๐ Survey Context: 196 respondents participated. Training satisfaction used a 4-point qualitative scale (Strongly Agree=4 down to Strongly Disagree=1). Policy compliance captured via Yes/No readings of the Acceptable Use Policy and AI Policy. Risk and topic data reflect multi-select responses.
134
Rated IT Security Training
Of 196 respondents
83.6%
Training Satisfaction โฅ3
Agree or Strongly Agree
3.10
Training Avg Score
Out of 4.0
87.7%
Read Acceptable Use Policy
100 of 114 who answered
59.1%
Read AI Policy
78 of 132 who answered
114
Top Risk: Phishing
Highest risk response count
โ
Key Insights
- Phishing and social engineering are the top-ranked cybersecurity concern: This category received 114 responses, making it the highest-ranked risk and suggesting that credential theft, impersonation, and user-targeted deception remain the dominant perceived threat.
- Accidental disclosure of sensitive data is nearly as prominent: With 104 responses, this result shows strong concern that data may be exposed unintentionally through email, cloud storage, or file-sharing behavior, pointing to the importance of secure handling practices and clear data governance.
- Malware and ransomware continue to be major risk concerns: This category received 62 responses and remains one of the most visible traditional cybersecurity threat areas.
- Learning demand is strongest around practical data and cyber-hygiene topics: The highest-demand cybersecurity learning topics were Cloud Storage (61), Recent Cyberattacks (48), and Public Wi-Fi (38), followed by IoT (33), Phishing (32), and Anti-Malware Software (31).
- Not all respondents feel underinformed: A notable 43 respondents selected "I have all the information I need," indicating that current communications or training are working for at least part of the audience.
- Training satisfaction is strong: 83.6% of rated respondents agreed or strongly agreed that annual IT security training is useful, with an average score of 3.10 out of 4.0.
โ ๏ธ Areas of Concern
- Users still associate cyber risk with training gaps and avoidable behaviors: Insufficient security awareness or training received 44 responses, while open-ended answers highlighted users working on personal computers, leaving computers unlocked, texting PPI, and using third-party cloud storage.
- AI Policy awareness significantly lags: Only 59.1% have read the AI Policy compared to 87.7% for the Acceptable Use Policy โ a 28.6 percentage-point gap. Awareness campaigns specifically targeting the AI Policy are warranted.
- Outdated systems and unapproved software/AI tools are tied concerns: Each received 40 responses (tied for 5th), reflecting worry about unpatched vulnerabilities and shadow IT.
- 6 respondents have never accessed annual IT security training: Reasons given include not receiving a notification, being new to the university, and administrative circumstances.
- Weak or re-used passwords remain a concern: 23 respondents flagged weak passwords leading to account compromise, and third-party vendor or supply chain breaches drew 21 responses.
๐ก Training Satisfaction Distribution
๐ Policy Compliance โ AUP vs AI Policy
โ ๏ธ Top Perceived Cybersecurity Risks โ All Responses
๐ Training Topics of Interest โ All Responses
โ Reasons Given for Not Accessing Annual IT Security Training
- ๐ฉ I have not received a notification to take the training. (mentioned twice)
- ๐ I have worked at the university less than a year.
- ๐ผ Administrative staff โ other reason
- โ "Not sure" / N/A
โ ๏ธ Gap Identified: The AI Policy has a significantly lower read rate (59.09%) vs. the Acceptable Use Policy (87.72%) โ a 28.6 percentage-point gap. Awareness campaigns specifically targeting the AI Policy are warranted.