<?xml version="1.0" encoding="UTF-8" standalone="no"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">Open Res Europe</journal-id>
            <journal-title-group>
                <journal-title>Open Research Europe</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2732-5121</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/openreseurope.17332.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Research Article</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Individual perceptions of cybersecurity and risk management</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: 2 approved with reservations, 1 not approved]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>Pickering</surname>
                        <given-names>Brian</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-6815-2938</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Taylor</surname>
                        <given-names>Steve</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Funding Acquisition</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-9937-1762</uri>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>Faculty of Engineering and Physical Sciences, University of Southampton, Southampton, England, SO17 7BJ, UK</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:j.b.pickering@soton.ac.uk">j.b.pickering@soton.ac.uk</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>22</day>
                <month>8</month><year>2025</year>
            </pub-date>
            <pub-date pub-type="collection"><year>2025</year>
            </pub-date><volume>5</volume>
            <elocation-id>252</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>16</day>
                    <month>4</month><year>2024</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#xA9; 2025 Pickering B and Taylor S</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://open-research-europe.ec.europa.eu/articles/5-252/pdf"/>
            <abstract>
                <p>Seeing human actors as a primary target for cybersecurity attacks suggests that awareness of threats and the willingness to implement controls may be lacking. Previous studies have identified context, demographic characteristics, and self-efficacy to be key factors influencing security-enhancing behaviours among private individuals. In this study, 801 UK private individuals responded to an anonymous online survey, identifying their ability to recognise threats and controls, who they believe responsible for implementing controls, and their general willingness to engage with cybersecurity via a Protection Motivation Theory behavioural model. Using a healthcare data context, results indicate that private individuals can identify threats, controls, and match them. They rarely, however, see themselves responsible for the security of their data. Further, an explanatory factor analysis based on 676 response sets suggests that decision making involved background considerations rather than a simple cost-benefit analysis or cognitive assessment of cybersecurity controls. This work adds to a growing body of literature which highlights that human actors are cybersecurity aware, but that they perceive the broader context to be relevant to their decision making. As such, it provides insights to consider in response to making technology end-users part of the solution to cybersecurity threats.</p>
            </abstract>
            <abstract abstract-type="plain-language-summary">
                <title>Plain Language Summary</title>
                <p>When it comes to what we do as private individuals using computer technology to protect our data, as well as international standards of how service providers should secure their infrastructure, research has suggested that factors like the demographic characteristics (age, expertise, etc) of the person and the context (such as whether people have a positive or negative attitude to the specific situation) using the technology will influence whether that individual will actually take appropriate steps to be secure. It's also commonly assumed that users themselves represent a significant threat to the security of the service or technology. For this study, we asked questions like: can private individuals recognise threats to their security? Can they also recognise and evaluate the measures to deal with those threats? And who do they believe is responsible for making sure those measures are applied? We used an anonymous online survey to collect responses around 800 UK residents imagining how they feel about their healthcare data being managed online. We found that users can identify and evaluate threats and control measures, but they rarely felt personally responsible for adopting those measures. We also concluded that it takes a lot more than just a cost-benefit analysis (e.g., balancing the impact against what needs to be done when implementing security measures). Private individuals are a lot more aware, therefore, and seem to make decisions based on more than just evaluating threats and the effectiveness of possible security measures.</p>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Cybersecurity</kwd>
                <kwd>Digital security</kwd>
                <kwd>Risk perception</kwd>
                <kwd>Threats</kwd>
                <kwd>Controls</kwd>
                <kwd>Priming</kwd>
                <kwd>Responsibility</kwd>
                <kwd>Healthcare data</kwd>
                <kwd>Protection Motivation Theory</kwd>
                <kwd>Exploratory Factor Analysis</kwd>
            </kwd-group>
            <funding-group>
                <award-group id="fund-1" xlink:href="http://dx.doi.org/10.13039/100010661">
                    <funding-source>Horizon 2020 Framework Programme</funding-source>
                    <award-id>826284</award-id>
                    <award-id>871525</award-id>
                </award-group>
                <funding-statement>This project has received funding from the European Union&#x2019;s Horizon 2020 research and innovation programme under grant agreement Nos. 826284 (Data-protection toolkit reducing risks in hospitals and care centers [ProTego]) and 871525 (Protecting Sensitive Data in the Computing Continuum [FogProtect]).</funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec sec-type="intro">
            <title>1.1 Introduction</title>
            <p>As our private and personal lives become increasingly digitalised (see 
                <xref ref-type="bibr" rid="ref-1">1</xref>) with more time spent in cyberspace, there is a growing need to consider the security of online data. Further, with an increased call for health data
                <sup>
                    <xref ref-type="bibr" rid="ref-2">2</xref>
                </sup> and data sharing
                <sup>
                    <xref ref-type="bibr" rid="ref-3">3</xref>,
                    <xref ref-type="bibr" rid="ref-4">4</xref>
                </sup>, but variable sensitivities and attitudes across individuals
                <sup>
                    <xref ref-type="bibr" rid="ref-5">5</xref>
                </sup>, the responsibility for protecting those data is unclear
                <sup>
                    <xref ref-type="bibr" rid="ref-6">6</xref>
                </sup>. Nonetheless, cyber-attacks which could compromise personal data are increasingly sophisticated
                <sup>
                    <xref ref-type="bibr" rid="ref-7">7</xref>
                </sup> and with significant impact
                <sup>
                    <xref ref-type="bibr" rid="ref-8">8</xref>
                </sup>. At the same time, and although contested
                <sup>
                    <xref ref-type="bibr" rid="ref-9">9</xref>
                </sup>, private individuals are generally thought to be a significant target for cyber-attacks
                <sup>
                    <xref ref-type="bibr" rid="ref-10">10</xref>
                </sup>. Such attacks might include playing on psychological vulnerabilities
                <sup>
                    <xref ref-type="bibr" rid="ref-11">11</xref>
                </sup> or using social engineering techniques
                <sup>
                    <xref ref-type="bibr" rid="ref-12">12</xref>
                </sup>. So, it is clearly important to understand the human factors behind potential vulnerability to cyber-attacks
                <sup>
                    <xref ref-type="bibr" rid="ref-13">13</xref>
                </sup>. Along with a focus on implementing appropriate infrastructure-based solutions and management actions
                <sup>
                    <xref ref-type="bibr" rid="ref-14">14</xref>
                </sup>, there is also the challenge of motivating individual behavioural change
                <sup>
                    <xref ref-type="bibr" rid="ref-15">15</xref>
                </sup> to adopt appropriate security-enhancing measures at a personal level, especially if individuals do not believe the potential risk to be relevant to them
                <sup>
                    <xref ref-type="bibr" rid="ref-16">16</xref>
                </sup>. Using the Protection Motivation Theory behavioural model
                <sup>
                    <xref ref-type="bibr" rid="ref-15">15</xref>,
                    <xref ref-type="bibr" rid="ref-17">17</xref>
                </sup>, this study investigates UK private citizen understanding of security-enhancing technologies and their subsequent willingness to adopt such technologies. On that basis, we explore some of the extraneous factors which are associated with the intention to adopt cybersecurity measures. Determining private citizen responses to threats and attitudes to available controls will increase our understanding of how to encourage behavioural change.</p>
        </sec>
        <sec>
            <title>1.2 Background</title>
            <p>Understanding private citizen responses to cybersecurity threats involves several perspectives. First, cybersecurity standards have been developed to define the landscape
                <sup>
                    <xref ref-type="bibr" rid="ref-18">18</xref>
                </sup> and procedures to manage associated risks for technology end-users and administrators
                <sup>
                    <xref ref-type="bibr" rid="ref-19">19</xref>
                </sup>. 
                <xref ref-type="other" rid="S1.2.1">Section 1.2.1</xref> describes a typical cybersecurity view which informs the rest of the paper. With that in mind, if security experts expect human actors to respond to threats in a socio-technical system, it is important to appreciate their perceptions of risk (
                <xref ref-type="other" rid="S1.2.2">Section 1.2.2</xref>). Finally, taking a behavioural perspective may throw some light on how private individuals make decisions about responding to threats. In 
                <xref ref-type="other" rid="S1.2.3">Section 1.2.3</xref>, a behavioural model previously associated with the decision to take security-supporting measures is introduced. For each of these sections, specific research questions arise which inform an empirical investigation into private individuals' attitudes to cybersecurity in 
                <xref ref-type="other" rid="S1.3">Section 1.3</xref>.</p>
            <sec>
                <title>1.2.1 Threats and controls</title>
                <p id="S1.2.1">Defining cybersecurity is not always straight forward
                    <sup>
                        <xref ref-type="bibr" rid="ref-20">20</xref>
                    </sup>. Although often used interchangeably with information security, von Solms and van Niekerk
                    <sup>
                        <xref ref-type="bibr" rid="ref-21">21</xref>
                    </sup> see cybersecurity in broader terms encompassing other assets including technology users themselves and not just their information. An asset, then, is &#x201C;anything that has value... and which, therefore, requires protection&#x201D;
                    <sup>
                        <xref ref-type="bibr" rid="ref-19">19</xref>
                    </sup> to avoid 
                    <italic toggle="yes">attack</italic> (&#x201C;attempt[s] to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset&#x201D;
                    <sup>
                        <xref ref-type="bibr" rid="ref-18">18</xref>,
                        <xref ref-type="bibr" rid="ref-19">19</xref>
                    </sup>) by 
                    <italic toggle="yes">threats</italic> or the &#x201C;potential cause(s) of an unwanted incident, which can result in harm&#x201D;
                    <sup>
                        <xref ref-type="bibr" rid="ref-18">18</xref>
                    </sup>. Threats exploit 
                    <italic toggle="yes">vulnerabilities</italic> (&#x201C;weakness(es) of an asset&#x201D;
                    <sup>
                        <xref ref-type="bibr" rid="ref-18">18</xref>
                    </sup>), and cause 
                    <italic toggle="yes">risks</italic> (the likelihood and impact of loss or damage). They may be either malicious behaviours (
                    <italic toggle="yes">attacks</italic>), or unintentional or inadvertent behaviours that lead to similar harms. The &#x201C;well-intentioned" user
                    <sup>
                        <xref ref-type="bibr" rid="ref-9">9</xref>
                    </sup> is likely to fall into the latter category. A 
                    <italic toggle="yes">control</italic> is a &#x201C;measure that is modifying risk"
                    <sup>
                        <xref ref-type="bibr" rid="ref-18">18</xref>
                    </sup> by either reducing the likelihood of a threat attacking an asset (reducing the asset's vulnerability) or lowering consequent impact or both. 
                    <xref ref-type="fig" rid="f1">Figure 1</xref> summarises relationships between these concepts, where 
                    <italic toggle="yes">threat events</italic> (an amalgam of 
                    <italic toggle="yes">threat</italic> and 
                    <italic toggle="yes">event</italic> in 
                    <xref ref-type="bibr" rid="ref-18">18</xref>) exploit 
                    <italic toggle="yes">vulnerabilities</italic> leading to cybersecurity 
                    <italic toggle="yes">risks</italic> to particular 
                    <italic toggle="yes">assets.</italic>
</p>
                <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                    <label>Figure 1. </label>
                    <caption>
                        <title>Schematic representation of the threat landscape (see also 
                            <xref ref-type="bibr" rid="ref-22">22</xref>,
                            <xref ref-type="bibr" rid="ref-23">23</xref>).</title>
                    </caption>
                    <graphic orientation="portrait" position="float" xlink:href="https://openreseurope-files.f1000.com/manuscripts/18732/ae204ca3-b386-4ef4-8652-b2afcb2a5c0d_figure1.gif"/>
                </fig>
                <p>Following Ganin and his colleagues
                    <sup>
                        <xref ref-type="bibr" rid="ref-22">22</xref>
                    </sup>, we emphasise that understanding the threat landscape requires a holistic approach. For simplicity, we use 
                    <italic toggle="yes">threat</italic> as shorthand for risk, threat and threat event, and 
                    <italic toggle="yes">control</italic> for any measure taken to contain the threat or mitigate the risk. This leads to our first two research questions (RQ):</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>RQ1. Can private individuals recognise and evaluate 
                            <italic toggle="yes">threats</italic> and 
                            <italic toggle="yes">controls</italic>?</p>
                    </list-item>
                    <list-item>
                        <label/>
                        <p>RQ2. Can private individuals identify an appropriate 
                            <italic toggle="yes">control</italic> to mitigate a specific 
                            <italic toggle="yes">threat</italic>?</p>
                    </list-item>
                </list>
            </sec>
            <sec>
                <title>1.2.2 Risk perception</title>
                <p id="S1.2.2">As mentioned, people represent a significant source of risk
                    <sup>
                        <xref ref-type="bibr" rid="ref-10">10</xref>
                    </sup> and ideally need to become part of the solution rather than the problem
                    <sup>
                        <xref ref-type="bibr" rid="ref-9">9</xref>
                    </sup>. Context, demographics, affect and beliefs around responsibility all seem to influence cybersecurity adoption decisions. For example, willingness to undertake security-appropriate behaviours may be generalised rather than specific
                    <sup>
                        <xref ref-type="bibr" rid="ref-24">24</xref>
                    </sup>. That assumes individuals attend fully to all information, though, which may not be the case
                    <sup>
                        <xref ref-type="bibr" rid="ref-25">25</xref>
                    </sup>, meaning no appropriate protective behaviours are undertaken
                    <sup>
                        <xref ref-type="bibr" rid="ref-26">26</xref>
                    </sup>. Individual responses appear to differ by how developed a country is
                    <sup>
                        <xref ref-type="bibr" rid="ref-27">27</xref>
                    </sup>, the measures that country adopts
                    <sup>
                        <xref ref-type="bibr" rid="ref-28">28</xref>
                    </sup>, cultural differences
                    <sup>
                        <xref ref-type="bibr" rid="ref-26">26</xref>
                    </sup>, and context-determined affect
                    <sup>
                        <xref ref-type="bibr" rid="ref-29">29</xref>
                    </sup>. For security professionals, as the amount of relevant information decreases, so the subjectivity of their responses increases
