
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Gunita Pahwa1, Abhishek 2, Manya Kaur Chopra3, Tanya Handa4 , Yogita Thareja5
5, Assistant Professor, Vivekananda Institute of Professional Studies-TC, New Delh
Abstract - This is a digital campus, where we submit our work, pay utilities, chat with friends, and therefore, our lives are mostly conducted using personal devices. So when we, as students, are using them all the time, it makes me think: are they actually safe with that kind of dependency on them? The paper examines the level of awareness that students have regarding cybersecurity and its alignment with the actions they take to ensure their gadgets are secure.
We used a questionnaire in Google Forms, which we distributed the questionnaires. The poll inquired into the level of familiarity of respondents with phishing, malware, weak passwords, and social engineering, and examined daily habits such as password hygiene, software updates, multi-factor authentication, and reactions to suspicious emails. We did not think of awareness as a mere concept; we knew that it could, or may not, become a consistent action.
Based on those answers, we assembled a risk assessment model, which approximates the vulnerability of every device. The model combines the indicators of knowledge not only with actual actions but also with a composite score of security. It is not a crystal ball, but it makes one feel exposed, according to what we reported.
The thing that we discovered is that being able to use the buzzwords in the realm of cybersecurity is not enough to guarantee that we are practising safely. Measuring that gap, we have a clearer picture of the degree of safety of our devices and provide some recommendations on how colleges can reinforce their awareness procedures.
Keywords: Cyber security Awareness, Student Behavior, Device Security, Risk Assessment Model, Phishing and Social Engineering, Password Hygiene, Awareness–Action Gap
College life in the digital era seems to be overwhelmed by the use of technology. We post grades and lecture notes on universityservers;weareinclassesonlearningplatformsandwecommunicateviaemails,messagingapplicationsandgroup chats.Inessence,bothphonesandlaptopsareourstudyaccessoriesandourpersonaldatabanks,inmostcases,extensionsof ourpersonalselves.
Althoughthatintegrationmaybeconvenient,weareexposedtocyberthreats.
Cybersecurityconcernsarenotanimaginaryphenomenon:phishedemailslooklikethey comethroughanofficialuniversity, there are malicious links in study-group discussions, and the Wi-Fi on campus can reveal our passwords. Malware may be contained in even harmless downloads. All it is captured in the academic papers and policy discussions, but nobody knows howtobesafewithoutawarenessalone.Awarenessissometimesbelievedtobeaone-dimensionalentityofpayingattention totherisks,beingawareoftheconsequences,andattemptingtoavoidthem.
In practice, it isn’t. There are those students, who understand that having weak passwords is dangerous, but they find themselves using them again, and there are those who install antivirus software and are not in the habit of updating their operating system. Such discrepancies lead to a question: are the measures of self-reported mindfulness levels of students consistentwiththeirrealsecuritypractices?CollegeisanidealplacetoexaminethissinceweareallactiveInternetuserswho canmanageourgrades,finances,andsociallivesonlinebyusingtheInternet,butwehardlyeverapplystandardizedpolicies onusingdevicesorhavecompulsorysecuritymeasures.
Themajorityofstudiesoncybersecuritymindfulnessdwellontheeffectivenessoftrainingorknowledgeassessments.Thatis notthebestwayofdescribingtheconnectionbetweenwhatweknowandwhatwedoonaday-to-daybasis.Wemustcheck

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
whetherthepersonwhodetectsaphishingsignalisthepersonwhodoesthefollow-upastotheauthenticityoftheemail,oris it the person who knows about two-factor authentication, who has already implemented the device. This intersection is the subjectofthepresentresearch.
TheinformationwascollectedbyusingastructuredquestionnairebasedonGoogleForms,assessingthelevel ofknowledgeof thestudentsconcerningtypicalcyberpitfallsandtheirreportedprotectionbehavior.Thequestionnaireincludedquestionson learning about phishing and malware, password habits, software updates, authentication procedures and reactions to suspicious messages. We also wish that by examining the abstract cognition and habitual action, we could transcend superficialindicatorsofmindfulness.
There are, however, pitfalls of relying on self-reported data. The students may be either more vigilant or less exposed than theyare.Thereactionscouldbebasedonwhattheybelievetheyneedtodoandnotwhattheyaredoing.Althoughwecannot saythatwearetotallycorrect,aggregatepatternsmayprovideusefulinformationwhenusedwithcaution.
