Cybersecurity Awareness in Schools: Review
Cybersecurity Awareness in Schools: Review
Abstract—This systematic literature review examines more opportunities to exploit outdated or unpatched systems
cybersecurity awareness in schools, focusing on effective practices, [1,4].
challenges, and future directions. Following the Preferred
Reporting Items for Systematic Reviews and Meta-Analyses Historically, responses to cybersecurity threats within
(PRISMA) guidelines, peer-reviewed publications in English were educational settings have tended to be reactive rather than
sourced from ACM Digital Library, IEEE Xplore, ScienceDirect, proactive. There is now a critical and urgent need to enhance
SpringerLink, and Emerald, covering the period from 2019 to cybersecurity awareness and improve practices across all
2024. Studies were included if they focused on cybersecurity stakeholders, particularly as the Internet becomes an
awareness in primary and secondary educational settings, indispensable part of educational infrastructure [5,6]. Effective
excluding those unrelated to educational contexts or published cybersecurity awareness programs must encompass a wide
before 2019. A total of 816 records were identified, of which 220 audience, including students, who require adequate guidance
were duplicates and removed. After screening and eligibility and supervision to navigate online risks safely [7]. The current
assessments, 14 studies met the inclusion criteria. Risk of bias was systematic literature review aims to meticulously examine the
minimized by adhering to strict inclusion criteria, such as limiting state of cybersecurity awareness in schools, delineating effective
the review to high-quality, peer-reviewed studies, and ensuring practices and identifying ongoing challenges. The review
consistency in the data extraction process. The review highlights addresses the growing complexity and scale of cyber threats and
effective practices such as using serious games, mobile apps, and underscores the necessity for comprehensive strategies that
tailored programs to enhance cybersecurity awareness.
integrate public education, technology updates, and community
Challenges include inconsistent curricula, insufficient parental
involvement, and resource limitations. These results emphasize
involvement [8,9]. The outcomes of this review are designed to
integrating cybersecurity education across school curricula and inform educational policymakers, school IT administrators, and
regularly updating content to reflect evolving threats. Limitations educators, providing them with strategic insights to develop and
include the exclusion of non-English and non-peer-reviewed implement robust, effective cybersecurity education and
studies. Future research should consider broader contexts and awareness programs.
additional sources. Research Questions:
Keywords—Cybersecurity awareness; threats; awareness 1) What are effective practices for improving cybersecurity
programs; education; school security awareness in schools?
I. INTRODUCTION 2) What are schools' current problems and challenges in
implementing cybersecurity awareness programs?
In the digital age, educational institutions have progressively
3) Who is the target audience for the current cybersecurity
embraced technology, integrating it extensively into classroom
instruction and administrative management. While this awareness assessment?
integration offers numerous advantages, it also significantly By addressing these questions, the research aims to
increases schools' exposure to cybersecurity risks, threatening contribute significantly to the body of knowledge on
the integrity of educational delivery and the privacy of student cybersecurity in education, facilitating the development of
and teacher data [1,2]. The vulnerability of schools to cyber secure learning environments that effectively leverage digital
threats is particularly exacerbated by limited resources, which technologies.
leave educational networks open to unauthorized access and
data theft [3]. Additionally, the swift transition to e-learning II. LITERATURE REVIEW
platforms, particularly during the COVID-19 pandemic, has Cybersecurity awareness has become an essential aspect of
expanded the attack surface, providing cybercriminals with contemporary education systems, driven by the widespread
467 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
integration of digital technologies in schools. As students, due to limited awareness of online risks and poor adherence to
educators, and administrators increasingly depend on digital safe practices [14].
platforms, educational institutions face heightened exposure to
cyber threats. This literature review examines the practices, The transition to online education, particularly during the
challenges, and target audiences in fostering cybersecurity COVID-19 pandemic, has further amplified these challenges.
awareness in school environments. Al-Fatlawi (2024) highlights how the rapid shift to digital
learning exposed vulnerabilities, as many educators lacked the
Yuliana (2022) underscores the importance of raising skills and resources to secure online environments. Students
cybersecurity awareness among children, particularly in the with low cybersecurity awareness became frequent targets of
context of online schooling, which increases their vulnerability phishing, malware, and data breaches. The lack of structured
to cyberattacks and malware. The study demonstrates that digital training for teachers has compounded these issues, preventing
literacy training can significantly enhance children’s awareness them from adequately guiding students in safe online
of cybersecurity. It advocates teaching children how to avoid behaviours. Additionally, disparities in motivations and levels
risky online behaviour, such as falling victim to phishing scams, of understanding between different demographics, including
pornography, cyberbullying, identity theft, and privacy educators and students, complicate the development of
breaches. Additionally, it stresses the importance of educating comprehensive and effective cybersecurity strategies [15].
children on password security and fostering caution when
engaging in online gaming [10]. Efforts to incorporate cybersecurity awareness into school
curriculums face significant hurdles. According to Triplett
Ondrušková and Pospíšil (2023) argue that the increasing (2023), while methods such as game-based learning show
use of the Internet necessitates adequate cybersecurity promise in engaging students and raising awareness, they often
awareness to mitigate the risks and dangers associated with the fall short of addressing the full range of skills and knowledge
online environment. Their findings reveal only a moderate level required to tackle real-world cybersecurity threats. A shortage
of cybersecurity awareness during initial testing and show that of trained mentors and educators specializing in cybersecurity
one-off training sessions have an insignificant impact on further diminishes the effectiveness of these initiatives. This gap
improving online behavior. The study concludes that one-time underscores the need for sustained investment in teacher training
interventions are insufficient and recommends integrating and the integration of cybersecurity education across all levels
cybersecurity awareness education throughout the entire of schooling [16].
educational process to effectively enhance online safety skills
[11]. The growing reliance on the Internet in education has also
led to an increase in cyber-related issues such as cyberbullying,
Nehrar and Deepanshi (2023) highlight the critical role of online fraud, racial abuse, pornography, and gambling, as noted
cybersecurity awareness and education programs in an era by Sareen and Jasaiwal (2021). These problems arise from a lack
characterized by pervasive digital connectivity and cyber of awareness among internet users and disproportionately affect
threats. They emphasize that such programs are effective in children, especially in the context of online education. Limited
enhancing knowledge, fostering behavioral changes, and teacher expertise, inadequate funding, and insufficient resources
ensuring long-term impact on cybersecurity practices [12]. hinder schools’ ability to implement robust cybersecurity
education programs. Addressing these challenges requires a
Prümmer et al. (2024) emphasize the growing significance collaborative effort among educators, parents, policymakers,
of cybersecurity in mitigating financial losses, productivity and media platforms to cultivate a culture of cybersecurity
disruptions, and reputational damage caused by cyberattacks. awareness from an early age [17].
