Back to all projects
Computer Science

CYBERSECURITY AWARENESS AND THREAT PERCEPTION AMONG NIGERIAN UNIVERSITY STUDENTS

Admin 0 views 0 downloadsBSc/BA

Notice: This is a sample project for study and reference. Submitting it as your own work violates most universities' academic integrity policies.

Abstract

About This Research Topic

Nigerian universities are undergoing rapid digital transformation. Learning management systems, institutional portals, digital libraries, and mobile financial services now mediate almost every aspect of student life. While this connectivity expands educational opportunity, it also exposes students to an evolving landscape of cyber threats. Recent studies on information security behaviour in higher education show that undergraduates are frequently targeted because they combine high digital activity with limited formal security training. This article re-examines the original undergraduate project on Cybersecurity Awareness and Threat Perception Among Nigerian University Students, presenting a rewritten, expanded, and SEO-optimized academic discussion that retains the original objectives while deepening its analytical value. We synthesize findings from a survey of 368 students across three Nigerian universities to provide a clear diagnostic baseline for institutional intervention. Understanding where awareness is strong, where it is uneven, and where institutional communication fails is critical for protecting both students and university networks.

Main Abstract

University students constitute a high-exposure, high-interest group for cybersecurity research. They are intensive users of email, social media, cloud collaboration tools, and institutional information systems, yet unless enrolled in Computer Science or allied programmes, they rarely receive structured information security education. This gap between digital exposure and security competence increases vulnerability to phishing, social engineering, password compromise, and malware. This study assessed cybersecurity awareness and threat perception among undergraduate students in Nigerian universities and examined how academic and demographic factors relate to awareness levels. Using a descriptive cross-sectional survey design, a structured 28-item questionnaire measured four constructs: general cybersecurity awareness, phishing and social engineering threat perception, password and account security practices, and institutional and policy awareness. The instrument used a five-point Likert scale and was administered to a stratified random sample of 400 undergraduates drawn from Computer Science and non-Computer Science departments across three universities. After data cleaning, 368 valid responses were retained (92% response rate). Internal consistency was good (Cronbach’s alpha = 0.84). Descriptive results indicated a moderate overall awareness mean of 3.42 out of 5 (SD = 0.61). Password and account security practice recorded the highest construct mean (3.71), while institutional and policy awareness recorded the lowest (2.89). Inferential analysis showed Computer Science students scored significantly higher than non-Computer Science students (t(366) = 5.87, p < 0.001). Academic level had a significant effect (F(3, 364) = 4.21, p = 0.006), with final-year students outperforming first-year students. Prior self-reported exposure to phishing or social engineering attempts was positively correlated with overall awareness (r = 0.31, p < 0.001). The findings confirm moderate but uneven awareness, with institutional policy communication emerging as a critical weakness. The study recommends mandatory, recurring cybersecurity awareness training embedded in general orientation rather than confined to technical curricula.

Chapter One Preview

Background to the Study

The proliferation of affordable smartphones, campus Wi-Fi, and cheap data bundles has placed Nigerian university students at the centre of Nigeria’s digital economy. According to the U.S. Cybersecurity and Infrastructure Security Agency, human error remains the leading enabler of successful cyber attacks, a pattern replicated in educational environments. Students routinely access sensitive portals using personal devices that may lack updated antivirus protection, reuse institutional passwords on external sites, and click links embedded in unsolicited messages promising scholarships, internship placements, or examination results. Attackers craft academically themed lures precisely because they are contextually credible.

Globally, the literature describes university students as paradoxical actors: digitally fluent but security-inexperienced. They demonstrate high confidence in navigating applications yet underperform on threat identification tasks. Studies grounded in Protection Motivation Theory and the Knowledge-Attitude-Behaviour model show that perceived vulnerability and perceived severity do not automatically translate into secure behaviour unless reinforced by concrete procedural knowledge. In Nigeria, where institutional cybersecurity policies are often nascent or poorly disseminated, this disconnect is amplified. While Computer Science curricula may cover cryptography, network security, or ethical hacking, students in Education, Management Sciences, Arts, and Social Sciences may complete a four-year degree without a single module dedicated to information security hygiene.

