECH employees in terms of cybersecurity?

Null Hypothesis ( H 0 )

  1. There is no significant difference in the level of cybersecurity awareness of employees when grouped according to age, sex, position, nature of work, employment status, and length of service.

  2. There is no significant relationship between employees’ level of cybersecurity awareness and their cybersecurity knowledge, skills and attitudes.

Alternative Hypothesis ( H 1 )

  1. There is a significant difference in the level of cybersecurity awareness of employees when grouped according to age, sex, position, nature of work, employment status, and length of service.

  2. There is a significant relationship between employees’ level of cybersecurity awareness and their cybersecurity knowledge, skills and attitudes.

Theoretical and Conceptual Framework

This study examines the intersection of individual behaviors, organizational practices, and attitudes towards cybersecurity, positing that employees’ actions are influenced by their knowledge, skills, and attitudes regarding cyber threat protection. It references the Unified Learning Model (ULM) which suggests that various factors, such as prior knowledge, motivation, and cognitive processing, shape how individuals acquire and utilize knowledge. The ULM implies that an employee’s cybersecurity awareness increases through training and practical experience with institutional systems and tasks.

Additionally, Protective Motivation Theory (PMT) is highlighted, explaining how individuals protect themselves from perceived threats by evaluating the severity and likelihood of those threats (Threat Appraisal) and their ability to respond (Coping Appraisal). The study indicates that employees’ cybersecurity knowledge relates to their awareness of potential cyberattacks and that their skills are indicative of their confidence in employing protective measures. Finally, the study introduces a conceptual framework linking cybersecurity awareness to three vital factors: knowledge (understanding of cybersecurity concepts), skills (ability to apply protective measures), and attitude (perceptions and responsibility towards cybersecurity). A positive attitude enhances the likelihood of adopting precautionary security behaviors.

Paradigm of the Study

Figure [fig:paradigm] illustrates the input-process-output (IPO) model in the context of cybersecurity employee training. The input includes employee profiles along with their knowledge, skills, and attitudes regarding cybersecurity. The process involves the distribution of surveys and statistical analysis aimed at identifying relationships among these variables. The study’s findings catalyzed the formulation of a proposed cybersecurity training program, the main output of this research. This program seeks to enhance participants’ knowledge, bolster their cybersecurity skills, and foster a positive attitude towards cybersecurity, ultimately improving their overall cybersecurity awareness. According to IBM Security (2025), organizations that provide cybersecurity training and educate their employees about various cyberattacks are less likely to experience significant data breaches, thereby highlighting the critical role of human factors in cybersecurity.

Method

Research Design

This study employed a descriptive-quantitative design with comparative and correlational elements to assess the cybersecurity awareness of BTECH employees regarding their knowledge, skills, and attitudes.

The descriptive approach generated an overview of employees’ understanding of sensitive data usage, information protection, password management, and cyberattack identification. Utilizing a Likert scale, the research evaluated employees’ knowledge, skills and attitude. While the comparative aspect investigated differences in awareness across demographic variables such as age, sex, and length of service, analyzed using the independent samples t-test and ANOVA.

Additionally, the study explored correlations between employees’ knowledge, skills, attitudes, and overall cybersecurity awareness via the Pearson Product-Moment Correlation Coefficient, ultimately providing insights into factors influencing cybersecurity readiness among BTECH employees.

Respondents/Participants

The respondents consisted of 190 teaching and non-teaching BTECH employees who are exposed to digital systems and institutions data. This study utilized purposive sampling, this approach ensures that the respondents were relevant to the research objectives by giving accurate information about their current cybersecurity knowledge, skills, and attitudes.

Before obtaining the data needed from the respondents, the researchers informed them regarding the objective of study and asked for their consent. Respondents who declined participation were excluded, while responses found to be invalid or incomplete were removed and not considered in the final analysis. This thorough selection process makes sure that the information mirrors the engagement of employees who are actively engaged with the institution’s digital system and sensitive information.