                    <sup>
                        <xref ref-type="bibr" rid="ref-30">30</xref>,
                        <xref ref-type="bibr" rid="ref-31">31</xref>
                    </sup>. For these experts and private individuals alike, though, affective responses to risk perceptions
                    <sup>
                        <xref ref-type="bibr" rid="ref-16">16</xref>,
                        <xref ref-type="bibr" rid="ref-32">32</xref>,
                        <xref ref-type="bibr" rid="ref-33">33</xref>
                    </sup> reveal a complicated interrelationship between emotional response and the intention to act based on risk perception
                    <sup>
                        <xref ref-type="bibr" rid="ref-34">34</xref>
                    </sup>. This may depend on self-belief (or 
                    <italic toggle="yes">self-efficacy</italic>
                    <sup>
                        <xref ref-type="bibr" rid="ref-35">35</xref>
                    </sup>) in applying mitigating controls
                    <sup>
                        <xref ref-type="bibr" rid="ref-36">36</xref>
                    </sup>, and to some degree personality traits
                    <sup>
                        <xref ref-type="bibr" rid="ref-37">37</xref>,
                        <xref ref-type="bibr" rid="ref-38">38</xref>
                    </sup>. Further, if experts are believed to be responsible for controls, when private individuals are unable to access and assess all relevant information
                    <sup>
                        <xref ref-type="bibr" rid="ref-39">39</xref>
                    </sup>, then trust plays a mediating, but complex
                    <sup>
                        <xref ref-type="bibr" rid="ref-38">38</xref>,
                        <xref ref-type="bibr" rid="ref-40">40</xref>
                    </sup> role as a socially constructed phenomenon related to confidence in system function
                    <sup>
                        <xref ref-type="bibr" rid="ref-41">41</xref>
                    </sup>. With specific reference to technology, trust is a moderating factor along with risk perceptions, subjective norms and self-efficacy all influencing perceived usefulness decisions in adoption
                    <sup>
                        <xref ref-type="bibr" rid="ref-42">42</xref>
                    </sup>. Ultimately, though, too much emphasis on the consequences of a given risk may leave individuals overwhelmed, the resulting &#x201C;security fatigue&#x201D; leading to inaction
                    <sup>
                        <xref ref-type="bibr" rid="ref-26">26</xref>
                    </sup> or even maladaptive behaviours
                    <sup>
                        <xref ref-type="bibr" rid="ref-39">39</xref>,
                        <xref ref-type="bibr" rid="ref-40">40</xref>
                    </sup>.</p>
                <p>For 
                    <italic toggle="yes">context</italic>, we will focus on the potential for sharing health data. These data are defined as special category personal data (Art. 9
                    <sup>
                        <xref ref-type="bibr" rid="ref-43">43</xref>
                    </sup>) and therefore require additional measures from any provider processing such data than other data types, including other types of personal data. Regarding the contextual effects outlined, we targeted the following RQs:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>RQ3. How do individual characteristics (demographics) influence cybersecurity judgements?</p>
                    </list-item>
                    <list-item>
                        <label/>
                        <p>RQ4. How does affect influence cybersecurity judgements?</p>
                    </list-item>
                    <list-item>
                        <label/>
                        <p>RQ5. Who do private individuals believe responsible to introduce 
                            <italic toggle="yes">controls</italic>?</p>
                    </list-item>
                </list>
            </sec>
            <sec>
                <title>1.2.3 Protection motivation: a behavioural perspective</title>
                <p id="S1.2.3">If risk perception is the result of the integration of an analytical with a more emotional pathway (see, for instance, 
                    <xref ref-type="bibr" rid="ref-29">29</xref>), we must contextualise risks as relevant to individuals to encourage them to adopt any associated controls on the one hand, but also account for affect in the decision-making process. Behavioural models related to risk prevention suggest that the decision to adopt appropriate measures depends on the balance between perceptions of threats and the benefits of adoption (cost-benefit) with self-efficacy and social norms (personal beliefs, experience and ingroup perceptions). All of these have been mentioned in the previous sections as significant for cybersecurity related behaviours.</p>
                <p>One common model in this area derives from Protection Motivation Theory (PMT) as shown in 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>
                    <sup>
                        <xref ref-type="bibr" rid="ref-15">15</xref>,
                        <xref ref-type="bibr" rid="ref-42">42</xref>,
                        <xref ref-type="bibr" rid="ref-43">43</xref>
                    </sup>. The PMT has been used to explore cybersecurity awareness and the willingness to adopt security-enhancing measures
                    <sup>
                        <xref ref-type="bibr" rid="ref-15">15</xref>
                    </sup>. Comparing 
                    <xref ref-type="fig" rid="f1">Figure 1</xref> with 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>, 
                    <italic toggle="yes">Threat Appraisal</italic> is effectively a risk assessment: what is the likelihood (or 
                    <italic toggle="yes">Susceptibility</italic> in 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>, 
                    <italic toggle="yes">vulnerability</italic> in 
                    <xref ref-type="fig" rid="f1">Figure 1</xref>) of an event and what would its impact (or 
                    <italic toggle="yes">Severity</italic> in 
                    <xref ref-type="fig" rid="f2">Figure 2</xref> or 
                    <italic toggle="yes">risk</italic> in 
                    <xref ref-type="fig" rid="f1">Figure 1</xref>) be? The 
                    <italic toggle="yes">Coping Appraisal</italic> is a judgement about how effective a control may be in dealing with the threat (or 
                    <italic toggle="yes">Response efficacy</italic> in 
                    <xref ref-type="fig" rid="f2">Figure 2</xref> or 
                    <italic toggle="yes">control</italic> in 
                    <xref ref-type="fig" rid="f1">Figure 1</xref>) and whether an individual feels able to implement that control (or 
                    <italic toggle="yes">Self-efficacy</italic>). To undertake this cost-benefit analysis leading to 
                    <italic toggle="yes">Protection Motivation</italic> (the intention to adopt the control), individuals must also feel themselves personally responsible.</p>
                <fig fig-type="figure" id="f2" orientation="portrait" position="float">
                    <label>Figure 2. </label>
                    <caption>
                        <title>Behavioural model derived from Protection Motivation Theory
                            <sup>
                                <xref ref-type="other" rid="FN1">1</xref>
                            </sup>.</title>
                    </caption>
                    <graphic orientation="portrait" position="float" xlink:href="https://openreseurope-files.f1000.com/manuscripts/18732/ae204ca3-b386-4ef4-8652-b2afcb2a5c0d_figure2.gif"/>
                </fig>
                <p>
                    <bold>
                        <italic toggle="yes">1.2.3.1 Sources of information and security-related behaviours</italic>.</bold> The 
                    <italic toggle="yes">Cognitive Mediating Processes</italic> of the PMT model (
                    <xref ref-type="fig" rid="f2">Figure 2</xref>), as the name suggests, represents the more rational decision-making arm of a dual process model. Such processing can be assumed to take place within a specific context, including an individual&#x2019;s experience and that of significant others (their ingroup). In their meta-analysis, Floyd and her colleagues
                    <sup>
                        <xref ref-type="bibr" rid="ref-42">42</xref>
                    </sup> also refer to 
                    <italic toggle="yes">Sources of Information</italic> such as contextual and individual factors (their Figure 1). Although not explicitly identified, others have suggested that individuals equate privacy (individual concern about how data are used) and security (how data are protected) orthogonally
                    <sup>
                        <xref ref-type="bibr" rid="ref-37">37</xref>
                    </sup> and may be behaviour specific
                    <sup>
                        <xref ref-type="bibr" rid="ref-44">44</xref>
                    </sup>; that trait mindfulness can reduce vulnerability
                    <sup>
                        <xref ref-type="bibr" rid="ref-45">45</xref>
                    </sup> while other traits influence antecedents of privacy concern
                    <sup>
                        <xref ref-type="bibr" rid="ref-38">38</xref>
                    </sup>; and that priming (i.e., contextual effects) can influence cybersecurity behaviours, though not in a straightforward manner
                    <sup>
                        <xref ref-type="bibr" rid="ref-29">29</xref>
                    </sup>. Our final RQ, therefore:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>RQ6. Is there evidence that 
                            <italic toggle="yes">Cognitive Mediating Processes</italic> from PMT alone account for private individual perspectives on privacy and security?</p>
                    </list-item>
                </list>
            </sec>
        </sec>
        <sec sec-type="methods">
            <title>1.3 Methods</title>
            <p id="S1.3">Using healthcare data as the overarching setting, the study design used a crowd-sourced, anonymous online survey to investigate private citizen perceptions of cybersecurity as it related to those data. As respondents were UK based, the National Health Service (NHS) was assumed to be the healthcare provider. The survey included a set of ranking and matching tasks using seven cybersecurity threats and seven controls identified in a European research and innovation project to address RQs 1 to 5. These tasks were followed by a pre-validated PMT questionnaire adapted to a healthcare data sharing scenario to explore RQ 6. (The survey is available online
                <sup>
                    <xref ref-type="bibr" rid="ref-46">46</xref>
                </sup>.)</p>
            <sec sec-type="materials">
                <title>1.3.1 Materials</title>
                <p>For ranking and matching, seven common threats were identified in the project: six relate to typical technology scenarios such as data misuse (T1), the loss of or unwise use of the end user's device (T3, T7), insecure ICT infrastructure at the healthcare provider (T4, T6), or misbehaviour of an application running on the user's equipment (T5); the seventh, a common source of information about data use etc. which may be overlooked by users (T2) (see 
                    <xref ref-type="table" rid="T1">Table 1</xref>). Seven appropriate security controls were suggested (see the last two columns of 
                    <xref ref-type="table" rid="T1">Table 1</xref>). These included measures to protect data at rest and in transit (C1), process issues (C2, C5 - restricting access; C3 - providing training); and technology-centric controls (C4, C6, C7). Positioning these controls against the threats in the first two columns as shown in 
                    <xref ref-type="table" rid="T1">Table 1</xref> is for illustrative purposes only: these matchings were not exposed to survey participants; and many of the controls could be used to mitigate more than one threat.</p>
                <table-wrap id="T1" orientation="portrait" position="anchor">
                    <label>Table 1. </label>
                    <caption>
                        <title>Threats (first two columns) and potential controls (second two columns).</title>
                        <p>Note that the matching of a control to a threat is suggestive only and was not exposed to participants.</p>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Threat</th>
                                <th align="center" colspan="2" rowspan="1" valign="top">Description</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Control</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T1</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">A hospital using my data for things other than treating me</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Making sure that medical staff only see the bits of my data that are essential for my treatment rather than all of it</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C2</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T2</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Trying to understand what all the Terms and Conditions mean when I'm signing up to an app</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Making sure that my medical data are protected and can only be looked at by medical staff</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C5</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T3</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">If I lost my phone or laptop, or someone got my password, someone getting at my medical records</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Having an automatic lock on a phone or computer app, so my data stays safe even if the phone or computer is stolen</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C4</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T4</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">If the hospital gets hacked, my medical records falling into the wrong hands</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Adding protection (encryption) to all medical data wherever it's stored, sent or viewed, so it can't be tampered with</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C1</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T5</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">An app on my phone or computer might send my data to the wrong people</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Only allowing my medical data to be used on a separate computer not connected to the Internet</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C7</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T6</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">The hospital storing my medical data in the cloud (i.e., somewhere else)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Giving staff at the hospital special training on how to protect my medical data</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C3</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T7</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Using my phone or laptop in a public place where anyone might get access to my medical records</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Having threats identified continuously and counter measures automatically activated to help me manage my medical data</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>C6</bold>
</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>A draft of the survey was reviewed by peers to ensure that wording was clear, and to estimate how long the survey would take to complete. The colleagues all have some experience with cybersecurity. They took an average of 10 to 11 minutes. Using this, we established a level of payment. Participants were therefore paid a modest amount
                    <sup>
                        <xref ref-type="other" rid="FN2">2</xref>
                    </sup> for taking part.</p>
            </sec>
            <sec sec-type="subjects">
                <title>1.3.2 Participants</title>
                <p>Some 801
                    <sup>
                        <xref ref-type="other" rid="FN3">3</xref>
                    </sup> participants were recruited via a crowd-sourcing platform (
                    <italic toggle="yes">Prolific.co</italic>), since others report comparable results from crowd-sourcing platforms and student participant panels
                    <sup>
                        <xref ref-type="bibr" rid="ref-47">47</xref>
                    </sup> and slightly better demographic coverage
                    <sup>
                        <xref ref-type="bibr" rid="ref-48">48</xref>
                    </sup>. In our survey, participants were asked to self-report 
                    <italic toggle="yes">Gender Identity</italic>, 
                    <italic toggle="yes">Age Group</italic> and what they claimed to be their level of 
                    <italic toggle="yes">Expertise</italic>. This information is summarised in 
                    <xref ref-type="table" rid="T2">Table 2</xref> and compares well with existing UK population projects on (binary) gender, though there is a bias towards younger citizens regarding age group
                    <sup>
                        <xref ref-type="bibr" rid="ref-49">49</xref>
                    </sup>.</p>
                <table-wrap id="T2" orientation="portrait" position="anchor">
                    <label>Table 2. </label>
                    <caption>
                        <title>Participant demographics.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Category</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">N</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">%</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <th align="left" colspan="3" rowspan="1" valign="top">

