The purpose of this study is to investigate the smartphone security behavior of the students of a public university in Bangladesh by focusing on the security measures obtained and potential risky practices performed by them while using smartphones.
This study used a quantitative method for collecting data from the students using a purposive sampling technique. A total of 304 students participated in this study who use smartphones in their daily lives. A structured questionnaire was designed using Google Forms for collecting data. The collected data were analyzed using MS Excel and SPSS.
Most of the participants used two-factor authentication, biometric security features and strong and unique passwords for their important accounts and apps on their smartphones. They also performed potentially risky practices such as connecting to public Wi-Fi networks without using a virtual private network, downloading apps and files from unofficial sources and using public charging cables to charge smartphones. However, students’ smartphone security measures were greatly influenced by their gender, faculty/ institute, experience of using smartphones and type of internet connection used, and the performance of the risky practices varied based on their gender, age group and experience of using smartphones.
This study offers a unique contribution to the limited literature in Bangladesh by concentrating on university students’ smartphone security behaviors, encompassing both preventive strategies and risky habits.
Introduction
In recent years, smartphones have become part and parcel of our daily lives, revolutionizing communication, logistics, commerce and access to information (Thompson et al., 2017). Apart from call and text functions, smartphones provide a wide range of computing competencies and connectivity choices via numerous mobile applications (Nowrin and Bawden, 2018). The adoption of these applications has a significant impact on smartphone user behavior (Alfawareh and Jusoh, 2014).
Smartphone security is essential, especially considering how much we depend on these devices for online activities, communication and information access. According to Poongodi et al. (2020), mobile device security refers to the procedures put in place to protect sensitive information stored and transferred by computers, smartphones, tablets, wearables and other portable devices. To protect private information, prevent identity theft and lessen the risk of cyberattacks, we need to keep our smartphones safe as they carry more personal information than personal computers do (Bergman and Yanai, 2018). Smartphone security behavior refers to the actions, habits and practices individuals adopt to safeguard their mobile devices against potential threats, including malware, data breaches, unauthorized access and privacy violations. These behaviors encompass a range of actions such as using strong passwords, enabling two-factor authentication, keeping software updated, avoiding suspicious links or apps and using security features like biometric authentication (Chang and Coppel, 2020).
It is well acknowledged that implementing proper security technologies plays an important role in guaranteeing the information security of smartphone users (Ng et al., 2009; Esmaeili, 2014). However, security technologies cannot fully protect users’ information (Imgraben et al., 2014). Furthermore, it is widely recognized that individual users’ information security behaviors have a direct impact on smartphone security (Rhee et al., 2009).
Smartphone usage statistics in Bangladesh
Bangladesh, a burgeoning hub of technological adoption, has seen an exponential surge in smartphone usage across diverse demographics. The number of smartphone users is increasing day by day. According to the Bangladesh Telecommunication Regulatory Commission, more than 190 million people are using smartphones in 2023 (The Business Standard, 2023). As stated in the Global System for Mobile Communications Association, the number of smartphone users in Bangladesh will increase to 63% by 2025 from 47% last year (Tonmoy, 2022). However, this rapid integration of smartphones into societal lives has also brought some significant concerns regarding personal information and other privacy issues. Understanding the security threats for smartphones in Bangladesh, policymakers, industry stakeholders and cybersecurity professionals should be concerned the users.
Problem statement
Understanding behavioral patterns and identifying knowledge gaps are essential in formulating targeted strategies to enhance cybersecurity education and promote safe security practices (Hong and Furnell, 2021). Knowing how students engage with information in their everyday lives is also crucial for educators to know what to teach and how to teach it (Islam and Mostofa, 2015). Students utilize smartphone applications for a variety of academic purposes (Hossain and Ahmed, 2016; Woodcock et al., 2012), including social networking, online shopping and banking and email access, among others. Because of the rapid proliferation of smartphones, providing information security has become a significant concern for information security specialists and academics (Esmaeili, 2014).
Although previous studies, such as Nowrin and Bawden (2018), investigated the general information security behavior among students, there has been a scarcity of targeted investigations on smartphone-specific security practices in Bangladesh. The rapid growth of smartphone usage in Bangladesh, particularly among youth and university students, has raised concerns about mobile security and data privacy. Students frequently use smartphones for academic, financial and personal purposes, making them more exposed to digital attacks (Azad et al., 2025). However, there is little awareness about how these people protect their devices or engage in harmful behavior. This study intended to fill that vacuum by producing evidence-based insights that can be used to influence awareness efforts, digital literacy initiatives and institutional policies focused on enhancing mobile cybersecurity practices.
Objective and research questions
The main aim of the study is to investigate the security behavior of smartphone users among the students of a public university in Bangladesh. The following research questions (RQs) guided our study:
To what extent do university students adopt different smartphone security measures?
What are the potential risky practices performed by the students while using their smartphones?
How do smartphone security measures vary among different student groups in terms of their academic and demographic variables?
How do the potentially risky practices performed by the students while using smartphones vary based on their academic and demographic variables?