Questionnaire/Survey Tool

An adopted-modified version of a validated research questionnaire by Nikel and Amaechi (2021) was utilized to assess BTECH employees’ cybersecurity awareness, encompassing their knowledge, skills, and attitudes. Following modifications, the questionnaire was validated by three experts, each with advanced qualifications in relevant fields. Feedback was solicited based on criteria such as clarity, organization, and content adequacy, leading to further enhancements of the instrument to align with the research objectives.

A pilot study involving 30 teaching and non-teaching employees (not the actual respondents of the study) was conducted to evaluate the questionnaire’s reliability, internal consistency, and clarity, providing insights for refinements prior to the main study. The instrument aimed to gauge employees’ knowledge of cybersecurity, their skills in safeguarding institutional data, and their attitudes towards cybersecurity practices. It specifically assessed understanding of cyberattacks, security policies, and principles of data protection, alongside practical skills like secure password management and safe handling of sensitive information.

Furthermore, the instrument measured attitudes towards cybersecurity, highlighting responsibility, risk awareness, and compliance with security measures. The methodology employed a Likert Scale format for responses, facilitating easy analysis and ensuring reliability and validity based on respondents’ perceptions, ultimately offering a thorough evaluation of cybersecurity awareness within the institution.

DimensionItem NumbersPossible Score Range
Knowledge1-1010-50
Skills11-2010-50
Attitudes21-3010-50
Overall Cybersecurity Awareness1-3030-150

Subscale Scoring. Each dimension contains 10 items

Scoring Method

Score RangeInterpretation
1.00 - 2.30Low Level
2.40 - 3.60Moderate Level
3.70 - 5.00High Level

Interpretation of Scores per Dimension (Knowledge / Skill / Attitudes)

Score RangeLevel of Awareness
1.00 - 2.30Low
2.33 - 3.63Moderate
3.67 - 5.00High

Overall Cybersecurity Awareness Interpretation

Validation of the Instrument

When all 30 items were analyzed collectively, the instrument obtained a Cronbach’s Alpha of 0.86, indicating good internal consistency. An alpha coefficient above 0.70 suggests that the items are correlated and consistently measure the intended constructs. This result confirms that the questionnaire is reliable and suitable for use in the study. Table [tab:reliability-construct] shows the reliability per construct.

ConstructNo. of ItemsCronbach’s AlphaInterpretation
Knowledge100.78Acceptable
Skills100.84Good
Attitude100.95Excellent
Overall300.86Good Internal Consistency

Reliability Per Construct

The reliability analysis results, as presented in Table [tab:reliability-construct], demonstrate an overall Cronbach’s alpha coefficient of 0.86 for the instrument, indicating good internal consistency. This suggests that the items within the constructs of knowledge, skills, and attitude reliably measure the intended constructs. Among these dimensions, attitude exhibited the highest reliability with a coefficient of 0.95, followed by skills at 0.84 and knowledge at 0.78. All reliability values surpass the minimum acceptable threshold of 0.70, confirming the instrument’s statistical reliability for both research and academic purposes.

Results and Discussion

This chapter presents the data gathered from the respondents, along with the analysis and interpretation of the results. The data were obtained through a survey questionnaire distributed to both teaching and non-teaching employees of BTECH. The presentation of data is organized according to the objectives of the study, which include the profile of the respondents, the level of cybersecurity knowledge, skills, and attitude, and the relationship between variables.

The researchers analyzed the profiles of the participants based on several criteria, including age group, sex, position, nature of work, employment status, and length of service. Additional details such as the type of device used for work, the amount of cybersecurity training received, the frequency of attending training, and the level of familiarity with institutional cybersecurity policies were included in the survey instrument.

AgeFrequencyPercentage
21-30 years old3015.79%
31-40 years old6634.74%
41-50 years old6936.32%
51-60 years old178.95%
61 and above84.21%
Total190100%

Distribution of Respondents According to Age

Table [tab:dist-age] shows that most respondents are 41-50 years old (69 respondents, 36.32%), followed closely by 31-40 years old (66 respondents, 34.74%). Respondents aged 21-30 years accounted for 15.79% (30 respondents), 51-60 years for 8.95% (17 respondents), and only 4.21% (8 respondents) were 61 years and above. This distribution reflects the workforce composition of BTECH, where mid-career employees dominate.

