The increasing reliance on digital systems in higher learning institutions has introduced significant information security challenges, particularly those associated with human behavior. This study examines the disconnect between information systems security awareness and actual user practices, conceptualized as the awareness–behavior gap. While many institutions invest in technical safeguards, limited attention is often given to how users interact with these systems in practice. This study adopts a mixed-methods case study approach, guided by the Theory of Planned Behavior (TPB) and the Knowledge–Attitude–Behavior (KAB) model, to explore how awareness translates into real-world security actions.
Data were collected from 65 staff members using structured questionnaires and key informant interviews, alongside a technical vulnerability assessment conducted using OWASP ZAP. The findings reveal a moderate level of awareness (70%), with most participants demonstrating positive attitudes toward information security. However, secure practices were inconsistent, indicating a clear gap between knowledge and behavior. Notably, 66.2% of respondents had not received formal training, and only 33.8% were aware of institutional security policies. The system assessment further revealed vulnerabilities such as application error disclosures and internal IP leakage.
The study concludes that awareness alone does not ensure secure behavior. Instead, effective information security requires a combination of user training, policy enforcement, and technical safeguards. The findings contribute to the understanding of human-centered cybersecurity in resource-constrained environments and offer practical insights for improving security resilience in higher learning institutions.