Their research highlights the pivotal role of end-user behavior in
achieving robust cybersecurity within organizational settings. The literature review underscores the critical need for robust
Comprehensive training programs are identified as an effective cybersecurity awareness initiatives in contemporary education
means of improving cybersecurity behavior, with most studies systems. As digital technologies become integral to learning,
reporting positive outcomes regardless of the training method or schools face escalating cyber threats that compromise safety,
topic. Notably, game-based training methods are frequently disrupt teaching, and erode trust. Studies highlight the
employed, demonstrating their effectiveness in engaging importance of integrating comprehensive and sustained
participants and enhancing cybersecurity practices [13]. cybersecurity education across all levels of schooling to address
vulnerabilities among students and educators. Effective
The integration of technology into education has brought approaches, such as digital literacy training and game-based
both opportunities and challenges, particularly in the realm of learning, show promise but require adequate resources, skilled
cybersecurity. Buyu & Ogange (2021) notes that the rapid mentors, and long-term strategies to ensure meaningful impact.
adoption of digital tools in schools has introduced significant Addressing these challenges necessitates collaboration among
cybersecurity risks, including malware, ransomware, phishing, educators, parents, policymakers, and media, fostering a culture
and denial-of-service attacks, which disrupt teaching, of cyber safety that empowers learners and mitigates the risks of
compromise data security, delay assessments, and erode trust
an increasingly connected educational landscape.
between teachers and students. These challenges are
exacerbated in developing countries, where schools often lack III. METHODOLOGY
the funding, infrastructure, and expertise to effectively address
these threats. Moreover, teachers frequently lack the necessary To deliver an exhaustive review of cybersecurity awareness
cybersecurity knowledge to protect themselves and their within school and educational settings and to bridge identified
students, while young learners remain particularly vulnerable research gaps, this study is grounded in the PRISMA ("Preferred
468 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
Reporting Items for Systematic Reviews and Meta-Analyses") 3) Initial search :In the initial search stage of the systematic
framework [18]. literature review (SLR) following the PRISMA framework, a
The Preferred Reporting Items for Systematic Reviews and comprehensive search was conducted across the selected
Meta-Analyses (PRISMA) 2020 statement is an authoritative databases. This search, based on the keywords identified in the
and updated guideline that enhances transparency in the previous stage, aimed to retrieve relevant scientific papers and
reporting of systematic reviews. It addresses the rationale, yielded a total of 816 records.
methods, and outcomes of reviews [19]. The choice of the 4) Inclusion/exclusion criteria: To maintain the integrity
PRISMA framework was driven by its standardization, which and relevance of the systematic review, rigorous inclusion and
ensures consistency and reliability in the systematic review exclusion criteria have been applied focused on impurity
process; and its comprehensiveness [20], which is crucial to removal. The review is confined to studies published within the
addressing the multi-faceted issues of cybersecurity
past five years (from 2019 to 2024), ensuring the data's freshness
comprehensively and practically in the education sector [21].
The review process was initiated using the PRISMA framework, and pertinence to current contexts. Sources have been restricted
which consists of four phases: identification, screening, to peer-reviewed articles which are critical for upholding high
eligibility, and inclusion. The flow diagram, providing detailed research standards and credibility. Additionally, all studies
information and statistics, is shown in Fig. 1. The four phases included in the review are published in English, setting a
are explained in detail below. Data collection was conducted by necessary linguistic criterion that aids in uniform
a single reviewer to maintain consistency in the extraction comprehension and analysis. Furthermore, only studies
process. Four instructors provided guidance and oversight, classified as Q1 or Q2 are included to ensure the inclusion of
ensuring the integrity and accuracy of the data collection. high-quality research. On the exclusion front, any studies
A. Identification Phase published before 2019 are omitted to reinforce the recency of the
1) Selecting database: In the initial phase of the literature included research. Non-peer-reviewed materials are also
review for a systematic review of cybersecurity awareness in excluded to preserve the scientific integrity and quality of the
schools, a range of scholarly and normative databases were review. Studies not available in English or not meeting the
carefully selected to ensure comprehensive coverage of the quality classification are systematically excluded.
relevant literature. Selected databases include ACM Digital 5) Duplicate removal: All the duplicate records were
Library, IEEE Xplore, ScienceDirect; SpringerLink, and eliminated, which summed up to 222. It resulted in many
Emerald .These platforms were strategically selected to access duplicate records. Finally, the total remaining articles after the
diverse, high-quality academic resources essential for the identification phase was .695
comprehensive exploration of current studies. B. Screening Phase
2) Selecting keywords: In the keyword selection phase of Following the identification phase, the screening phase
the Systematic Literature Review (SLR) on cybersecurity involved a detailed review of the title and abstract of each
awareness in schools, specific research questions were identified selected article 5 95articles met the criteria during this phase and
to guide the research process. were advanced to the subsequent eligibility phase. The screening
was conducted using new inclusion and exclusion criteria
- To explore practices for improving cybersecurity specifically tailored for this stage, as outlined below.
awareness in schools, (“cybersecurity” OR
“security” OR “cybersecurity”) AND (“awareness” Inclusion and Exclusion Criteria: During this phase of the
OR “learning”) AND (“framework” OR “model”), PRISMA systematic review, criteria to refine the selection of
and Added Educational Context More detailed articles were applied. Only studies that specifically focused on
(“Education Sector”, “Academy”, “School” or cybersecurity awareness within educational settings were
“Educational Institution”) were used. included, as articles that did not directly focus on cybersecurity
awareness within educational settings were excluded. For
- Regarding the current problems and challenges that example, the study by Renaud & Ophoff, which explored
schools face in implementing cybersecurity cybersecurity implementation in SMEs rather than educational
awareness programs, the keywords (“challenges of institutions, was excluded [22]. Additional exclusions included
cybersecurity education” OR “barriers to works such as those reported in Reference, Although it presents
cybersecurity training” OR “cyber threats”) and a cybersecurity awareness framework based on the behaviour
(“education sector”) were used. change wheel, did not specifically target educational settings
[23]. When information was missing or unclear, assumptions
- For the target audience in cybersecurity awareness were made based on the available data. For instance, if a study
assessments, the keywords (“cybersecurity” OR did not specify the age range of students but was conducted in
“security” OR “cybersecurity”) AND (“awareness” primary schools, it was assumed that the participants were aged
OR “learning”) AND (“assessment” OR 5–12 years, based on common educational structures. Similarly,
“evaluation”) were used. for studies with incomplete intervention details, those elements
were excluded from the analysis unless sufficient information
These keywords were carefully selected to ensure justified their inclusion. This criterion led to the exclusion of 252
comprehensive coverage and relevance to the study's specific records that solely addressed information security awareness,
areas of investigation.