SexFrequencyPercentage
Male8544.74%
Female10555.26%
Total190100%

Distribution of Respondents According to Sex

The majority of respondents were female (105 respondents, 55.26%), while males comprised 44.74% (85 respondents). Including sex as a demographic variable is important for analyzing potential differences in workplace behavior and cybersecurity awareness (Robbins & Judge, 2017).

PositionFrequencyPercentage
Head Office73.68%
Program Director31.58%
Administrative4121.58%
Faculty13973.16%
Total190100%

Distribution of Respondents According to Position

Most respondents were faculty members (139 respondents, 73.16%), followed by administrative staff (41 respondents, 21.58%). Head Office personnel accounted for 7 respondents (3.68%), while Program Directors were the smallest group with 3 respondents (1.58%).

Nature of WorkFrequencyPercentage
Teaching15280%
Non-Teaching3820%
Total190100%

Distribution of Respondents According to Nature of Work

A majority of respondents (152 respondents, 80%) were engaged in teaching-related work, while 38 respondents (20%) performed non-teaching tasks. Teaching employees frequently interact with computers, institutional databases, and online platforms, highlighting their relevance in assessing cybersecurity knowledge and practices (DoE, 2020; Flores, 2025).

Years of ServiceFrequencyPercentage
Less than 1 year42.11%
1-2 years2513.16%
3-4 years7137.37%
5 years and above9047.37%
Total190100%

Distribution of Respondents According to Length of Service

Respondents with 5 or more years of service comprised 47.37% (90 respondents), followed by those with 3-4 years at 37.37% (71 respondents). This indicates that employees generally stay long-term in the institution, likely due to job stability, organizational support, and job satisfaction (Camlian & Baron, 2025; Anog, 2024).

Employment StatusFrequencyPercentage
Permanent8544.74%
Part-Time10555.26%
Total190100%

Distribution of Respondents According to Employment Status

Most respondents were part-time employees (105 respondents, 55.26%), while permanent employees comprised 44.74% (85 respondents). Including both groups provides a broader understanding of cybersecurity awareness (Pugong, 2025).

Device UsedFrequencyPercentage
Desktop9751.05%
Laptop6936.32%
Tablet2412.63%
Total190100%

Distribution of Respondents According to Device Used

The majority of respondents primarily used desktop computers (97 respondents, 51.05%), followed by laptops (69 respondents, 36.32%) and tablets (24 respondents, 12.63%).

Attended TrainingFrequencyPercentage
Yes8846.32%
No10253.68%
Total190100%

Distribution of Respondents According to Attendance in Cybersecurity Training

Out of 190 respondents, 88 (46.32%) reported having attended cybersecurity training, while 102 (53.68%) had not. This highlights a gap in formal cybersecurity education.

Frequency of TrainingFrequencyPercentage
Never10253.68%
Once a year5227.37%
Twice a year2613.68%
Frequently (3+ per year)105.26%
Total190100%

Distribution of Respondents According to Frequency of Training Attendance

Among respondents, 53.68% (102) had never attended training. This demonstrates low participation in regular cybersecurity training.

Aware of PolicyFrequencyPercentage
Yes8544.74%
No10555.26%
Total190100%

Awareness of Existing Cybersecurity Policy in the Institution

A majority, 105 respondents (55.26%), reported not being aware of the institution’s cybersecurity policy.

Familiarity LevelFrequencyPercentage
Not Familiar / Never heard10555.26%
Slightly Familiar4423.16%
Familiar3618.95%
Very Familiar52.63%
Total190100%

Familiarity with Existing Cybersecurity Policy in the Institution

The majority of respondents (105, 55.26%) were not familiar with the policy.