Literature review
Smartphone security measures adopted by users
Nowadays, smartphone security behavior has become a focal point in recent research endeavors. Researchers have investigated the information security behavior of smartphone users from different parts of the world and revealed noteworthy findings. For instance, Das and Khan’s (2016) study investigated the information security behaviors of 500 smartphone users within the Middle East. The research uncovered a trend of low adherence to security behaviors among these users. Giwah et al.’s (2020) empirical study investigated the information security behavior of 390 mobile device users and suggested that security training programs must be conducted and the users must be aware of the permissions they are giving to the apps they are using. Several previous studies have focused on the behavioral aspects of smartphone users from different perspectives. For example, Chen and Li (2017) surveyed to understand 384 mobile device users’ privacy and security assurance behavior from a technology threat avoidance perspective. In a quantitative study, Mi et al. (2020) aimed to reveal individual differences in 292 student smartphone users’ security behavior and revealed that the respondents weren’t concerned about their data privacy. Xiao (2021) conducted a comparative study to understand the asymmetric perceptions of smartphone security from a security feature perspective. Chin et al. (2021) studied how smartphone users select different applications, their comfort levels in performing different tasks and overall perceptions of the platform. Knapova et al. (2021) used the Protection Motivation Theory (PMT) in conjunction with the Health Belief Model to assess the factors that influence smartphone security behavior. The findings demonstrated that people who had less firsthand experience with a digital security incident, higher smartphone self-efficacy, a more general orientation and interest in digital security and a more severe perception of a potential threat to smartphone security reported more secure smartphone behavior. Similarly, recently Khan et al. (2025) used PMT to better understand smartphone users’ security behaviors. The findings demonstrated that the threat-appraisal component of the PMT did not influence the desire to protect a smartphone; however, reaction efficacy played a role in explaining smartphone security intention and behavior.
Security concerns and awareness among smartphone users
Some studies attempted to measure the level of awareness of smartphone users’ security concerns. For instance, Ophoff and Robinson (2013) investigated the awareness level of smartphone security among 619 South African general smartphone users. Results from this study indicated that the respondents perceived a high level of trust toward smartphone app stores, as they rarely consider privacy and security deliberations when installing new apps and inadequately adopt smartphone protection mechanisms. Koyuncu and Pusatli (2019) conducted an exploratory case study focusing on the security awareness level of smartphone users based on different groups according to their demographic data. The results showed that the awareness level of participants was very low, which needs continuous improvement. In a recent study, Taha and Dahabiyeh (2021) conducted an empirical study to compare college students’ information security behavior while using smartphones and computers. Results showed a high level of information security awareness among the students and they put more emphasis on protecting their mobiles compared to computers.
Risky practices performed by smartphone users
Very few studies investigated the risky practices performed by smartphone users. For instance, Knapova et al. (2021) highlighted the diverse factors influencing the smartphone security behavior of 331 Czech smartphone users. The study found that perceived vulnerability to security threats and previous digital security incidents did not predict smartphone security behavior, but general security orientation indirectly affected it. Alsaleh et al. (2017) explored how security mechanisms are perceived by smartphone users and revealed unforeseen correlations and dependencies between various privacy- and security-related behaviors of smartphone users. Zhang et al. (2017) conducted an empirical analysis regarding the information security behaviors of smartphone users in China. The study found that the users were not aware of smartphone security and they provided all the required permissions while downloading apps on their smartphones.
Differences in smartphone security awareness and behavior
Some of the previous research has focused on the smartphone and cybersecurity concerns of users and identified differences based on different academic and demographic factors. For example, Zhang et al. (2017) conducted an empirical analysis regarding the information security behaviors of smartphone users in China. The study revealed a significant difference between different age groups, digitally divided people and different classes of users on information security in smartphone use. Wahab et al. (2021) studied the behavior of smartphone internet users and found that behavior was positive in the younger generation’s perceptions but negative for the older generations. Zwilling et al.’s (2022) study focused on the cybersecurity awareness and behavior of smartphone users and found differences based on their country, gender and age. In an empirical study, Shah and Agarwal (2020) studied the cybersecurity behavior of 300 smartphone users in India. Results showed that the respondents did not exhibit good cybersecurity behavior and significant behavioral differences were found based on their gender, age and mobile operating system. Thompson et al. (2017) explored the determinants affecting security behaviors for home computers and mobile devices. The result indicated that the personal computing security intentions and behavior of both user groups were influenced by their age, self-efficacy, education levels, vulnerability and psychological ownership. Recently, Al-Saggaf and Maclean (2024) measured adolescents’ understanding of the security concerns of smartphone privacy breaches and found initially that females had less knowledge of smartphone settings than males.
In Bangladesh, while research such as Nowrin and Bawden (2018) has explored information security behavior among smartphone users, it addressed the topic broadly without specifically examining behaviors related to smartphone-specific risks. Conversely, the current study concentrates on particular smartphone security practices, including biometric authentication, public charging habits, virtual private network (VPN) usage and the installation of risky applications. In addition, it analyzes the impact of demographic and experiential factors on both secure and risky smartphone usage behaviors, an area previously unexamined in Bangladeshi studies. Besides, some research has been conducted exploring the academic use of smartphones by university students (Hossain and Ahmed, 2016), students’ use of smartphones for retrieving information from academic libraries (Elahi et al., 2018) and university websites (Yesmin and Atikuzzaman, 2023) and college students’ cybersecurity awareness (Azad et al., 2025). Apart from these few cases, no previous study has been found that has investigated the smartphone usage patterns and security behaviors focusing on the students of public universities in a developing country setting like Bangladesh. The present study aims to bridge this gap.
Methodology
The present study adopted a quantitative approach to investigate the stated topic. In this research, an online survey was conducted. All the responses were collected from the students of Noakhali Science and Technology University. Before data collection from the respondents, using Google Forms, a well-structured questionnaire was developed. It was delivered to the participants via email and social media platforms. The beginning of the questionnaire included a consent form with clear instructions. All the questions were self-developed by the investigators. Before starting the actual survey, the whole questionnaire was sent to two different experts for their observations and potential corrections. After that, the questionnaire was revised and finalized for data collection.