469 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
cybersecurity awareness, or other general security issues educational settings, particularly schools, highlighting the
without a direct educational context. challenge of finding research that focuses exclusively on the
educational context, especially in schools. A careful selection
C. Eligibility Phase and exclusion process ensures that the final set of articles
A total of 344 articles that successfully passed the second strongly represents the most relevant and up-to-date research
screening stage were chosen for in-depth full-text review during regarding cybersecurity awareness in schools, thus providing a
the eligibility stage. All articles were accessed, and the solid foundation for identifying effective strategies and
established filtering criteria were applied to evaluate each article challenges specific to this educational context. In addition, a
at this stage. group of articles was excluded due to a lack of access to the full
Inclusion and Exclusion Criteria: During the eligibility text, which will be illustrated in Fig. 1. Given that the studies
phase of the PRISMA systematic review, stringent criteria were evaluated during the Q1-2 phases are peer-reviewed, validated
applied to refine the selection of articles, focusing on studies articles that have been thoroughly evaluated and reviewed by
specifically within the context of schools to ensure alignment referees, issues of bias due to missing data were not encountered.
with the research aim. For example, the framework proposed in This rigorous selection process ensures the reliability and
[24] for assessing cybersecurity maturity in higher education integrity of the systematic review findings, providing a solid
institutes (HEIs) in the UK, despite its comprehensive approach foundation for identifying effective strategies and challenges
and use of recognized Capability Maturity Model (CMM) specific to cybersecurity awareness in schools.
methodology, was excluded due to its specific focus on higher D. Included Phase
education. Rather than the specific educational context All articles that successfully passed the third eligibility stage
(schools), this careful selection process resulted in a significant were carried forward into the final in-depth analysis of this
reduction in eligible articles. This drastic decline stems from the study. Consequently, 14 articles that met all the criteria of this
overwhelming number of studies focusing on cybersecurity in search were included for detailed examination.
470 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
IV. RESULTS AND ANALYSIS extensively used to foster engaging and interactive cybersecurity
education, enhancing learning experiences by employing real-
The results of this systematic review are presented based on world scenarios and relevant challenges. This approach is
the research questions through the analysis of the included particularly effective in engaging children and enhancing their
studies (n = 14). Fig. 2 shows the distribution of the studied understanding of cybersecurity concepts [25].Techniques such
articles over the years in which they were published, these as the use of a web-based Learning Content Management
studies span from 2020 to 2024. System (LCMS) and mobile apps provide game-based
cybersecurity education that captivates students' interest through
Articles distribution by publication years interactive gameplay, which is crucial in maintaining student
6
engagement and reinforcing cybersecurity [26]. Additionally,
the gamified framework "Cyber-Hero" incorporates narrative
4 techniques with serious games to offer an immersive learning
2 experience that emphasizes critical cybersecurity skills, such as
creating robust passwords and understanding online threats [27].
0
2020 2021 2022 2023 2024 Tailored educational programs and comprehensive
integration of cybersecurity into curricula are fundamental to
Fig. 2. Articles distribution by publication years. creating a robust educational foundation. Segmented
educational programs cater to specific demographic groups such
While Fig. 3 shows the classification of the types of studied
as students, teachers, and parents, ensuring that each group
articles:
receives relevant and effective cybersecurity knowledge [28].
Furthermore, the integration of cybersecurity topics throughout
Systematic all K-12 levels ensures that students develop a comprehensive
Literature understanding from an early age, which is crucial for building a
Review solid cybersecurity foundation [29].
Quasi- 3
Qualitative
experimental 2.5 Comprehensive cybersecurity education also involves the
Study
research with… 2 integration of national cybersecurity strategies into school
Quantitative 1.5
curricula to align educational efforts with broader national
and Qualitative 1 Survey Study
Survey 0.5 security objectives [30]. Narrative-based learning techniques,
0 which use storytelling and problem-solving to enhance
Developmental
Cross-sectional
engagement and understanding, are also highlighted as effective
and Evaluative methods in making cybersecurity education more relatable and
survey
Study effective [11] [31].
Systematic
Research Study Literature Enhanced training programs for teachers and parents are
Review (SLR) critical to equipping them with the necessary skills to effectively
Qualitative
Study (Focus impart cybersecurity knowledge and oversee children's online
Groups) activities. These training programs not only enhance teachers'
ability to teach cybersecurity effectively but also empower
parents to supervise their children's online interactions more
Fig. 3. The classification of the types of studied articles. effectively [29]. Regular training sessions for both educators and
parents help to ensure that children are adequately supervised
Addressing bias in systematic reviews and educated about the risks and safety measures associated with
- Consultation with Experts: Collaboration with cyber activities [31] [32]. Additionally, the development of E-
experts in the field of cybersecurity education was Safety frameworks that address ICT risks and the incorporation
done to uncover any overlooked or insufficiently of feedback mechanisms into cyber wellness programs help
reported elements of cybersecurity awareness monitor and control the effectiveness of cybersecurity
initiatives. education, adapting to new challenges and ensuring the safety of
learners [33] [28]. Curriculum content that is framed around
- The comprehensiveness of Reporting: Each study's broad categories and uses innovative teaching methods like
reporting thoroughness was meticulously evaluated. gamification not only enhances learning but also encourages
Any discrepancies were looked for where expected active participation from students, making the learning process
results or data were absent and unaccounted for in both enjoyable and educational [34]. Finally, the
the reports. recommendations for interactive and practical teaching methods
aim to engage students effectively and ensure that cybersecurity
RQ1: what are effective practices to improve Cybersecurity education evolves in response to new cybersecurity challenges,
awareness in schools? thus maintaining its relevance and effectiveness in educating
Digital comics, serious games, and mobile applications are young learners [11]
471 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
study
Ref Authors & year Study type Practices
appraisal
The review highlights multiple approaches to raising cybersecurity awareness
Farzana Quayyum Systematic among children. These include digital comics, serious games, and mobile apps
[25] , Daniela S. Cruzes, Q1 Literature focused on cybersecurity education. It emphasizes engaging children through
Letizia Jaccheri (2021) Review interactive learning that covers internet fundamentals, privacy awareness, and risk
management strategies.
The research utilizes detailed surveys to identify specific gaps in cyber wellness
knowledge among students, teachers, and parents. Based on survey results, it
recommends tailored educational interventions that address these specific
knowledge gaps. Key practices include 1. Segmented Educational Programs:
Developing age and role-specific educational materials that cater specifically to
T€urkera, Mıhcı and
Cross-sectional students, teachers, or parents. 2. Interactive Learning Modules: Implementing
[28] C¸akmakb, Ebru Kılıc¸ Q2
survey interactive and engaging learning modules that cover key topics like netiquette,
(2020)
cyberbullying, and online privacy practices. 3. Awareness Campaigns: Running
targeted awareness campaigns that encourage safe and responsible internet use,
focusing on the risks of internet addiction and the importance of copyright laws. 4.