This study therefore positions cybersecurity awareness not merely as individual competence but as an institutional responsibility. Awareness encompasses knowledge of threats, recognition of attack indicators, understanding of protective actions, and familiarity with institutional reporting mechanisms. By measuring awareness across four distinct constructs, the research avoids a monolithic score and instead reveals construct-level gaps. For related discussions on technology adoption in academic settings, see our analysis on digital literacy challenges in Nigerian tertiary institutions and computer science research project topics on information security

Statement of the Problem

Despite growing exposure to cyber threats, empirical evidence on cybersecurity awareness among Nigerian university students remains fragmented and often limited to single-institution convenience samples. Several specific problems justify this investigation:

1. Targeted Threat Landscape: Nigerian students are increasingly exposed to academically themed phishing, business email compromise, and scholarship scams, yet the extent of their threat perception has not been robustly quantified across multiple institutions.

2. Curricular Inequality: Where cybersecurity training exists, it is concentrated within Computer Science and related departments. This creates a structural inequality where non-technical students face identical threat exposure without equivalent preparation.

3. Untested Predictors: Assumptions that year of study, discipline, or prior attack exposure automatically confer higher awareness have not been systematically tested in the Nigerian university context.

4. Policy Communication Gap: Even when universities have acceptable use policies and incident response procedures, students often report no awareness of such documents or channels.

5. Intervention Design Deficit: Without baseline data disaggregated by discipline and level, ICT units lack evidence to prioritize, sequence, and tailor awareness programmes.

Aim and Objectives of the Study

Aim:
To investigate the level of cybersecurity awareness and threat perception among undergraduate students at Nigerian universities and examine its relationship with selected demographic and academic factors.

Specific Objectives:
1. To review existing literature and survey instruments on cybersecurity awareness among students and general populations.
2. To design and validate a structured questionnaire measuring four constructs: general awareness, phishing and social engineering threat perception, password and account security practice, and institutional and policy awareness.
3. To administer the instrument to a stratified random sample of students across Computer Science and non-Computer Science departments in three Nigerian universities.
4. To determine overall and construct-level cybersecurity awareness levels.
5. To examine whether academic discipline, year of study, and prior exposure to phishing or social engineering attempts are significantly associated with overall awareness scores.
6. To provide evidence-based recommendations for targeted cybersecurity awareness interventions.

Research Questions

1. What is the overall level of cybersecurity awareness among the surveyed Nigerian university student population?
2. How does awareness vary across the four measured constructs: general awareness, phishing and social engineering threat perception, password and account security practice, and institutional policy awareness?
3. Is there a significant difference in overall awareness scores between Computer Science and non-Computer Science students?
4. Is there a significant difference in overall awareness scores across academic levels (year of study)?
5. Is there a significant relationship between prior exposure to a phishing or social engineering attempt and overall awareness scores?

Research Hypotheses

Tested at 0.05 significance level:
H01: There is no statistically significant difference in overall cybersecurity awareness score between Computer Science and non-Computer Science students.
H02: There is no statistically significant difference in overall cybersecurity awareness score across year of study.
H03: There is no statistically significant relationship between prior exposure to a phishing or social engineering attempt and overall cybersecurity awareness score.

Significance of the Study

This study offers practical and theoretical contributions. For university administrations and ICT security teams, it provides a transparent, replicable baseline to guide resource allocation for awareness campaigns. Identifying that institutional policy awareness scored lowest (2.89) signals that improving communication may yield greater returns than repeating generic password advice. For students in non-Computer Science disciplines, the evidence supports equity-focused training. For researchers, the study adds a multi-institution Nigerian dataset to a literature dominated by North American and European corporate samples. For regulators such as the National Universities Commission, findings support arguments for integrating baseline cybersecurity literacy into general studies curricula. Explore related work on undergraduate project topics on ICT security awareness for comparative methodological approaches.

