๐Ÿ“Š Overview โ€” Cybersecurity Training & Policy

196 Respondents ยท 134 Rated Training
๐Ÿ” Survey Context: 196 respondents participated. Training satisfaction used a 4-point qualitative scale (Strongly Agree=4 down to Strongly Disagree=1). Policy compliance captured via Yes/No readings of the Acceptable Use Policy and AI Policy. Risk and topic data reflect multi-select responses.
134
Rated IT Security Training
Of 196 respondents
83.6%
Training Satisfaction โ‰ฅ3
Agree or Strongly Agree
3.10
Training Avg Score
Out of 4.0
87.7%
Read Acceptable Use Policy
100 of 114 who answered
59.1%
Read AI Policy
78 of 132 who answered
114
Top Risk: Phishing
Highest risk response count

โœ… Key Insights

  • Phishing and social engineering are the top-ranked cybersecurity concern: This category received 114 responses, making it the highest-ranked risk and suggesting that credential theft, impersonation, and user-targeted deception remain the dominant perceived threat.
  • Accidental disclosure of sensitive data is nearly as prominent: With 104 responses, this result shows strong concern that data may be exposed unintentionally through email, cloud storage, or file-sharing behavior, pointing to the importance of secure handling practices and clear data governance.
  • Malware and ransomware continue to be major risk concerns: This category received 62 responses and remains one of the most visible traditional cybersecurity threat areas.
  • Learning demand is strongest around practical data and cyber-hygiene topics: The highest-demand cybersecurity learning topics were Cloud Storage (61), Recent Cyberattacks (48), and Public Wi-Fi (38), followed by IoT (33), Phishing (32), and Anti-Malware Software (31).
  • Not all respondents feel underinformed: A notable 43 respondents selected "I have all the information I need," indicating that current communications or training are working for at least part of the audience.
  • Training satisfaction is strong: 83.6% of rated respondents agreed or strongly agreed that annual IT security training is useful, with an average score of 3.10 out of 4.0.

โš ๏ธ Areas of Concern

  • Users still associate cyber risk with training gaps and avoidable behaviors: Insufficient security awareness or training received 44 responses, while open-ended answers highlighted users working on personal computers, leaving computers unlocked, texting PPI, and using third-party cloud storage.
  • AI Policy awareness significantly lags: Only 59.1% have read the AI Policy compared to 87.7% for the Acceptable Use Policy โ€” a 28.6 percentage-point gap. Awareness campaigns specifically targeting the AI Policy are warranted.
  • Outdated systems and unapproved software/AI tools are tied concerns: Each received 40 responses (tied for 5th), reflecting worry about unpatched vulnerabilities and shadow IT.
  • 6 respondents have never accessed annual IT security training: Reasons given include not receiving a notification, being new to the university, and administrative circumstances.
  • Weak or re-used passwords remain a concern: 23 respondents flagged weak passwords leading to account compromise, and third-party vendor or supply chain breaches drew 21 responses.

๐Ÿ“ก Training Satisfaction Distribution

๐Ÿ“‹ Policy Compliance โ€” AUP vs AI Policy

โš ๏ธ Top Perceived Cybersecurity Risks โ€” All Responses

๐Ÿ“š Training Topics of Interest โ€” All Responses

โ“ Reasons Given for Not Accessing Annual IT Security Training

  • ๐Ÿ“ฉ I have not received a notification to take the training. (mentioned twice)
  • ๐Ÿ†• I have worked at the university less than a year.
  • ๐Ÿ’ผ Administrative staff โ€” other reason
  • โ“ "Not sure" / N/A
โš ๏ธ Gap Identified: The AI Policy has a significantly lower read rate (59.09%) vs. the Acceptable Use Policy (87.72%) โ€” a 28.6 percentage-point gap. Awareness campaigns specifically targeting the AI Policy are warranted.