Feedback Mechanisms: Incorporating feedback mechanisms to continuously assess
and improve the effectiveness of cyber wellness programs.
The review suggests several targeted practices to enhance cybersecurity awareness:
1. Development of clear and consistent terminology across cybersecurity education
Ahmed Ibrahim, to standardize teaching materials.
Systematic
Marnie McKee, Leslie 2. Incorporation of cybersecurity topics into curricula at all K-12 levels, ensuring a
[29] Q1 Literature
F. Sikos, Nicola F. comprehensive understanding from a young age.
Review (SLR)
Johnson (2022) 3. Enhanced teacher training programs to provide educators with the necessary
skills and knowledge to effectively teach cybersecurity. 4. Use of interactive and
practical learning modules to engage students and reinforce cybersecurity concepts
Inclusive Education Programs: Implement specialized cybersecurity education
programs that account for the diverse needs of ASN students, emphasizing practical
Stephanie Bannon,
Qualitative strategies to manage online risks. Parent and Teacher Training: Provide training for
Tracy McGlynn,
[32] Q1 Study (Focus parents and teachers on how to support ASN students in navigating online spaces
Karen McKenzie,
Groups) safely. Development of Tailored Online Safety Rules: Create school policies that
Ethel Quayle (2024)
address the specific online safety needs of ASN students, ensuring that they are
comprehensible and enforceable.
Mohamed Ayyash, Integration of Cybersecurity in Curriculum: Implement comprehensive
Tariq Alsboi, Omar cybersecurity education in schools. Narrative-based Learning: Emphasize
Alshaikh, Isa Inuwa- storytelling, problem-solving, and video-based teaching methods to enhance
[31] Q1 Survey Study
Dutse, Saad Khan, and engagement and understanding. Parent and Teacher Workshops: Organize regular
Simon Parkinson training for parents and teachers to equip them with effective strategies to supervise
(2024) and educate children on cybersecurity.
Curriculum Improvement: Based on the study's findings, schools can enhance their
Ana Kovačević, curriculum to include more comprehensive cybersecurity education, focusing on
[35] Nenad Putnik, Oliver Q1 Survey Study practical knowledge and secure behaviors. Educational Programs: Development of
Tošković (2222) targeted educational programs that address identified gaps in student knowledge and
behaviors.
Rahime Belen Sağlam, - Curriculum content framed around six broad categories
Systematic
Vincent Miller, -Innovative teaching methods like gamification for a 'hands-on' experience.
[34] Q1 Literature
Virginia N. L. - Engaging students in curriculum design
Review
Franqueira (2023) - Incorporating a 'bottom-up' approach listening to children’s views.
Abel Moyo, Theo
- Development of an E-Safety framework to teach and safeguard learners from ICT-
Tsokota, Caroline
Qualitative related risks.
[36] Ruvinga, Colletor T. Q1
Research - Integration of cybersecurity knowledge into school curricula.
Chipfumbu
- Continuous education, monitoring, and control of ICT use.
Kangara(2021)
- The study found that parents often discuss online security with their children at
Farzana Quayyum, home, using real-world incidents reported in the media as teachable moments.
Jonas Bueie, Daniela - Schools in Norway enhance cybersecurity awareness by collaborating with
Qualitative
[37] S. Cruzes, Letizia Q1 organizations like Barnevakten, Bruk Hue, and Medietilsynet. These organizations
Study
Jaccheri, Juan Carlos assist in providing targeted cybersecurity training and lectures, not just for students
Torrado Vida (2021) but also for teachers and parents, fostering a comprehensive educational
environment.
- A new educational method is presented, the Gamification Framework (Cyber-
Hero), which utilizes a specially designed gamified framework to boost early
Hani Qusa, Jumana cybersecurity training in high schools.
[27] Q1 Research Study
Tarazi (2021) - This framework incorporates narrative instruction into serious games, which are
strategically used to teach critical cybersecurity concepts, such as creating strong
passwords. This method aims to make learning both engaging and effective.
472 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
473 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
understanding of cybersecurity across all stakeholders. The Intervention and Training Impact [11]
disparities in awareness based on demographic factors such as
gender, class, and daily internet usage necessitate tailored Intervention and Training Impact 1
educational efforts to ensure that all students, regardless of Monitoring and Control… 1
background, receive adequate and effective cybersecurity Engagement and Methodology… 2
training [28] [29] [35]. Human and Resource… 2
Human and Resource Limitations: Knowledge and Awareness Gaps 3
Parental Involvement and… 2
Human error is identified as a significant vulnerability in Comprehensive Curriculum… 3
cybersecurity, exacerbated by a shortage of trained specialists
within the educational sector. This shortage hampers the ability 0 1 2 3 4
of schools to develop and deliver effective cybersecurity Number of references
education, further strained by inadequate resources. Addressing
these limitations requires not only more specialized training for
educators but also sufficient funding to ensure that schools can Fig. 5. Challenges of cybersecurity awareness.
afford to implement robust cybersecurity programs [27] [30].
RQ3: Who is the target audience in the current assessment
Engagement and Methodology Effectiveness: of cybersecurity awareness?
Keeping students engaged in cybersecurity learning is a The current assessment of cybersecurity awareness (Fig. 5)
major challenge, particularly for younger audiences who may comprehensively addresses a diverse array of target audiences,
find traditional methods unappealing. The effectiveness of each identified as critical in the ongoing efforts to enhance
various training methodologies varies widely, and contradictory cybersecurity education. Primary school students are among the
findings in research on optimal training methods create youngest learners, and their engagement is facilitated through
confusion about the best approaches to take. This situation calls digital tools such as comics, serious games, and mobile
for continuous experimentation and adaptation of teaching applications. These tools are essential in introducing
strategies to find what works best in different educational foundational cybersecurity concepts in an age-appropriate and
contexts [26] [13] engaging manner, fostering early awareness and safe online
behaviours [26] [25]. Secondary and high school students
Monitoring and Control Difficulties: represent a slightly older demographic that faces more complex
Implementing effective digital monitoring in schools online risks, including cyberbullying, online privacy issues, and
involves navigating complex privacy issues and technical password security. For these students, educational programs
challenges. Schools must balance the need to monitor students’ often incorporate interactive and gamified learning experiences
online activities to ensure their safety with the need to respect designed to maintain their engagement while reinforcing critical
privacy rights. Effective policies and tools are needed to cybersecurity skills. These approaches are tailored to address the
navigate these waters successfully, which requires ongoing developmental and cognitive abilities of this age group, ensuring
dialogue among educators, parents, and policymakers [33] that the learning is both relevant and effective [28][33][27][30].
Teachers are a pivotal audience in this context, as they are the
Intervention and Training Impact: primary facilitators of cybersecurity education within schools.