Scope of the Study

The study is delimited to undergraduate students at three Nigerian universities, selected to reflect variation in ownership structure and geographic location. It relies on self-reported awareness and attitudes measured through a 28-item questionnaire and does not include postgraduate students, academic staff, or non-academic staff. The research does not incorporate a behavioural experiment such as a simulated phishing campaign to measure actual click-through susceptibility. Such behavioural validation is recommended for future research to complement self-report data and mitigate social desirability bias.

Operational Definition of Terms

Cybersecurity Awareness: An individual’s knowledge of and attentiveness to information security risks, threats, and appropriate protective behaviours, as measured by the questionnaire score. The National Institute of Standards and Technology defines awareness as activities that focus attention on security.

Threat Perception: An individual’s subjective assessment of the likelihood and severity of encountering a cybersecurity threat, influencing motivation to adopt protective behaviours.

Phishing: A social engineering technique using deceptive electronic communications to induce disclosure of credentials or execution of malicious content.

Social Engineering: Psychological manipulation of individuals into performing actions or divulging confidential information that compromises security.

Construct: A thematic sub-domain within the measurement instrument comprising related items.

Likert Scale: An ordinal psychometric scale measuring degree of agreement, in this study five-point from Strongly Agree to Strongly Disagree.

Cronbach’s Alpha: A coefficient of internal consistency reliability, where values above 0.70 generally indicate acceptable reliability.

NIST definition of security awareness | CISA guidance on phishing and social engineering | US-CERT advice on password security

Conclusion

The survey of 368 Nigerian undergraduates confirms a moderate overall cybersecurity awareness level (M = 3.42/5) that masks significant unevenness across constructs and subgroups. Students exhibit relatively stronger confidence in password and account practices but markedly weaker awareness of institutional cybersecurity policies and reporting mechanisms. Disciplinary affiliation and academic progression matter: Computer Science students and final-year students report higher awareness, while prior exposure to phishing attempts correlates positively with awareness, suggesting experiential learning plays a role. The critical implication is that reliance on discipline-specific coursework is insufficient. Universities should implement mandatory, recurring, institution-wide cybersecurity awareness training embedded in orientation and reinforced annually, with clear, accessible communication of policies and incident reporting channels. Future research should combine self-report measures with simulated phishing to assess the awareness-behaviour gap. For more evidence-based project guides, visit our collection of computer science project materials on Scholarnesthub

Frequently Asked Questions (FAQs)

1. What is cybersecurity awareness among university students?

Cybersecurity awareness among university students refers to their knowledge of digital threats like phishing and their ability to apply protective practices such as strong passwords and safe browsing.

2. Why are Nigerian university students vulnerable to phishing?

They are high-frequency users of academic portals and social media, often reuse passwords, and encounter academically themed scams like fake scholarships or result notifications.

3. What were the four constructs measured in this study?

General cybersecurity awareness, phishing and social engineering threat perception, password and account security practice, and institutional/policy awareness.

4. What was the overall awareness score in the Nigerian study?

The study found a moderate overall mean score of 3.42 out of 5, with password practices highest and institutional policy awareness lowest.

5. Do Computer Science students have higher cybersecurity awareness?

Yes. Computer Science students scored significantly higher than non-Computer Science students, indicating curricular exposure improves awareness.

6. Does year of study affect cybersecurity awareness?

Yes. Final-year students scored higher than first-year students, suggesting cumulative exposure and experience increase awareness over time.

7. Does prior exposure to phishing increase awareness?

The study found a positive correlation (r=0.31). Students who reported prior phishing attempts tended to have higher awareness scores.

8. What is the biggest gap in student cybersecurity knowledge?

Institutional and policy awareness. Students were least familiar with university acceptable-use policies and incident reporting channels.

9. How can universities improve cybersecurity awareness?

Through mandatory, recurring training integrated into orientation, clear policy communication, and simulated phishing exercises.

10. What methodology was used to assess cybersecurity awareness?

A validated 28-item Likert-scale questionnaire administered to 368 undergraduates across three universities, with reliability confirmed by Cronbach's alpha of 0.84.

Purchase to unlock the full material.