โš ๏ธ Group 1 โ€” Perceived Cybersecurity Risks

Multi-Select ยท Top 3 Choices ยท 9 Risk Categories + Other
What this group measures: Respondents selected what they consider the three most serious cybersecurity risks to themselves and the university. Results reflect total selection count across all respondents โ€” higher counts indicate wider perceived severity.
114
๐Ÿฅ‡ Phishing / Social Engineering
Most selected risk
104
๐Ÿฅˆ Accidental Data Disclosure
Email / cloud / file sharing
62
๐Ÿฅ‰ Malware / Ransomware
Third highest
40
Outdated / Unpatched Systems
Tied 4th
40
Unapproved Software & AI
Tied 4th
21
Lowest: Supply Chain
Third-party vendor breaches

๐Ÿ“‹ Cybersecurity Risk Rankings โ€” Full Table

Rank Risk Category Responses Severity Tag Response Bar
1Phishing / Social Engineering114HIGH
2Accidental Disclosure (Email/Cloud/File Sharing)104HIGH
3Malware or Ransomware62HIGH
4Insufficient Security Awareness / Training44MED
5Outdated / Unpatched Software Vulnerabilities40MED
5Use of Unapproved / Insecure Software & AI40MED
7Weak / Re-used Passwords23LOW
8Third-Party / Supply Chain Breaches21LOW
9Other4LOW

๐Ÿ“š Group 2 โ€” Cybersecurity Learning Interests

Multi-Select ยท 11 Topics + "I have all the information I need"
What this group measures: Topics respondents want to learn more about. High counts indicate unmet training demand. The "I have all the information I need" option (43 responses) serves as a baseline satisfaction indicator.
โœ… Note: 43 respondents (22% of those who engaged with this question) indicated they already have sufficient cybersecurity knowledge โ€” a healthy baseline. However, the high interest in Cloud Storage (61) and Recent Cyberattacks (48) points to clear curriculum opportunities.
61
๐Ÿฅ‡ Cloud Storage
Highest demand topic
48
๐Ÿฅˆ Recent Cyberattacks
Second highest
43
Already Informed
"I have all info I need"
38
Public Wi-Fi
Third highest demand
33
IoT Security
Growing interest
16
Lowest: Passwords/Auth
May already feel informed

๐Ÿ“š Topic Interest โ€” Response Count (Ranked)

๐Ÿ“‹ Learning Interest Rankings โ€” Full Table

Rank Topic Responses Priority Interest Bar
1Cloud Storage61HIGH
2Recent Cyberattacks48HIGH
โ€”I have all the information I need43SATISFIED
3Public (Non-UT) Wi-Fi38MED-HIGH
4IoT (Internet of Things)33MED-HIGH
5Phishing32MED-HIGH
6Anti-Malware Software31MED-HIGH
7Ransomware25MEDIUM
7Personally Identifiable Information (PII)25MEDIUM
9Social Engineering24MEDIUM
10Reporting Security Concerns23MEDIUM
11Passwords and Authentication16LOW

๐Ÿ† Overall Rankings & Summary

Training ยท Policy Compliance ยท Risk Perception ยท Learning Demand

๐Ÿ“‹ Master Summary Table โ€” All Metrics

Group Metric Score / Count # โ‰ฅ3 or Yes # <3 or No % Positive Status
Training & Policy Annual IT Security Training 3.10 / 4.0 112 16 83.58% GOOD
Training & Policy Read Acceptable Use Policy โ€” 100 14 87.72% GOOD
Training & Policy Read AI Policy โ€” 78 54 59.09% โš ๏ธ GAP
Risks Top Risk: Phishing/Social Engineering 114 selections โ€”โ€” โ€” HIGH RISK
Risks 2nd Risk: Accidental Data Disclosure 104 selections โ€”โ€” โ€” HIGH RISK
Learning Top Topic: Cloud Storage 61 interested โ€”โ€” โ€” HIGH DEMAND
Learning 2nd Topic: Recent Cyberattacks 48 interested โ€”โ€” โ€” HIGH DEMAND
โš ๏ธ Top 3 Action Items: (1) Close the 28.6-point AI Policy awareness gap โ€” only 59% have read it vs. 88% for AUP. (2) Prioritize Phishing and Accidental Disclosure training โ€” these are the top two self-reported risks. (3) Develop Cloud Storage and Recent Cyberattacks content โ€” highest unmet learning demand.
Jul 21, 2026