This paper is an implementation of a threat-assessment framework based on such survey results. The model integrates knowledge clues with behavioral variables to provide estimates of device security posture as opposed to merely indicating thatstudentsareconcerned orignorant.All responsescontributetoa compounded score,whichindicatespossibleexposure tocyberrisks.Thequalitativeunderstandingiscodedintoa systematicframework,throughwhichitispossibletoengagein relativeanalysisamongparticipants.
The model is not supposed to represent all the aspects of cyber threat; it is just an abstract tool that helps to correlate mindfulness to measurable behavior. Numerous students are digitally savvy, which does not necessarily mean that they are well-informedwithregardtotheirsecurity.Therecanbeacomfortlevelintechnologyandriskybehavior.Constantexposure tothedigitalarenamayalsocauseustogetusedtosomeofthethreatssincetheymaynolongerbeeasilydetected.Therefore, anecdotalinferencesarenotasefficientasempiricalevaluation.
Incidentsofcybersecurityinuniversitiesmayhavemorefar-reachingconsequencesaswell.Onehackedaccountwillprovide accesstotheuniversitysystems,stealsensitiveinformationorleadtothelossofmoney.Onevulnerabledevicecanbeusedto causemoredamageinaninterconnectednetwork.Althoughweareresearchingacaseofindividualstudentmindfulness,the resultsmightbeusedtodirectinstitutionalpoliciesandcybersecurityprograms.
It is rational and realistic to develop this threat-assessment model. Analytically, it allows us to investigate the association of knowledge and behavior. In practice, it marks the regions that require specific interventions. However, changing threats shouldalsobemetwithmitigationstrategies,andthemodelmustbeaccordinglychanged.
When outlining this study, we should be wary: the model is investigative, and it does not substitute rigorous testing of the vulnerabilities. It is not a conclusive measure but a calculated estimate which helps in explaining the association between perception and protection. Finally, the research question is as follows: to what extent, in practice, are students secure, consideringwhattheyknowandwhattheypurporttodo?Itiswiththeaimofilluminatingthedisparityintheawarenessand on-the-jobprotectionthatweaimtoexplorecybersecuritymindfulnessandpreventativemeasures,andestablishthelinkage ofthesetoasystematicevaluation.
We are always on phones, laptops, and tablets studying, paying bills, and being in contact with friends. Such devices store confidentialdataandarecommonlyconnectedtotheopenWi-Fi,whichisnotnecessarilysecure.However,wedonotactually knowtheextenttowhichweactuallyknowaboutcybersecurity.
The conversations frequently emphasize the fact that since we spend a lot of time on the Internet, we should be good at recognizing cyber threats. That might be overblown. Being aware of such words as phishing or the necessity to use a strong password does not mean that you will not fall into awkward links or use the same password on multiple accounts. These trendsindicatethattheremayexistanactualdisparitybetweenwhatisknownandwhatisactuallyfollowed.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
A high number of university outreach efforts disseminate information and posters about cyber safety and pay minimal attentiontowhetherstudentsaltertheirbehaviors.Thisleavesuswithafewindicatorsthatstudentsactuallyunderstandhow todefendthemselvesandwhethertheyareactuallyindanger.
It is not just a matter of knowing whether we are conscious of the threat that is at stake, but also of how this knowledge is applied to how safe our devices are. To the extent that we have no good means to view how knowledge is transformed into action,wecanonlyobtainasuperficialratherthanaprofoundviewofthesituation.
The proposed paper attempts to address this issue by exploring cybersecurity awareness among students in colleges and a basicmodelofriskassessment.Themodelreliesonself-reportedhabitstogetanestimationofhowsusceptibleeachstudent canbetoadevice
In this study, we have a series of objectives that we wish to transcend beyond mere observations. We would like to explore furtherourrealthinkingoncybersecurityoncampus.Thesegoalsarestatedasfollows:
Todeterminetheextentof ourknowledgeof cybersecurity.Wewillevaluateourunderstandingofthemostcommonthreats ontheinternet,suchasphishing,malware,etc.
Toinvestigatethesafetyhabitsthatweapplyinourdailylivesonline. Thatincludessuchaspectsaspasswordmanagement, softwareupdatesandourresponsetosuspiciousmessages.Thesepracticesdemonstratehowattentiveweareregardingour gadgets.
To identify discrepancies between what we know and what we really do. In essence, are we as aware of the theoretical and practicalactivitiesofprotectionoraretherediscrepanciesbetweenwhatweknowandwhatweareactuallydoing?
