<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="research-article"><front><journal-meta><journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id><journal-id journal-id-type="publisher-id">jmir</journal-id><journal-id journal-id-type="index">1</journal-id><journal-title>Journal of Medical Internet Research</journal-title><abbrev-journal-title>J Med Internet Res</abbrev-journal-title><issn pub-type="epub">1438-8871</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v28i1e68051</article-id><article-id pub-id-type="doi">10.2196/68051</article-id><article-categories><subj-group subj-group-type="heading"><subject>Original Paper</subject></subj-group></article-categories><title-group><article-title>Cognitive Dissonance&#x2013;Based Priming Intervention: Randomized Encouragement With in-the-Wild Phishing Simulation Attack in Health Care</article-title></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name name-style="western"><surname>Yeng</surname><given-names>Prosper Kandabongee</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Fauzi</surname><given-names>Muhammad Ali</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff2">2</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Vestad</surname><given-names>Arnstein</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff3">3</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Yang</surname><given-names>Bian</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff3">3</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>De Moor</surname><given-names>Katrien</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff4">4</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Jacobsen</surname><given-names>Christian</given-names></name><xref ref-type="aff" rid="aff5">5</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Diekuu</surname><given-names>John-Bosco</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff6">6</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Bettayeb</surname><given-names>Meriem</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib></contrib-group><aff id="aff1"><institution>Department of Computer Science and IT, College of Engineering, Abu Dhabi University</institution><addr-line>Al Ain</addr-line><addr-line>Abu Dhabi</addr-line><country>United Arab Emirates</country></aff><aff id="aff2"><institution>Department of Informatics Engineering, Faculty of Computer Science, University of Brawijaya</institution><addr-line>Malang</addr-line><country>Indonesia</country></aff><aff id="aff3"><institution>Department of Information Security and Communication Technology, Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology (NTNU)</institution><addr-line>Gj&#x00F8;vik</addr-line><country>Norway</country></aff><aff id="aff4"><institution>Department of Information Security and Communication Technology, Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology (NTNU)</institution><addr-line>Trondheim</addr-line><country>Norway</country></aff><aff id="aff5"><institution>Department of Security and Risk Governance, Aidn AS</institution><addr-line>Oslo</addr-line><country>Norway</country></aff><aff id="aff6"><institution>Department of Machine Learning and Computer Vision, School of Computing, Engineering and Technology, Robert Gordon University</institution><addr-line>Aberdeen</addr-line><country>United Kingdom</country></aff><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Sarvestan</surname><given-names>Javad</given-names></name></contrib><contrib contrib-type="editor"><name name-style="western"><surname>Cardoso</surname><given-names>Taiane de Azevedo</given-names></name></contrib></contrib-group><contrib-group><contrib contrib-type="reviewer"><name name-style="western"><surname>Dykstra</surname><given-names>Josiah</given-names></name></contrib><contrib contrib-type="reviewer"><name name-style="western"><surname>Moussaoui</surname><given-names>L S</given-names></name></contrib></contrib-group><author-notes><corresp>Correspondence to Prosper Kandabongee Yeng, PhD, Department of Computer Science and IT, College of Engineering, Abu Dhabi University, Al Ain, Abu Dhabi, United Arab Emirates, +971 0506991627; <email>prosper.yeng@adu.ac.ae</email></corresp></author-notes><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>1</day><month>6</month><year>2026</year></pub-date><volume>28</volume><elocation-id>e68051</elocation-id><history><date date-type="received"><day>27</day><month>10</month><year>2024</year></date><date date-type="rev-recd"><day>15</day><month>01</month><year>2026</year></date><date date-type="accepted"><day>16</day><month>01</month><year>2026</year></date></history><copyright-statement>&#x00A9; Prosper Kandabongee Yeng, Muhammad Ali Fauzi, Arnstein Vestad, Bian Yang, Katrien De Moor, Christian Jacobsen, John-Bosco Diekuu, Meriem Bettayeb. Originally published in the Journal of Medical Internet Research (<ext-link ext-link-type="uri" xlink:href="https://www.jmir.org">https://www.jmir.org</ext-link>), 1.6.2026. </copyright-statement><copyright-year>2026</copyright-year><license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (<ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link>), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research (ISSN 1438-8871), is properly cited. The complete bibliographic information, a link to the original publication on <ext-link ext-link-type="uri" xlink:href="https://www.jmir.org/">https://www.jmir.org/</ext-link>, as well as this copyright and license information must be included.