Digital Security Awareness and Practices in Omani Higher Education: A Qualitative SWOT Analysis
DOI:
https://doi.org/10.33152/jmphss-10.2.9Keywords:
digital security, SWOT, strengths, weaknesses, opportunities, threats, practices, awarenessAbstract
The rapid pace of digital transformation has reshaped educational environments worldwide, generating new opportunities while posing complex challenges related to digital security. For higher education students, secure engagement with technology has become a vital competency, particularly in contexts where digital learning, research, and communication are central to academic and professional success. The present paper investigates the digital security practices of higher education students in Oman to uncover the strengths, weaknesses, opportunities and threats. A phenomenological qualitative approach is utilized to study digital awareness and practices and sixteen students from different high education institutions were interviewed. The data collected were analyzed using SWOT framework. The students’ answers to the questions related to their knowledge, understanding and practices of digital security revealed their understanding of digital security as protection and socio-technical practice, awareness of digital risks, knowledge about sources of security awareness and secure practices of password and account protection practices. However, the weaknesses that students explained underscores their awareness-practices gaps and barriers which are results of limited security knowledge and risk awareness and low interest, seriousness, and perceived importance and convenience, time pressure, and security fatigue. The opportunities provided by the institutions include institutional awareness and guidance, practical and experiential security training, curriculum integration and formal security learning and early, mandatory, and continuous training. The students’ responses to the interview questions underscore the digital security threats that include phishing, suspicious links, fake websites, account hacking, compromise, and misuse, financial fraud and information theft and data leakage, exposure, and privacy misuse. In conclusion, while the students possess basic security knowledge, high education institutions are urged to establish comprehensive security cultures and maintain continuous awareness programs, clear security policies, regular training and effective reporting mechanisms to enhance digital security awareness and practices in Omani higher education institutions.
References
Adebesin, F., Adeliyi, T., & Oluwadele, D. (2024). Mapping the knowledge landscape of AI in higher education: A SWOT analysis. Educational Administration: Theory and Practice, 30(5), 9068–9087. https://kuey.net/index.php/kuey/article/view/4514
Al-Buraiki, S. A. S. (2026). Empowering educators for the AI era: Strategies for teacher training and professional development. In Human-Centered Approaches to AI-Enhanced English Language Learning and Teaching (pp. 1-32). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3373-3561-2.ch001
Al-Buraiki, S. A., & Al-Ruheili, H. S. (2025). A qualitative SWOT analysis study of the integration of AI technologies into higher education institutions in the Sultanate of Oman. International Journal of Learning, Teaching and Educational Research, 24(3). https://doi.org/10.26803/ijlter.24.3.26
Alobaid, A. (2025). A didactical framework for raising awareness of digital multiliteracies among university students: Objectives, expectations and challenges. Discover Education, 4(181). https://doi.org/10.1007/s44217-025-00599-z
Al Ruheili, H., & Al-Buraiki, S. A. S. (2025). Incorporating AI in Educational Leadership: Trends and Innovations. In Optimizing Research Techniques and Learning Strategies with Digital Technologies (pp. 239-268). IGI Global Scientific Publishing. https://doi.org/10.4018/979-8-3693-7863-2.ch009
Arachchilage, N. A. G. (2015). User-centred security education: A game design to thwart phishing attacks. arXiv. https://doi.org/10.48550/arXiv.1511.03459
Arachchilage, N. A. G., & Hameed, M. A. (2017). Integrating self-efficacy into a gamified approach to thwart phishing attacks. arXiv. https://doi.org/10.48550/arXiv.1706.07748
Armas, R., & Taherdoost, H. (2025). Building a cybersecurity culture in higher education: Proposing a cybersecurity awareness paradigm. Information, 16(5), 336. https://doi.org/10.3390/info16050336
Azzeh, M., Altamimi, A. M., Albashayreh, M., & Al-Oudat, M. A. (2022). Adopting the cybersecurity concepts into curriculum: The potential effects on students’ cybersecurity knowledge. Indonesian Journal of Electrical Engineering and Computer Science, 25(3), 1749–1758. https://doi.org/10.11591/ijeecs.v25.i3.pp1749-1758
Bada, M., Sasse, A. M., & Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour. arXiv. https://doi.org/10.48550/arXiv.1901.02672
Benzaghta, M. A., Elwalda, A., Mousa, M. M., Erkan, I., & Rahman, M. (2021). SWOT analysis applications: An integrative literature review. Journal of Global Business Insights, 6(1), 55–73. https://doi.org/10.5038/2640-6489.6.1.1148
Bitton, R., Boymgold, K., Puzis, R., & Shabtai, A. (2020). Evaluating the information security awareness of smartphone users. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems (Article 3376385, pp. 1–13). Association for Computing Machinery. https://doi.org/10.1145/3313831.3376385
Bognár, L., & Bottyán, L. (2024). Evaluating online security behavior: Development and validation of a personal cybersecurity awareness scale for university students. Education Sciences, 14(6), 588. https://doi.org/10.3390/educsci14060588
Diaz, A., Sherman, A. T., & Joshi, A. (2020). Phishing in an academic community: A study of user susceptibility and behavior. Cryptologia, 44(1), 53–67. https://doi.org/10.1080/01611194.2019.1623343
Goliath, S., Tsibolane, P., & Snyman, D. (2025). Exploring the cybersecurity-resilience gap: An analysis of student attitudes and behaviors in higher education. In H. Venter, M. Eloff, J. Eloff, R. Botha, M. Loock, & U. Mushtaq (Eds.), Information and cyber security (pp. 185–195). Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-09660-9_19
Gürel, E., & Tat, M. (2017). SWOT analysis: A theoretical review. Journal of International Social Research, 10(51). http://dx.doi.org/10.17719/jisr.2017.1832
Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2024). Why people still fall for phishing emails: An empirical investigation into how users make email response decisions. In Proceedings of the 2024 Symposium on Usable Security (USEC’24). Internet Society. https://doi.org/10.14722/usec.2024.23072
Kebande, V. R. (2024). The impact of virtual laboratories on active learning and engagement in cybersecurity distance education. arXiv. https://doi.org/10.48550/arXiv.2404.04952
Kraus, L., Švábenský, V., Horák, M., Matyáš, V., Vykopal, J., & Čeleda, P. (2023). Want to raise cybersecurity awareness? Start with future IT professionals. In Proceedings of the 2023 Conference on Innovation and Technology in Computer Science Education V. 1 (ITiCSE 2023) (pp. 236–242). Association for Computing Machinery. https://doi.org/10.1145/3587102.3588862
Kshetri, N., Vasudha, & Hoxha, D. (2023). knowCC: Knowledge, awareness of computer & cyber ethics between CS/non-CS university students. In 2023 International Conference on Computing, Communication, and Intelligent Systems (ICCCIS) (pp. 515–520). IEEE. https://doi.org/10.1109/ICCCIS60361.2023.10425385
Lain, D., Jost, T., Matetic, S., Kostiainen, K., & Čapkun, S. (2024). Content, nudges and incentives: A study on the effectiveness and perception of embedded phishing training. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (pp. 4182–4196). Association for Computing Machinery. https://doi.org/10.1145/3658644.3690348
Noble, H., & Smith, J. (2025). Ensuring validity and reliability in qualitative research. Evidence-Based Nursing, 28(4), 206–208. https://doi.org/10.1136/ebnurs-2024-104232
Ramalingam, R., Khan, S., & Mohammed, S. (2015, May). The need for effective information security awareness practices in Oman higher educational institutions. In Proceedings of the 1st Symposium on Communication, Information Technology and Biotechnology: Current Trends and Future Scope. https://www.researchgate.net/publication/282333411_The_need_for_effective_information_security_awareness_practices_in_Oman_higher_educational_institutions
Ramalingam, R., Lakshminarayanan, R., & Khan, S. (2016). Information security awareness at Oman educational institutions: An academic perspective. arXiv. https://doi.org/10.48550/arXiv.1605.05580
Creswell, J. W., & Poth, C. N. (2023). Qualitative inquiry and research design: Choosing among five approaches (5th ed.). SAGE Publications. SAGE Publications
Tchao, E. T., Ansah, R. Y., & Kotey, S. D. (2017). Barrier free internet access: Evaluating the cyber security risk posed by the adoption of bring your own devices to e-learning network infrastructure. International Journal of Computer Applications, 176(3), 53–62. https://doi.org/10.5120/ijca2017915581
Zhu, C., & Kintu, M. J. (2015). A SWOT analysis of the integration of e-learning at a university in Uganda and a university in Tanzania. Technology, Pedagogy and Education, 24(5), 585–603. https://doi.org/10.1080/1475939X.2015.1093537
Published
Issue
Section
License
Copyright (c) 2026 Dr. Sheikha Al-Buraiki, Dr. Fatma Hassan Abd Elbasset Mourgan, Anas Hanandeh

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