                                    <italic toggle="yes">Gender Identity</italic>
</th>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Female</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">398</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">49.69</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Male</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">396</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">49.44</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Third gender/non-binary</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">0.50</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Prefer not to say</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">0.37</td>
                            </tr>
                            <tr>
                                <th align="left" colspan="3" rowspan="1" valign="top">

                                    <italic toggle="yes">Age Group</italic>
</th>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">18 &#x2013; 29</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">337</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">42.07</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">30 &#x2013; 49</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">359</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">44.82</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">50 &#x2013; 69</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">100</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">12.84</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">70 or over</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">0.62</td>
                            </tr>
                            <tr>
                                <th align="left" colspan="3" rowspan="1" valign="top">

                                    <italic toggle="yes">Expertise</italic>
</th>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">I'm a novice, and I prefer
                                    <break/> not to use technology</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">0.50</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">I'm OK with technology. I 
                                    <break/>use it when I need it</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">427</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">53.31</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">I'm an expert. I use
                                    <break/> technology all the time</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">370</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">46.19</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec>
                <title>1.3.3 Online survey</title>
                <p>The survey was hosted on an external platform (
                    <italic toggle="yes">Qualtrics.com</italic>) and comprised four main sections
                    <sup>
                        <xref ref-type="bibr" rid="ref-46">46</xref>
                    </sup>. First, respondents were asked to read a short passage on the threat of cybersecurity retrieved from an online website
                    <sup>
                        <xref ref-type="bibr" rid="ref-50">50</xref>
                    </sup>. This was followed by a task where respondents were asked to rank threats for seriousness or controls for effectiveness, match controls against threats, or identify who they thought responsible for implementing the control (see 
                    <xref ref-type="other" rid="S1.3.3.1">Section 1.3.3.1</xref>). Third, they were asked to respond to a set of pre-validated, PMT-derived assertions (see 
                    <xref ref-type="other" rid="S1.3.3.2">Section 1.3.3.2</xref>). Finally, they were given an opportunity to leave any general comments and asked to provide selected demographic information. None of the questions or tasks was mandatory.</p>
                <p>The survey ran twice. Initially, 500 participants responded. However, there was confusion with the way the matching task had been presented. In 
                    <xref ref-type="other" rid="S1.3.3.1">Section 1.3.3.1</xref> below, these are grouped as condition 
                    <italic toggle="yes">None</italic>. A second iteration with 301 participants was run making sure the matching task was rendered appropriately. This time, they were asked to match threats and controls, but were randomly assigned to one of two conditions: either they were given a discursive description of the control to aid understanding (
                    <italic toggle="yes">Matching &#x2013; Long Description</italic>) or a more succinct one, enough only to identify the control (
                    <italic toggle="yes">Matching &#x2013; Short Description</italic>). Different participants took part in the first and second iterations; and different participants were assigned randomly to a different task.</p>
                <p id="S1.3.3.1">
                    <bold>
                        <italic toggle="yes">1.3.3.1 Priming task</italic>.</bold> Different participants took part in the first and second iterations; and different participants were assigned randomly to each different task (see 
                    <xref ref-type="table" rid="T3">Table 3</xref>). Each activity was intended to act as a primer: threats to lead to negative affect, controls and responsibility as well as the matching tasks to positive affect.</p>
                <table-wrap id="T3" orientation="portrait" position="anchor">
                    <label>Table 3. </label>
                    <caption>
                        <title>The 6 overall priming tasks after pre-processing, showing the number of participants assigned to each task and the median time taken to respond to the whole survey.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="2" valign="middle">Label</th>
                                <th align="center" colspan="1" rowspan="2" valign="middle">Description</th>
                                <th align="center" colspan="2" rowspan="1" valign="top">Participants</th>
                                <th align="center" colspan="1" rowspan="2" valign="middle">RQs</th>
                            </tr>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="middle">N</th>
                                <th align="center" colspan="1" rowspan="1" valign="middle">Time</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Threats</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to rank seven threats by potential impact</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">94</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5m40s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">RQ1</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Controls</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to rank seven controls by perceived effectiveness of that control</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">93</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5m18s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">RQ1</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Responsibility</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to identify whom they believed responsible for implementing the control</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">109</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5m30s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">RQ5</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Matching &#x2013; Long Description</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to match the control which would best mitigate the threat (the description of the controls was more discursive)</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">142</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">7m18s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">RQ2</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Matching &#x2013; Short Description</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to match the control which would best mitigate the threat (the description of the controls was brief)</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">125</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">7m40s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">RQ2</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">None</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Participants were asked to match threats and controls, but their matching responses were discarded</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">113</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">6m53s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">(RQ2)</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">TOTAL</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">-</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">676</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">6m09s</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle"/>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>The number in the third column shows the total number randomly assigned to a given activity once outliers were removed (see 
                    <xref ref-type="other" rid="S1.4.1">Section 1.4.1</xref>). The fourth column shows the median time taken to respond to the whole survey. The timings for 
                    <italic toggle="yes">Control, Threat</italic> and 
                    <italic toggle="yes">Responsibility</italic> are approximately the same. For 
                    <italic toggle="yes">None</italic>, the time increases reflecting the confusion which the formatting caused
                    <sup>
                        <xref ref-type="other" rid="FN4">4</xref>
                    </sup>. For the 
                    <italic toggle="yes">Long</italic> and 
                    <italic toggle="yes">Short</italic> matching task, participants took longer as expected: they had to read the description of the threat, the description of the control, and then match the two. With that in mind and based on time taken, therefore, we do not believe any of the tasks to have been more or less demanding. The final column indicates the RQ targeted with the task.</p>
                <p>The intention with these tasks was to provide a positive or negative context for participants to respond to the PMT assertions: for instance, asking them to rank threats was expected to highlight vulnerability, whereas ranking controls might reduce the perceived vulnerability. Matching controls to threat would be expected to increase self-efficacy. These, therefore, target RQ4. Finally, asking participants to identify who they believed responsible for implementing controls would indicate whether they felt it their job to adopt appropriate protective behaviours (RQ5). These may be regarded as priming tasks
                    <sup>
                        <xref ref-type="bibr" rid="ref-51">51</xref>,
                        <xref ref-type="bibr" rid="ref-52">52</xref>
                    </sup> (RQ4).</p>
                <p id="S1.3.3.2">
                    <bold>
                        <italic toggle="yes">1.3.3.2 PMT questionnaire</italic>.</bold> Based on work reported by 
                    <xref ref-type="bibr" rid="ref-53">53</xref>, six constructs from a PMT model were selected as shown in 
                    <xref ref-type="table" rid="T4">Table 4</xref>. According to the PMT, these are assumed to relate to the following latent variables as follows:  
                    <italic toggle="yes">Threat Appraisal</italic> is comprised of SUS and SEV; 
                    <italic toggle="yes">Coping Appraisal</italic> of COST, BENE and SELF; and 
                    <italic toggle="yes">Intention to Act</italic> of INTEN. To pace presentation in the online survey, they were presented in pairs: SUS and SEV appeared in a section titled &#x201C;
                    <italic toggle="yes">How do you feel about cyber security now</italic>?&#x201D;; COST and BENE in &#x201C;
                    <italic toggle="yes">How do you feel about the security measures available to protect your information</italic>?&#x201D;; and SELF and INTEN in &#x201C;
                    <italic toggle="yes">Finally, how do you feel in general about threats to your information and what can be done to protect you?</italic>&#x201D;; the construct labels were not exposed to participants. A six-point Likert scale was used to collect participant responses to each of the assertions ("
                    <italic toggle="yes">Strongly Agree</italic>" to "
                    <italic toggle="yes">Strongly Disagree</italic>"). In common with other such surveys, some items were presented with opposite valence: 
                    <italic toggle="yes">I</italic>

                    <italic toggle="yes">believe that...</italic> became 
                    <italic toggle="yes">I don't believe that...</italic> (see, for instance, 
                    <xref ref-type="bibr" rid="ref-54">54</xref>). The PMT-derived assertions targeted RQ6.</p>
                <table-wrap id="T4" orientation="portrait" position="anchor">
                    <label>Table 4. </label>
                    <caption>
                        <title>Constructs from the PMT model covered in the online survey.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="middle">Construct</th>
                                <th align="center" colspan="1" rowspan="1" valign="middle">Label</th>
                                <th align="center" colspan="1" rowspan="1" valign="middle">Items</th>
                                <th align="center" colspan="1" rowspan="1" valign="middle">Description</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Susceptibility</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">SUS</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">4</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The individual's belief that they are vulnerable to attack</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Severity</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">SEV</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">4</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The individual's belief concerning the impact of such an attack</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Cost</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">COST</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">3</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The effort or resource required by the individual to take appropriate 
                                    <break/>measures to avoid an attack</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Benefit</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">BENE</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The likely benefit from taking appropriate measures to avoid attack</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Self-Efficacy</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">SELF</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">3</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The individual's belief that they are able to take appropriate action to
                                    <break/> avoid attack</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="middle">Intention to Act
                                    <sup>
                                        <xref ref-type="other" rid="FN5">5</xref>
                                    </sup>
                                </td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">INTEN</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The individual's intention to take appropriate action to avoid attack</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
        </sec>
        <sec sec-type="results">
            <title>1.4 Results</title>
            <p>In the following sections, we report how individuals responded to the priming tasks (
                <xref ref-type="other" rid="S1.4.2">Section 1.4.2</xref>) and specifically around who is perceived to be responsible for implementing controls (
                <xref ref-type="other" rid="S1.4.2.4">Section 1.4.2.4</xref>). After that, we look at the responses to the PMT-derived questionnaire (
                <xref ref-type="other" rid="S1.4.3">Section 1.4.3</xref>); and finally, any significant effects that context in terms of the priming task (
                <xref ref-type="other" rid="S1.4.4.1">Section 1.4.4.1</xref>) or demographic characteristics (
                <xref ref-type="other" rid="S1.4.4.2">Section 1.4.4.2</xref>) may have on those responses.</p>
            <sec>
                <title>1.4.1 Data pre-processing</title>
                <p id="S1.4.1">None of the individual items in the survey was mandatory. In consequence, there were occasions when responses were missing. For the PMT assertions, we removed the whole set of responses if any individual answers were missing
                    <sup>
                        <xref ref-type="other" rid="FN6">6</xref>
                    </sup>. From the original 801 original, removing incomplete responses in this way left 776 responses.</p>
                <p>From experience with crowd sourcing survey responses, we know that participants will generally complete all questions within a relatively short period of time; in our case, all initial 500 participants had responded within a matter of hours
                    <sup>
                        <xref ref-type="other" rid="FN7">7</xref>
                    </sup>. The average time was 7 minutes 7 seconds (median duration: 5 minutes 52 seconds); the shortest time was 1 minute 12 seconds, the longest 53 minutes 29 seconds. We removed any responses which were returned in less than 210 seconds (3.5 minutes), which we felt was reasonable for this survey and these participants who were accustomed to responding to surveys. This left us with a total of 676 responses.</p>
            </sec>
            <sec>
                <title>1.4.2 Private individual awareness of threats and controls</title>
                <p id="S1.4.2">For Threats and Controls, an overall score for ranking purposes was calculated as follows. When a threat was ranked first (most concerning), it was given a score of 7; when ranked second, it was given a score of 6; down to when it was ranked as the least concerning, it was given a score of 1. For example, for Threat T1, it was ranked most concerning 15 times, ranked second 11 times, and ranked least concerning 8 times. The overall score of 379 in 
                    <xref ref-type="table" rid="T5">Table 5</xref> was calculated as ((7 * 15)+(6 *11)+(5 * 11)+(4 * 14)+(3 * 19)+(2 * 16)+(1 * 8)). This process was repeated for the 
                    <italic toggle="yes">Control</italic> context.</p>
                <table-wrap id="T5" orientation="portrait" position="anchor">
                    <label>Table 5. </label>
                    <caption>
                        <title>Threats in Rank Order (N = 94
                            <sup>
                                <xref ref-type="other" rid="FN9">9</xref>
                            </sup>).</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Threat</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Description</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Rank</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Score</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">T3</italic>
</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">If I lost my phone or laptop, or someone got my password, someone getting at my medical records</italic>
</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">1st</italic>
</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">515</italic>
</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T4</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">If the hospital gets hacked, my medical records falling into the wrong hands</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">2
                                    <sup>nd</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">488</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T5</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">An app on my phone or computer might send my data to the wrong people</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">3
                                    <sup>rd</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">403</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T1</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">A hospital using my data for things other than treating me</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">4
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">379</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T7</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Using my phone or laptop in a public place where anyone might get access to my medical records</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">366</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T6</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">The hospital storing my medical data somewhere else (i.e., in the cloud)</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">6
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">257</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">T2</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Trying to understand what all the Terms and Conditions mean when I&#x2019;m signing up to an app</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">7
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">224</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p id="S1.4.2.1">
                    <bold>
                        <italic toggle="yes">1.4.2.1 Threats</italic>.</bold> 
                    <xref ref-type="table" rid="T5">Table 5</xref> summarises the calculated overall rankings provided by private individuals assigned to this task. The highest threat (T3) was deemed to come from loss of a personal device (the 
                    <italic toggle="yes">threat event</italic>), leading to a breach of personal health data (the 
                    <italic toggle="yes">risk</italic>). Similarly, T4 refers to a breach at the service provider (in this case, a hospital) premises. There was less concern for threats relating to actions they could take (T7 and T2), or about secondary use of data (T1). Private individuals are therefore capable of assessing the relative importance of cybersecurity threats. RQ1 is therefore partially answered
                    <sup>
                        <xref ref-type="other" rid="FN8">8</xref>
                    </sup>.</p>
                <p>
                    <bold>
                        <italic toggle="yes">1.4.2.2 Controls</italic>.</bold> 
                    <xref ref-type="table" rid="T6">Table 6</xref> summarises the rankings assigned to the suggested controls when presented in isolation. Overall, participants regarded measures to protect their data wherever they are stored or transmitted (C1) as the most effective control. Controls restricting access (C5 and C4) were next. The infrastructure in the terms of data stored outside the data controller&#x2019;s premises (C7) was regarded as least important. As with threats, private individuals were able to make decisions about cybersecurity controls. In terms of effectiveness, encryption is a reasonable control as a default mechanism to protect the data. Along with ranking 
                    <italic toggle="yes">threats</italic> (
                    <xref ref-type="other" rid="S1.4.2.1">Section 1.4.2.1</xref>), RQ1 is answered: private individuals in the UK 
                    <italic toggle="yes">can</italic> evaluate threats and controls in terms of perceived severity / effectiveness.</p>
                <table-wrap id="T6" orientation="portrait" position="anchor">
                    <label>Table 6. </label>
                    <caption>
                        <title>Controls in rank order (N = 93
                            <sup>
                                <xref ref-type="other" rid="FN9">9</xref>
                            </sup>).</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Control</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Description (
                                    <italic toggle="yes">Long</italic>)</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Rank</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Score</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">C1</italic>
</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">Adding protection (encryption) to all medical data wherever it's stored, sent or viewed, so it can't be tampered with</italic>
</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">1
                                            <sup>st</sup>
</italic>
</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">

                                    <bold>

                                        <italic toggle="yes">559</italic>
</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C5</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Making sure that my medical data are protected and can only be looked at by medical staff</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">2
                                    <sup>nd</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">458</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C4</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Having an automatic lock on a phone or computer app, so my data stays safe even if the phone or computer is stolen</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">3
                                    <sup>rd</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">367</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C6</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Having threats identified continuously and counter measures automatically activated to help me manage my medical data</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">4
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">348</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C2</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Making sure that medical staff only see the bits of my data that are essential for my treatment rather than all of it</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">5
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">324</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C3</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Giving staff at the hospital special training on how to protect my medical data</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">6
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">308</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="middle">C7</td>
                                <td align="left" colspan="1" rowspan="1" valign="middle">Only allowing my medical data to be used on a separate computer not connected to the Internet</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">7
                                    <sup>th</sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="middle">240</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>
                    <bold>
                        <italic toggle="yes">1.4.2.3 Matching threats and controls</italic>.</bold> In the second iteration of the survey, participants were asked to match a control to a threat, i.e., how would they mitigate the risk associated with a given threat? Participants could match the same control to different threats. 
                    <xref ref-type="table" rid="T7">Table 7</xref> and 
                    <xref ref-type="table" rid="T8">Table 8</xref> summarise the results using short and long descriptions respectively.</p>
                <table-wrap id="T7" orientation="portrait" position="anchor">
                    <label>Table 7. </label>
                    <caption>
                        <title>Matching controls to threats based on a short description of the control.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top"/>
                                <th align="center" colspan="7" rowspan="1" valign="top">Control (
                                    <italic toggle="yes">Short Description</italic>)</th>
                            </tr>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Threat</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C5</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C6</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C7</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">
                                    <bold>T1</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>56</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">35</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">18</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">14</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">
                                    <bold>T2</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>46</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">21</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">29</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T3</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">31</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>79</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T4</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>61</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">11</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">24</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">17</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T5</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>53</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">11</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">14</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">21</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">19</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T6</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>65</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">14</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">25</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T7</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <italic toggle="yes">38</italic>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>39</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">12</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">25</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Total</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">350</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">56</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">65</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">137</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">68</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">99</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">100</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Rank</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <table-wrap id="T8" orientation="portrait" position="anchor">
                    <label>Table 8. </label>
                    <caption>
                        <title>Matching controls to threats based on a long description of the control.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top"/>
                                <th align="center" colspan="7" rowspan="1" valign="top">Control (
                                    <italic toggle="yes">Long Description</italic>)</th>
                            </tr>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Threat</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C5</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C6</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C7</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T1</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>56</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">28</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">28</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T2</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>36</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">22</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">11</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">28</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">30</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T3</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">23</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>102</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T4</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>86</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">19</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">21</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T5</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>56</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">13</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">31</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">21</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T6</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>79</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">13</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">15</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">24</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>T7</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>58</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">36</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">20</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">12</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Total</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">403</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">51</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">49</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">167</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">127</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">116</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">79</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Rank</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>A Mann-Whitney U test on the totals in these two tables showed no significant differences based on the length of the control description when matched against a potential threat (Z = 23.00, p = 0.902).</p>
                <p>
                    <xref ref-type="table" rid="T9">Table 9</xref> compares the selection of controls from the matching task with the selection of controls in isolation, that is when participants were asked to rank controls from the most effective to the least effective with no reference to 
                    <italic toggle="yes">threat</italic> (see 
                    <xref ref-type="table" rid="T6">Table 6</xref>
                    <sup>
                        <xref ref-type="other" rid="FN11">11</xref>
                    </sup>). C1 (
                    <italic toggle="yes">Adding protection (encryption) to all medical data wherever it's stored, sent or viewed, so it can't be tampered with</italic>) has been ranked as most effective and matched most often to the threats presented in the survey. On its own, this may indicate that participants regarded this control as a catchall. However, since other rankings lower down in effectiveness are close across the matching task and ranking in isolation, this may suggest that participants are making informed decisions about cybersecurity controls. We therefore believe RQ2 has also been answered affirmatively.</p>
                <table-wrap id="T9" orientation="portrait" position="anchor">
                    <label>Table 9. </label>
                    <caption>
                        <title>Comparing the selection of controls.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="2" valign="top"/>
                                <th align="center" colspan="7" rowspan="1" valign="top">Control</th>
                            </tr>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">C1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C5</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C6</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C7</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="8" rowspan="1" valign="top">&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;
                                    <bold>Matching (
                                        <italic toggle="yes">Short Description</italic>)</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Total</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">350</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">56</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">65</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">137</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">68</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">99</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">100</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Rank</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="8" rowspan="1" valign="top">&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;
                                    <bold>Matching (
                                        <italic toggle="yes">Long Description</italic>)</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Total</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">403</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">51</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">49</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">167</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">127</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">116</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">79</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Rank</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="8" rowspan="1" valign="top">&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;&#xA0;
                                    <bold>Independent Ranking (
                                        <italic toggle="yes">regardless of</italic>
                                    </bold> 
                                    <break/>
                                    <bold>
                                        <italic toggle="yes">Threat
                                            <sup>
                                                <xref ref-type="other" rid="FN10">10</xref>
                                            </sup>)</italic>
</bold>
</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Total</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">559</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">324</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">308</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">367</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">458</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">348</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">240</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">