Study population and sample
The main population of this study consisted of undergraduate and graduate students from different faculties and institutes of Noakhali Science and Technology University. A purposive sampling technique was used to select participants who were known to use smartphones in their daily lives. At the very beginning of the questionnaire, the students were asked whether they used a smartphone. The students who confirmed using a smartphone were allowed to respond to the actual survey questions. Consideration was given to the participant’s willingness to participate in the survey. Initially, the questionnaire link was shared across different Facebook groups catering to students from the university. After that, it was disseminated through different messaging apps to the university students. Finally, the survey link was posted on the personal social networking walls. Additionally, the link was directly distributed to certain participants via email on their request. Here, the students shared their official email addresses (provided by the university) and the authors sent the questionnaire link to them via those emails. In this way, the questionnaire was distributed to around 500 students and 304 responses were retrieved, with a response rate of about 61%.
Data collection and analysis
It took place over more than one month for the data collection process, from the first week of November to the last week of December 2023. Microsoft Excel and SPSS version 25 were used to analyze the data. First, Microsoft Excel was used to clean and arrange the gathered data, and then simple descriptive summaries (such as frequencies and percentages) were created. The data set was then imported into SPSS for more complex statistical analyses, such as nonparametric tests to measure variations in smartphone security behavior according to academic and demographic factors.
Analysis of the study
Academic and demographic details of the students
A total of 304 students from different faculties and institutes of the university participated in the survey. Table 1 shows that the majority of the students participated from the Institute of Information Sciences (77, 25.3%), followed by the Faculty of Social Science and Humanities (14.1%) and the Faculty of Business Administration (38, 12.5%).
Faculty/institute of the students
| Faculty/institute name | Frequency | % |
|---|---|---|
| Institute of Information Technology (IIT) | 32 | 10.5 |
| Institute of Information Sciences (IIS) | 77 | 25.3 |
| Faculty of Engineering | 36 | 11.8 |
| Faculty of Science | 26 | 8.6 |
| Faculty of Social Science and Humanities | 43 | 14.1 |
| Faculty of Business Administration | 38 | 12.5 |
| Faculty of Education Sciences | 29 | 9.5 |
| Faculty of Law | 23 | 7.6 |
| Total | 304 | 100 |
| Faculty/institute name | Frequency | % |
|---|---|---|
| Institute of Information Technology ( | 32 | 10.5 |
| Institute of Information Sciences ( | 77 | 25.3 |
| Faculty of Engineering | 36 | 11.8 |
| Faculty of Science | 26 | 8.6 |
| Faculty of Social Science and Humanities | 43 | 14.1 |
| Faculty of Business Administration | 38 | 12.5 |
| Faculty of Education Sciences | 29 | 9.5 |
| Faculty of Law | 23 | 7.6 |
| Total | 304 | 100 |
The detailed demographic and academic information of the students is shown in Table 2. The majority of the participants were male students (212, 69.7%). More than half of them were from the 23–25 years age group (167, 54.9%), followed by the 19–22 years age group (114, 37.5%). fourth year students (101, 33.2%) consisted of the largest group in terms of study level. A significant proportion of the students had 7–9 years (114, 37.5%) of experience in using smartphones. The majority of them used both mobile data and Wi-Fi (173, 56.9%) to connect to the internet with their smartphones. Finally, almost two-thirds of the students (202, 66.4%) did not receive any formal training or participate in a workshop on smartphone security.
Demographic and academic details of the students
| Demographic and academic details | Frequency | % |
|---|---|---|
| Gender | ||
| Male | 212 | 69.7 |
| Female | 92 | 30.3 |
| Age group | ||
| 19–22 years | 114 | 37.5 |
| 23–25 years | 167 | 54.9 |
| Above 25 years | 23 | 7.6 |
| Study level | ||
| First year | 37 | 12.2 |
| Second year | 50 | 16.4 |
| Third year | 64 | 21.1 |
| Fourth year | 101 | 33.2 |
| Masters | 52 | 17.1 |
| Smartphone use experience | ||
| Less than 3 years | 17 | 5.6 |
| 3–5 years | 42 | 13.8 |
| 5–7 years | 93 | 30.6 |
| 7–9 years | 114 | 37.5 |
| Above 9 years | 38 | 12.5 |
| Type of internet connection used | ||
| Only mobile data | 100 | 32.9 |
| Only Wi-Fi | 31 | 10.2 |
| Both | 173 | 56.9 |
| Training/workshop on smartphone security | ||
| Yes | 102 | 33.6 |
| No | 202 | 66.4 |
| Demographic and academic details | Frequency | % |
|---|---|---|
| Gender | ||
| Male | 212 | 69.7 |
| Female | 92 | 30.3 |
| Age group | ||
| 19–22 years | 114 | 37.5 |
| 23–25 years | 167 | 54.9 |
| Above 25 years | 23 | 7.6 |
| Study level | ||
| First year | 37 | 12.2 |
| Second year | 50 | 16.4 |
| Third year | 64 | 21.1 |
| Fourth year | 101 | 33.2 |
| Masters | 52 | 17.1 |
| Smartphone use experience | ||
| Less than 3 years | 17 | 5.6 |
| 3–5 years | 42 | 13.8 |
| 5–7 years | 93 | 30.6 |
| 7–9 years | 114 | 37.5 |
| Above 9 years | 38 | 12.5 |
| Type of internet connection used | ||
| Only mobile data | 100 | 32.9 |
| Only Wi-Fi | 31 | 10.2 |
| Both | 173 | 56.9 |
| Training/workshop on smartphone security | ||
| Yes | 102 | 33.6 |
| No | 202 | 66.4 |
Security measures followed by the students while using the smartphone
The students were asked to rate their frequency of following different security measures while using their smartphones, on a five-point Likert scale. The mean and standard deviation of their responses are shown in Table 3. According to the results, most of the participants use two-factor authentication for safeguarding their important accounts on their smartphones, biometric (fingerprint, face recognition) security features to secure the data, as well as strong and unique passwords for their smartphones and apps. However, the mean scores of seven out of nine items were greater than the average mean score of 3, meaning that the students regularly follow these security measures while using their smartphones.