The impact of cybersecurity interventions and training Training programs for teachers are therefore crucial, providing
programs varies widely, with some interventions showing them with the necessary knowledge and pedagogical tools to
limited effects on long-term behavioural changes and awareness effectively deliver cybersecurity education. Such programs also
among children. The success of these interventions often hinges emphasize the importance of continuous professional
on their duration and intensity. Well-designed, sustained development, enabling teachers to stay updated with the latest
programs that are integrated into the regular curriculum are more cybersecurity trends and threats [28][31][33]. Meanwhile,
likely to have a lasting impact, highlighting the need for parents are recognized as the first line of defense in a child's
continuous evaluation and adaptation of these programs to meet online life. However, many parents lack the requisite knowledge
evolving educational needs [11]. and tools to effectively monitor and guide their children's online
activities. Studies recommend targeted training for parents to
TABLE II. ANALYSIS OF CHALLENGES OF CYBERSECURITY AWARENESS improve their understanding of cybersecurity risks and how to
IN SCHOOL communicate these risks effectively to their children, thereby
challenges No. references
extending cybersecurity education from the classroom to the
Comprehensive Curriculum and Effective
home environment [31][37]
[25] [34] [26]
Educational Approaches Curriculum designers and policymakers play a strategic role
Parental Involvement and Supervision [31] [37] in shaping the educational landscape to include comprehensive
Knowledge and Awareness Gaps [28] [29] [35] cybersecurity education. Their responsibility involves
integrating cybersecurity topics into the broader educational
Human and Resource Limitations [27] [30]
curriculum, ensuring that these efforts are aligned with national
Engagement and Methodology Effectiveness [26] [13] security objectives and are adaptable to the rapidly evolving
Monitoring and Control Difficulties [36] digital threats [29] [11]. Additionally, in the corporate sector,
corporate trainers and HR professionals are identified as key
474 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
audiences for cybersecurity training. These professionals are challenges such as inconsistencies in curricular content,
tasked with implementing training programs that not only insufficient parental involvement, and resource constraints
educate employees about cybersecurity risks but also engage persist as significant barriers. The review underscores the
them through innovative methods such as game-based learning, necessity of tailoring cybersecurity practices to diverse target
which has been shown to enhance the effectiveness of these groups, including students, teachers, parents, and policymakers,
programs[13]. Finally, cybersecurity professionals are a crucial to develop a comprehensive and resilient cybersecurity
audience, as they are directly involved in protecting education framework. Crucially, the practices identified in the
organizations from cyber threats. literature varied substantially depending on the target audience,
leading to a wide range of specific outcomes for each group. The
The studies underscore the need for advanced educational certainty of the evidence was evaluated, with particular attention
frameworks tailored to these professionals, focusing on to directness, ensuring that the findings closely aligned with the
developing their skills to address the dynamic and complex research questions and provided a robust foundation for the
nature of cyber threats. These frameworks are designed to recommendations, despite some variations in study design and
enhance the preparedness of cybersecurity teams, ensuring they reporting rigor.
are equipped to handle real-world challenges effectively
[30][13]. V. DISCUSSION
This comprehensive, multi-audience approach to The findings from this systematic literature review reveal
cybersecurity awareness is critical in creating a resilient several dimensions of cybersecurity awareness in schools,
educational ecosystem that prepares all relevant stakeholders to emphasizing both effective practices and persistent challenges.
navigate the digital world safely and responsibly. The necessity for comprehensive and adaptable cybersecurity
curricula is underscored, reflecting a critical need to bridge the
TABLE III. ANALYSIS OF TARGET AUDIENCES gap between the evolving demands of the digital world and
current educational offerings. This aligns with Blažič & Blažič,
Category Reference Numbers
2022 [38], who highlight the disconnect between educational
Primary School Students [26][25] content and the realities of digital threats, suggesting a pressing
Secondary School Students [28] [34] [36] [27] need for curriculum updates that mirror current technological
landscapes. Innovative teaching methods, particularly those
K-12 Students [29]
incorporating interactive tools like serious games and mobile
Children Aged 13-15 [11] apps, have proven effective. These methods resonate with
Special Needs Students [32] findings from Jin et al., 2018, who confirm the efficacy of game-
based learning in engaging students and enhancing their
Teachers [28] [36] [31] understanding of complex cybersecurity concepts [39].
Parents [31] [37] However, the review also points to significant barriers in the
Curriculum Designers and development and implementation of such curricula, notably the
[26] [29] [11] inconsistency across educational programs which leads to gaps
Policymakers
Cybersecurity Professionals [30] [13]
in cybersecurity knowledge and preparedness, as discussed by
Lehto, 2022, this inconsistency can leave students
underprepared for the cybersecurity challenges they face [40].
Primary
Cybersecurit Target Audiences School Furthermore, the review brings attention to the necessity of
y Students inclusive education strategies, particularly for students with
Professional 10% Additional Support Needs (ASN). Ensuring that cybersecurity
s
Curriculum
11%
education is accessible to all students is crucial, a sentiment
Secondary
Designers School
echoed by Ondrušková & Pospíšil, 2023 , who stress the
and Students importance of tailored approaches for students with special
Policymaker 21% needs to safely navigate the digital world [11]. Parental
s K-12 engagement emerges as another vital component. The
16% Students
Parents effectiveness of cybersecurity education often hinges on the
Special Children
5%
11% Needs Aged 13- support and knowledge of parents, yet many lack the necessary
Teachers Students skills to guide their children in safe online behaviors, a gap
15
16% 5% 5% highlighted by Al-Naser et al., 2019 emphasizes the need for
programs that not only educate students but also empower
Fig. 6. Target audiences for cybersecurity awareness.
parents with the necessary cybersecurity knowledge[41].
This systematic review systematically explores key Additionally, the review identifies widespread gaps in
practices, challenges, and target audiences (Fig. 6) in advancing knowledge among students, teachers, and parents, exacerbated
cybersecurity awareness within educational institutions. The by unclear cybersecurity terminology and a lack of systematic
findings demonstrate that strategies such as the integration of teaching approaches. This challenge is supported by O’Brien,
digital tools, embedding cybersecurity within K-12 curricula, 2019, who notes that the absence of standardized cybersecurity
and targeted training for educators and parents significantly curricula in public schools underscores a widespread
enhance student engagement and comprehension. However, educational deficiency [42].
475 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
Demographic factors such as age, gender, and internet usage assessments, establishing partnerships with cybersecurity
habits also influence cybersecurity awareness, necessitating organizations, and promoting safe online practices.
more personalized educational interventions to address these Implementing these recommendations can significantly enhance
disparities, as noted by Fatokun et al., 2019, this approach cybersecurity awareness among students, educators, and
ensures that cybersecurity education is effective and inclusive, parents, creating a safer online environment.
catering to the diverse needs of all students [43].