                                    <bold>Rank</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">=</td>
                                <td align="center" colspan="1" rowspan="1" valign="top"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">&#x2248;</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">&#x2248;</td>
                                <td align="center" colspan="1" rowspan="1" valign="top"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">=</td>
                                <td align="center" colspan="1" rowspan="1" valign="top"/>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p id="S1.4.2.4">
                    <bold>
                        <italic toggle="yes">1.4.2.4 Responsibility for implementing cybersecurity controls</italic>.</bold> 
                    <xref ref-type="table" rid="T10">Table 10</xref> summarises private individual perceptions of who is responsible for implementing a given control. Looking at the final column (labelled &#x2018;
                    <italic toggle="yes">Total</italic>&#x2019;), not surprisingly since participants were asked to consider health data, it is the data controller (the NHS or the hospital) who is regarded as responsible for implementing controls in most cases. On the other hand, since data encryption at rest and in transit was regarded as the most effective control (see 
                    <xref ref-type="table" rid="T9">Table 9</xref> and Control C1), presumably data subjects believe someone else to be responsible for the secure handling of their data.</p>
                <table-wrap id="T10" orientation="portrait" position="anchor">
                    <label>Table 10. </label>
                    <caption>
                        <title>Who participants believe to be responsible for implementing the control (N = 109); the highest ranked agent(s) is shown in bold.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Who is Responsible?</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C5</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C6</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C7</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Total</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">I am</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>60</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">78</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the Government</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">13</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">20</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">53</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the NHS</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>37</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>49</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>52</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>52</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">19</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>45</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">257</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the Hospital</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">23</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">42</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">22</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">36</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">135</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the phone / computer manufacturer</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">26</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">43</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the person who wrote the app</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <italic toggle="yes">
                                        <bold>32</bold>
                                    </italic>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">26</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">13</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">20</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>27</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">11</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">130</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">the network carrying the information</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">19</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">5</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">0</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">7</td>
                                <td align="center" colspan="1" rowspan="1" style="background-color:#D0CECE" valign="top">
                                    <bold>27</bold>
                                </td>
                                <td align="center" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">67</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>Looking at the detail in 
                    <xref ref-type="table" rid="T10">Table 10</xref> (the columns marked C1 to C7), there are two exceptions to the data controller having responsibility for all controls. First, in response to C4 (
                    <italic toggle="yes">Having an automatic lock on a phone or computer app, so my data stays safe even if the phone or computer is stolen</italic>), the individual who owns or manages the device is identified as responsible. Encouragingly, private individuals recognise their own obligation to protect their own devices. Secondly, for C6 (
                    <italic toggle="yes">Having threats identified continuously and counter measures automatically activated to help me manage my medical data</italic>)
                    <italic toggle="yes">,</italic> private individuals identify the manufacturer or network provider as responsible. This makes sense 
                    <italic toggle="yes">a priori</italic> in that the developer could be expected to maintain cybersecurity standards on behalf of the end user. Further, it is common nowadays for software by default to install necessary updates whenever they become available and the device running the software is connected to the Internet.</p>
                <p>There is some indication, therefore, that private individuals are making informed decisions about cybersecurity threats and controls. More importantly, that they may also decide who is responsible when it comes to implementing a control based on the specific context as illustrated in 
                    <xref ref-type="table" rid="T10">Table 10</xref>. RQ5 is therefore answered for this context (healthcare data).</p>
            </sec>
            <sec>
                <title>1.4.3 Modelling private individual responses to cybersecurity threats to healthcare data</title>
                <p id="S1.4.3">Pooled responses to the PMT-type assertions (
                    <italic toggle="yes">676</italic> after initial screening for outliers as described) were quantified including reverse coded items  marked with an asterisk (*) in 
                    <xref ref-type="table" rid="T11">Table 11</xref> (
                    <italic toggle="yes">Strongly Agree</italic> as 6 to 
                    <italic toggle="yes">Strongly Disagree</italic> as 1; reverse coded items: 
                    <italic toggle="yes">Strongly Agree</italic> as 1 to 
                    <italic toggle="yes">Strongly Disagree</italic> as 6). The Likert scores were used to drive an exploratory factor analysis (EFA)
                    <sup>
                        <xref ref-type="other" rid="FN12">12</xref>
                    </sup>. The rationale for factor analysis was to find structure within a data set as it might relate to the PMT model (see 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>).</p>
                <table-wrap id="T11" orientation="portrait" position="anchor">
                    <label>Table 11. </label>
                    <caption>
                        <title>Factor loadings from the 5-factor solution (with Oblimin rotation).</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Item</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">Description</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">C
                                    <sup>
                                        <xref ref-type="other" rid="FN13">13</xref>
                                    </sup>
                                </th>
                                <th align="center" colspan="5" rowspan="1" valign="top">Factor Loadings</th>
                            </tr>
                            <tr>
                                <th align="left" colspan="8" rowspan="1" valign="top">
                                    <bold>Subscale</bold> 
                                    <italic toggle="yes">Intention to Act</italic> (Cronbach&#x2019;s &#x3B1; = 0.890)</th>
                            </tr>
                            <tr>
                                <th colspan="1" rowspan="1"/>
                                <th colspan="1" rowspan="1"/>
                                <th colspan="1" rowspan="1"/>
                                <th align="center" colspan="1" rowspan="1" valign="top">1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">5</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">INTEN4</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I am certain I will keep using security measures</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.834</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.929</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">INTEN1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I'm going to keep using security measures</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.702</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.790</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">INTEN3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I would use security measures wherever possible</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.621</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.776</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">INTEN2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">It is possible that I will use security measures</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.574</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.673</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">INTEN5</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I'm not likely to keep using security measures *
                                    <sup>
                                        <xref ref-type="other" rid="FN14">14</xref>
                                    </sup>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.488</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.670</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <th align="left" colspan="8" rowspan="1" valign="top">
                                    <bold>Subscale</bold> 
                                    <bold>
                                        <italic toggle="yes">Self-Efficacy</italic> (Cronbach&#x2019;s &#x3B1; = 0.888)
                                        <sup>
                                            <xref ref-type="other" rid="FN15">15</xref>
                                        </sup>
                                    </bold>
</th>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SELF2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I have the expertise to add measures to stop people from getting my confidential information</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.819</td>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.886</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SELF1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I have the necessary skills to protect myself from hackers</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.784</td>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.874</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <th align="left" colspan="8" rowspan="1" valign="top">
                                    <bold>Subscale</bold>

                                    <italic toggle="yes">Benefit</italic>

                                    <bold>(Cronbach&#x2019;s &#x3B1; = 0.742)</bold>
</th>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">BENE2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Efforts to ensure the safety of my confidential information are really effective</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.626</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.707</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">BENE1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enabling the security measures is an effective way to deter hacker attacks</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.538</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.649</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">BENE3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Enabling security measures would stop hackers getting access to sensitive information</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.371</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.560</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <th align="left" colspan="8" rowspan="1" valign="top">
                                    <bold>Subscale</bold>

                                    <italic toggle="yes">Severity</italic>

                                    <bold>(Cronbach&#x2019;s &#x3B1; = 0.832)</bold>
</th>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SEV2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I could fall victim to a malicious attack if I don't take appropriate security measures</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.808</td>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.896</td>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SEV1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I know I could be vulnerable to security breaches if I don't take care</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.583</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.798</td>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SEV4</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">My data and computer or phone may be compromised if I don't pay attention to security</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.558</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.651</td>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                            <tr>
                                <th align="left" colspan="8" rowspan="1" valign="top">
                                    <bold>Subscale</bold>

                                    <italic toggle="yes">Sources of Information</italic>

                                    <bold>(Cronbach&#x2019;s &#x3B1; = 0.631)</bold>
</th>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SEV3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I don't believe that trying to protect my information will reduce illegal access to it *</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.317</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.542</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">BENE4</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Available measures to protect my information are not effective *</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.341</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.536</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">SELF3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">I don't believe it's in my control to protect my information *</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.319</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.508</td>
                            </tr>
                            <tr>
                                <td align="center" colspan="1" rowspan="1" valign="top">COST1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">It would be too costly for me to adopt many security measures *</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">.333</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">.492</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>Using all 676 response sets, a Principal Axis Factoring analysis with Oblimin rotation
                    <sup>
                        <xref ref-type="other" rid="FN16">16</xref>
                    </sup> and Kaiser normalisation yielded a determinant of 0.00037, Kaiser-Meyer-Olkin of 0.892, and a significant Bartlett&#x2019;s test of sphericity result (
                    <italic toggle="yes">&#x3C7;</italic>
                    <sup>2</sup> (276) = 6861.08, p&lt;.001). This suggested the data were suitable for factor analysis. With that in mind, the analysis was repeated iteratively as follows: any items where correlations were &#x2264; |0.300| were removed; any extraction communalities below 0.300 and factor loadings less than |0.400| were all removed. After an initial analysis retaining factors with eigenvalues &#x2265; 1 and using the .40-.30-.20 rule
                    <sup>
                        <xref ref-type="bibr" rid="ref-55">55</xref>
                    </sup> and the scree plot, a 5 factor solution was generated
                    <sup>
                        <xref ref-type="other" rid="FN17">17</xref>
                    </sup>: Principal Axis Factoring with Oblimin rotation and Kaiser normalisation and rotation converging in 7 iterations, accounting for 68.61% of the variance. 
                    <xref ref-type="table" rid="T11">Table 11</xref> summarises the solution; reliability of each construct ranges between 0.890 and 0.631, as measured with Cronbach&#x2019;s &#x3B1;. The table shows the individual items, their extraction communalities, and factor loadings. Note that all five items for the 
                    <italic toggle="yes">Intention to Act</italic> construct (see 
                    <xref ref-type="table" rid="T4">Table 4</xref>) contribute to the model; this is not the case for the others.</p>
                <p>
                    <xref ref-type="table" rid="T12">Table 12</xref> shows corresponding correlations between the factors. Correlations generally indicate reasonable separation between factors. Factors 1 (
                    <italic toggle="yes">Intention to Act</italic>) and 4 (
                    <italic toggle="yes">Severity</italic>) represent a possible exception. With a correlation of 0.501 suggesting the factors covary and so may effectively reflect similar constructs, this is not surprising though, since it is to be expected that as perceived 
                    <italic toggle="yes">Severity</italic> increases, so the intention to take action will increase. Excepting possibly Factor 4 (
                    <italic toggle="yes">Severity</italic>), all factors correlate with the Factor 5 (which we have labelled: 
                    <italic toggle="yes">Sources of Information</italic>). This suggests that this factor is significant in the decisions making leading to the 
                    <italic toggle="yes">Intention to Adopt</italic> security measures.</p>
                <table-wrap id="T12" orientation="portrait" position="anchor">
                    <label>Table 12. </label>
                    <caption>
                        <title>Factor correlations for the 5-factor solution.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="center" colspan="1" rowspan="1" valign="top">Factor</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">1</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">2</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">3</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">4</th>
                                <th align="center" colspan="1" rowspan="1" valign="top">5</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">

                                    <bold>1</bold>
</td>
                                <td align="center" colspan="1" rowspan="1" valign="top">-</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.292</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.380</td>
                                <td colspan="1" rowspan="1">

                                    <italic toggle="yes">

                                        <bold>.501</bold>
</italic>
</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.365</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">

                                    <bold>2</bold>
</td>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">-</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.197</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.075</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.436</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">

                                    <bold>3</bold>
</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">-</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.334</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.397</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">

                                    <bold>4</bold>
</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">-</td>
                                <td align="right" colspan="1" rowspan="1" valign="top">.196</td>
                            </tr>
                            <tr>
                                <td align="right" colspan="1" rowspan="1" valign="top">

                                    <bold>5</bold>
</td>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td colspan="1" rowspan="1"/>
                                <td align="center" colspan="1" rowspan="1" valign="top">-</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>The subscale 
                    <italic toggle="yes">Cost</italic> is not represented in the 5-factor solution, which may be either because another party is assumed to take responsibility to implement controls or simply that it&#x2019;s accepted as part and parcel of online activity (see below). Apart from 
                    <italic toggle="yes">Cost,</italic> therefore
                    <italic toggle="yes">,</italic> the PMT model (see 
                    <xref ref-type="other" rid="S1.2.3">Section 1.2.3</xref> is partially validated as expected: specifically, with reference to the original model (see 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>), private individuals do make some kind of 
                    <italic toggle="yes">Threat Appraisal</italic> (Factor 4, 
                    <italic toggle="yes">Severity</italic>) and corresponding 
                    <italic toggle="yes">Coping Appraisal</italic> (Factors 3, 
                    <italic toggle="yes">Benefit</italic>, and 2, 
                    <italic toggle="yes">Self-Efficacy</italic>), leading to an intention to do something to counter the threats (Factor 1, 
                    <italic toggle="yes">Intention to Act</italic>). Factor 5, which we have labelled 
                    <italic toggle="yes">Sources of Information</italic> in 
                    <xref ref-type="table" rid="T11">Table 11</xref>, does not fit the 
                    <italic toggle="yes">Cognitive Mediating Processes</italic> of the PMT model completely, however. In answer to RQ6, therefore, there is evidence that private individuals in the UK rely on additional 
                    <italic toggle="yes">Sources of Information</italic> when making decisions about implementing cybersecurity 
                    <italic toggle="yes">controls</italic>.</p>
                <p>
                    <bold>
                        <italic toggle="yes">1.4.3.1 Freeform comments</italic>.</bold> There were 72 comments left including expressing thanks, pointing out issues with the survey format, and so forth. However, there was evidence that participants had given some thought independently to cybersecurity. From identifying who should be responsible:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>&#x201C;Companies should up their security as online has become so common now&#x201D; and</p>
                    </list-item>
                    <list-item>
                        <label/>
                        <p>&#x201C;Emphasis should be on user. My workplace was hacked and my personal data taken, despite me taking personal measures to not share my info.&#x201D;</p>
                    </list-item>
                </list>
                <p>Including recognising problems of visibility online:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>&#x201C;In my opinion the highest threat about most people getting hacked is by publicly displaying much of their information by themselves, filling all the facebook info down the phone number and secondly using an universal password, so getting hacked on something, gives the hackers accest [
                            <italic toggle="yes">sic.</italic>] to many other things.&#x201D;</p>
                    </list-item>
                </list>
                <p>Concerns about cost:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>&#x201C;I am on a low income therefore cannot afford to pay for these kind of things.&#x201D; and &#x201C;No mention made about costs This could be a determining factor as to the level of security obtainable&#x201D;</p>
                    </list-item>
                </list>
                <p>And about the field in general:</p>
                <list list-type="bullet">
                    <list-item>
                        <label/>
                        <p>&#x201C;I read that cyber attacks occur continuously 24/7 and that criminal elements are often involved as well as state actors who try to harm important state infrastructure. I wonder what role AI will play in protecting from cyber attacks, or worse, if it could be used to perpetrate such acts.&#x201D;</p>
                    </list-item>
                </list>
                <p>Participants are aware, of course, and had been primed if not by the ranking and matching tasks, then at least by the introductory passage on cybersecurity. But they do recognise that there are multiple factors associated with maintaining cybersecurity readiness. This includes:</p>
                <list list-type="bullet">
                    <list-item>
                        <p>an awareness of all online activity affecting security of data (
                            <italic toggle="yes">living in a digital world)</italic>
                        </p>
                    </list-item>
                    <list-item>
                        <p>the cost of implementation (
                            <italic toggle="yes">what digitalisation implies</italic>), and</p>
                    </list-item>
                    <list-item>
                        <p>a need for service-providers and users to cooperate and coordinate responses to cybersecurity threats (
                            <italic toggle="yes">responsibility</italic>)</p>
                    </list-item>
                </list>
                <p>Their comments seem to expand on Factor 5 (
                    <italic toggle="yes">Sources of Information</italic>) in the EFA model above (
                    <xref ref-type="table" rid="T11">Table 11</xref>): participants appreciate that something must be done, that there are multiple aspects to ensuring cybersecurity readiness, that this will be costly, but do not see themselves solely responsible to implement controls.</p>
            </sec>
            <sec>
                <title>1.4.4 The effect of context</title>
                <p>For each of the six constructs in 
                    <xref ref-type="table" rid="T4">Table 4</xref>, the total Likert response score for a given respondent was summed across all items to give a total score for that construct. Thus, for each participant responding to the four items under 
                    <italic toggle="yes">Susceptibility</italic> a total was derived by summing the individual responses for each of those four items. Parametric tests were undertaken to identify potential effects of these contexts on responses to the PMT-derived assertions. Given the assumptions associated with parametric tests, we first reviewed the frequency distributions for the total values for each construct and for 
                    <italic toggle="yes">Threat Appraisal</italic>, 
                    <italic toggle="yes">Coping Appraisal</italic> and the grand total for each participant. Although 
                    <italic toggle="yes">Susceptibility, Severity</italic> and 
                    <italic toggle="yes">Intention to Act</italic> showed a negative skew by eye, all other constructs approximated a normal distribution. Much has been written about violation of the assumption of a normal distribution (see, for example, 
                    <xref ref-type="bibr" rid="ref-56">56</xref>). Because of the sample sizes here and an assumption based on the central limit theorem that with sufficient samples the distribution of sample means will tend towards a normal distribution, we decided to proceed with parametric tests. The assumptions of equal variance were individually tested as reported below.</p>
                <p id="S1.4.4.1">
                    <bold>
                        <italic toggle="yes">1.4.4.1 Priming</italic>.</bold> To test if the priming tasks affected the total Likert scores for each construct, a MANOVA was run
                    <sup>
                        <xref ref-type="other" rid="FN12">12</xref>
                    </sup>. First, responses from the original survey associated with matching controls and threats (labelled 
                    <italic toggle="yes">None</italic>) were removed, giving a revised total of (676 &#x2013; 113 =) 563 responses. Box&#x2019;s M (85.371, p=0.499) was not significant, indicating that there was no violation of the assumption of homogeneity of the variance-covariance matrices. Further, there was a significant difference in total Likert scores across the constructs depending on priming task: 
                    <italic toggle="yes">F(24,1930.40)</italic> = 1.594, Wilks&#x2019; &#x3BB; = 0.934, p = 0.034, &#x3B7;
                    <sup>2</sup> = 0.017. Although significant, the effect is small accounting for around 1.7% of the variance.</p>
                <p id="S1.4.4.2">
                    <bold>
                        <italic toggle="yes">1.4.4.2 Demographic category removal.</italic>
                    </bold> When testing for any significant effects of context, and to avoid very large discrepancies in the samples within a given category, responses from 
                    <bold>
                        <italic toggle="yes">Gender Identity</italic>
                    </bold> (for 
                    <italic toggle="yes">Third gender&#x2026;</italic> and 
                    <italic toggle="yes">Prefer not to say</italic>), from 
                    <bold>
                        <italic toggle="yes">Age Group</italic>
                    </bold>, (for 
                    <italic toggle="yes">70 or over</italic>), and 
                    <bold>
                        <italic toggle="yes">Expertise</italic>
                    </bold>, (for 
                    <italic toggle="yes">I&#x2019;m a novice</italic>&#x2026;) were removed for the significance testing only. This left two groups for 
                    <italic toggle="yes">Gender Identity</italic> and 
                    <italic toggle="yes">Expertise,</italic> and three for 
                    <italic toggle="yes">Age Group</italic>.</p>
                <p>
                    <bold>1.4.4.2.1 Self-reported expertise</bold>
                </p>
                <p>Although Box&#x2019;s test was significant (M = 33.995, p=.040), differences between the total Likert scores associated with Self-Reported Expertise seemed to be significant (
                    <italic toggle="yes">F(6,543) =</italic> 8.245, Wilks&#x2019; &#x3BB; = 0.916, p &lt; 0.001, &#x3B7;
                    <sup>2</sup> = 0.084). From visual inspection of plots for the means associated with self-reported expertise, all Likert totals were higher for the experts than for those reporting that they were 
                    <italic toggle="yes">OK with technology</italic>&#x2026;. Between-Subject tests, however, revealed the differences for the constructs COST (p &lt; .001, &#x3B7;
                    <sup>2</sup> = .029), BENE (p = .045, &#x3B7;
                    <sup>2</sup> = .007), SELF (p&lt;.001, &#x3B7;
                    <sup>2</sup> = .069) and INTEN (p &lt; .001, &#x3B7;
                    <sup>2</sup> = .025) to be significant. These differences, therefore, account for at least .7 % (for 
                    <italic toggle="yes">Benefit</italic>) but no more than 6.9% (for 
                    <italic toggle="yes">Self-Efficacy</italic>) of the variance in the data.</p>
                <p>
                    <bold>1.4.4.2.2 Age</bold>
                </p>
                <p>Box&#x2019;s test was not significant (M = 54.960, p=.104). The differences between the total Likert scores associated with Age Group was significant (
                    <italic toggle="yes">F(12,1084) =</italic> 2.765, Wilks&#x2019; &#x3BB; = 0.941, p = 0.001, &#x3B7;
                    <sup>2</sup> = 0.030). Visual inspection of the plots of the means associated with age group, for SUS, SEV, COST, and INTEN, the oldest group (50 to 69) reported the highest and the youngest (18 to 29) the lowest total Likert scores; for BENE and SELF, the oldest group reported scores lower than the middle age group. However, Between-Subject tests revealed that only SEV (p=.010, &#x3B7;
                    <sup>2</sup> = .017), COST (p=.001, &#x3B7;
                    <sup>2</sup> = .025), SELF (p=.031, &#x3B7;
                    <sup>2</sup> = .013), and INTEN (p=.004, &#x3B7;
                    <sup>2</sup> = .020) showed significant effects for age group. These differences account for between 1.3% (
                    <italic toggle="yes">Self-Efficacy</italic>) and 2.5% (
                    <italic toggle="yes">Cost</italic>) in the variance.</p>
                <p>
                    <bold>1.4.4.2.3 Gender identity</bold>
                </p>
                <p>Box&#x2019;s test was not significant (M = 29.526, p=.110). The differences between the total Likert scores associated with self-reported Gender Identity was significant (
                    <italic toggle="yes">F(6,543) =</italic> 8.330, Wilks&#x2019; &#x3BB; = 0.916, p &lt; 0.001, &#x3B7;
                    <sup>2</sup> = 0.084). From visual inspection of plots for self-reported expertise, Likert totals for construct SUS were higher for Females than for Males; for all other constructs, the opposite was true.  Between-Subject tests, however, revealed the differences for the constructs SUS (p = .010, &#x3B7;
                    <sup>2</sup> = .012), COST (p &lt; .001, &#x3B7;
                    <sup>2</sup> = .023), SELF (p&lt;.001, &#x3B7;
                    <sup>2</sup> = .045) and INTEN (p = .020, &#x3B7;
                    <sup>2</sup> = .010) to be significant. Gender Identity appears to account for between 1% (
                    <italic toggle="yes">Intention to Act</italic>) and 4.5% (
                    <italic toggle="yes">Self-Efficacy</italic>) of the variance.</p>
                <p>
                    <bold>
                        <italic toggle="yes">1.4.4.3 Does context affect responses?</italic>
                    </bold> From 
                    <xref ref-type="other" rid="S1.4.4.1">Section 1.4.4.1</xref>, and assuming priming to influence affect (i.e., an emotional response
                    <sup>
                        <xref ref-type="bibr" rid="ref-29">29</xref>
                    </sup>), there is some evidence to support RQ4: context does have a small effect (here about 1.7% of variance) on cybersecurity judgements based on the constructs of the PMT. From 
                    <xref ref-type="other" rid="S1.4.4.2">Section 1.4.4.2</xref> and the associated subsections, there is further evidence to support RQ4: speaker characteristics also have a small effect (though no more than would account for 6.9% of the variance) on cybersecurity judgements. This suggests that the five factors identified in 
                    <xref ref-type="other" rid="S1.4.3">Section 1.4.3</xref> are generally robust across contexts (including demographics), with other some minor influence from such factors.</p>
            </sec>
        </sec>
        <sec sec-type="discussion">
            <title>1.5 Discussion</title>
            <p>The previous sections showed that private individuals were able to make judgements about threats and controls, certainly in terms of ranking severity or effectiveness respectively, and were able to match a suitable control to a given threat. They did not, however, see themselves responsible across the board for protecting their (health) data. Awareness is therefore not the issue, we believe, when assessing private individual role in addressing cybersecurity threats. At the same time, from the EFA and the resulting Factor 5, making decisions to act on that awareness is not solely a cost-benefit decision. From the original PMT model, the 
                <italic toggle="yes">Sources of Information</italic> act as antecedents to the cost-benefit activity. As borne out by the freeform comments, private individuals are considering broader challenges such as cost, the effectiveness of controls and their self-efficacy.</p>
            <p>Drawing a parallel with a traditional view that technology acceptance is predicted by the perceived usefulness and perceived ease-of-use of that technology (the Technology Acceptance Model and derivatives
                <sup>
                    <xref ref-type="bibr" rid="ref-57">57</xref>,
                    <xref ref-type="bibr" rid="ref-58">58</xref>
                </sup>), decision-making around technology adoption has to be contextualised within potential users&#x2019; understanding of background issues independent of the technology itself. They are capable of being part of the solution for cybersecurity threats
                <sup>
                    <xref ref-type="bibr" rid="ref-9">9</xref>
                </sup>, but that means that infrastructure operators and technology suppliers need to understand who their target audience believes responsible for control measures. Beyond that, they need to appreciate what those users believe the effectiveness of the technology to be and consider cost to the end user which seems to be part of a generalised consideration (the 
                <italic toggle="yes">Sources of Information</italic> above) rather than the cost-benefit assessment for the specific domain.</p>
        </sec>
        <sec>
            <title>1.6 Limitations and future work</title>
            <p>The priming had only a marginal effect on attitudes, which may be the result of an ambiguous effect of priming on cybersecurity behaviours. As Sharma and her colleagues found, there was an effect when priming for risks, but they could not provoke behaviour change through positive and negative messaging
                <sup>
                    <xref ref-type="bibr" rid="ref-29">29</xref>
                </sup>. Nevertheless, the failure here to see a highly significant effect may result from one or both of the following: first, it could be that our common cybersecurity awareness introductory message had the primary effect and not subsequent exposure to threats or controls; secondly, there were more scenarios (
                <italic toggle="yes">controls, responsibility</italic> and 
                <italic toggle="yes">matching</italic>) which were intended to produce a positive effect. In future, we will revisit this aspect of our survey or any associated discussion groups. Further, using a crowdsourcing platform to distribute the anonymous survey to a balanced cohort has advantages
                <sup>
                    <xref ref-type="bibr" rid="ref-47">47</xref>,
                    <xref ref-type="bibr" rid="ref-48">48</xref>
                </sup>. For this study, there are two potential caveats. First, by definition, and regardless of the expertise question in the survey, as members of the platform participant pool, they can be expected to be more aware of the digital environment than the population as a whole. Secondly, the NHS is the UK is generally trusted regarding healthcare, especially during and following the SARS-CoV-2 pandemic
                <sup>
                    <xref ref-type="other" rid="FN18">18</xref>
                </sup>. This may have influenced perceptions, inflating the reliance on the NHS to hold healthcare data securely. In future, we would look to using a different context than healthcare data sharing to establish whether current responses persist for different data types and different data controllers. Additionally, the selection of threats and possibly controls was dictated at the time by the research and innovation project. Some of the threats, therefore, may have seemed only remotely relevant to the participants, especially situated in a &#x2018;hospital&#x2019; or regarding infrastructure. This could be addressed either by looking for common threats identified in the press or by generating the list of threats based on focus-group discussion with members of the public. Finally, we did not separately ask participants who might be responsible to handle a specific threat. For instance, T3 and T7 could be construed as something the individual user should be aware of and take measures to address. This could easily be added to a future iteration and thereby provide greater understand of participants&#x2019; (private individuals&#x2019;) awareness of digital security threats.</p>
        </sec>
        <sec sec-type="conclusions">
            <title>1.7 Conclusion</title>
            <p>Using healthcare data as an umbrella context, responses to an online anonymous survey of a total of 801 UK private individuals demonstrated that they were able to evaluate the severity of threats to the security of their data and the effectiveness of potential controls to mitigate the risks associated with those threats (RQ1, RQ2). Participant demographics had marginal effects on their responses to a standard (PMT-based) set of assertions (RQ3); similarly, any emotional response to the priming tasks was also marginal (RQ4). However, they did not see themselves responsible for implementing controls in all environments (RQ5): they expected device manufacturers or software developers to handle automatic updates to keep their data safe, and only accepted responsibility for their own device. Overwhelmingly, though, they saw the data controller processing their data (the NHS in the UK or associated hospital) to be responsible for most aspects of cybersecurity. Finally, an exploratory factor analysis revealed that decisions to protect their data may not only rely on rational judgement (
                <italic toggle="yes">Cognitive Mediating Processes</italic> from PMT). Instead, there was some suggestion borne out by freeform comments that broader concerns such as the complexity of online activity, the cost associated with being secure, and the need for service provider and service user to collaborate on cybersecurity (RQ6). This research study has therefore contributed to our understanding of how end users within a socio-technical context respond to cybersecurity. To succeed, approaches like Zimmermann and Renaud&#x2019;s 
                <italic toggle="yes">Cybersecurity, Differently,</italic> whereby private individuals become &#x201C;part of the solution&#x201D;
                <sup>
                    <xref ref-type="bibr" rid="ref-9">9</xref>
                </sup>, need to include the latter&#x2019;s perceptions of the digital environment in general and the co-creation of a safe environment.</p>
        </sec>
        <sec>
            <title>Ethics and consent</title>
            <p>This work was approved by the Faculty of Engineering and Physical Sciences (FEPS) Research Ethics Committee at the University of Southampton; ERGO/FEPS/67628 for the base study, and ERGO/FEPS/69107 for the follow-on study. In accordance with the ethics review and approval, participants were asked to confirm via tick box that they were 18 years of age or over and that they agreed to take part</p>
        </sec>
    </body>
    <back>
        <sec sec-type="data-availability">
            <title>Data availability</title>
            <p>University of Southampton Institutional Repository: Dataset in support of the publication 'Person-centred data sharing: empirical studies in private individuals&#x2019; attitudes'. 
                <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5258/SOTON/D2946">https://doi.org/10.5258/SOTON/D2946</ext-link>
                <sup>
                    <xref ref-type="bibr" rid="ref-59">59</xref>
                </sup>.</p>
            <p>Data are available under the terms of the 
                <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/legalcode">Creative Commons Attribution 4.0 International license</ext-link> (CC-BY 4.0).</p>
        </sec>
        <ack>
            <title>Acknowledgements</title>
            <p>We would like to acknowledge our colleague, Dr Sarah Kirby, Associate Professor of Psychology, for her support with the initial statistical analyses reported in the 
                <italic toggle="yes">Results</italic> section (
                <xref ref-type="other" rid="S1.4.3">Section 1.4.3</xref>).</p>
        </ack>
        <fn-group>
            <fn id="FN1">
                <p>
                    <sup>1</sup> Based on the original (
                    <ext-link ext-link-type="uri" xlink:href="https://upload.wikimedia.org/wikipedia/commons/b/be/Protection_Motivation_Theory.png">https://upload.wikimedia.org/wikipedia/commons/b/be/Protection_Motivation_Theory.png</ext-link>) by U3054791, under licence 
                    <bold>CC BY-SA 3.0</bold> &lt;
                    <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by-sa/3.0">https://creativecommons.org/licenses/by-sa/3.0</ext-link>&gt;, via Wikimedia Commons. This version is also licensed CC BY-SA, therefore.</p>
            </fn>
            <fn id="FN2">
                <p>
                    <sup>2</sup> Payment levels were set based on an amount slightly above the UK Minimum Wage at the time: &#xA3;1.60 for the first iteration; and &#xA3;1.40 for the second.</p>
            </fn>
            <fn id="FN3">
                <p>
                    <sup>3</sup> 498 participants on 8th Nov 2021, 2 manual participants (9th and 10th November), 301 on 3rd Dec 2021</p>
            </fn>
            <fn id="FN4">
                <p>
                    <sup>4</sup> Before pre-processing, 127 participants were assigned to this task. Therefore, 889 responses were expected (127 participants * 7 matching questions). Only 598 were received or approximately 67%. These responses were ignored, though responses to the PMT-derived assertions were retained for analysis.</p>
            </fn>
            <fn id="FN5">
                <p>
                    <sup>5</sup> 
                    <italic toggle="yes">Intention to Act</italic> is the equivalent of 
                    <italic toggle="yes">Protection Motivation</italic> in 
                    <xref ref-type="fig" rid="f2">Figure 2</xref>.</p>
            </fn>
            <fn id="FN6">
                <p>
                    <sup>6</sup> Except for the matching task in the first iteration where presentation was deemed confusing.</p>
            </fn>
            <fn id="FN7">
                <p>
                    <sup>7</sup> It took 6 hours 42 minutes for the first 498 responses during the first iteration.</p>
            </fn>
            <fn id="FN8">
                <p>
                    <sup>8</sup> Note that in this and subsequent sections, we are not concerned with the rank order per se, only that participants could consistently order the threats or controls.</p>
            </fn>
            <fn id="FN9">
                <p>
                    <sup>9</sup> The number of participants who responded to this task (see 
                    <xref ref-type="table" rid="T3">Table 3</xref>).</p>
            </fn>
            <fn id="FN10">
                <p>
                    <sup>10</sup> See 
                    <xref ref-type="table" rid="T6">Table 6</xref>
                </p>
            </fn>
            <fn id="FN11">
                <p>
                    <sup>11</sup> The last line in the table shows where rankings were the same across the three tasks (shown with &#x2018;=&#x2019;), as well as where the rankings were close with one deviation (&#x2018;&#x2248;&#x2019;).</p>
            </fn>
            <fn id="FN12">
                <p>
                    <sup>12</sup> Using IBM SPSS Ver 28.0.1.1 (15)</p>
            </fn>
            <fn id="FN13">
                <p>
                    <sup>13</sup> Extraction communalities</p>
            </fn>
            <fn id="FN14">
                <p>
                    <sup>14</sup> Items marked (*) were reverse coded; 
                    <italic toggle="yes">I&#x2019;m not likely to keep using security measures</italic> is therefore effectively 
                    <italic toggle="yes">I am likely to keep using security measures,</italic> and so forth</p>
            </fn>
            <fn id="FN15">
                <p>
                    <sup>15</sup> At this stage and despite there being only two items for this subscale, a Spearman-Brown formula was not calculated</p>
            </fn>
            <fn id="FN16">
                <p>
                    <sup>16</sup> We had assumed 
                    <italic toggle="yes">a priori</italic> that there would be a relationship between different factors.</p>
            </fn>
            <fn id="FN17">
                <p>
                    <sup>17</sup> The determinant was 0.001, Kaiser-Meyer-Olkin was high (0.861) and Bartlett&#x2019;s test of sphericity (
                    <italic toggle="yes">&#x3C7;</italic>
                    <sup>2</sup> (136) = 5057.19, p&lt;.001)</p>
            </fn>
            <fn id="FN18">
                <p>
                    <sup>18</sup> The survey ran in late 2021</p>
            </fn>
        </fn-group>
        <ref-list>
            <ref id="ref-1">
                <label>1</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dufva</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dufva</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Grasping the future of the digital society.</article-title>
                    <source>