</p></license><self-uri xlink:type="simple" xlink:href="https://www.jmir.org/2026/1/e68051"/><abstract><sec><title>Background</title><p>Phishing remains a dominant initial attack vector in health care, exploiting psychological factors such as urgency and authority. Despite extensive investment in technical controls and awareness training, health care staff remain highly susceptible in real operational conditions. Cognitive dissonance (CD), the discomfort arising from inconsistencies between beliefs and actions, has been proposed as a mechanism to disrupt unsafe rationalization at the moment of exposure, but has rarely been evaluated in live organizational settings using objective behavioral outcomes.</p></sec><sec><title>Objective</title><p>This study examined whether a brief CD-based priming intervention, delivered immediately prior to a real-world phishing simulation, was associated with differences in phishing susceptibility among health care staff. Secondary objectives explored whether CD exposure was associated with directional differences in security-related perceptions and self-reported practices.</p></sec><sec sec-type="methods"><title>Methods</title><p>A 2-stage hybrid randomized-encouragement experiment was conducted at a large Norwegian hospital. In Stage 1, staff were randomly assigned to a control or CD-primed condition and completed a survey assessing security perceptions and self-reported practices (n=62). In Stage 2, an in-the-wild phishing simulation was sent to all staff, enabling objective measurement of phishing susceptibility via observed link-click behavior. Behavioral outcomes were analyzed across 3 groups&#x2014;control (n=34), CD-primed (n=32), and neutral nonresponders (n=753)&#x2014;using a prespecified omnibus chi-square test as the sole confirmatory analysis. Survey-based multivariate and univariate analyses were treated as exploratory due to limited sample size and variable construct reliability.</p></sec><sec sec-type="results"><title>Results</title><p>Due to voluntary uptake, only a subset of randomized participants received the intervention. Observed phishing click rates were 65% (22/34) in the control group, 44% (14/32) in the CD-primed group, and 53% (396/753) in the neutral group. The omnibus chi-square test did not detect a statistically significant association between group membership and click behavior (<italic>&#x03C7;</italic>&#x00B2;<sub>2</sub>=3.00; n=819; <italic>P</italic>=.22; Cram&#x00E9;r V=0.06). Descriptive comparisons within the randomized subset suggested lower click rates in the CD-primed group, but effect estimates were imprecise and associated with wide CIs. Survey-based analyses indicated group differences across combined psychological constructs; however, several constructs exhibited low internal consistency, and follow-up analyses were underpowered.</p></sec><sec sec-type="conclusions"><title>Conclusions</title><p>In a real-world hospital phishing simulation, pre-exposure CD priming was associated with a directional but statistically nonsignificant pattern of reduced phishing click behavior. This evidence does not establish a reliable behavioral effect, and construct-level findings are exploratory. CD-based prompts may serve as a lightweight behavioral signal in real-world conditions, but larger, fully randomized, and longitudinal studies with improved psychometric validation are needed before such interventions can be considered reliable complements to established cybersecurity controls.</p></sec></abstract><kwd-group><kwd>cognitive dissonance</kwd><kwd>phishing simulation</kwd><kwd>health care</kwd><kwd>randomized encouragement</kwd><kwd>psychological incentive</kwd><kwd>health belief model</kwd><kwd>protection motivation theory</kwd><kwd>cognition</kwd><kwd>phishing</kwd><kwd>phishing attacks</kwd><kwd>cybersecurity</kwd><kwd>phishing attempts</kwd><kwd>health care staff</kwd><kwd>security</kwd><kwd>Norway</kwd></kwd-group></article-meta></front><body><sec id="s1" sec-type="intro"><title>Introduction</title><sec id="s1-1"><title>Background</title><p>Phishing remains the dominant initial attack vector in health care, accounting for a substantial proportion of breaches between 2022 and 2025 through credential theft, business email compromise, and ransomware deployment [<xref ref-type="bibr" rid="ref1">1</xref>-<xref