VII. STUDY LIMITATIONS
Moreover, the scarcity of trained cybersecurity specialists
and adequate funding further constrains the ability of schools to Despite the comprehensive approach taken in this systematic
offer effective cybersecurity education, a situation highlighted literature review, several limitations must be acknowledged. The
by Catota et al., 2019 argue for increased investment in both scope was confined to studies published in the past five years
human resources and financial support to enable the and limited to peer-reviewed articles in English, potentially
development of comprehensive cybersecurity programs [44]. excluding valuable insights from earlier research, non-English
Issues of privacy and the need for effective digital monitoring publications, and grey literature. The selected databases,
are also discussed, pointing out the increasing complexity of although extensive, may not encompass all relevant studies,
maintaining privacy in an age of widespread digital especially those in lesser-known journals or emerging sources,
surveillance[45]. This complexity necessitates clear policies and leading to an incomplete representation of the current state of
careful decision-making to balance safety and privacy rights cybersecurity awareness in schools. The PRISMA framework
effectively. Lastly, the variable impact of cybersecurity relies heavily on the quality and reporting standards of included
interventions is noted, with some programs significantly studies, so any deficiencies directly impact the reliability and
enhancing awareness and behavior, while others show limited generalizability of the findings. Additionally, the exclusion of
long-term effects. Nasir, 2023 supports this observation, articles due to lack of full-text access or lower quality thresholds
suggesting that the effectiveness of cybersecurity education might have omitted pertinent studies. Potential bias introduced
programs can vary greatly depending on their design and by the subjective nature of the inclusion and exclusion criteria,
implementation, highlighting the need for well-structured, despite consistent application efforts, could influence the final
sustainable initiatives[46]. selection of articles. Furthermore, the review did not deeply
analyze the diverse educational contexts and varying levels of
Based on the discussion, this systematic literature review technological infrastructure across different regions and
outlines strategies to boost cybersecurity awareness across countries, which means the applicability of certain findings and
educational levels through adaptable curricula incorporating key recommendations may be limited or require adaptation to fit
cybersecurity concepts and evolving through expert specific local contexts. Addressing these limitations in future
collaboration. It emphasizes creating targeted programs to research will be essential to developing a more comprehensive
enhance parental awareness, designing inclusive curricula with and nuanced understanding of cybersecurity awareness in
interactive tools like comics and games, and engaging the schools, enhancing the effectiveness of educational strategies
community through regular outreach. Recommendations and interventions across diverse settings.
include ongoing professional development for teachers, regular
curriculum assessments, and partnerships with cybersecurity Funding statement:
organizations to keep educational content current. Additionally, This research did not receive any specific grant from funding
establishing clear online safety policies is advocated to ensure a agencies in the public, commercial, or not-for-profit sectors. All
secure learning environment. These measures aim to prepare resources utilized were provided by the authors' own efforts.
students, teachers, and parents to confidently navigate digital
challenges, underscoring the need for continuous research to Registration Information:
keep educational practices up-to-date with the digital landscape. The review was not registered in any systematic review
VI. CONCLUSION protocol registry.
The systematic literature review on cybersecurity awareness Review Protocol Access:
in schools reveals critical issues and effective practices No protocol was prepared for this systematic review.
necessary for improving cybersecurity education. Key
challenges include the lack of a consistent and comprehensive Amendments to Protocol or Registration:
curriculum, inadequate parental supervision and knowledge, and
the diverse needs of students, especially those with additional As no protocol was prepared or registered, there were no
support needs (ASN). Effective practices identified include amendments related to registration or protocol.
using interactive educational tools, tailored interventions, Competing Interests
gamification, and narrative-based learning. Additionally,
community involvement and continuous improvement of There are no competing interests to declare. No financial,
cybersecurity programs are essential. Recommendations include personal, or professional conflicts influenced the conduct,
developing standardized curricula, enhancing parental results, or reporting of this systematic review.
education, tailoring programs for diverse needs, using Availability of Data, Code, and Other Materials:
interactive tools, implementing innovative teaching methods,
fostering community involvement, providing ongoing This systematic review exclusively involves the inclusion
professional development for educators, conducting regular and analysis of previously published studies. No new data,
476 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
analytic code, or other materials were generated for this review. [19] M. J. Page et al., “The PRISMA 2020 statement: an updated guideline for
Therefore, there are no additional materials available for public reporting systematic reviews.,” BMJ, vol. 372, p. n71, Mar. 2021, doi:
10.1136/bmj.n71.
access. All relevant data have been extracted from the included
[20] Li T, Higgins JPT, and Deeks JJ (editors)., “Chapter 5: Collecting data |
studies and are presented within the manuscript. Cochrane Training,” in Cochrane Handbook for Systematic Reviews of
Interventions version 6.2 (updated February 2021)., 2021.
REFERENCES
[21] R. Hamdi, “CYBERSECURITY AWARENESS IN SAUDI ARABIA: A
[1] M. Bada and J. R. C. Nurse, “Chapter 4 - The social and psychological SYSTEMATIC LITERATURE REVIEW,” 14th International Conference
impact of cyberattacks,” V. Benson and J. B. T.-E. C. T. and C. V. on Education and New Learning Technologies. pp. 4805–4815, 2022.
Mcalaney, Eds. Academic Press, 2020, pp. 73–92. doi: [22] K. Renaud and J. Ophoff, “A cyber situational awareness model to predict
[Link] the implementation of cyber security controls and precautions by SMEs,”
[2] B. Pranggono and A. Arabo, “COVID-19 pande.. cybersecurity issues,” Organ. Cybersecurity J. Pract. Process People, vol. 1, no. 1, pp. 24–46,
Internet Technol. Lett., vol. 4, no. 2, p. e247, Mar. 2021, doi: 2021.
[Link] [23] M. Alshaikh, H. Naseer, A. Ahmad, and S. B. Maynard, “Toward
[3] M. Muthuppalaniappan and K. Stevenson, “Healthcare cyber-attacks and sustainable behaviour change: an approach for cyber security education
the COVID-19 pandemic: An urgent threat to global health,” Int. J. Qual. training and awareness,” 2019.
Heal. Care, vol. 33, no. 1, pp. 1–12, 2021, doi: 10.1093/intqhc/mzaa117. [24] A. Aliyu et al., “A holistic cybersecurity maturity assessment framework
[4] S. A. Jawaid, “Cyber Security Threats to Educational Institutes: A Growing for higher education institutions in the United Kingdom,” Appl. Sci., vol.
Concern for the New Era of Cybersecurity,” Int. J. Data Sci. Big Data 10, no. 10, p. 3660, 2020.