                        <italic toggle="yes">Futures.</italic>
</source><year>2019</year>;<volume>107</volume>:<fpage>17</fpage>&#x2013;<lpage>28</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.futures.2018.11.001</pub-id></mixed-citation>
            </ref>
            <ref id="ref-2">
                <label>2</label>
                <mixed-citation publication-type="confproc">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Iivari</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gomes</surname>
                            <given-names>JF</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pikkarainen</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Digitalisation of healthcare: use of data in policy making.</article-title>In: Editor:
                    <italic toggle="yes">Book Digitalisation of Healthcare: Use of Data in Policy Making.</italic>(The International Society for Professional Innovation Management (ISPIM)),<year>2017</year>;<fpage>1</fpage>&#x2013;<lpage>13</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/publication/328686924_Digitalisation_of_healthcare_Use_of_data_in_policy_making">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-3">
                <label>3</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Torres</surname>
                            <given-names>LH</given-names>
                        </name>
</person-group>:
                    <article-title>Citizen sourcing in the public interest.</article-title>
                    <source>

                        <italic toggle="yes">Knowl Manag Dev J.</italic>
</source><year>2007</year>;<volume>3</volume>(<issue>1</issue>):<fpage>134</fpage>&#x2013;<lpage>145</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.km4djournal.org/index.php/km4dj/article/view/103">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-4">
                <label>4</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kung</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Byrd</surname>
                            <given-names>TA</given-names>
                        </name>
</person-group>:
                    <article-title>Big data analytics: understanding its capabilities and potential benefits for healthcare organizations.</article-title>
                    <source>

                        <italic toggle="yes">Technol Forecast Soc Change.</italic>
</source><year>2018</year>;<volume>126</volume>:<fpage>3</fpage>&#x2013;<lpage>13</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.techfore.2015.12.019</pub-id></mixed-citation>
            </ref>
            <ref id="ref-5">
                <label>5</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Helou</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Abou-Khalil</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>El Helou</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Factors related to personal health data sharing: data usefulness, sensitivity and anonymity.</article-title>
                    <source>

                        <italic toggle="yes">Stud Health Technol Inform.</italic>
</source><year>2021</year>;<volume>281</volume>:<fpage>1051</fpage>&#x2013;<lpage>1055</lpage>.
                    <pub-id pub-id-type="pmid">34042839</pub-id>
                    <pub-id pub-id-type="doi">10.3233/SHTI210345</pub-id></mixed-citation>
            </ref>
            <ref id="ref-6">
                <label>6</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tractenberg</surname>
                            <given-names>RE</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Russell</surname>
                            <given-names>AJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morgan</surname>
                            <given-names>GJ</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Using ethical reasoning to amplify the reach and resonance of professional codes of conduct in training big data scientists.</article-title>
                    <source>

                        <italic toggle="yes">Sci Eng Ethics.</italic>
</source><year>2015</year>;<volume>21</volume>(<issue>6</issue>):<fpage>1485</fpage>&#x2013;<lpage>1507</lpage>.
                    <pub-id pub-id-type="pmid">25431219</pub-id>
                    <pub-id pub-id-type="doi">10.1007/s11948-014-9613-1</pub-id>
                    <pub-id pub-id-type="pmcid">4656703</pub-id></mixed-citation>
            </ref>
            <ref id="ref-7">
                <label>7</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jang-Jaccard</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nepal</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>A survey of emerging threats in cybersecurity.</article-title>
                    <source>

                        <italic toggle="yes">J Comput Syst Sci.</italic>
</source><year>2014</year>;<volume>80</volume>(<issue>5</issue>):<fpage>973</fpage>&#x2013;<lpage>993</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.jcss.2014.02.005</pub-id></mixed-citation>
            </ref>
            <ref id="ref-8">
                <label>8</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Agrafiotis</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nurse</surname>
                            <given-names>JRC</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Goldsmith</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A taxonomy of cyber-harms: defining the impacts of cyber-attacks and understanding how they propagate.</article-title>
                    <source>

                        <italic toggle="yes">J Cybersecur.</italic>
</source><year>2018</year>;<volume>4</volume>(<issue>1</issue>):
                    <elocation-id>tyy006</elocation-id>.
                    <pub-id pub-id-type="doi">10.1093/cybsec/tyy006</pub-id></mixed-citation>
            </ref>
            <ref id="ref-9">
                <label>9</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zimmermann</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Renaud</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Moving from a &#x2018;human-as-problem&#x201D; to a &#x2018;human-as-solution&#x201D; cybersecurity mindset.</article-title>
                    <source>

                        <italic toggle="yes">Int J Hum Comput Stud.</italic>
</source><year>2019</year>;<volume>131</volume>:<fpage>169</fpage>&#x2013;<lpage>187</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.ijhcs.2019.05.005</pub-id></mixed-citation>
            </ref>
            <ref id="ref-10">
                <label>10</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>&#xD6;&#x11F;&#xFC;t&#xE7;&#xFC;</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Testik</surname>
                            <given-names>&#xD6;M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Chouseinoglou</surname>
                            <given-names>O</given-names>
                        </name>
</person-group>:
                    <article-title>Analysis of personal information security behavior and awareness.</article-title>
                    <source>

                        <italic toggle="yes">Comput Secur.</italic>
</source><year>2016</year>;<volume>56</volume>:<fpage>83</fpage>&#x2013;<lpage>93</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2015.10.002</pub-id></mixed-citation>
            </ref>
            <ref id="ref-11">
                <label>11</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Goel</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Williams</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dincelli</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Got phished? internet security and human vulnerability.</article-title>
                    <source>

                        <italic toggle="yes">J Assoc Inf Syst.</italic>
</source><year>2017</year>;<volume>18</volume>(<issue>1</issue>):<fpage>22</fpage>&#x2013;<lpage>44</lpage>.
                    <pub-id pub-id-type="doi">10.17705/1jais.00447</pub-id></mixed-citation>
            </ref>
            <ref id="ref-12">
                <label>12</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Krombholz</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hobel</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Huber</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Advanced social engineering attacks.</article-title>
                    <source>

                        <italic toggle="yes">J Inf Secur Appl.</italic>
</source><year>2015</year>;<volume>22</volume>:<fpage>113</fpage>&#x2013;<lpage>122</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.jisa.2014.09.005</pub-id></mixed-citation>
            </ref>
            <ref id="ref-13">
                <label>13</label>
                <mixed-citation publication-type="confproc">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jeong</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mihelcic</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Oliver</surname>
                            <given-names>G</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Towards an improved understanding of human factors in cybersecurity</article-title>.
                    <italic toggle="yes">Proc. IEEE 2019:  Proceedings of the 1st International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS) &amp; the 5th International Conference on Collaboration and Internet Computing (CIC).</italic>Piscataway, NJ2019,<year>2019</year>.
                    <pub-id pub-id-type="doi">10.1109/CIC48465.2019.00047</pub-id></mixed-citation>
            </ref>
            <ref id="ref-14">
                <label>14</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Martin</surname>
                            <given-names>G</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ghafur</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kinross</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>WannaCry-a year on.</article-title>In: Editor:
                    <italic toggle="yes">Book WannaCry-a year on</italic>. (British Medical Journal Publishing Group),
                    <source>

                        <italic toggle="yes">BMJ.</italic>
</source><year>2018</year>;<volume>361</volume>:
                    <elocation-id>k2381</elocation-id>.
                    <pub-id pub-id-type="pmid">29866711</pub-id>
                    <pub-id pub-id-type="doi">10.1136/bmj.k2381</pub-id></mixed-citation>
            </ref>
            <ref id="ref-15">
                <label>15</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Briggs</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jeske</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Coventry</surname>
                            <given-names>L</given-names>
                        </name>
</person-group>:
                    <article-title>Behavior change interventions for cybersecurity.</article-title>In: Little, L., Sillence, E., and Joinson, A.N. (Eds.):
                    <italic toggle="yes">Behavior Change Research and Theory.</italic>(Academic Press),<year>2017</year>;<fpage>115</fpage>&#x2013;<lpage>136</lpage>.
                    <pub-id pub-id-type="doi">10.1016/B978-0-12-802690-8.00004-9</pub-id></mixed-citation>
            </ref>
            <ref id="ref-16">
                <label>16</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Paek</surname>
                            <given-names>HJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hove</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Risk perceptions and risk characteristics.</article-title>
                    <source>

                        <italic toggle="yes">Oxford Research Encyclopedia of Communication.</italic>
</source>(Oxford University Press),<year>2017</year>.
                    <pub-id pub-id-type="doi">10.1093/acrefore/9780190228613.013.283</pub-id></mixed-citation>
            </ref>
            <ref id="ref-17">
                <label>17</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vance</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Siponen</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Pahnila</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Motivating IS security compliance: insights from habit and protection motivation theory.</article-title>
                    <source>

                        <italic toggle="yes">Inf Manag.</italic>
</source><year>2012</year>;<volume>49</volume>(<issue>3&#x2013;4</issue>):<fpage>190</fpage>&#x2013;<lpage>198</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.im.2012.04.002</pub-id></mixed-citation>
            </ref>
            <ref id="ref-18">
                <label>18</label>
                <mixed-citation publication-type="web">
                    <collab>International Organization for Standardization</collab>:
                    <article-title>ISO/IEC 27000:2018.</article-title>In: Editor:
                    <italic toggle="yes">ISO/IEC 27000:2018.</italic><year> 2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.iso.org/standard/73906.html#:~:text=ISO%2FIEC%2027000%3A2018%20provides,the%20ISMS%20family%20of%20standards.">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-19">
                <label>19</label>
                <mixed-citation publication-type="book">
                    <collab>International Organization for Standardization</collab>:
                    <article-title>IISO/IEC 27005:2020.</article-title>In: Editor:
                    <italic toggle="yes">Book ISO/IEC 27005:2020.</italic><year> 2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.iso.org/standard/80585.html">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-20">
                <label>20</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Craigen</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Diakun-Thibault</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Purse</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>:
                    <article-title>Defining cybersecurity.</article-title>
                    <source>

                        <italic toggle="yes">Technology Innovation Management Review.</italic>
</source><year>2014</year>;<volume>4</volume>(<issue>10</issue>):<fpage>13</fpage>&#x2013;<lpage>21</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/publication/326309769_Defining_Cybersecurity">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref-21">
                <label>21</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>von Solms</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>van Niekerk</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>From information security to cyber security.</article-title>
                    <source>

                        <italic toggle="yes">Comput Secur.</italic>
</source><year>2013</year>;<volume>38</volume>:<fpage>97</fpage>&#x2013;<lpage>102</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2013.04.004</pub-id></mixed-citation>
            </ref>
            <ref id="ref-22">
                <label>22</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ganin</surname>
                            <given-names>AA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Quach</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Panwar</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Multicriteria decision framework for cybersecurity risk assessment and management.</article-title>
                    <source>