Tocreateaninitialriskassessmentframeworkwiththehelpofthesurvey.Themodelbringstogetherwhatweknowandwhat weactuallydo,projectingapossiblelevelofriskinessofourdevices.Wearenottargetingaccuracyinourpredictions;we just wanttohaveaclearandstructuredideaofthelevelofsecurityinourdevices.
Tocontributevaluableinformationthatcanenablecollegestotightentheirfocusonawarenessprograms.
Allinall,theseobjectivesareregardingthestudyofcybersecurityawarenessinareal,practicalsense,namelybyquantifying andrelatingittoourrealcollege-lifebehavior.
Cybersecurityhasbecomeamajorconcernintoday’sdigitalera.Internet,smartphones,socialmediaandonlineplatformsare heavilyusedbycollegestudentsforacademics,communicationandentertainment.Duetothis,studentsaremorevulnerable to cyber threats like phishing attacks, malware, identity theft, ransom ware, and data breaches. That is why ensuring cyber securityawarenesshasbecomeanimportantareaofresearch.
Many previous studies have assessed cyber security awareness among college students via questionnaire-based surveys. In thesestudies,ithasbeennoticedthatstudentshavebasictheoreticalknowledgeofcyber securitytermslikehacking,viruses andphishing,etc.Buttheirbehaviorisnotthatsecureatapracticallevel.Accordingtotheresearchfindings,studentsmostly use weak passwords, use the same password for multiple accounts, ignore software updates and also click on suspicious or unknownlinks.Fromthis,itisclearthatbeingawareisnotenough;onemustuseandfollowsafepracticesalso.
Some studies have also highlighted that students from a technical background have a better awareness level than students withanon-technicalbackground.Butevenstudentswithcomputer-relatedcoursesdonotfollowsecurepracticesineachand everysituation.Itclearlyshowsthatthereisagapthatexistsbetweenawarenessandreal-lifebehavior.Andtomeasurethis gapsystematically,weneedastructuredevaluationmodel.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
An important part of cyber security research is the development of risk assessment models. Traditional cyber security risk assessment frameworks have been designed mainly for organizations and enterprises. In these models, assets are identified, vulnerabilitiesareanalyzed,threatlikelihoodiscalculated,andthentheoverallrisklevelisdetermined.
Risk is generally divided into categories like low, medium and high risk. These models are detailed and structured but are mostlydesignedfortheinstitutionallevel.
Recentresearchhasfocusedon quantifyingrisksusing scoring systemsandweighted parameters.Risk level is calculatedby consideringvariableslikepasswordstrength,antivirus usage,softwareupdates,phishingawarenessandprivacysettings.But themajorityofstudiesapplyonorganizationalcontextandfocuslessonthebehaviorofanindividualcollegestudent.
In existing literature, awareness studies and risk assessment frameworks have been studied separately. Awareness studies focusonandmeasuretheknowledgelevelmainly,whileriskmodelsfocusonsystem-levelanalysis.
Researchthatcombinesbothaspectsisverylimited,especiallyforcollegestudents.Thisiswhatwecallaresearchgap.
Thatiswhythepresentstudyaimstomeasurecybersecurityawarenessandtointegrateitwithastructuredriskassessment model. With this approach, risk classification can be performed on students’ knowledge, along with their practical behavior Thisintegratedmodelhelpseducationalinstitutionstodesigntargetedawarenessprogramsandtoimprovethedigitalsafety levelofstudents.
The objective of this study is to measure cyber security awareness among college students and develop a structured risk assessment model on the basis of their online behavior. In this section, research design, data collection process, sampling method,toolsused,scoringmodelanddataanalysisareexplained.
1. Research design
Thisstudyisbasedonaquantitativeresearchdesign.Aquestionnaire-basedsurveyisadoptedfordatacollection.Quantitative approach was chosen because we had to collect numerical data, perform statistical analysis, and classify students into risk categories.
The research nature iscross-sectional,asthe data werecollectedovera specific time period,andnolong-termtracking was done.
2. Population and sampling
The target populationofthisstudyiscollegestudents whousethe internet,smartphones,laptopsand online platforms on a regular basis. Participants can be from different academic streams, including technical and non-technical backgrounds. The convenience sampling technique is used as a sampling method. The link to the Google Form is circulated among WhatsApp groups,collegegroupsandacademicnetworks.Studentshavevoluntarilyfilledoutthesurvey.