Security measures followed by the students while using their smartphones
| Smartphone security measures | Never | Rarely | Sometimes | Frequently | Always | Mean (SD) |
|---|---|---|---|---|---|---|
| I regularly update the operating system and apps | 7 (2.3) | 21 (6.9) | 83 (27.3) | 43 (14.1) | 150 (49.3) | 4.01 (1.12) |
| I use strong and unique passwords for my smartphone and apps | 12 (3.9) | 12 (3.9) | 57 (18.8) | 45 (14.8) | 178 (58.6) | 4.2 (1.118) |
| I use biometric (fingerprint, face recognition) security features in my phone | 15 (4.9) | 11 (3.6) | 48 (15.8) | 51 (16.8) | 179 (58.9) | 4.21 (1.138) |
| I carefully review app permissions during installation | 23 (7.6) | 18 (5.9) | 78 (25.7) | 61 (20.1) | 124 (40.8) | 3.81 (1.245) |
| I keep back-up of my important data | 16 (5.3) | 11 (3.6) | 81 (26.6) | 76 (25) | 120 (39.5) | 3.9 (1.128) |
| I use two-factor authentication for my important accounts | 13 (4.3) | 10 (3.3) | 48 (15.8) | 53 (17.4) | 180 (59.2) | 4.24 (1.101) |
| I use anti-virus software in my smartphone | 120 (39.5) | 30 (9.9) | 57 (18.8) | 33 (10.9) | 64 (21.1) | 2.64 (1.584) |
| I customize the privacy settings of my smartphone | 87 (28.6) | 23 (7.6) | 60 (19.7) | 48 (15.8) | 86 (28.3) | 3.08 (1.585) |
| I use remote management apps, i.e. TeamViewer, AnyDesk, etc. | 138 (45.4) | 31 (10.2) | 62 (20.4) | 29 (9.5) | 44 (14.5) | 2.38 (1.486) |
| Smartphone security measures | Never | Rarely | Sometimes | Frequently | Always | Mean ( |
|---|---|---|---|---|---|---|
| I regularly update the operating system and apps | 7 (2.3) | 21 (6.9) | 83 (27.3) | 43 (14.1) | 150 (49.3) | 4.01 (1.12) |
| I use strong and unique passwords for my smartphone and apps | 12 (3.9) | 12 (3.9) | 57 (18.8) | 45 (14.8) | 178 (58.6) | 4.2 (1.118) |
| I use biometric (fingerprint, face recognition) security features in my phone | 15 (4.9) | 11 (3.6) | 48 (15.8) | 51 (16.8) | 179 (58.9) | 4.21 (1.138) |
| I carefully review app permissions during installation | 23 (7.6) | 18 (5.9) | 78 (25.7) | 61 (20.1) | 124 (40.8) | 3.81 (1.245) |
| I keep back-up of my important data | 16 (5.3) | 11 (3.6) | 81 (26.6) | 76 (25) | 120 (39.5) | 3.9 (1.128) |
| I use two-factor authentication for my important accounts | 13 (4.3) | 10 (3.3) | 48 (15.8) | 53 (17.4) | 180 (59.2) | 4.24 (1.101) |
| I use anti-virus software in my smartphone | 120 (39.5) | 30 (9.9) | 57 (18.8) | 33 (10.9) | 64 (21.1) | 2.64 (1.584) |
| I customize the privacy settings of my smartphone | 87 (28.6) | 23 (7.6) | 60 (19.7) | 48 (15.8) | 86 (28.3) | 3.08 (1.585) |
| I use remote management apps, i.e. TeamViewer, AnyDesk, etc. | 138 (45.4) | 31 (10.2) | 62 (20.4) | 29 (9.5) | 44 (14.5) | 2.38 (1.486) |
Potential risky practices performed by the students while using the smartphone
The students were asked to rate their frequency of performing different potentially risky activities while using their smartphones, on a five-point Likert scale. The mean and standard deviation of their responses are shown in Table 4. Results showed that most of the participants connected their smartphones to public Wi-Fi networks without using a VPN (mean 3.31). The mean scores of the other five items were below the average mean score of 3, meaning that the majority of the students are aware of their smartphone security and avoid performing these potentially risky activities while using their smartphones. However, though small in numbers, a good number of the students perform these activities frequently and always, which might be harmful to their personal data on smartphones (see Table 4).