                        <italic toggle="yes">Risk Anal.</italic>
</source><year>2020</year>;<volume>40</volume>(<issue>1</issue>):<fpage>183</fpage>&#x2013;<lpage>199</lpage>.
                    <pub-id pub-id-type="pmid">28873246</pub-id>
                    <pub-id pub-id-type="doi">10.1111/risa.12891</pub-id></mixed-citation>
            </ref>
            <ref id="ref-23">
                <label>23</label>
                <mixed-citation publication-type="web">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Muckin</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fitch</surname>
                            <given-names>SC</given-names>
                        </name>
</person-group>:
                    <article-title>A threat-driven approach to cyber security.</article-title>In: Editor:
                    <italic toggle="yes">Book A Threat-Driven Approach to Cyber Security.</italic>(Lockheed Martin Corporation),<year>2014</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Threat-Driven-Approach.pdf">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-24">
                <label>24</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mamonov</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Benbunan-Fich</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>:
                    <article-title>The impact of information security threat awareness on privacy-protective behaviors.</article-title>
                    <source>

                        <italic toggle="yes">Comput Hum Behav.</italic>
</source><year>2018</year>;<volume>83</volume>:<fpage>32</fpage>&#x2013;<lpage>44</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.chb.2018.01.028</pub-id></mixed-citation>
            </ref>
            <ref id="ref-25">
                <label>25</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Smerecnik</surname>
                            <given-names>CMR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mesters</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Candel</surname>
                            <given-names>MJJM</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Risk perception and information processing: the development and validation of a questionnaire to assess self-reported information processing.</article-title>
                    <source>

                        <italic toggle="yes">Risk Anal.</italic>
</source><year>2012</year>;<volume>32</volume>(<issue>1</issue>):<fpage>54</fpage>&#x2013;<lpage>66</lpage>.
                    <pub-id pub-id-type="pmid">21707686</pub-id>
                    <pub-id pub-id-type="doi">10.1111/j.1539-6924.2011.01651.x</pub-id></mixed-citation>
            </ref>
            <ref id="ref-26">
                <label>26</label>
                <mixed-citation publication-type="confproc">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bada</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sasse</surname>
                            <given-names>AM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nurse</surname>
                            <given-names>JR</given-names>
                        </name>
</person-group>:
                    <article-title>Cyber security awareness campaigns: why do they fail to change behaviour?</article-title>
                    <source>

                        <italic toggle="yes">Proc International Conference on Cyber Security for Sustainable Society.</italic>
</source>Coventry, UK,<year>2015</year>.
                    <pub-id pub-id-type="doi">10.48550/arXiv.1901.02672</pub-id></mixed-citation>
            </ref>
            <ref id="ref-27">
                <label>27</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pawlak</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wendling</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Trends in cyberspace: can governments keep up?</article-title>
                    <source>

                        <italic toggle="yes">Environ Syst Decis.</italic>
</source><year>2013</year>;<volume>33</volume>(<issue>4</issue>):<fpage>536</fpage>&#x2013;<lpage>543</lpage>.
                    <pub-id pub-id-type="doi">10.1007/s10669-013-9470-5</pub-id></mixed-citation>
            </ref>
            <ref id="ref-28">
                <label>28</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Dryhurst</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Schneider</surname>
                            <given-names>CR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kerr</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Risk perceptions of COVID-19 around the world.</article-title>
                    <source>

                        <italic toggle="yes">J Risk Res.</italic>
</source><year>2020</year>;<volume>23</volume>(<issue>7&#x2013;8</issue>):<fpage>994</fpage>&#x2013;<lpage>1006</lpage>.
                    <pub-id pub-id-type="doi">10.1080/13669877.2020.1758193</pub-id></mixed-citation>
            </ref>
            <ref id="ref-29">
                <label>29</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sharma</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Zhan</surname>
                            <given-names>X</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Nah</surname>
                            <given-names>FFH</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Impact of digital nudging on information security behavior: an experimental study on framing and priming in cybersecurity.</article-title>
                    <source>

                        <italic toggle="yes">Organizational Cybersecurity Journal: Practice, Process and People.</italic>
</source><year>2021</year>;<volume>1</volume>(<issue>1</issue>):<fpage>69</fpage>&#x2013;<lpage>91</lpage>.
                    <pub-id pub-id-type="doi">10.1108/OCJ-03-2021-0009</pub-id></mixed-citation>
            </ref>
            <ref id="ref-30">
                <label>30</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vasv&#xE1;ri</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Risk, risk perception, risk management - a review of the literature.</article-title>
                    <source>

                        <italic toggle="yes">Public Finan Q.</italic>
</source><year>2015</year>;<volume>60</volume>(<issue>1</issue>):<fpage>29</fpage>&#x2013;<lpage>48</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://ideas.repec.org/a/pfq/journl/v60y2015i1p29-48.html">Reference Source</ext-link></mixed-citation>
            </ref>
            <ref id="ref-31">
                <label>31</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ioannou</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tussyadiah</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>:
                    <article-title>Privacy and surveillance attitudes during health crises: acceptance of surveillance and privacy protection behaviours.</article-title>
                    <source>

                        <italic toggle="yes">Technol Soc.</italic>
</source><year>2021</year>;<volume>67</volume>:
                    <elocation-id>101774</elocation-id>.
                    <pub-id pub-id-type="pmid">34642512</pub-id>
                    <pub-id pub-id-type="doi">10.1016/j.techsoc.2021.101774</pub-id>
                    <pub-id pub-id-type="pmcid">8497958</pub-id></mixed-citation>
            </ref>
            <ref id="ref-32">
                <label>32</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Loewenstein</surname>
                            <given-names>GF</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Weber</surname>
                            <given-names>EU</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hsee</surname>
                            <given-names>CK</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Risk as feelings.</article-title>
                    <source>

                        <italic toggle="yes">Psychol Bull.</italic>
</source><year>2001</year>;<volume>127</volume>(<issue>2</issue>):<fpage>267</fpage>&#x2013;<lpage>286</lpage>.
                    <pub-id pub-id-type="pmid">11316014</pub-id>
                    <pub-id pub-id-type="doi">10.1037/0033-2909.127.2.267</pub-id></mixed-citation>
            </ref>
            <ref id="ref-33">
                <label>33</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Slovic</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Finucane</surname>
                            <given-names>ML</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Peters</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Risk as analysis and risk as feelings: some thoughts about affect, reason, risk, and rationality.</article-title>
                    <source>

                        <italic toggle="yes">Risk Anal.</italic>
</source><year>2004</year>;<volume>24</volume>(<issue>2</issue>):<fpage>311</fpage>&#x2013;<lpage>322</lpage>.
                    <pub-id pub-id-type="pmid">15078302</pub-id>
                    <pub-id pub-id-type="doi">10.1111/j.0272-4332.2004.00433.x</pub-id></mixed-citation>
            </ref>
            <ref id="ref-34">
                <label>34</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Betsch</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Renkewitz</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Betsch</surname>
                            <given-names>T</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The influence of vaccine-critical websites on perceiving vaccination risks.</article-title>
                    <source>

                        <italic toggle="yes">J Health Psychol.</italic>
</source><year>2010</year>;<volume>15</volume>(<issue>3</issue>):<fpage>446</fpage>&#x2013;<lpage>455</lpage>.
                    <pub-id pub-id-type="pmid">20348365</pub-id>
                    <pub-id pub-id-type="doi">10.1177/1359105309353647</pub-id></mixed-citation>
            </ref>
            <ref id="ref-35">
                <label>35</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bandura</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>On the functional properties of perceived self-efficacy revisited.</article-title>
                    <source>

                        <italic toggle="yes">J Manag.</italic>
</source><year>2012</year>;<volume>38</volume>(<issue>1</issue>):<fpage>9</fpage>&#x2013;<lpage>44</lpage>.
                    <pub-id pub-id-type="doi">10.1177/0149206311410606</pub-id></mixed-citation>
            </ref>
            <ref id="ref-36">
                <label>36</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rimal</surname>
                            <given-names>RN</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Real</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Perceived risk and efficacy beliefs as motivators of change: use of the Risk Perception Attitude (RPA) framework to understand health behaviors.</article-title>
                    <source>

                        <italic toggle="yes">Hum Commun Res.</italic>
</source><year>2003</year>;<volume>29</volume>(<issue>3</issue>):<fpage>370</fpage>&#x2013;<lpage>399</lpage>.
                    <pub-id pub-id-type="doi">10.1111/j.1468-2958.2003.tb00844.x</pub-id></mixed-citation>
            </ref>
            <ref id="ref-37">
                <label>37</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Egelman</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Peer</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Predicting privacy and security attitudes.</article-title>
                    <source>

                        <italic toggle="yes">ACM SIGCAS Computers and Society.</italic>
</source><year>2015</year>;<volume>45</volume>(<issue>1</issue>):<fpage>22</fpage>&#x2013;<lpage>28</lpage>.
                    <pub-id pub-id-type="doi">10.1145/2738210.2738215</pub-id></mixed-citation>
            </ref>
            <ref id="ref-38">
                <label>38</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Junglas</surname>
                            <given-names>IA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Johnson</surname>
                            <given-names>NA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Spitzm&#xFC;ller</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>Personality traits and concern for privacy: an empirical study in the context of location-based services.</article-title>
                    <source>

                        <italic toggle="yes">Eur J Inf Syst.</italic>
</source><year>2008</year>;<volume>17</volume>(<issue>4</issue>):<fpage>387</fpage>&#x2013;<lpage>402</lpage>.
                    <pub-id pub-id-type="doi">10.1057/ejis.2008.29</pub-id></mixed-citation>
            </ref>
            <ref id="ref-39">
                <label>39</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Witte</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Allen</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>A meta-analysis of fear appeals: implications for effective public health campaigns.</article-title>
                    <source>

                        <italic toggle="yes">Health Educ Behav.</italic>
</source><year>2000</year>;<volume>27</volume>(<issue>5</issue>):<fpage>591</fpage>&#x2013;<lpage>615</lpage>.
                    <pub-id pub-id-type="pmid">11009129</pub-id>
                    <pub-id pub-id-type="doi">10.1177/109019810002700506</pub-id></mixed-citation>
            </ref>
            <ref id="ref-40">
                <label>40</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Witte</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Putting the fear back into fear appeals: the extended parallel process model.</article-title>
                    <source>

                        <italic toggle="yes">Commun Monogr.</italic>
</source><year>1992</year>;<volume>59</volume>(<issue>4</issue>):<fpage>329</fpage>&#x2013;<lpage>349</lpage>.
                    <pub-id pub-id-type="doi">10.1080/03637759209376276</pub-id></mixed-citation>
            </ref>
            <ref id="ref-41">
                <label>41</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Rogers</surname>
                            <given-names>RW</given-names>
                        </name>
</person-group>:
                    <article-title>A protection motivation theory of fear appeals and attitude change1.</article-title>
                    <source>

                        <italic toggle="yes">J Psychol.</italic>
</source><year>1975</year>;<volume>91</volume>(<issue>1</issue>):<fpage>93</fpage>&#x2013;<lpage>114</lpage>.
                    <pub-id pub-id-type="pmid">28136248</pub-id>
                    <pub-id pub-id-type="doi">10.1080/00223980.1975.9915803</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-42">
                <label>42</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Floyd</surname>
                            <given-names>DL</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Prentice-Dunn</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rogers</surname>
                            <given-names>RW</given-names>
                        </name>
</person-group>:
                    <article-title>A meta-analysis of research on protection motivation theory.</article-title>
                    <source>

                        <italic toggle="yes">J Appl Soc Psychol.</italic>
</source><year>2000</year>;<volume>30</volume>(<issue>2</issue>):<fpage>407</fpage>&#x2013;<lpage>429</lpage>.
                    <pub-id pub-id-type="doi">10.1111/j.1559-1816.2000.tb02323.x</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-43">
                <label>43</label>
                <mixed-citation publication-type="regulation">
                    <collab>European Commission</collab>:
                    <article-title>Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.</article-title><year> 2016</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.eumonitor.eu/9353000/1/j9vvik7m1c3gyxp/vk3sygzz13zi">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref-44">
                <label>44</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Egelman</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Harbach</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Peer</surname>
                            <given-names>E</given-names>
                        </name>
</person-group>:
                    <article-title>Behavior ever follows intention?: A validation of the Security Behavior Intentions Scale (SeBIS).</article-title>
                    <source>

                        <italic toggle="yes">Proc CHI 2016.</italic>
</source>San Jose, CA, May,<year>2016</year>;<fpage>5257</fpage>&#x2013;<lpage>5261</lpage>.
                    <pub-id pub-id-type="doi">10.1145/2858036.2858265</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-45">
                <label>45</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ioannou</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tussyadiah</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Marsham</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Dispositional mindfulness as an antecedent of privacy concerns: a protection motivation theory perspective.</article-title>
                    <source>

                        <italic toggle="yes">Psychol Mark.</italic>
</source><year>2021</year>;<volume>38</volume>(<issue>10</issue>):<fpage>1766</fpage>&#x2013;<lpage>1778</lpage>.
                    <pub-id pub-id-type="doi">10.1002/mar.21529</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-46">
                <label>46</label>
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pickering</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Taylor</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Cybersecurity Survey (Version 1).</article-title>In: Editor
                    <italic toggle="yes">Book Cybersecurity Survey (Version 1).</italic><year> 2023</year>.
                    <pub-id pub-id-type="doi">10.5281/zenodo.7589508</pub-id></mixed-citation>
            </ref>
            <ref id="ref-47">
                <label>47</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sprouse</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>A validation of Amazon Mechanical Turk for the collection of acceptability judgments in linguistic theory.</article-title>
                    <source>

                        <italic toggle="yes">Behav Res Methods.</italic>
</source><year>2011</year>;<volume>43</volume>(<issue>1</issue>):<fpage>155</fpage>&#x2013;<lpage>167</lpage>.
                    <pub-id pub-id-type="pmid">21287108</pub-id>
                    <pub-id pub-id-type="doi">10.3758/s13428-010-0039-7</pub-id>
                    <pub-id pub-id-type="pmcid">3048456</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-48">
                <label>48</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Behrend</surname>
                            <given-names>TS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sharek</surname>
                            <given-names>DJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Meade</surname>
                            <given-names>AW</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The viability of crowdsourcing for survey research.</article-title>
                    <source>

                        <italic toggle="yes">Behav Res Methods.</italic>
</source><year>2011</year>;<volume>43</volume>(<issue>3</issue>):<fpage>800</fpage>&#x2013;<lpage>13</lpage>.
                    <pub-id pub-id-type="pmid">21437749</pub-id>
                    <pub-id pub-id-type="doi">10.3758/s13428-011-0081-0</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-49">
                <label>49</label>
                <mixed-citation publication-type="journal">
                    <ext-link ext-link-type="uri" xlink:href="https://tinyurl.com/373brakb">https://tinyurl.com/373brakb</ext-link><year> 2022</year>; accessed 11th January 2022.</mixed-citation>
            </ref>
            <ref id="ref-50">
                <label>50</label>
                <mixed-citation publication-type="journal">
                    <ext-link ext-link-type="uri" xlink:href="https://www.security-everywhere.com/why-should-i-care-about-cybersecurity/">https://www.security-everywhere.com/why-should-i-care-about-cybersecurity/</ext-link><year> 2021</year>; accessed 29.09.2021.</mixed-citation>
            </ref>
            <ref id="ref-51">
                <label>51</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bargh</surname>
                            <given-names>JA</given-names>
                        </name>
</person-group>:
                    <article-title>The historical origins of priming as the preparation of behavioral responses: unconscious carryover and contextual influences of real-world importance.</article-title>
                    <source>

                        <italic toggle="yes">Social Cognition.</italic>
</source><year>2014</year>;<volume>32</volume>:<fpage>209</fpage>&#x2013;<lpage>224</lpage>.
                    <pub-id pub-id-type="doi">10.1521/soco.2014.32.supp.209</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-52">
                <label>52</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Herring</surname>
                            <given-names>DR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>White</surname>
                            <given-names>KR</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Jabeen</surname>
                            <given-names>LN</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>On the automatic activation of attitudes: a quarter century of evaluative priming research.</article-title>
                    <source>