3. Data Collection Tool
A structured questionnaire is designed for primary data collection. The questionnaire was created on Google Forms, and mainlyclosed-endedquestionswereincludedinthat.
Thequestionnairewasdividedmainlyinto2sections.
Section A: Basicinformation,likeagegroup.
Section B: Cybersecuritypracticesandbehavior.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Real-lifepracticesaremeasuredinthissection.
Iftheyusethesamepasswordformultipleaccounts
Iftheyregularlyupdatesoftware.
Iftheyverifysuspiciouslinks.
Havetheyinstalledanantivirus?
Thissectionismostimportantfortheriskassessmentmodel.
The major contribution of this research is to develop a simplified risk assessment model which is specifically designed for collegestudents.
Step 1: ScoringMechanism
Anumericalscoreisassignedtoeachawarenessandbehavior-basedquestion.
Securepractice/correctawareness=2points.
Moderatepractice=1point
Riskypractice/Lackofawareness=0points.
Thetotalscoreofeachparticipantiscalculatedfromthisscoringsystem.
Step 2: Totalscorecalculation
Thetotalcybersecurityscoreiscalculatedbyaddingscoresofallrelevantquestions.
Example:
Maximumpossiblescore=20
Individualparticipantscore=14
Step 3: RiskClassification
Studentsaredividedinto3categoriesbasedontheirtotalscore
Lowrisk-Highawareness+securepractices.
Mediumrisk-Moderateawareness+Inconsistentpractices
Highrisk-Lowawareness+riskyonlinebehavior
Scorerangesarealsodividedproportionally(forexample):

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
0-7-> High Risk
8-14 -> Medium Risk
15-20->Lowrisk
Thisclassificationmodelissimpleandpractical,whichconvertsawarenessintoameasurablerisklevel.
5. Data Analysis Techniques
CollectedresponsesareexportedfromGoogleFormsandthenanalyzedinExcel.Incompleteresponseswereremovedinthe datacleaningprocess.
Thefollowinganalysistechniqueswereused:
1. Descriptive Statistics
Totalnumberofrespondents
Percentagedistribution
Meanawarenessscore
Riskcategorypercentage
2. Frequency Analysis
Responsepercentageiscalculatedforeachquestiontoidentifycommonpatterns.
3. Risk Distribution Analysis
Overalldistributionisevaluatedafterclassifyingstudentsintolow,medium,andhighriskgroups.
Chartsandgraphs(bargraph,piegraph)wereusedtovisuallyrepresentresults.
6. Ethical Considerations
Ethicalguidelineswerefollowedinresearch:
Volunteerparticipation.
Personalidentitywasnotmandatory.
Emailcollectionwaskeptananymissed.
Dataisstrictlyusedforacademicpurposes.
Privacyandconfidentialityofrespondentsweremaintained
7. Reliability and validity
Previously published awareness-based studies were referred to while designing the questionnaire. Questions were designed insimpleandclearlanguagetoavoidambiguity.
The risk assessment model is based on a logically structured scoring mechanism which considers both awareness and behavior.Thisintegratedapproachstrengthenedtheconstructvalidityofthestudy.
© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1654

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Conveniencesamplingwasused,sotheresultsmaynotfullyrepresenttheentirepopulation.
Responsebiasispossiblebecauseofself-reporteddata.
Thestudyisbasedonalimitedsamplesize.
Still, this methodology provides an effective framework to measure student-level cyber security awareness and behavioral risk.
In this segment, we will understand how the proposed cyber security awareness survey and risk assessment model were practicallyimplementedandalsohowwetracedtheworkingprocessofthesame.
1. Questionnaire Implementation
The research implementation process started with preparing and designing the questionnaire and deploying it over various online platforms. We developed the questionnaire using Google Forms because it was user-friendly, free and also offered automaticdatacollection.Thefollowingstepswereusedtodeveloptheform:
● Therewasacleartitleanddescription.
● Therewasaconsentstatementthatexplicitlysaidthattheparticipant’sinvolvementwasvoluntary.
● Enteringemailswasoptionaltoconfirmanonymity.
● Questionsweredividedintoalogicalorder –thefirstgroupwasthatofdemographics,thenthequestionsrelatedto awarenessandthelastgroupincludedbehavior-relatedquestions.
Wepreviewedtheformtomakesurethattherewerenotechnicalerrorsandalltheoptionswerevisible.
2.
