The digital transformation of higher education has increased reliance on information systems while expanding risks arising from employee behaviour. This study examines the effectiveness of security awareness training in shaping employees' understanding, awareness, compliance, and information security behaviour at Universitas Prasetiya Mulya. A qualitative single-case design was employed. Data were collected through semi-structured interviews with eight informants, expert judgement, a focus group discussion, observation, and document analysis, and were analysed through data condensation, data display, and conclusion drawing and verification. The findings indicate that, within the case examined, training was associated with improved risk understanding, stronger awareness that security is a shared responsibility, and more cautious practices when handling email, passwords, links, and documents. Behavioural change, however, remained inconsistent because only 135 of 336 employees had completed the training, while workload, established habits, limited post-training reinforcement, underdeveloped behavioural evaluation, and unclear reporting channels constrained transfer to daily work. The programme should therefore become mandatory and continuous, be integrated with human-resource development and onboarding, use microlearning and phishing simulations, and be evaluated through behavioural indicators.
Copyrights © 2026