ref-type="bibr" rid="ref3">3</xref>]. Despite significant investment in email filtering and endpoint defenses, health care employees continue to be exposed to highly contextualized phishing campaigns that exploit clinical workflows, trust relationships, professional hierarchies, and time pressure [<xref ref-type="bibr" rid="ref2">2</xref>-<xref ref-type="bibr" rid="ref6">6</xref>]. Consequently, health care has become one of the costliest sectors for data breaches, with human-driven social engineering outweighing purely technical exploitation [<xref ref-type="bibr" rid="ref2">2</xref>,<xref ref-type="bibr" rid="ref2">2</xref>,<xref ref-type="bibr" rid="ref4">4</xref>,<xref ref-type="bibr" rid="ref7">7</xref>-<xref ref-type="bibr" rid="ref9">9</xref>]. These attacks not only compromise data confidentiality but also disrupt care delivery, delay clinical workflows, and threaten patient safety [<xref ref-type="bibr" rid="ref9">9</xref>-<xref ref-type="bibr" rid="ref11">11</xref>].</p><p>To explain persistent phishing susceptibility, prior research has increasingly applied psychological frameworks such as the Health Belief Model (HBM) and Protection Motivation Theory (PMT) [<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>]. These models examine how perceived severity (PS), perceived vulnerability (PV), self-efficacy (SE), and response efficacy (RE) influence individual security behavior. However, most health care phishing studies rely on self-reported intentions, survey-based perceptions, or post-hoc evaluations conducted in training contexts rather than during real operational attacks [<xref ref-type="bibr" rid="ref4">4</xref>-<xref ref-type="bibr" rid="ref6">6</xref>,<xref ref-type="bibr" rid="ref14">14</xref>-<xref ref-type="bibr" rid="ref16">16</xref>]. As a result, existing interventions rarely disrupt unsafe cognition at the moment of threat exposure, nor do they validate effectiveness using objective behavioral outcomes [<xref ref-type="bibr" rid="ref3">3</xref>,<xref ref-type="bibr" rid="ref4">4</xref>,<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref14">14</xref>].</p><p>The objectives of this study are therefore outlined as follows:</p><list list-type="bullet"><list-item><p>Delivering the first cognitive dissonance (CD)&#x2013;based prephishing intervention tested in a live hospital;</p></list-item><list-item><p>Experimentally linking CD to shifts in HBM or PMT perceptions;</p></list-item><list-item><p>Measuring real click behavior during an in-the-wild phishing event;</p></list-item><list-item><p>Demonstrating a theory-driven, low-cost behavioral security control with ecological validity.</p></list-item></list></sec><sec id="s1-2"><title>CD-Based in-the-Wild Phishing Intervention</title><p>CD theory explains how individuals experience psychological discomfort when their beliefs conflict with their actions, such as recognizing phishing risks while still clicking urgent or authoritative emails [<xref ref-type="bibr" rid="ref17">17</xref>-<xref ref-type="bibr" rid="ref19">19</xref>]. To reduce this discomfort, individuals often rationalize risky behavior through neutralization techniques, including denial of harm, denial of responsibility, or appeals to higher organizational goals [<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref20">20</xref>-<xref ref-type="bibr" rid="ref22">22</xref>]. In health care contexts, such rationalizations have been observed in email-policy violations, unsafe password practices, and delayed incident reporting justified by clinical urgency [<xref ref-type="bibr" rid="ref4">4</xref>,<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref23">23</xref>].</p><p>Phishing attackers deliberately exploit these same psychological mechanisms by embedding urgency, authority, fear, and trust cues into realistic clinical narratives, thereby intensifying cognitive conflict and impairing reflective judgment [<xref ref-type="bibr" rid="ref3">3</xref>,<xref ref-type="bibr" rid="ref6">6</xref>,<xref ref-type="bibr" rid="ref23">23</xref>,<xref ref-type="bibr" rid="ref24">24</xref>]. Recent reviews emphasize that such human-factor vulnerabilities remain inadequately addressed by purely technical controls and awareness-only training approaches [<xref ref-type="bibr" rid="ref8">8</xref>,<xref ref-type="bibr" rid="ref9">9</xref>,<xref ref-type="bibr" rid="ref13">13</xref>,<xref ref-type="bibr" rid="ref25">25</xref>].</p><p>This study introduces a CD-based priming intervention delivered immediately before an in-the-wild phishing simulation at one of Norway&#x2019;s largest hospitals. Unlike traditional training, deterrence-based sanctions, or postincident awareness programs [<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref13">13</xref>-<xref ref-type="bibr" rid="ref15">15</xref>,<xref ref-type="bibr" rid="ref25">25</xref>], CD priming operates as a proactive, preattack behavioral control that directly targets rationalization before exposure. The intervention is lightweight, theory-driven, and embedded within routine organizational communication, making it suitable for real clinical environments characterized by time pressure and high cognitive load [<xref ref-type="bibr" rid="ref3">3</xref>,<xref ref-type="bibr" rid="ref3">3</xref>,<xref ref-type="bibr" rid="ref9">9</xref>].