Anal., vol. 2, no. 2, 2022, doi: 10.51483/ijdsbda.2.2.2022.11-17. [25] F. Quayyum, D. S. Cruzes, and L. Jaccheri, “Cybersecurity awareness for
[5] S. M. Zurkarnain and A. A. Abdulsahib, “Investigating The Correlation children: A systematic literature review,” Int. J. Child-Computer Interact.,
between The Five Major Personality Traits and a Student’s Online Habits,” vol. 30, p. 100343, 2021, doi: 10.1016/[Link].2021.100343.
Asia-Pacific J. Inf. Technol. Multimed., vol. 12, no. 01, pp. 57–69, 2023, [26] F. Giannakas, A. Papasalouros, G. Kambourakis, and S. Gritzalis, “A
doi: 10.17576/apjitm-2023-1201-04. comprehensive cybersecurity learning platform for elementary education,”
[6] A. Arifin, U. Mokhtar, Z. Hood, S. Tiun, and D. Jambari, “Parental Inf. Secur. J., vol. 28, no. 3, pp. 81–106, 2019, doi:
Awareness on Cyber Threats Using Social Media,” J. Komun. Malaysian 10.1080/19393555.2019.1657527.
J. Commun., vol. 35, pp. 485–498, Jun. 2019, doi: 10.17576/JKMJC-2019- [27] H. Qusa, “Cyber-Hero : A Gamification framework for Cyber Security
3502-29. Awareness for High Schools Students,” pp. 677–682, 2021.
[7] M. J. A. Rahman, M. I. Hamzah, M. H. M. Yasin, M. M. Tahar, Z. Haron, [28] P. Mıhcı Türker and E. Kılıç Çakmak, “An Investigation of Cyber Wellness
and N. K. E. Ensimau, “The UKM Students Perception towards Cyber Awareness: Turkey Secondary School Students, Teachers, and Parents,”
Security,” Creat. Educ., vol. 10, no. 12, pp. 2850–2858, 2019, doi: Comput. Sch., vol. 36, no. 4, pp. 293–318, 2019, doi:
10.4236/ce.2019.1012211. 10.1080/07380569.2019.1677433.
[8] B. M. Dioubate, W. D. W. Norhayate, Z. F. Anwar, S. Fauzilah, H. M. Faiz, [29] A. Ibrahim, M. McKee, L. F. Sikos, and N. F. Johnson, “A Systematic
and L. O. Hai, “The Role of Cybersecurity on the Performance of Review of K-12 Cybersecurity Education Around the World,” IEEE
Malaysian Higher Education Institutions,” J. Pengur., vol. 67, pp. 31–41, Access, vol. 12, pp. 59726–59738, 2024, doi:
2023, doi: 10.17576/pengurusan-2022-67-03. 10.1109/ACCESS.2024.3393425.
[9] S. S. I. Rahim, M. I. M. Huda, S. Sa’ad, and R. Moorthy, “Cyber Security [30] S. Aldaajeh, H. Saleous, S. Alrabaee, E. Barka, F. Breitinger, and K. R.
Crisis/Threat: Analysis of Malaysia National Security Council (NSC) Choo, “The Role of National Cybersecurity Strategies on the Improvement
Involvement Through the Perceptions of Government, Private and People of Cybersecurity Education,” 2022.
Based on the 3P Model,” vol. 1, no. 2, pp. 4–6, 2024.
[31] M. Ayyash, T. Alsboui, O. Alshaikh, I. Inuwa-Dute, S. Khan, and S.
[10] Y. Yuliana, “THE IMPORTANCE OF CYBERSECURITY Parkinson, “Cybersecurity Education and Awareness among Parents and
AWARENESS FOR CHILDREN,” Lampung J. Int. Law, vol. 4, pp. 41– Teachers: A Survey of Bahrain,” IEEE Access, vol. 12, no. May, pp.
48, Jun. 2022, doi: 10.25041/lajil.v4i1.2526. 86596–86617, 2024, doi: 10.1109/ACCESS.2024.3416045.
[11] D. Ondrušková and R. Pospíšil, “The good practices for implementation of [32] S. Bannon, T. McGlynn, K. McKenzie, and E. Quayle, “The internet and
cyber security education for school children,” Contemp. Educ. Technol., young people with Additional Support Needs (ASN): Risk and safety,”
vol. 15, no. 3, 2023. Comput. Human Behav., vol. 53, pp. 495–503, 2014, doi:
[12] S. Nehra and M. Deepanshi, “Cybersecurity Awareness and Education 10.1016/[Link].2014.12.057.
Programs : A Review of Effectiveness,” Int. J. Creat. Res. Thoughts, vol. [33] A. Moyo, T. Tsokota, C. Ruvinga, and C. T. Chipfumbu, “An E _ safety
11, no. 7, pp. 504–508, 2023. Framework for Secondary Schools in Zimbabwe,” Technol. Knowl.
[13] J. Prümmer, T. van Steen, and B. van den Berg, “A systematic review of Learn., no. 0123456789, 2021, doi: 10.1007/s10758-021-09545-y.
current cybersecurity training methods,” Comput. Secur., vol. 136, no. July [34] R. Belen and N. L. Virginia, “Kent Academic Repository A Systematic
2023, p. 103585, 2024, doi: 10.1016/[Link].2023.103585. Literature Review on Cyber Security Education for Children,” vol. 66,
[14] W. Buyu and B. Ogange, “Cybersecurity in Online Learning: Innovations 2023, doi: 10.1109/TE.2022.3231019.
for Teacher Training and Empowerment,” p. 6, 2021. [35] A. N. A. Kovačević, N. Putnik, and O. Tošković, “Factors Related to Cyber
[15] H. H. M. A. Al-Fatlawi, “Awareness of cyber security aspects in distance Security Behavior,” vol. 8, 2020, doi: 10.1109/ACCESS.2020.3007867.
education,” J. Pedagog. Sociol. Psychol., vol. 6, no. 1, 2024, doi: [36] A. Moyo, T. Tsokota, C. Ruvinga, and C. T. Chipfumbu, “An E ‑ safety
10.33902/jpsp.202424403. Framework for Secondary Schools in Zimbabwe,” Technol. Knowl.
[16] W. Triplett, “Addressing Cybersecurity Challenges in Education,” Int. J. Learn., no. 0123456789, 2021, doi: 10.1007/s10758-021-09545-y.