Potential risky activities performed by the students while using the smartphone
| Potential risky activities | Never | Rarely | Sometimes | Frequently | Always | Mean (SD) |
|---|---|---|---|---|---|---|
| Connect to public Wi-Fi networks without using a VPN | 75 (24.7) | 19 (6.3) | 67 (22) | 23 (7.6) | 120 (39.5) | 3.31 (1.618) |
| Download apps and files from unofficial sources (outside of official app stores) | 101 (33.2) | 28 (9.2) | 96 (31.6) | 20 (6.6) | 59 (19.4) | 2.7 (1.476) |
| Use public charging cables to charge smartphone | 102 (33.6) | 40 (13.2) | 99 (32.6) | 23 (7.6) | 40 (13.2) | 2.54 (1.366) |
| Share smartphone’s password or PIN with others | 205 (67.4) | 24 (7.9) | 45 (14.8) | 17 (5.6) | 13 (4.3) | 1.71 (1.163) |
| Click on links received from untrusted sources | 167 (54.9) | 33 (10.9) | 68 (22.4) | 17 (5.6) | 19 (6.3) | 1.97 (1.25) |
| Click on links in text messages and/or emails from unknown senders | 216 (71.1) | 29 (9.5) | 39 (12.8) | 9 (3) | 11 (3.6) | 1.59 (1.056) |
| Potential risky activities | Never | Rarely | Sometimes | Frequently | Always | Mean ( |
|---|---|---|---|---|---|---|
| Connect to public Wi-Fi networks without using a | 75 (24.7) | 19 (6.3) | 67 (22) | 23 (7.6) | 120 (39.5) | 3.31 (1.618) |
| Download apps and files from unofficial sources (outside of official app stores) | 101 (33.2) | 28 (9.2) | 96 (31.6) | 20 (6.6) | 59 (19.4) | 2.7 (1.476) |
| Use public charging cables to charge smartphone | 102 (33.6) | 40 (13.2) | 99 (32.6) | 23 (7.6) | 40 (13.2) | 2.54 (1.366) |
| Share smartphone’s password or | 205 (67.4) | 24 (7.9) | 45 (14.8) | 17 (5.6) | 13 (4.3) | 1.71 (1.163) |
| Click on links received from untrusted sources | 167 (54.9) | 33 (10.9) | 68 (22.4) | 17 (5.6) | 19 (6.3) | 1.97 (1.25) |
| Click on links in text messages and/or emails from unknown senders | 216 (71.1) | 29 (9.5) | 39 (12.8) | 9 (3) | 11 (3.6) | 1.59 (1.056) |
Differences among different student groups in terms of their smartphone security measures
Separate Mann–Whitney U tests and Kruskal–Wallis tests were conducted to examine the differences in students’ security measures while using the smartphone in terms of their academic and demographic variables, i.e. gender, age group, study level, faculty/institute, the experience of using a smartphone, type of internet connection used by the smartphone and training/workshop on smartphone security.
For measuring the differences in students’ different security measures while using the smartphone in terms of their gender and training/workshop on smartphone security, Mann–Whitney U tests were conducted. The test results are shown in Table 5.
Differences in students’ smartphone security measures in terms of their gender and training/workshop on smartphone security
| Smartphone security practices | Gender | Training/workshop | ||||
|---|---|---|---|---|---|---|
| Mann–Whitney U | Z | p-value | Mann–Whitney U | Z | p-value | |
| I regularly update the operating system and apps | 7663.500 | −3.205 | 0.001*** | 10151.500 | −0.225 | 0.822 |
| I use strong and unique passwords for my smartphone and apps | 6720.500 | −4.846 | 0.000*** | 10221.000 | −0.126 | 0.900 |
| I use biometric (fingerprint, face recognition) security features in my phone | 7266.000 | −3.980 | 0.000*** | 9568.000 | −1.143 | 0.253 |
| I carefully review app permissions during installation | 7885.500 | −2.784 | 0.005** | 10085.500 | −0.314 | 0.753 |
| I keep back-up of my important data | 9295.500 | −0.682 | 0.495 | 9315.500 | −1.434 | 0.152 |
| I use two-factor authentication for my important accounts | 8966.500 | −1.261 | 0.207 | 9700.000 | −0.940 | 0.347 |
| I use anti-virus software in my smartphone | 9043.500 | −1.049 | 0.294 | 10162.000 | −0.202 | 0.840 |
| I customize the privacy settings of my smartphone | 9476.000 | −0.404 | 0.686 | 8759.000 | −2.197 | 0.028* |
| I use remote management apps, i.e., TeamViewer, AnyDesk, etc. | 9343.000 | −0.615 | 0.539 | 9908.500 | −0.575 | 0.565 |
| Smartphone security practices | Gender | Training/workshop | ||||
|---|---|---|---|---|---|---|
| Mann–Whitney U | Z | p-value | Mann–Whitney U | Z | p-value | |
| I regularly update the operating system and apps | 7663.500 | −3.205 | 0.001 | 10151.500 | −0.225 | 0.822 |
| I use strong and unique passwords for my smartphone and apps | 6720.500 | −4.846 | 0.000 | 10221.000 | −0.126 | 0.900 |
| I use biometric (fingerprint, face recognition) security features in my phone | 7266.000 | −3.980 | 0.000 | 9568.000 | −1.143 | 0.253 |
| I carefully review app permissions during installation | 7885.500 | −2.784 | 0.005 | 10085.500 | −0.314 | 0.753 |
| I keep back-up of my important data | 9295.500 | −0.682 | 0.495 | 9315.500 | −1.434 | 0.152 |
| I use two-factor authentication for my important accounts | 8966.500 | −1.261 | 0.207 | 9700.000 | −0.940 | 0.347 |
| I use anti-virus software in my smartphone | 9043.500 | −1.049 | 0.294 | 10162.000 | −0.202 | 0.840 |
| I customize the privacy settings of my smartphone | 9476.000 | −0.404 | 0.686 | 8759.000 | −2.197 | 0.028 |
| I use remote management apps, i.e., TeamViewer, AnyDesk, etc. | 9343.000 | −0.615 | 0.539 | 9908.500 | −0.575 | 0.565 |
p-Value is significant at *p ≤ 0.05;**p ≤ 0.01; and ***p ≤ 0.001
Based on students’ gender, significant differences were found between male and female students’ smartphone security measures in four out of the nine statements, i.e. I regularly update the operating system and apps, use strong, I use unique passwords for smartphones and apps, I use biometric (fingerprint, face recognition) security features and I carefully review app permissions during installation. In these cases, the mean scores of male students were higher than those of female students, suggesting that males follow these security measures more frequently. On the other hand, based on training/workshop on smartphone security, significant difference was found in only one out of the nine statements, i.e. I customize the privacy settings of my smartphone. In this case, the mean score of the students who participated in a training program/workshop was higher than that of the students who didn’t. However, no significant differences were found between these two groups of students for the rest eight statements (Table 5).
For measuring the differences in students’ different security measures while using the smartphone in terms of their age group, study level, faculty/institute, experience of using the smartphone and type of internet connection used by the smartphone, separate Kruskal–Wallis tests were performed. The test results are shown in Table 6.
Differences in students’ smartphone security measures in terms of their age group, education level, faculty, years of experience and internet connection
| Smartphone security practices | Age group | Educationlevel | Faculty/institute | Years ofexperience | Internetconnection |
|---|---|---|---|---|---|
| I regularly update the operating system and apps | 0.885 | 0.392 | 0.000*** | 0.000*** | 0.085 |
| I use strong and unique passwords for my smartphone and apps | 0.208 | 0.284 | 0.000*** | 0.000*** | 0.026* |
| I use biometric (fingerprint, face recognition) security features in my phone | 0.041* | 0.115 | 0.001*** | 0.000*** | 0.002** |
| I carefully review app permissions during installation | 0.881 | 0.057 | 0.325 | 0.079 | 0.657 |
| I keep back-up of my important data | 0.879 | 0.236 | 0.116 | 0.227 | 0.075 |
| I use two-factor authentication for my important accounts | 0.067 | 0.135 | 0.005** | 0.017* | 0.193 |
| I use anti-virus software in my smartphone | 0.346 | 0.401 | 0.000*** | 0.485 | 0.160 |
| I customize the privacy settings of my smartphone | 0.290 | 0.232 | 0.106 | 0.357 | 0.991 |
| I use remote management apps, i.e. TeamViewer, AnyDesk, etc. | 0.409 | 0.006** | 0.013* | 0.865 | 0.863 |
| Smartphone security practices | Age group | Educationlevel | Faculty/institute | Years ofexperience | Internetconnection |
|---|---|---|---|---|---|
| I regularly update the operating system and apps | 0.885 | 0.392 | 0.000 | 0.000 | 0.085 |
| I use strong and unique passwords for my smartphone and apps | 0.208 | 0.284 | 0.000 | 0.000 | 0.026 |
| I use biometric (fingerprint, face recognition) security features in my phone | 0.041 | 0.115 | 0.001 | 0.000 | 0.002 |
| I carefully review app permissions during installation | 0.881 | 0.057 | 0.325 | 0.079 | 0.657 |
| I keep back-up of my important data | 0.879 | 0.236 | 0.116 | 0.227 | 0.075 |
| I use two-factor authentication for my important accounts | 0.067 | 0.135 | 0.005 | 0.017 | 0.193 |
| I use anti-virus software in my smartphone | 0.346 | 0.401 | 0.000 | 0.485 | 0.160 |
| I customize the privacy settings of my smartphone | 0.290 | 0.232 | 0.106 | 0.357 | 0.991 |
| I use remote management apps, i.e. TeamViewer, AnyDesk, etc. | 0.409 | 0.006 | 0.013 | 0.865 | 0.863 |
p-Value is significant at *p ≤ 0.05; **p ≤ 0.01; and ***p ≤ 0.001
Based on age group, significant difference was found in only one out of the nine statements, i.e. I use biometric (fingerprint, face recognition) security features in my phone. In this case, the mean score of the “Above 25 years” students was higher than that of other students, suggesting that students from this age group follow this security measure more frequently than others. Based on education level, a significant difference was found in only one out of the nine statements, i.e. I use remote management apps, i.e. TeamViewer, AnyDesk, etc. In this case, the mean score of fourth year students was higher than those of other students, suggesting that fourth year students follow this security measure more frequently than others. Based on students’ faculty/institute, significant differences were found in six out of the nine statements, i.e. I update operating system and apps, I use strong and unique passwords for smartphones and apps, I use biometric (fingerprint, face recognition) security features, I use two-factor authentication for important accounts, I use anti-virus software and I use remote management apps. However, no significant differences were found among the students of different faculties for the rest three statements. Based on the years of experience of using smartphone, significant differences were found in four out of the nine statements, i.e. I regularly update operating system and apps, use strong, I use unique passwords for smartphones and apps, I use biometric (fingerprint, face recognition) security features and I use two-factor authentication for my important accounts. In these cases, the mean scores of the students having five to seven years of experience in using smartphone were higher than those of other students, suggesting that the students with five to seven years of experience follow these security measures more frequently than others. Finally, based on internet connection, significant differences were found in two out of the nine statements, i.e. I use unique passwords for smartphones and apps and I use biometric (fingerprint, face recognition) security features. In these cases, the mean scores of the students who use only mobile data were higher than those of other students, suggesting that the mobile data users follow these security measures more frequently than others (Table 6).
Differences among different student groups in terms of their potential risky practices while using smartphones
To measure the differences among different student groups in terms of their potentially risky practices related to smartphone usage, independent sample t-tests were conducted based on their gender and age group. On the other hand, one-way ANOVA tests were conducted based on their study level, faculty/institute, experience of using a smartphone, type of internet connection used by the smartphone and training/workshop on smartphone security.
The t-test results showed that there were statistically significant differences in students’ potential risky practices based on their gender (t-value = 0.689, F = 8.261, p-value = 0.004). The mean value of male students was higher than the females indicating that the males perform these practices more frequently compared to their female counterparts. On the other hand, no significant difference was found based on training/workshops on smartphone security (Table 7).
Differences in students’ potential risky practices in terms of their gender and training/workshop on smartphone security
| Grouping variables | Mean | SD | t-value | F | p-value |
|---|---|---|---|---|---|
| Gender | |||||
| Male | 2.33 | 0.962 | 0.689 | 8.261 | 0.004** |
| Female | 2.25 | 0.766 | |||
| Training/workshop on smartphone security | |||||
| Yes | 2.24 | 0.860 | −1.856 | 3.114 | 0.079 |
| No | 2.44 | 0.983 | |||
| Grouping variables | Mean | t-value | F | p-value | |
|---|---|---|---|---|---|
| Gender | |||||
| Male | 2.33 | 0.962 | 0.689 | 8.261 | 0.004 |
| Female | 2.25 | 0.766 | |||
| Training/workshop on smartphone security | |||||
| Yes | 2.24 | 0.860 | −1.856 | 3.114 | 0.079 |
| No | 2.44 | 0.983 | |||
p-Value is significant at *p ≤ 0.05; **p ≤ 0.01; and ***p ≤ 0.001
The ANOVA test results found statistically significant differences in the potential risky practices based on students age group (df = 2, F = 4.540, p-value = 0.011) and smartphone use experience (df = 4, F = 3.434, p-value = 0.009). However, no significant differences were found based on students’ study level, faculty/institute and internet connection used by the smartphones (Table 8).
Differences in students’ potential risky practices in terms of their age group, education level, faculty, years of experience and internet connection
| Grouping variables | Sum of square | df | Mean square | F | p-value |
|---|---|---|---|---|---|
| Age group | |||||
| Between groups | 7.290 | 2 | 3.645 | 4.540 | 0.011* |
| Within groups | 241.701 | 301 | 0.803 | ||
| Study level | |||||
| Between groups | 3.329 | 4 | 0.832 | 1.013 | 0.401 |
| Within groups | 245.662 | 299 | 0.822 | ||
| Faculty/institute | |||||
| Between groups | 5.575 | 7 | 0.796 | 0.969 | 0.454 |
| Within groups | 243.416 | 296 | 0.822 | ||
| Smartphone use experience | |||||
| Between groups | 10.935 | 4 | 2.734 | 3.434 | 0.009** |
| Within groups | 238.056 | 299 | 0.796 | ||
| Internet connection | |||||
| Between groups | 2.680 | 2 | 1.340 | 1.637 | 0.196 |
| Within groups | 246.312 | 301 | 0.818 | ||
| Grouping variables | Sum of square | df | Mean square | F | p-value |
|---|---|---|---|---|---|
| Age group | |||||
| Between groups | 7.290 | 2 | 3.645 | 4.540 | 0.011 |
| Within groups | 241.701 | 301 | 0.803 | ||
| Study level | |||||
| Between groups | 3.329 | 4 | 0.832 | 1.013 | 0.401 |
| Within groups | 245.662 | 299 | 0.822 | ||
| Faculty/institute | |||||
| Between groups | 5.575 | 7 | 0.796 | 0.969 | 0.454 |
| Within groups | 243.416 | 296 | 0.822 | ||
| Smartphone use experience | |||||
| Between groups | 10.935 | 4 | 2.734 | 3.434 | 0.009 |
| Within groups | 238.056 | 299 | 0.796 | ||
| Internet connection | |||||
| Between groups | 2.680 | 2 | 1.340 | 1.637 | 0.196 |
| Within groups | 246.312 | 301 | 0.818 | ||
p-Value is significant at *p ≤ 0.05; **p ≤ 0.01; and ***p ≤ 0.001
Discussion and recommendations
The main aim of the present study was to measure the smartphone security behavior of the students of a remote public university in Bangladesh. To fulfill this objective, four research questions were developed. The data analysis chapter revealed some interesting and significant findings that have been discussed below based on the RQs.
In response to the RQ1, the study found that a significant proportion of the students frequently use a two-factor authentication system to protect their important accounts, biometric (fingerprint, face recognition) security features to secure the data and strong as well as unique passwords for their smartphones and apps. This trend indicates a growing awareness of cybersecurity among students, driven by the increasing prevalence of cyber threats. The use of 2FA and biometric features enhances protection against unauthorized access, while strong passwords help prevent breaches. This proactive approach highlights a positive shift toward better digital hygiene. However, broader educational efforts are needed to extend these practices to the wider population, ensuring comprehensive digital security awareness across all demographics in Bangladesh. This aligns with the findings of Chang and Coppel (2020), who also observed increased adoption of biometric features and multifactor authentication among university students. Our results confirm these global trends within the context of Bangladeshi students. This finding is also quite similar to the findings of the study of Taha and Dahabiyeh (2021), Breitinger et al. (2020), Jones et al. (2014), Jones and Heinrichs (2012), Knapova et al. (2021) and Chin et al. (2021), where the authors found the users were highly aware of different security measures while using their smartphones.