StatementWMInterpretation
1. I have prior knowledge about cyberattacks.3.01Neutral
2. I have sufficient information about cybersecurity policies and procedures.3.10Neutral
3. My organization practiced multi-factor authentication.2.83Neutral
4. My office device is connected to the internet.4.37Strongly Agree
5. I know whether my device has an enabled firewall.2.65Neutral
6. I know how to check if my device has an updated anti-virus.2.72Neutral
7. I am the only person who has access to passwords for my work-related accounts.3.17Neutral
8. I use different passwords for everything that requires a password.3.09Neutral
9. I only open email attachments from trusted or verified sources.3.67Agree
Overall Composite Mean3.29Moderate

Weighted Mean for Cybersecurity Knowledge of BTECH Employees

The overall composite mean for knowledge was 3.29 (moderate). Respondents demonstrated high awareness of general practices but remained neutral on technical aspects like firewalls and antivirus updates.

StatementWMInterpretation
1. I feel confident handling cybersecurity threats.3.17Neutral
2. I am open to attending cybersecurity training programs.3.87Agree
3. Cybersecurity training is important for my job.3.81Agree
4. I need training on identifying phishing emails and messages.4.07Agree
5. I need training on how to prevent malware infections.3.94Agree
6. I need training on how to respond to ransomware attacks.4.00Agree
7. I need training on creating and managing strong passwords.4.02Agree
8. I need training on protecting personal and institutional data.4.16Agree
9. I need training on safe internet and email usage.3.88Agree
10. I think regular training can reduce successful cyberattacks.3.89Agree
Overall Composite Mean3.88High

Weighted Mean for Cybersecurity Skills of BTECH Employees

The composite mean for skills was 3.88 (high). Respondents expressed strong recognition of the need for training.

StatementWMInterpretation
1. Management responsibility to ensure organization is protected.3.99Agree
2. Existing computer systems already provide enough protection.3.32Neutral
3. IT security is a priority within my organization.3.33Neutral
4. Reporting a cyberattack is a responsibility of every employee.4.15Agree
5. I am confident that I would be able to spot signs of a cyberattack.3.23Neutral
6. I can help protect my organization from cyberattacks.3.50Agree
7. Cybercriminals may be more knowledgeable than people protecting us.3.02Neutral
8. Cybercriminals only target a company for financial gain.3.23Neutral
9. Cybersecurity is a public safety issue.3.64Agree
10. Mistakes or violations are disciplined or penalized.3.28Neutral
Overall Composite Mean3.47Moderate

Cybersecurity Attitude of BTECH Employees

The overall composite mean for attitude was 3.47 (moderate). Respondents showed a positive attitude regarding shared responsibility.

DimensionOverall MeanInterpretation
Knowledge3.29Moderate Level
Skills3.88High Level
Attitude3.47Moderate Level
Grand Weighted Mean3.55Moderate Awareness

Overall Cybersecurity Awareness Summary

The grand mean was 3.55 (moderate). Skills ranked highest, followed by attitude and knowledge.

SexNMeanSDt-valuedfp-valueDecision
Male853.2840.474-0.1421880.887Fail to Reject H 0
Female1053.2930.474

T-Test comparing Awareness based on Sex

There was no significant difference in cybersecurity awareness based on sex ( p = 0.887 ).

Nature of WorkNMeanSDt-valuedfp-valueDecision
Teaching1523.3110.4651.3001880.195Fail to Reject H 0
Non-Teaching383.2000.498

T-Test Comparing Awareness between Teaching and Non-Teaching Employees

Awareness is consistent across teaching and non-teaching employees ( p = 0.195 ).

Employment StatusNMeanSDt-valuedfp-valueDecision
Permanent853.2620.497-0.6971880.486Fail to Reject H 0
Part-Time1053.3100.453

T-Test Comparing Awareness between Permanent and Part-Time Employees

Employment status does not significantly influence cybersecurity awareness ( p = 0.486 ).

Age GroupNMeanSDF/p-valueDecision
21-30303.200.481.26Fail to Reject H 0
31-40663.330.49(p=0.287)
41-50693.300.48
51-60173.390.26
61 and above83.010.57

One-Way ANOVA across Different Age Groups

No significant differences in cybersecurity awareness among different age groups ( p = 0.287 ).

PositionNMeanSDF/p-valueDecision
Head Office72.970.604.08Reject H 0
Program Director32.830.42(p=0.008)
Administrative413.160.43
Faculty1393.350.47

One-Way ANOVA Comparing Awareness across Different Positions

There is a significant difference in cybersecurity awareness based on employees’ positions ( p = 0.008 ).

Length of ServiceNMeanSDF/p-valueDecision
< 1 year43.530.421.15Fail to Reject H 0
1-2 years253.330.37(p=0.331)
3-4 years713.160.56
5+ years903.290.45

One-Way ANOVA based on Length of Service

No significant difference in awareness based on length of service ( p = 0.331 ).

VariablesKnowledgeSkillsAttitudeAwareness
Knowledge1.0000.58**0.61**0.62**
Skills0.58**1.0000.66**0.74**
Attitude0.61**0.66**1.0000.68**
Awareness0.62**0.74**0.68**1.000

Correlation Matrix (Relationship among Knowledge, Skills, Attitude, and Awareness)

Correlation analysis indicated a significant positive relationship between overall cybersecurity awareness and each dimension. Skills showed the strongest association with overall awareness.

The study employs the Unified Learning Model (ULM) and Protection Motivation Theory (PMT) to interpret findings. It reveals that awareness is more significantly shaped by common institutional experiences than by demographic factors. Differences between job positions highlight that role impacts exposure to cybersecurity tasks. The findings underscore the necessity for structured and ongoing training programs that enhance knowledge, skills, and attitudes effectively.

Conclusion

A moderate level of cybersecurity awareness among BTECH employees was revealed in this study. While employees generally demonstrate positive attitudes toward cybersecurity practices, there are still gaps in their knowledge and skills that may increase susceptibility to cyberthreats.

Furthermore, the significant relationship among knowledge, skills, attitude, and overall cybersecurity awareness emphasizes the importance of strengthening these factors to enhance employees’ preparedness. Additionally, the relationship between these dimensions confirms that cybersecurity awareness is multidimensional. The results also suggested a significant knowledge gap regarding training and policies, as the majority had never had formal training and were unfamiliar with institutional guidelines.

Given these findings, to enhance employees’ cybersecurity awareness and promote responsible digital behavior, this study proposes a structured cybersecurity training program. This program can contribute to the improvement of the institution’s cybersecurity posture and minimize risks associated with cyberattacks. This highlights the need for making policies more accessible and providing structured training to address the knowledge gap.

This study is limited to employees of a single institution, which may restrict the generalizability of the findings. Future studies may explore additional factors influencing cybersecurity awareness and assess the effectiveness of proposed training programs within the organization.

The researchers would like to express their sincere gratitude to all the individuals who contributed to the successful completion of this research study.

First and foremost, the researchers extend their deepest appreciation to their research adviser, Mr. Jared P. Manalastas, LPT, MAED, for his guidance throughout the conduct of this study.

The researchers also express their heartfelt gratitude to Dr. Ma. Socorro N. Bartolom, DBA, CPA, Dean of the Institute of Business and Accountancy, for sharing her expertise to the researchers for the development of this study.

Sincere appreciation is also extended to Prof. Al-Lawrence G. Cruz, Vice President for Administration and Finance; Ms. Aida S. Ramos, Ed.D., Vice President for Academic Affairs and Research; Ms. Reina Rodie Lyn Cruz, LPT, Ms. Danica G. Camarino, Mr. John Nicole S. Vizcarra, and Atty. Marynelle A. Salinas-De Jesus, for their assistance in facilitating the dissemination of the survey questionnaires to the respondents of the study.

The researchers would also like to thank Mr. Renz Allan V. Canlas, MIT, for generously sharing his knowledge in information technology, which greatly contributed to this research.

Special thanks are extended to Ms. Ma. Niña I. Adriano, MPA, MALLE, for her significant assistance and valuable contributions that greatly helped in the completion of this study.

Heartfelt gratitude is also extended to Ms. Angelica F. Cando and Ms. Jonabeth B. Ingaran for their assistance that greatly contributed to the success of this study.

Sincere appreciation is given to Mr. Jhed Ting for the generous financial support extended throughout the conduct of this study.

The researchers likewise express their sincere appreciation to the teaching and non-teaching employees of BTECH for their voluntary participation and meaningful contribution to the successful completion of this research.

Above all, the researchers offer their deepest gratitude to God Almighty for granting them wisdom, strength, and guidance throughout the entire research process.

References

55 Cites in Article
  1. A. Abubakar,H. Elrehail,M. Alatailat,A. Elçi (2019). Knowledge management, innovation, and organizational performance: A study of SMEs in developing countries.
  2. R. AlKuwari (2024). Enhancing cybersecurity awareness training for mitigating humaninduced cybersecurity breaches.
  3. M. Alenzi,M. Rusho (2024). A field study on the impact of the level of knowledge of Human Resources employees about the principles and applications of cybersecurity on Human Resources laws.
  4. M. Anog (2024). Examining teacher retention through the lens of job satisfaction and school commitment in a private school in Cebu, Philippines.
  5. D. Asido (2024). Ifugao State U taps DICT, Meta to retake FB page from hackers.
  6. M. Camlian,J. Baron (2025). Workplace health and safety, social support, and turnover intention in private higher education institutions in the Philippines.
  7. J. Creswell,J. Creswell (2018). Research design: Qualitative, quantitative, and mixed methods approach.
  8. A. Clubb,J. Hinkle (2015). Protection motivation theory as a theoretical framework for understanding the use of protective measures.
  9. (2025). DepEd Ilocos Norte data breach exposes 3 million records.
  10. (2020). DepEd Order No. 018, s. 2020: Policy guidelines for the provision of learning resources in the implementation of the basic education learning continuity plan.
  11. S. Egelman,E. Peer (2015). Scaling the security wall: Developing a security behavior intentions scale (SeBIS).
  12. (2022). Cybersecurity threats for social media platforms.
  13. Ernest Nonum,Oghenetega Avwokuruaye,Aliyu Umar (2025). Social Engineering: Understanding Human Factors In Cyber Security.
  14. (2021). Facebook data breach exposes 533 million users.
  15. M. Gil (2024). Romblon State U assesses data breach after website hacking.
  16. L. Hadlington (2017). Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours.
  17. L. Hadlington (2018). Employees’ attitudes towards cybersecurity and risky online behaviours: An empirical assessment in the United Kingdom.
  18. J. Ho,A. Miller,L. Zhang (2025). Cybersecurity knowledge and human error in organizational data breaches.
  19. (2025). Cybersecurity trends and breach prevention report.
  20. (2025). Univ takes proactive steps to bolster data privacy, and kicks-off manual development.
  21. (2024). University personnel trained on cybersecurity in DICT workshop [News release].
  22. (2024). Manila PIO takes on PLM announcements as the university's Facebook gets hacked.
  23. (2024). PLM Facebook page hacked, renamed by attackers.
  24. (2025). The 21st century ICTbased skills and pedagogical practices of public elementary school teachers in Cotabato Province.
  25. (2023). Cybersecurity leadership and organizational support guidelines.
  26. Kathryn Parsons,Agata McCormac,Malcolm Pattinson,Marcus Butavicius,Cate Jerram (2015). The design of phishing studies: Challenges for researchers.
  27. R. Kaur,P. Singh (2022). Data privacy and access control vulnerabilities in social media platforms: A study on Facebook.
  28. H. A. Kruger,W. D. Kearney (2005). A prototype for assessing information security awareness.
  29. J. E. Maddux,R. W. Rogers (1983). Protection motivation and self-efficacy: A revised theory of fear appeals and attitude change.
  30. R. Martínez-Peláez,P. Velarde-Alvarado,V. G. Félix,A. Ochoa-Brust,R. Ostos,L. J. Mena (2024). Assessing employee susceptibility to cybersecurity risks.
  31. J. Nash (2022). Cyberattacks on critical infrastructure: Lessons from recent incidents.
  32. (2003). Building an information technology security awareness and training program (SP 800-50).
  33. (2021). NPC validation of compromised Facebook accounts in the Philippines.
  34. (2022). Annual report on personal data protection and breaches in the education sector.
  35. (2024). Breach notification report 2022–2024: Trends and causes across sectors.
  36. (2025). Annual security incident reporting (ASIR) and data breach causes.
  37. T. W. H. Ng,D. C. Feldman (2010). The relationships of age with job attitudes: A metaanalysis.
  38. K. Parsons,A. McCormac,M. Butavicius,M. Pattinson,C. Jerram (2017). Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q).
  39. J. Peters (2023). Human error is responsible for 74 % of data breaches.
  40. (2024). DICT probes possible hacking of DepEd office.
  41. (2024). PLM’s Facebook page was hacked.
  42. J. Prümmer (2024). Cybersecurity threats in educational institutions: Challenges and mitigation strategies.
  43. F. J. A. Pugong (2025). Assessing information security awareness for a tailored intervention program: A study of employees at Ifugao State University, Cordillera Administrative Region, Philippines.
  44. P. Puhakainen,M. Siponen (2020). Improving employees’ compliance through information systems security training: An action research study.
  45. S. P. Robbins,T. A. Judge (2017). Organizational behavior.
  46. R. W. Rogers (1975). A protection motivation theory of fear appeals and attitude change.
  47. (2024). Bid bulletin: Clarification No. 3 — RSU-2024-10-088 Development of Smart Campus Data Security and Cyberattack Prevention Hub RSU.
  48. R. Roy,J. J. Francis (2023). The impact of cybercrime awareness training among employees in corporations for better information management.
  49. H. F. Sapanca (2022). Risk management in digitalized educational environments.
  50. B. Schneier (2025). Data and Goliath: The hidden battles to collect your data and control your world.
  51. R. Shillair (2020). Protection motivation theory.
  52. M. Souppaya,K. Scarfone (2016). User's Guide to Telework and Bring Your Own Device (BYOD) Security.
  53. H. Taherdoost (2024). Impact of employee cybersecurity awareness on security incidents.
  54. D. L. D. Tomas (2024). University personnel trained on cybersecurity in DICT workshop.
  55. M. Wilson,J. Hash (2003). Building an information technology security awareness and training program (NIST Special Publication 800-50).

