Publication: Evaluating Cybersecurity Awareness in Sri Lankan Healthcare Sector: A Role-Based Training Framework for Public and Private Institutions
| dc.contributor.author | Hewamanna I.U.K | |
| dc.date.accessioned | 2026-02-10T08:37:44Z | |
| dc.date.issued | 2025-12 | |
| dc.description.abstract | This study investigates cybersecurity awareness within Sri Lanka’s healthcare sector and develops a role-based training framework to enhance awareness and secure digital practices across public and private healthcare institutions. As healthcare systems increasingly digitize, human factors remain a major vulnerability, particularly in environments with limited resources and inconsistent policy enforcement. A quantitative survey was conducted among healthcare professionals to assess their awareness levels, training exposure, institutional support, and perceptions of cybersecurity importance. Data collected through Google Forms were analyzed using Excel and Jamovi. Descriptive statistics, Independent Sample T-Tests, One-Way ANOVA, and Regression Analysis were employed to explore patterns and relationships across professional roles and institution types. Results revealed moderate awareness levels overall, with significant variation between public and private institutions and across roles, emphasizing the need for contextualized, role-specific training. Based on these findings, a Role-Based Cybersecurity Awareness and Training Framework was developed, aligned with NIST SP 800-50r1, the Personal Data Protection Act (2022), and Ministry of Health Information Security Guidelines (2023). Expert evaluation (n = 6) rated the framework highly for clarity, practicality, and policy alignment (mean score = 4.37/5). The study concludes that micro-learning modules, continuous reinforcement, and leadership involvement can significantly enhance cybersecurity culture in healthcare while minimizing operational disruption. The proposed framework offers a feasible, low-cost, and scalable model to strengthen human-centered cybersecurity resilience across Sri Lanka’s healthcare sector. | |
| dc.identifier.uri | https://rda.sliit.lk/handle/123456789/4591 | |
| dc.language.iso | en | |
| dc.publisher | Sri Lanka Institute of Information Technology | |
| dc.subject | Evaluating Cybersecurity | |
| dc.subject | Cybersecurity Awareness | |
| dc.subject | Sri Lankan Healthcare | |
| dc.subject | Healthcare Sector | |
| dc.subject | Role-Based Training | |
| dc.subject | Training Framework | |
| dc.subject | Public | |
| dc.subject | Private Institutions | |
| dc.title | Evaluating Cybersecurity Awareness in Sri Lankan Healthcare Sector: A Role-Based Training Framework for Public and Private Institutions | |
| dc.type | Thesis | |
| dspace.entity.type | Publication |
Files
Original bundle
1 - 2 of 2
- Name:
- Evaluating Cybersecurity Awareness in Sri Lankan Healthcare Sector 1-10.pdf
- Size:
- 280.58 KB
- Format:
- Adobe Portable Document Format
No Thumbnail Available
- Name:
- Evaluating Cybersecurity Awareness in Sri Lankan Healthcare Sector.pdf
- Size:
- 1.08 MB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 1.69 KB
- Format:
- Item-specific license agreed upon to submission
- Description:
