Social engineering poses a considerable challenge to higher education institutions, with human behavior contributing to security threat identification, reporting mechanisms, and the safeguarding of evidence. This study investigated the self-reports of participants from several Philippine universities regarding their experience with social engineering attacks, which included cybersecurity, human-factor conditions, and reporting behavior. The trial was conducted from July 21 to July 29, 2026, utilizing a cross-sectional descriptive correlational survey framework using online questionnaires. Data from 130 participants was analyzed using descriptive statistics, reliability testing, Mann–Whitney U test, Chi-square test, Spearman rank correlation, and coding. Results indicated that 31.5% of participants had experienced any suspicious contact with the university while 32.3% had self-reported as having been a victim of crime. In addition, only 13.1% had reported the incident to any personnel of the university’s IT or security divisions. The result of the scale assessing knowledge and recognition was noted as highly reliable (α = 0.923; M = 3.71, SD = 0.87). The respondents with formal cybersecurity training scored significantly higher (M = 4.03) than those lacking this type of education (M = 3.59). Knowledge was strongly connected to the caution of working remotely and personal accountability regarding the safety of the university’s assets. The research contributes to the field of cybersecurity governance in higher education by providing an identification of the gaps relating to human factor and reporting which may aid institutions in developing awareness programs, reporting processes and forensic readiness measures. The findings are, however, limited by the fact that the data is cross-sectional, pooled and self-reported.