Funding

No external funding was declared for this work.

Conflict of Interest

The authors declare no conflict of interest.

Ethical Approval

No ethics committee approval was required for this article type.

Data Availability

Not applicable for this article.

How to Cite This Article

Dr. Joseph L. Atayde, Katherine V. Caballero, Marielyn C. Icawat, Jhon Michael D. Mariano, Roel Mark R. Tagaan, Mary Jane M. Toribio. 2026. "Level of Cybersecurity Awareness of Btech Employees: Basis for Proposing Cybersecurity Training". Global Journal of Computer Science and Technology - G: Interdisciplinary GJCST-G Volume 26 (GJCST Volume 26 Issue G1).

Download Citation

Journal Specifications

Crossref Journal DOI 10.17406/gjcst

Print ISSN 0975-4350

e-ISSN 0975-4172

Keywords
Classification
ACM K.6.5
ACM K.3.2
arXiv cs.CR
arXiv cs.CY
DDC 005.8
Version of record

v1.2

Issue date
July 10, 2026

Language
English
Experiance in AR

Explore published articles in an immersive Augmented Reality environment. Our platform converts research papers into interactive 3D books, allowing readers to view and interact with content using AR and VR compatible devices.

Read in 3D

Your published article is automatically converted into a realistic 3D book. Flip through pages and read research papers in a more engaging and interactive format.

Article Matrices
Total Views: 87
Total Downloads: 2
All Trends

Request Access

Please fill out the form below to request access to this research paper. Your request will be reviewed by the editorial or author team.
X

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

High-quality academic research articles on global topics and journals.

Level of Cybersecurity Awareness of Btech Employees: Basis for Proposing Cybersecurity Training

Joseph L. Atayde
Joseph L. Atayde Institute of Business and Accountancy
Katherine V. Caballero
Katherine V. Caballero Institute of Business and Accountancy
Marielyn C. Icawat
Marielyn C. Icawat Institute of Business and Accountancy
Jhon Michael D. Mariano
Jhon Michael D. Mariano Institute of Business and Accountancy
Roel Mark R. Tagaan
Roel Mark R. Tagaan Institute of Business and Accountancy
Mary Jane M. Toribio
Mary Jane M. Toribio Institute of Business and Accountancy