In response to the RQ2, the findings of the study revealed some quite positive approaches of the students toward their smartphone security. It was found that the students generally avoid potentially risky practices such as sharing their smartphone’s password or PIN with others, clicking on links received from untrusted sources and opening links in text messages and/or emails from unknown senders that might be harmful to the security of their data. However, though limited in number, some of the students admitted to performing these activities frequently. Though limited in number, these practices can be very dangerous for an individual’s personal data security. However, this finding is significant to the findings of several studies conducted by Anshari et al. (2017), Kuss et al. (2018) and Kim et al. (2017), where it was found that several potentially risky practices are performed by the users while using their smartphones.
In response to the RQ3, the Mann–Whitney U test and Kruskal–Wallis test results revealed that the students’ smartphone security measures were greatly influenced by their gender, faculty/institute, experience of using a smartphone and type of internet connection used. Surprisingly, the test results found no differences among students’ security measures based on their education level, age group and whether they participated in a workshop or training program on smartphone security. This result implies that while certain demographic and contextual elements influence security behaviors, traditional indicators such as education level, age and formal training do not always translate into better security practices. This emphasizes the importance of customized awareness initiatives that take these key elements into account to improve overall student smartphone security. However, previous studies found slightly different results compared to our findings, as some studies found differences in users’ security behavior based on gender and age (see Wahab et al., 2021; Zwilling et al., 2022; Shah and Agarwal, 2020).
In response to RQ4, the independent sample t-test and one-way ANOVA test results indicated that the performance of the potentially risky practices while using the smartphone varied based on students’ gender, age group and experience of using the smartphone. Surprisingly, no significant difference was observed based on whether they participated in training/workshop on smartphone security, their study level, faculty/institute and the type of internet connection used by them with their smartphones. This finding implies that students’ potentially risky practices are more significantly influenced by demographic characteristics and practical smartphone experience than by formal education or training. It emphasizes the need for more sophisticated and useful strategies to raise students’ awareness of and adherence to safe smartphone usage practices. However, findings of some previous studies are in line with this finding. For example, Nowrin and Bawden (2018) demonstrated reasonably secure behavior among the students in terms of avoiding practices related to smartphone use. In another study, Zhang et al. (2017) revealed there are serious concerns among users regarding information security in the use of smartphones, including ignorance of security information when downloading and using applications, inadequate phone settings and inappropriate enabling of add-on utilities, and lack of proper disaster recovery plans, which is also similar to this study.
Based on the findings of the study and the responses received from the participants, this study suggests the following recommendations to create positive aspects about smartphones and other devices on the university campus, with a particular focus on student awareness and proper data protection:
As the study found that only one-third of the respondents participated in a formal training program or workshop on smartphone security, educational workshops and awareness campaigns are necessary to make students competent in navigating the digital landscape securely. In addition, information and security awareness training and education programs should be developed in a variety of forms to intensify personal security knowledge management and skills (Mi et al., 2020; Chen and Li, 2017; Imgraben et al., 2014).
Cybersecurity modules should be integrated into the academic curriculum to make students academically trained and provide them with essential knowledge about online safety and cyber threats (Zwilling et al., 2022).
Adding an extra layer of security and safeguarding users from potential cyber threats, VPNs need to be used while using public Wi-Fi.
To reduce the risk of malware and other security vulnerabilities, downloading files and apps from unofficial sources should be avoided.
In case of cyber incidents or system failures, regular backups should be ensured to provide safety to critical and personal data.
Students should be encouraged to create complex and unique passwords to make it harder for unauthorized individuals to gain access to their accounts. In addition, a two-factor authentication system should be enabled for the accounts.
Use of anti-virus software should be encouraged among the students. This software provides virus protection, spam protection, firewall and spyware protection that will safeguard for all possible threats.
Limitations and conclusion
Limitations
The study is subject to certain limitations. Primarily, the research was confined to students from a single university, thereby constraining the generalizability of the findings to a broader population of university students in Bangladesh. Future studies should consider several universities in different locations in the country to obtain a wider perspective. Moreover, to make future studies more effective and comprehensive, it would be beneficial to include not only students but also researchers, professionals and people from the general public as the targeted sample. Second, the notable limitation of our study lies in the relatively modest sample size, which may not be representative of the larger population. Future studies might take into consideration a larger sample size. Self-report surveys were used for data collection, which may introduce response bias and impact the accuracy of reported information. As mentioned earlier, the study was conducted in a limited time. So, long-term effects or trends may not be captured. Some facts in this study may change over time, and the study may not capture those changes adequately. Finally, the study was solely quantitative. A mixed-method approach could have brought an in-depth result from different angles. Future studies might consider these limitations.
Conclusion
The present study investigated a public university students’ smartphone security behavior and revealed some noteworthy findings. The significance of the present study lies in different aspects, as nowadays, smartphones hold critical information about their users. Protecting such information and credentials is a major problem in today’s environment. As a result, users must be prepared to adapt to the security situation. Researchers and cybersecurity specialists are working to find new ways to guard against security threats. It is time for field specialists, schools and government groups to increase awareness about smartphone security issues. Because the majority of students do not have any formal education on smartphone security, the authorities should organize appropriate seminars to successfully promote awareness and strive toward a safe environment for students at the university level. Some offices within the university, such as the ICT Cell and Cyber Center, can play significant roles in this area. The study’s findings will guide future device security research and serve as a basis for the university authorities to develop dedicated security standards. The findings of this study would also be beneficial to the ICT Division of the Ministry of Posts, Telecommunications and Information Technology for future decision-making.