Thesurveywasdistributedbycirculatingthesurveylinkwiththefinalisedquestionnairethrough:
● CollegeWhatsAppgroups
● Academicdiscussiongroups
● Personalacademiccontacts
Therespondentswereinformedthatthesurveywaspartofanacademicresearchfieldandthatitwouldnottakemorethan23minutestocomplete.
The data collection process was left open during a given period of time (3-4 days). We stopped the responses at this time periodinordertocommencetheanalysisprocess.
After the completion of the survey responses, we exported the Google Forms responses in an Excel format (.csv file). Thestepsinvolvedinthedatacleaningprocesswereasfollows:

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
● Eliminatingunfinishedanswers.
● Checkedforduplicateentries.
Weusedthefinalcleaneddatasetintheanalysis.
4. Implementation of Scoring System
The scoring mechanism was the main component of the risk assessment model. At this stage, each response was given a numericalvalue.
Step1:DeterminingScoringCriteria
Ascoringpatternwasestablishedbasedoneveryawarenessandbehavior-basedquestion:
● Securebehavior–2marks
● Moderatebehavior–1mark
● Riskybehavior–0marks
Thescoringrulewasproperlyoutlinedoneachquestion.
Forexample:“Doyouusestrongpasswords?”
-Yes:2
-Sometimes:1
-No:0
Step 2: Scoring Responses
● AlltheresponseswereallocateddifferentnumericalvaluesintheExcelsheet.
● Andeachquestionwasprovidedwithaseparatecolumn.
Step 3: Validate Scoring Consistency
● Wemadesurethatalltheresponseswereappropriatelyscored.
● Random entries were confirmed to prevent errors in any calculation.
5. Total Score Calculation
Todeterminetheoverallcybersecurityscoreofeachparticipant:
● Scoresofallquestionsrelatedtoawarenessandbehaviorweresummedup.
● Anewcolumnnamed‘TotalScore’wasadded.
● WethenappliedtheExcelformula(=SUM),whichautomaticallysummedthetotal.
Forexample,whensummativepotentialis20andastudenthasascoreof12,his/herlevelofawarenessandbehaviourwould be‘moderate’.
© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1656

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
6. Process of Risk Categorization
Thetotalscoreofthestudentswasusedtodividethemintocategories.Therangeofscoreswaslogicallysplitinto:
● 0-7:Highrisk
● 8-14:Mediumrisk
● 15-20:Lowrisk
RiskclassificationwasdoneautomaticallyintheExcelspreadsheetusingtheIFformula.
Throughthisprocedure,thelevelofriskwasautomaticallyidentifiedforeachparticipant.
7. Statistical Implementation
Thedatawasanalyzedusingdescriptivestatisticaltools.
(A)FrequencyDistribution
Thefollowingwascalculatedinrelationtoeachquestion:
● Thepercentageofstudentswhousestrongpasswords.
● Proportionofstudentswith2FAenabled.
● Proportionofstudentswhowereabletorecognizephishingemails.
Thisassistedindeterminingbehavioralpatterns.
(B) PercentageAnalysis
Thetotalpercentageofriskcategorieswassummedup:
● %ofstudentswithLowRisk
● %ofstudentswithMediumRisk
● %ofstudentswithHighRisk
Thisdescriptionsymbolizedthegeneralcybersecurityposition.
(C) MeanScoreCalculation
Tocalculatethelevelofawarenessingeneral:
● Theaveragescore(Mean)ofallparticipantswascomputed.
● Thisscoreassistedinknowingthelevelofcybersecurityofanaveragestudent.
ThesamewascalculatedbyusingtheAVERAGEformulainExcel.
8. Graphical Representation
Tovisuallyillustratethefindings:
● Awarenessquestionswerecoveredthroughbarcharts.
● Thedistributionofriskswasillustratedwiththehelpofpiecharts.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
● Comparisonwasdoneusingcolumncharts.
Thesegraphicalrepresentationsmadethefindingsmoreunderstandableandclear.
TheprocessoftheproposedRiskAssessmentModelisrathersimpleandstructured.
1. Thequestionnairewasfilledoutbythestudents.
2. Alltheresponseswerethenautomaticallytransformedintoanumericalscore.
3. Thetotalscorewascalculated.
4. Thisscoreisthenusedtodeterminetheriskcategory.
5. Thegeneraldistributionisexamined.
Thisisdonetotransformthemodelawarenessintoanoutcomeofriskthatcanbemeasured.
Conventionalorganizationalparadigmsareusuallycomplicated,whereasthisisastudent-orientedmodelthatisveryeasyand viabletoapply.
Thismodelcanbeveryusefulinlearningestablishments:
● Identifyinghigh-riskstudents.
● Developingawarenessprograms.
● Organizecybersecuritytraining.
● Enhancingonlinesecuritymeasures.
This model can be transformed into an automatic web-based application, which would allow students to find out their risk levelbyfillingoutthesurveyandimmediatelyreceivingtheirresultsinthefuture.
● Themodelreliesonself-reportedinformation.
● Samplesizecanbelimited.
● Riskclassificationisnotanenterprisemodel,butasimplifiedformofit.
Thisundergraduate-levelcybersecuritytestisquitepracticalandoffersaflexiblemodeltoapplytoit.
The main purpose of this research study was to estimate the level of cybersecurity awareness among college students and createasystematizedriskevaluationmodel,whichwasbuiltonthebasisoftheseresults.Eighty-sixstudentstookpartinthe survey. The systematized analysis of the obtained responses was performed using descriptive statistics and categorical risk classification.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Thestudycollected86 validresponses.All the responseswere assessed basedonthescoring model after data cleaning. The highestpossiblescorewas24,whichwasthegeneralcybersecurityawareness.
Themostbasicaspectofcybersecurityispasswordusagebehavior.Basedontheresultsofthesurvey:
● 72students(around84%)statedthattheyAlwaysusestrongpasswords.
● 12students(around14%)saidthattheySometimesusestrongpasswords.
● Thenumberofstudentswhoacknowledgedthattheydonotusestrongpasswordswas2(approximately2%).

AnalyticalInterpretation:Thisdatamakesitobviousthatmoststudentsknowabouttheimportanceofpasswordsecurityand applyit.The84%directresponseofYesisa positivesignal.Nevertheless,the16% (Sometimes+No)category canalsobea possibleweakness,particularlyincasethepasswordsarepredictableorduplicated.
Onthewhole,thehygieneofstudentswithregardtopasswordsissatisfactory
Two-factor authentication provides an added level of security and reduces the risk of unauthorized access. Based on the resultsofthesurvey:
● 46students(about53%)mentionedthattheyenable2FAAlways.
● 35students(approximately41%)saidtheySometimesuse2FA.
● 5students(around6%)saidthattheyNeveruse2FA.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072

Analytical Interpretation:2FA is used consistently by more than half of the students, but 41% of the Sometimes respondents meanthatthereisnoconsistency.Cybersecurityrepresentsasituationwhosemereimplementationmakesitavulnerability. Therateof6%non-adoptionisrelativelylow,yetthelong-termoutlookofdigitalsafetyisalarming.
Thisinformationindicatesthatconsciousnessexists,anditismeaningfultoenhancebehavioralconsistency.
Antivirus software is used to offer system-level security against malware, ransom ware and spyware attacks. Survey results show:
● Therewere49students(around57%)whorepliedintheaffirmative.
● Whereas,37students(approximately43%)answeredNo.

Analytical Interpretation: This demonstrates that over half of the students take care of the device-level protection. The 43% who did not use antivirus however, illustrate huge security lapses. Antivirus protection is strongly advised in a learning institutionbecauseoftheprevalenceofpublicwi-fiandfilesharing.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Itmeansthatthelevelofimplementationoftechnicalprotectivemeasuresisnotuniversalandismoderate.
The process of Phishing detection is a very important indicator of practical cyber security awareness. The survey responses show:
● Therewere32students(roughly37%)whoclaimedtheywouldbeabletoestablishafakesitewithconfidence.
● 51outof100students(around59%)werealsonotcertainwhethertheycanrecognizeanyfraudulentsites.
● Nowasansweredby3students(approximately4%).

Analytical Interpretation: This finding means that most of the students (59%) are unable to spot phishing attacks. The detection ability of only 37% of the students is confident. This makes it clear that, despite the fact that after performing the simple cybersecurity measures, there is a low level of advanced threat recognition. Phishing enlightenment should also be enhancedinordertoensurethatstudentsaremoresafeguardedagainstreal-lifecyberthreats.
The responses of the participants were rated. The maximum score was 24. The ranges of scores were categorized into 4 groups:

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Analytical Interpretation:
● Noneofthestudentshasanextremelylowawareness(0-6)level,whichisagoodsign.
● Thepercentageofstudentsinthelowerawarenessbracket(7-12)was11(13%).