</p><p>Methodologically, the study advances prior work in 3 ways. First, it deploys CD priming immediately prior to a live operational phishing event rather than within simulated, laboratory, or training-only contexts [<xref ref-type="bibr" rid="ref5">5</xref>,<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref14">14</xref>,<xref ref-type="bibr" rid="ref26">26</xref>]. Second, it integrates CD with established HBM and PMT constructs to examine shifts in theory-driven security perceptions [<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref12">12</xref>,<xref ref-type="bibr" rid="ref13">13</xref>,<xref ref-type="bibr" rid="ref15">15</xref>]. Third, it validates intervention effectiveness using objective behavioral outcomes&#x2014;actual link-click behavior&#x2014;while minimizing ethical risk by avoiding credential harvesting and excessive deception [<xref ref-type="bibr" rid="ref27">27</xref>,<xref ref-type="bibr" rid="ref28">28</xref>]. To our knowledge, no prior health care study has combined CD-based priming, health-behavior theory, and in-the-wild behavioral measurement within a single experimental design [<xref ref-type="bibr" rid="ref3">3</xref>,<xref ref-type="bibr" rid="ref9">9</xref>,<xref ref-type="bibr" rid="ref29">29</xref>].</p></sec><sec id="s1-3"><title>Hypothesis Formulation and Contributions</title><p>The primary objective of this study was to examine whether exposure to a CD-based priming intervention was associated with differences in observed phishing susceptibility during a real-world phishing simulation (hypothesis 1). Secondary analyses explored whether CD exposure was associated with directional differences in psychological security perceptions and self-reported security practices.</p><p>The following hypothesis and research questions were therefore specified:</p><sec id="s1-3-1"><title>Hypothesis 1 (Confirmatory)</title><p>Exposure to a CD-based priming intervention is associated with differences in observed phishing susceptibility, measured by link-click behavior during an in-the-wild phishing simulation.</p></sec><sec id="s1-3-2"><title>Research Question (RQ) 1 (Exploratory)</title><p>Is exposure to a CD-based priming message associated with directional differences in selected security-related perceptions derived from the Health Belief Model (HBM) and Protection Motivation Theory (PMT), including PV, PS, SE, RE, perceived barriers (PBs), and cues to action (CA)?</p></sec><sec id="s1-3-3"><title>RQ2 (Exploratory)</title><p>Is exposure to a CD-based priming message associated with directional differences in self-reported security practices related to password management, incident reporting, email handling, and mobile-device security?</p></sec></sec></sec><sec id="s2" sec-type="methods"><title>Methods</title><sec id="s2-1"><title>Overview</title><p>This study used a 2-stage randomized encouragement design [<xref ref-type="bibr" rid="ref30">30</xref>,<xref ref-type="bibr" rid="ref31">31</xref>], involving approximately 830 health care staff who were randomly assigned at the invitation stage to receive either a control or a CD-primed questionnaire [<xref ref-type="bibr" rid="ref27">27</xref>,<xref ref-type="bibr" rid="ref32">32</xref>,<xref ref-type="bibr" rid="ref33">33</xref>]. Only a subset of invited staff completed the questionnaire and were therefore exposed to the intervention (control: n=42; CD-primed: n=40), while nonresponse was treated as nonreceipt rather than exclusion, consistent with established methodological guidance [<xref ref-type="bibr" rid="ref34">34</xref>]. Randomization, therefore, applies only to encouragement and survey exposure, not to subsequent receipt of the phishing email or behavioral outcome measurement.</p><p>In Stage 2, an in-the-wild phishing simulation [<xref ref-type="bibr" rid="ref4">4</xref>] message (as shown in <xref ref-type="fig" rid="figure1">Figure 1</xref>) was sent to all staff with valid email addresses, enabling objective measurement of phishing click behavior under real-world conditions. Primary outcome analyses for the randomized component were conducted among questionnaire respondents who received valid phishing emails. These participants were the only ones plausibly exposed to both the intervention and the behavioral outcome. In parallel, a large Neutral group comprising staff who did not complete the questionnaire but received the in-the-wild phishing email was included as an observational comparison. Analyses involving this group are reported descriptively and interpreted without causal inference in accordance with STROBE (Strengthening the Reporting of Observational Studies in Epidemiology) guidelines [<xref ref-type="bibr" rid="ref35">35</xref>], while the randomized encouragement component is reported following CONSORT (Consolidated Standards of Reporting Trials) principles [<xref ref-type="bibr" rid="ref36">36</xref>], ensuring transparent reporting of participant flow, uptake, and inferential boundaries.