STEM Educ. Sustain., vol. 3, pp. 47–67, Jan. 2023, doi: [37] F. Quayyum, J. Bueie, D. S. Cruzes, L. Jaccheri, and J. Carlos,
10.53889/ijses.v3i1.132. “Understanding parents ’ perceptions of children ’ s cybersecurity
[17] D. A. Sareen and S. Jasaiwal, “Need of cyber security education in modern awareness in Norway,” vol. 1, no. 1, pp. 1–6, 2021.
times,” Int. J. Multidiscip. Trends, vol. 3, no. 2, pp. 188–191, 2021, doi: [38] B. J. Blažič and A. J. Blažič, “Cybersecurity Skills among European High-
10.22271/multi.2021.v3.i2c.179. School Students: A New Approach in the Design of Sustainable
[18] B. Kitchenham, O. Pearl Brereton, D. Budgen, M. Turner, J. Bailey, and S. Educational Development in Cybersecurity,” Sustain., vol. 14, no. 8, 2022,
Linkman, “Systematic literature reviews in software engineering – A doi: 10.3390/su14084763.
systematic literature review,” Inf. Softw. Technol., vol. 51, no. 1, pp. 7–15, [39] G. Jin, M. Tu, T.-H. Kim, J. Heffron, and J. White, “Evaluation of Game-
2009, doi: [Link] Based Learning in Cybersecurity Education for High School Students,” J.
477 | P a g e
[Link]
(IJACSA) International Journal of Advanced Computer Science and Applications,
Vol. 15, No. 12, 2024
Educ. Learn., vol. 12, no. 1, pp. 150–158, 2018, doi: Tertiary Institution Students: An Empirical investigation on Malaysian
10.11591/edulearn.v12i1.7736. Universities,” J. Phys. Conf. Ser., vol. 1339, no. 1, 2019, doi:
[40] M. Lehto, Development Needs in Cybersecurity Education : Final report of 10.1088/1742-6596/1339/1/012098.
the project, no. 96. 2022. [44] F. E. Catota, M. Granger Morgan, and D. C. Sicker, “Cybersecurity
[41] A. E. Al-Naser, A. Bushager, and H. Al-Junaid, “Parents’ awareness and education in a developing nation: The Ecuadorian environment,” J.
readiness for smart devices’ cybersecurity,” IET Conf. Publ., vol. 2019, no. Cybersecurity, vol. 5, no. 1, pp. 1–19, 2019, doi: 10.1093/cybsec/tyz001.
CP758, pp. 0–6, 2019, doi: 10.1049/cp.2019.0226. [45] D. J. Power, C. Heavin, and Y. O’Connor, “Balancing privacy rights and
[42] C. O’Brien, “TEACHERS’ PERCEPTIONS ABOUT USE OF DIGITAL surveillance analytics: a decision process guide,” J. Bus. Anal., vol. 4, no.
GAMES AND ONLINE RESOURCES FOR CYBERSECURITY 2, pp. 155–170, Jul. 2021, doi: 10.1080/2573234X.2021.1920856.
BASICS EDUCATION: A CASE STUDY,” no. January, pp. 1–19, 2019. [46] S. Nasir, “Exploring the Effectiveness of Cybersecurity Training
[43] F. B. Fatokun, S. Hamid, A. Norman, and J. O. Fatokun, “The Impact of Programs : Factors , Best Exploring the Effectiveness of Cybersecurity
Age, Gender, and Educational level on the Cybersecurity Behaviors of Training Programs : Factors , Best Practices , and Future Directions,” no.
August, 2023, doi: 10.22624/AIMS/CSEAN-SMART2023P18.
478 | P a g e
[Link]
A tailored approach is essential for cybersecurity education to ensure accessibility and effectiveness, particularly for students with Additional Support Needs (ASN). This approach accommodates diverse learning requirements and ensures that all students, regardless of their individual challenges, receive adequate training to safely navigate the digital world. Tailored strategies help to bridge the gap in cybersecurity understanding and preparedness, which is crucial for helping ASN students meet the same educational outcomes as their peers .
Parental involvement is crucial in reinforcing cybersecurity education at home because parents play a key role in overseeing children's online activities and supporting safe online practices. However, schools face challenges as many parents lack adequate cybersecurity awareness, which undermines their ability to effectively support their children's learning. To address this, schools must empower parents with the necessary tools and knowledge through training and regular updates about cybersecurity threats and practices .
The involvement of multiple stakeholders, including students, teachers, parents, and policymakers, enhances the resilience of cybersecurity education frameworks. Tailoring cybersecurity practices to diverse target groups ensures that the education provided is comprehensive and relevant. It encourages different perspectives and expertise, improving the overall quality and effectiveness of the education framework. Each group contributes uniquely to the understanding and implementation of cybersecurity measures, thus creating a more robust education system .
Schools face several challenges in implementing effective cybersecurity awareness programs, including the development of comprehensive curricula that can adapt to various learning needs, inconsistency in educational content, and insufficient parental involvement. The lack of clarity in cybersecurity terminology and the absence of systematic teaching methods particularly affect K-12 education. Additionally, there is a shortage of trained cybersecurity specialists and limitations in resources, which hamper schools' ability to deliver robust cybersecurity education .
Human and resource limitations significantly affect the ability to provide effective cybersecurity education in schools. A shortage of trained cybersecurity specialists limits the development and delivery of education programs. Additionally, inadequate resources can hinder schools' ability to implement robust educational frameworks. Addressing these challenges requires more specialized training for educators and sufficient funding to support the creation and maintenance of comprehensive cybersecurity programs .
Schools can adopt several strategies to bridge the gap between current educational offerings and the evolving demands of cybersecurity. These include developing comprehensive and adaptable curricula, incorporating innovative and interactive teaching methods, and integrating national cybersecurity strategies. Furthermore, continuous assessment and adaptation of educational content are necessary to keep up with evolving cyber threats. Schools should also engage in collaborations with multiple stakeholders, ensuring that educational practices remain relevant and effective .
E-Safety frameworks are crucial in continuously adapting and monitoring the effectiveness of cybersecurity education. They address ICT risks and incorporate feedback mechanisms to ensure educational practices remain relevant and effective. These frameworks allow for the evaluation and adjustment of cybersecurity programs in response to new challenges, which helps maintain the curriculum's relevance and effectiveness in educating young learners .
Interactive tools like serious games and mobile apps offer significant benefits in cybersecurity education, such as enhanced engagement and a better understanding of complex concepts through game-based learning. These tools make learning more accessible and enjoyable for students. However, challenges include ensuring consistent curricular content, integrating these tools effectively into different educational programs, and addressing disparities in access to technology, which can impact the uniform delivery of cybersecurity education .
Innovative teaching methods, such as narrative-based learning, gamification, and interactive digital tools, enhance student engagement in cybersecurity education by making learning more relatable, enjoyable, and effective. These methods actively involve students, thus maintaining their interest and improving their understanding of complex cybersecurity concepts. For example, storytelling and problem-solving techniques can be particularly effective in addressing varied learning styles and keeping students focused on cybersecurity topics .
Integrating national cybersecurity strategies into school curricula enhances the effectiveness of cybersecurity education by aligning educational efforts with broader national security objectives. This approach ensures that students are taught relevant and current cybersecurity knowledge in alignment with national priorities. It helps create a uniform standard of education across the board, which is crucial for building a solid cybersecurity foundation from an early age .