● Mostofthestudents,i.e.54(63%),belongtothemoderateawareness(13-18)group.
● Thenumberofstudentswhoareunderthehighawareness(19-24)isonly21(24%).
The general level of awareness of the students is average, except that high-level cybersecurity is confined to a small percentage.Themoderatelevelofawarenesscannotbeconsideredadequateforlong-termdigitalsafety.
7. Risk Assessment Model Classification
Withtheriskassessmentmodelthatwecreated,studentswerecategorizedinto3groups:
Table -2: RiskAssessmentClassification
AnalyticalInterpretation:Thefindingsoftheriskmodelareasfollows:
● Thereisalow-riskpopulation(2.33%),whichisanencouragingfactor.
● Mostofthestudents(52.33%)areplacedundertheMediumRiskcategory.
● ThecategoryofLowRiskcomprised45.35%,whichwasfairlysatisfactory.
A high percentage of medium risk is an indication that, despite the simple security measures taken by the students, their actionsarenotcompletelysafe.
8. Correlation Between Awareness and Risk
Basedon theanalysis,itcan beclearlysaidthat the higherawarenessscore isdirectlyrelated to the risk of beingless risky. Thestudentswhosescoreswereeither19-24werepredominantlyinthelow-riskgroup.Onthesamenote,thestudentswith lowscoresweregroupedunderthemediumorhigh-riskcategory.
This indicates that a well-modelled scoring model is useful in predicting the risk. It could be used practically in learning institutionsintermsofcybersecuritysurveillance.
Findings indicate clearly that theoretical knowledge does not aid students in maintaining the security of their devices, and thereisaneedforlife-structuredcybersecurityawarenessprogramsandtrainingtobeundertaken.
© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1662

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
The primary objective of this research study was to evaluate cyber security awareness amongst college students and to classifytherisklevelusingastructuredriskassessmentmodel.Asurvey-basedanalysisrevealedthatstudentspossessbasic cybersecurityawareness,buttherearenoticeablegapsinpracticalimplementationandadvancedthreatrecognition.
The password security results indicate that the majority of students create strong passwords, which is a positive behavioral indicator. Students have a solid grasp of the fundamental concepts of digital hygiene. However, the inconsistent behavior of some students suggests that there are gaps in awareness and consistent practice. The two-factor authentication (2FA) adoptionresultsshowamixedpattern.Althoughmorethanhalfofthestudentsregularlyenable2FA,asignificantpercentage either use it occasionally or do not use it at all. In the context of cyber security, partial implementation can create vulnerabilities,whichiswhyimprovingbehavioralconsistencyintheadoptionof2FAisnecessary.
Theusageofantivirusorsecuritysoftwareindicatesa moderatelevelofadoption. Slightlymorethanhalfoftheparticipants maintain device-level protection; however, a considerable percentage of students' devices remain potentially unprotected. Frequent internet usage, public Wi-Fi access, and file sharing are common in academic environments, increasing the importanceofprotectingdevices.

The most critical finding is related to phishing awareness. The majority of students cannot confidently identify phishing attacks.Thisresulthighlightsthatpossessingonlytheoreticalawarenessisnotenoughifreal-worldthreatdetectionskillsare weak. In today's digital ecosystem, phishing is the most common cyber -attack method, especially for targeting students. Therefore,thereisastrongrequirementforfocusedawarenessprogramsandpracticaltrainingsessions.
Scoredistribution analysis shows that the majority of students fall into the moderate level awareness category, whereas the high awareness level category is limited to a comparatively smaller group. Through the risk assessment model, it has been concluded that most students are classified in the medium-risk zone. This situation is neither alarming nor satisfactory. It indicatesthatstudentsarenotcompletelyvulnerablebutarenotcompletelysecureeither.


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Overall,thisstudyconcludesthatfoundational cybersecurityknowledgeispresent amongstcollegestudents;however,there is an urgent need to strengthen advanced security practices and threat identification skills. Educational institutions should conductstructuredcybersecurityawareness programs, workshops, andcurriculum-level integration to reducestudents'risk levelssystematically.
This research clearly demonstrates that awareness alone is not sufficient; consistent implementation and practical exposure are equally important. If targeted training and institutional support are provided, then the medium-risk population can be shiftedintothelow-riskcategory,whichisessentialforlong-termdigitalsafetyandasecureacademicecosystem.