</p><fig position="float" id="figure1"><label>Figure 1.</label><caption><p>Phishing attack simulation message.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig01.png"/></fig><p>Behavioral outcomes were assessed independently of survey participation. Valid delivery and outcome records were available for 819 participants, who formed the sample used for behavioral analysis. These participants fell into 3 groups based on their prior exposure to the CD message:</p><list list-type="bullet"><list-item><p>Control group: survey respondents who did not receive the CD message and had valid phishing-outcome data (n=34).</p></list-item><list-item><p>Experiment group: survey respondents who received the CD message and had valid phishing-outcome data (n=32). The architecture is shown in <xref ref-type="fig" rid="figure2">Figure 2</xref>.</p></list-item><list-item><p>Neutral group: all remaining staff who did not receive any CD-related priming but successfully received the phishing email (n=753).</p></list-item></list><fig position="float" id="figure2"><label>Figure 2.</label><caption><p>Experiment model for psychological incentive.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig02.png"/></fig><p>The difference between the invited population (~830) and the Stage 2 analyzed sample (819) reflects staff with undeliverable emails. This grouping structure enabled the study to (1) evaluate the causal effect of the CD intervention on psychological and self-reported outcomes among survey respondents and (2) compare their actual phishing susceptibility against a large neutral group not exposed to any experimental priming.</p><p>As an incentive, participants in both stages were offered a free lunch at the hospital canteen and also entered into a draw in which 10 individuals could win a US $50 gift card [<xref ref-type="bibr" rid="ref37">37</xref>,<xref ref-type="bibr" rid="ref38">38</xref>].</p></sec><sec id="s2-2"><title>Behavioral Outcome: Phishing Click Susceptibility</title><p>Actual behavioral phishing susceptibility was measured by recording objective link-click behavior during the in-the-wild phishing simulation and coding it as a binary outcome (clicked vs not clicked) across 3 groups, including control (n=34), CD-primed (n=32), and neutral (n=753).</p><p>The primary, prespecified analysis was an omnibus Pearson chi-square test of independence (3&#x00D7;2 contingency table; 2-sided <italic>&#x03B1;</italic>=.05). While this test was designated a priori as the primary behavioral analysis, causal inference is limited to the randomized comparison between the control and CD-primed groups; comparisons involving the neutral group are observational.</p><p>Effect size was quantified using Cohen w and Cram&#x00E9;r V, and group-specific click rates were reported with 95% CIs (Wilson method) [<xref ref-type="bibr" rid="ref39">39</xref>]. Pairwise comparisons between the CD-primed and control groups were reported descriptively using risk difference, relative risk, and odds ratio with 95% CIs and treated as exploratory due to limited sample size [<xref ref-type="bibr" rid="ref40">40</xref>].</p><p>A post hoc power assessment for the omnibus test was reported descriptively to characterize statistical sensitivity, rather than to support inferential claims. All analyses were conducted using the statsmodels Python (Python Software Foundation) library [<xref ref-type="bibr" rid="ref16">16</xref>,<xref ref-type="bibr" rid="ref41">41</xref>].</p></sec><sec id="s2-3"><title>Ethical, Privacy, and Security Measures With an in-the-Wild Study</title><p>In this experiment, a questionnaire and an in-the-wild study were combined. The hybrid approach was essential, as the survey provided a basis for the researchers to understand participants&#x2019; intended phishing security behavior, while the in-the-wild study tested participants&#x2019; actual phishing security practice (ie, the clicking action). An in-the-wild study is a type of phishing simulation in which the researcher conducts a phishing attack on participants in their natural working environment without prior warning to observe real-world security behavior under realistic conditions. Unlike laboratory-based or survey-based studies, in-the-wild studies capture authentic user responses but raise additional ethical and methodological considerations [<xref ref-type="bibr" rid="ref4">4</xref>,<xref ref-type="bibr" rid="ref27">27</xref>].