                        <italic toggle="yes">Psychol Bull.</italic>
</source><year>2013</year>;<volume>139</volume>(<issue>5</issue>):<fpage>1062</fpage>&#x2013;<lpage>89</lpage>.
                    <pub-id pub-id-type="pmid">23339522</pub-id>
                    <pub-id pub-id-type="doi">10.1037/a0031309</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-53">
                <label>53</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ifinedo</surname>
                            <given-names>P</given-names>
                        </name>
</person-group>:
                    <article-title>Understanding information systems security policy compliance: an integration of the theory of planned behavior and the protection motivation theory.</article-title>
                    <source>

                        <italic toggle="yes">Comput Secur.</italic>
</source><year>2012</year>;<volume>31</volume>(<issue>1</issue>):<fpage>83</fpage>&#x2013;<lpage>95</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2011.10.007</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-54">
                <label>54</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>J&#xF3;zsa</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morgan</surname>
                            <given-names>GA</given-names>
                        </name>
</person-group>:
                    <article-title>Reversed items in likert scales: filtering out invalid responders.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Psychological and Educational Research.</italic>
</source><year>2017</year>;<volume>25</volume>(<issue>1</issue>):<fpage>7</fpage>&#x2013;<lpage>25</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/publication/317264817_Reversed_Items_in_Likert_Scales_Filtering_Out_Invalid_Responders">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref-55">
                <label>55</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Howard</surname>
                            <given-names>MC</given-names>
                        </name>
</person-group>:
                    <article-title>A review of exploratory factor analysis decisions and overview of current practices: what we are doing and how can we improve?</article-title>
                    <source>

                        <italic toggle="yes">Int J Hum Comput Interact.</italic>
</source><year>2016</year>;<volume>32</volume>(<issue>1</issue>):<fpage>51</fpage>&#x2013;<lpage>62</lpage>.
                    <pub-id pub-id-type="doi">10.1080/10447318.2015.1087664</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-56">
                <label>56</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fagerland</surname>
                            <given-names>MW</given-names>
                        </name>
</person-group>:
                    <article-title>t-tests, non-parametric tests, and large studies&#x2014;a paradox of statistical practice?</article-title>
                    <source>

                        <italic toggle="yes">BMC Med Res Methodol.</italic>
</source><year>2012</year>;<volume>12</volume>(<issue>1</issue>): 78.
                    <pub-id pub-id-type="pmid">22697476</pub-id>
                    <pub-id pub-id-type="doi">10.1186/1471-2288-12-78</pub-id>
                    <pub-id pub-id-type="pmcid">3445820</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-57">
                <label>57</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Davis</surname>
                            <given-names>FD</given-names>
                        </name>
</person-group>:
                    <article-title>Perceived usefulness, perceived ease of use, and user acceptance of information technology.</article-title>
                    <source>

                        <italic toggle="yes">MIS Quarterly.</italic>
</source><year>1989</year>;<volume>13</volume>(<issue>3</issue>):<fpage>319</fpage>&#x2013;<lpage>340</lpage>.
                    <pub-id pub-id-type="doi">10.2307/249008</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref-58">
                <label>58</label>
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Venkatesh</surname>
                            <given-names>V</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Morris</surname>
                            <given-names>MG</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Davis</surname>
                            <given-names>GB</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>User acceptance of information technology: toward a unified view.</article-title>
                    <source>

                        <italic toggle="yes">MIS Quarterly.</italic>
</source><year>2003</year>;<volume>27</volume>(<issue>3</issue>):<fpage>425</fpage>&#x2013;<lpage>478</lpage>.
                    <ext-link ext-link-type="uri" xlink:href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3375136">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref-59">
                <label>59</label>
                <mixed-citation publication-type="data">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pickering</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Taylor</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <data-title>Dataset in support of the publication 'person-centred data sharing: empirical studies in private individuals&#x2019; attitudes'.</data-title>University of Southampton. [Dataset].<year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="http://www.doi.org/10.5258/SOTON/D2946">http://www.doi.org/10.5258/SOTON/D2946</ext-link>
                </mixed-citation>
            </ref>
        </ref-list>
    </back>
    <sub-article article-type="reviewer-report" id="report59585">
        <front-stub>
            <article-id pub-id-type="doi">10.21956/openreseurope.18732.r59585</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Mizrak</surname>
                        <given-names>Filiz</given-names>
                    </name>
                    <xref ref-type="aff" rid="r59585a1">1</xref>
                    <xref ref-type="aff" rid="r59585a1">1</xref>
                    <role>Referee</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-3472-394X</uri>
                </contrib>
                <aff id="r59585a1">
                    <label>1</label>Istanbul Atlas University, Istanbul, Turkey</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>27</day>
                <month>9</month><year>2025</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#xA9; 2025 Mizrak F</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport59585" related-article-type="peer-reviewed-article" xlink:href="10.12688/openreseurope.17332.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve-with-reservations</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>The article is well-written and makes a valuable contribution to understanding individual perceptions of cybersecurity through the lens of Protection Motivation Theory (PMT). However, several areas in the&#xA0;analysis, introduction, and conclusion&#xA0;could be strengthened to improve coherence, interpretation, and scholarly impact.</p>
            <p> 1. Introduction: The introduction sets the scene effectively, but it mixes general background on cybersecurity with study-specific details, which can reduce clarity. 
                <list list-type="bullet">
                    <list-item>
                        <p>Suggestions for improvement: 
                            <list list-type="bullet">
                                <list-item>
                                    <p>Separate&#xA0;broad problem framing&#xA0;(cyber threats, importance of human factors) from&#xA0;study-specific focus(UK individuals, healthcare data).</p>
                                </list-item>
                                <list-item>
                                    <p>Clarify the&#xA0;research gap: emphasize how previous studies looked at awareness but did not fully explain perceptions of responsibility and contextual influences.</p>
                                </list-item>
                                <list-item>
                                    <p>Explicitly state how this study advances knowledge by showing that awareness exists, but responsibility attribution and contextual information affect behavioural intentions.</p>
                                </list-item>
                                <list-item>
                                    <p>Example revision point: Instead of saying&#xA0;
                                        <italic>&#x201C;With increased call for health data and data sharing, responsibility for protecting those data is unclear&#x201D;</italic>, add&#xA0;
                                        <italic>&#x201C;&#x2026;this study goes beyond prior work by examining not only whether individuals recognize threats and controls, but also how they assign responsibility and what broader considerations drive decision-making.&#x201D;</italic>
                                    </p>
                                </list-item>
                            </list> </p>
                    </list-item>
                </list> </p>
            <p> 2. Analysis Results: The results are rich but sometimes presented descriptively without enough interpretation. 
                <list list-type="bullet">
                    <list-item>
                        <p>Suggestions for improvement: 
                            <list list-type="bullet">
                                <list-item>
                                    <p>Highlight key contrasts&#xA0;more explicitly. For instance, show the tension between participants&#x2019; ability to recognize threats/controls and their reluctance to accept responsibility.</p>
                                </list-item>
                                <list-item>
                                    <p>In demographic results, explain the&#xA0;practical meaning: e.g., &#x201C;Experts reported higher self-efficacy scores, which suggests that technical familiarity strengthens intention to act, but cost and effort remain barriers.&#x201D;</p>
                                </list-item>
                                <list-item>
                                    <p>For priming tasks, note that even small effects (1.7% variance explained) still show that&#xA0;contextual cues matter, though modestly. This prevents the results from appearing trivial.</p>
                                </list-item>
                                <list-item>
                                    <p>In the factor analysis,&#xA0;emphasize the novelty of the &#x2018;Sources of Information&#x2019; factor&#xA0;as evidence that individuals make decisions with background considerations, not just PMT&#x2019;s rational pathways.</p>
                                </list-item>
                            </list> </p>
                    </list-item>
                </list> </p>
            <p> 3. Discussion and Conclusion: The discussion identifies interesting themes but does not fully integrate them into a cohesive argument. The conclusion repeats findings but could emphasize contributions more clearly. 
                <list list-type="bullet">
                    <list-item>
                        <p>Suggestions for improvement: 
                            <list list-type="bullet">
                                <list-item>
                                    <p>Stress the&#xA0;paradox: individuals are aware of threats and controls but do not assume responsibility&#x2014;this gap is central to the study&#x2019;s contribution.</p>
                                </list-item>
                                <list-item>
                                    <p>Link freeform comments (e.g., cost concerns, trust in institutions) directly to the factor analysis results, showing how they reinforce the emergence of the &#x201C;Sources of Information&#x201D; factor.</p>
                                </list-item>
                                <list-item>
                                    <p>Strengthen the conclusion by explicitly stating&#xA0;what this means for future cybersecurity approaches: that awareness alone is insufficient&#x2014;responsibility perceptions and contextual beliefs shape behaviour.</p>
                                </list-item>
                                <list-item>
                                    <p>Example revision point: Instead of ending with&#xA0;
                                        <italic>&#x201C;This research has contributed to understanding of how end users respond to cybersecurity&#x201D;</italic>, close with&#xA0;
                                        <italic>&#x201C;&#x2026;our findings demonstrate that cybersecurity strategies must not only inform individuals of risks but also address their contextual beliefs&#x2014;such as cost, institutional trust, and perceived responsibility&#x2014;in order to convert awareness into protective action.&#x201D;</italic>
                                    </p>
                                </list-item>
                            </list> </p>
                    </list-item>
                </list>
            </p>
            <p>Is the study design appropriate and does the work have academic merit?</p>
            <p>Yes</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Partly</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>Partly</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Partly</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Yes</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Yes</p>
            <p>Reviewer Expertise:</p>
            <p>Management and cybersecurity</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above.</p>
        </body>
    </sub-article>
    <sub-article article-type="reviewer-report" id="report60473">
        <front-stub>
            <article-id pub-id-type="doi">10.21956/openreseurope.18732.r60473</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Lashkari</surname>
                        <given-names>Arash Habibi</given-names>
                    </name>
                    <xref ref-type="aff" rid="r60473a1">1</xref>
                    <role>Referee</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-1240-6433</uri>
                </contrib>
                <aff id="r60473a1">
                    <label>1</label>York University, Ontario, Canada</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>26</day>
                <month>9</month><year>2025</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#xA9; 2025 Lashkari AH</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport60473" related-article-type="peer-reviewed-article" xlink:href="10.12688/openreseurope.17332.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>reject</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>This study investigates how private individuals in the UK perceive cybersecurity threats and controls in the context of healthcare data. Using an anonymous online survey with 801 participants, the authors assess respondents&#x2019; ability to recognize threats, evaluate controls, and assign responsibility for security measures.</p>
            <p> </p>
            <p> Findings show that individuals can identify threats and appropriate controls but often shift responsibility to institutions such as the NHS or technology providers rather than themselves. An exploratory factor analysis further reveals that decisions are not solely based on Protection Motivation Theory&#x2019;s cost&#x2013;benefit model but also influenced by broader contextual and emotional factors such as trust, cost, and perceived responsibility.</p>
            <p> </p>
            <p> The authors need to cover the shortcomings below:</p>
            <p> </p>
            <p> - The study&#x2019;s focus on UK healthcare data limits generalizability; future research should replicate across sectors like finance, education, or IoT and in other countries to validate broader applicability.</p>
            <p> -&#xA0;Reliance on crowdsourced participants likely biased results toward digitally experienced individuals; including less tech-savvy groups in stratified samples would provide more balanced insights.</p>
            <p> - Priming tasks produced only marginal effects, suggesting weak influence; stronger, real-world scenarios or longitudinal designs could better capture behavioral change.</p>
            <p> - Responsibility attribution leaned heavily toward institutions, overlooking shared accountability; clearer questions distinguishing user, institutional, and joint roles could yield more nuanced findings.</p>
            <p> - The restricted set of threats and controls reduced ecological validity; incorporating focus groups or live threat intelligence would ensure scenarios align with participants&#x2019; real experiences.</p>
            <p>Is the study design appropriate and does the work have academic merit?</p>
            <p>Yes</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Yes</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>Partly</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Partly</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Partly</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Partly</p>
            <p>Reviewer Expertise:</p>
            <p>Cybersecurity.</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to state that I do not consider it to be of an acceptable scientific standard, for reasons outlined above.</p>
        </body>
    </sub-article>
    <sub-article article-type="reviewer-report" id="report59582">
        <front-stub>
            <article-id pub-id-type="doi">10.21956/openreseurope.18732.r59582</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Almaiah</surname>
                        <given-names>Mohammed</given-names>
                    </name>
                    <xref ref-type="aff" rid="r59582a1">1</xref>
                    <role>Referee</role>
                </contrib>
                <aff id="r59582a1">
                    <label>1</label>University of Jordan, Amman, Jordan</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>15</day>
                <month>9</month><year>2025</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#xA9; 2025 Almaiah M</copyright-statement>
                <copyright-year>2025</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport59582" related-article-type="peer-reviewed-article" xlink:href="10.12688/openreseurope.17332.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve-with-reservations</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>In this study, 801 UK private individuals responded to an anonymous&#xA0;online survey, identifying their ability to recognize threats and&#xA0;controls, who they believe responsible for implementing controls, and&#xA0; their general willingness to engage with cybersecurity via a Protection&#xA0;Motivation Theory behavioural model.&#xA0;</p>
            <p> </p>
            <p> The paper presents significant contributions in the cybersecurity field. But some comments should be considered:</p>
            <p> </p>
            <p> - Point 1: The abstract is missing some important parts like, what is the research methodology used? and what are the main future direction of the research for future researchers. So, my suggestion to rewrite the abstract.&#xA0;</p>
            <p> - Point 2: The study focused on risk management as one of the methods used to identify threats. The authors have to clarify the importance of risk management in classification threats. So my suggestion, authors have to add new section to clarify that and use recent studies. Use these studies:- (1) Applying risk analysis for determining threats and countermeasures in workstation domain. Journal of Cyber Security and Risk Auditing. (2) Classification of threats and countermeasures of cloud computing. Journal of Cyber Security and Risk Auditing.</p>
            <p> - Point 3: In the Introduction section, the authors have to discuss the critical security issues and Security Weaknesses. Use this recent study: [Reference 1]</p>
            <p> - Point 4: Clarify what is the problem statement of the research.&#xA0;</p>
            <p> - Point 5: Add future works.</p>
            <p> - Point 6: Rewrite the conclusion.</p>
            <p>Is the study design appropriate and does the work have academic merit?</p>
            <p>Yes</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Yes</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>I cannot comment. A qualified statistician is required.</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Yes</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Yes</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Yes</p>
            <p>Reviewer Expertise:</p>
            <p>Cybersecurity</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above.</p>
        </body>
        <back>
            <ref-list>
                <title>References</title>
                <ref id="rep-ref-59582-1">
                    <label>1</label>
                    <mixed-citation publication-type="journal">
                        <person-group person-group-type="author"/>:
                        <article-title>Analyzing Cybersecurity Risks and Threats in IT Infrastructure based on NIST Framework</article-title>.
                        <source>
                            <italic>Journal of Cyber Security and Risk Auditing</italic>
                        </source>.<year>2025</year>;<volume>2025</volume>(<issue>2</issue>) :
                        <elocation-id>10.63180/jcsra.thestap.2025.2.2</elocation-id><fpage>12</fpage>-<lpage>26</lpage>
                        <pub-id pub-id-type="doi">10.63180/jcsra.thestap.2025.2.2</pub-id>
                    </mixed-citation>
                </ref>
            </ref-list>
        </back>
    </sub-article>
</article>