The findings of this research study reveal that while college students possess a moderate level of cybersecurity awareness, noticeablegaps betweentheirknowledgeand practical applicationstill exist.Given these gaps,the futurescopeisextensive, withthepotentialtoexpandthistopicintomultipledimensions.
Oneprimaryareaforfutureresearchistheconductoflongitudinalstudies.Thepresentresearchisbasedonacross-sectional design, wherein data is collected within a specific time period. In future research, students can be observed for a longer timeframe,typicallyonetotwoyears,todetermineifawarenessprograms,workshops,orinstitutionalpolicieshavealasting impact.Thiswillalsoallowaccuratemeasurementofbehaviouralchangesandriskreduction.
Anotherimportantareaforfutureresearchisintervention-basedresearch.Whilethisstudyfocusedonevaluatingawareness level and risk assessment model, structured cybersecurity training modules can be provided to students using an experimental design in the future. By providing this training and comparing pre-test and post-test results, researchers can measureactualimprovement.Thiswouldhelpidentifythemosteffectivetrainingmethodforstudents.
Athirddirectionfor expansioninvolvescomparativeresearchacrossdiversegroupssuchaspostgraduatestudents,working professionals,orfacultymembers,ratherthanlimitingthestudytoundergraduates.Moreover,acomparisonbetweenprivate andgovernmentinstitutionscouldrevealhowdifferentenvironmentsinfluencestudentawarenessandrisklevels.
Althoughthepresentriskassessmentmodelismainlydependentonaquestionnaire-basedscoringsystem,itcandefinitelybe enhancedinthefuture.Featureslikeweightedscoringtechnique,machinelearningalgorithms,orpredictiveanalyticscanalso be integrated into the model. For instance, developing an artificial intelligence-based model can be used not only to predict future vulnerabilities based on students' behavioural patterns but also to help institutions design proactive cybersecurity strategies.
Future research could also explore the behavioural and psychological aspects of cybersecurity awareness. In many cases, studentspossessbasicawareness,yettheydonotfollowsafepractices.Thiscouldbeduetomanyfactors,suchasprioritising convenience,alackofperceivingthreats,orbeingtoooverconfidentintheirdigitalskills.Henceforth,behaviouralframeworks likeriskperceptiontheory ortechnologyacceptancemodelscouldbeusedinfuturestudiestocomprehendthegapbetween actualbehaviourandawareness.
Moreover, integrating cybersecurity awareness in the academic curriculum can also be a part of future research. Future studies could also help evaluate how cybersecurity education improves students’ awareness level and practical security behaviour. Additionally, research-emerging cyber threats like AI-generated phishing emails, deepfake scams, and advanced socialengineeringattackscanbeusedtoassessthestudents’preparedness.
Overall, the future scope of this research goes beyond simply measuring cybersecurity awareness amongst students. This study provides multiple opportunities for future research, including behavioural analysis, advanced risk assessment models, curriculum-basedcybersecurityeducation,andanemergingunderstandingofcyberthreats.Asaferandmoreresilientdigital academicenvironmentcanbecreatedthroughcontinuousresearchandinstitutionalsupport.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
[1] S.Furnell andK.Clarke,“Powertothepeople?Theevolvingrecognitionofhumanaspectsofsecurity,” Computers& Security,vol.31,no.8,pp.983–988,Nov.2012,doi:10.1016/j.cose.2012.08.004.
[2] A.Moallem,N.B.N.Bakar,andS.Sadiq,“Theimportanceofcybersecurityawarenessamongstudents,” International JournalofAdvancedComputerScienceandApplications,vol.10,no.9,pp.1–7,2019.
[3] M.Al-JanabiandI.Al-Shourbaji,“AstudyofcybersecurityawarenessineducationalenvironmentintheMiddleEast,” JournalofInformation&KnowledgeManagement,vol.15,no.1,2016.
[4] J.KumarandP.Kumar,“Cybersecurityawarenessamongcollegestudents:Asurveyanalysis,”InternationalJournalof ComputerApplications,vol.182,no.44,pp.10–15,2019.
[5] A. Alharbi, “Users’ awareness of cybersecurity threats and practices,” International Journal of Advanced Computer ScienceandApplications,vol.11,no.4,pp.1–6,2020.
[6] P. van Schaik, D. Jeske, J. Onibokun, L. Coventry, J. Jansen, and P. Kusev, "Risk perceptions of cyber-security and precautionarybehaviour,"ScienceDirect,vol.75,pp.547–559,Oct.2017.[Online].