</p></sec><sec id="s2-4"><title>Survey Instrument</title><p>In the first section of the questionnaire, we adopted the approach of Parsons et al [<xref ref-type="bibr" rid="ref42">42</xref>], the human aspect of the information security questionnaire. This consists of 42 items that measure knowledge, attitude, and behavior (KAB) regarding phishing, as well as risk factors associated with password management, email use, incident reporting, and mobile device use. A 5-point Likert scale was used in this instrument. These areas of security practice are considered more vulnerable to phishing attacks. Additionally, approximately 25 items in this instrument measured other psychological constructs, including PV, SE, CA, PB, and RE. <xref ref-type="fig" rid="figure2">Figure 2</xref> shows the questionnaire structure. The instrument was developed with an online, secure Norwegian version of a survey system called Nettskjema [<xref ref-type="bibr" rid="ref43">43</xref>]. The questionnaire was then divided into 2 groups, a control group and the experiment group. The difference between them was that the experiment group questionnaire included a CD message, as shown in <xref ref-type="supplementary-material" rid="app1">Multimedia Appendix 1</xref>, and in the model in <xref ref-type="fig" rid="figure3">Figure 3</xref>. Participants also indicated in the questionnaire if they believe in the CD message as shown in <xref ref-type="fig" rid="figure4">Figure 4</xref>. The questionnaire for the control group did not include the CD message item. The instrument was then pretested with 4 PhD students and a professor specializing in cybersecurity. Issues, including complex terminologies and the length of the CD message, were identified and resolved. Measures were also taken against error variances [<xref ref-type="bibr" rid="ref44">44</xref>]. Error variance can be caused by preexisting factors that introduce differences among the study groups, beyond the treatment effect. In this regard, the health care personnel were randomly assigned to reduce potential biases. Additionally, the participants were asked not to share their questionnaires with others. Attention checkers [<xref ref-type="bibr" rid="ref45">45</xref>] were among the survey items in the study, and these required the participants to choose specified responses. Participants who fail to correctly answer 2 of the 3 attention checkers are inferred to have not paid attention while answering the questionnaire. As a result, 2 records were discarded. This has been one of the most popular methods for improving survey response quality without compromising research findings. The participants also had to either agree or disagree with the cognitive dissonance message, as shown in <xref ref-type="fig" rid="figure5">Figure 5</xref>.</p><fig position="float" id="figure3"><label>Figure 3.</label><caption><p>Experiment setup.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig03.png"/></fig><fig position="float" id="figure4"><label>Figure 4.</label><caption><p>Response rate.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig04.png"/></fig><fig position="float" id="figure5"><label>Figure 5.</label><caption><p>Cognitive dissonance message agreement for experiment group.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig05.png"/></fig></sec><sec id="s2-5"><title>Phishing Simulation Setup and Experiment Process</title><p>A phishing simulation tool, known as Gophish (Jordan Wright) [<xref ref-type="bibr" rid="ref28">28</xref>], was set up on a server, as illustrated in <xref ref-type="fig" rid="figure3">Figure 3</xref>. It has a feature that allows an attacker to simulate a phishing email and send it to a target. It can also record click events on links in phishing emails.</p><p>During the initial setup, the simulated phishing email was tested with the staff of the target hospital; however, it was flagged as spam by the service provider&#x2019;s email filtering system. Since the study goal was not to test the technical email security controls of the target facility, we collaborated with the providers who configured the email system to allow the phishing simulation email to land in the inboxes of the targeted participants. The email message content is shown in <xref ref-type="supplementary-material" rid="app2">Multimedia Appendix 2</xref>.</p><p>The in-the-wild phishing simulation was implemented using the open-source GoPhish platform, which was configured to deliver a single simulated phishing email to staff with valid institutional email addresses [<xref ref-type="bibr" rid="ref28">28</xref>]. The platform automatically recorded email delivery status and objective link-click events, which were used as the primary behavioral outcome measure [<xref ref-type="bibr" rid="ref11">11</xref>,<xref ref-type="bibr" rid="ref26">26</xref>,<xref ref-type="bibr" rid="ref29">29</xref>,<xref ref-type="bibr" rid="ref46">46</xref>-<xref ref-type="bibr" rid="ref50">50</xref>].</p><p>The flow of participants in both the controlled experiment and the observational study is shown in <xref ref-type="fig" rid="figure6">Figures 6</xref> and <xref ref-type="fig" rid="figure7">7</xref>, respectively. The CONSORT and STROBE checklists have also been provided in <xref ref-type="supplementary-material" rid="app3">Checklist 1</xref> and <xref ref-type="supplementary-material" rid="app4">Checklist 2</xref><ext-link ext-link-type="uri" xlink:href="https://studentsaduac-my.sharepoint.com/personal/prosper_yeng_adu_ac_ae/Documents/Documents/Yeng/Research/CD/Final%20Round/STROBE_Combined_Checklist.docx">,</ext-link> respectively.</p><fig position="float" id="figure6"><label>Figure 6.</label><caption><p>CONSORT (Consolidated Standards of Reporting Trials) diagram.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig06.png"/></fig><fig position="float" id="figure7"><label>Figure 7.</label><caption><p>STROBE (Strengthening the Reporting of Observational Studies in Epidemiology) diagram.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e68051_fig07.png"/></fig><p>Fourteen dependent scale variables representing psychosocial constructs derived from the Health Belief Model and Protection Motivation Theory were included in the exploratory multivariate analysis [<xref ref-type="bibr" rid="ref51">51</xref>,<xref ref-type="bibr" rid="ref52">52</xref>]. Additionally, a minimum of one independent variable is required with at least 2 categorical groups. Our study also meets this condition with an independent 2-level design: in the first stage, there are 2 levels (control and experiment), and in the second stage, there are 3 groups (neutral, control, and experiment). A multivariate analysis of variance (MANOVA) assumes multivariate normality. The test also requires homogeneity of covariate metrics, and the dependent variables must not be multicollinear. A sufficient sample size is also needed in MANOVA. A sample size is required for each level of the independent variable. The rule of thumb requires 30 participants per group level [<xref ref-type="bibr" rid="ref53">53</xref>]. The actual behavior (AB) variable has the lowest number of participants in the control and experimental groups, 30 and 32, respectively, indicating that the study met the minimum requirement [<xref ref-type="bibr" rid="ref54">54</xref>]. Cronbach &#x03B1; was used in this study because it is a widely used measure of reliability [<xref ref-type="bibr" rid="ref40">40</xref>].</p></sec><sec id="s2-6"><title>Ethical Considerations</title><p>Prior to the launch of the phishing study, a press release was issued to administrators. Additionally, during the launch of the attack, data protection and the well-being of the participants were considered by providing a debriefing and obtaining informed consent [<xref ref-type="bibr" rid="ref27">27</xref>]. Having followed these measures, this study obtained ethical clearance from the targeted hospital, the Regional Committees for Medical and Health Research Ethics of Norway (REK), and the Norwegian Center for Research Data (NSD). A phishing simulation was then conducted via email in this experiment.</p></sec></sec><sec id="s3" sec-type="results"><title>Results</title><sec id="s3-1"><title>Overview</title><p>To ensure methodological transparency and inferential clarity, the analytical strategy was explicitly aligned with the study objectives. The omnibus chi-square test of independence comparing click behavior across the control, CD-primed, and neutral groups (n=819) was designated a priori as the sole confirmatory test of behavioral impact (hypothesis 1). All survey-based multivariate and univariate analyses, conducted on a substantially smaller subsample (n=62), were treated as exploratory and hypothesis-generating due to limited statistical power and variable construct reliability. This alignment ensures that confirmatory claims are restricted to adequately powered, objective behavioral outcomes, while construct-level findings are interpreted conservatively and used to inform future research design. This section presents the analysis of the results, covering descriptive statistics, click rates, reliability, normality tests, and the significance of the studies.</p></sec><sec id="s3-2"><title>Descriptive Statistics</title><p>All participants in the CD condition agreed with the presented message. As shown in <xref ref-type="table" rid="table1">Table 1</xref>, a total of 80 records from the survey were analyzed out of 82 participants. Two records were removed from the analysis because they did not pass the attention checks that were placed in the questionnaire [<xref ref-type="bibr" rid="ref45">45</xref>].</p><table-wrap id="t1" position="float"><label>Table 1.</label><caption><p>Descriptive statistics of demographic variables (N=80).</p></caption><table id="table1" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom" colspan="2">Variable category</td><td align="left" valign="bottom" colspan="2">n (%)</td></tr></thead><tbody><tr><td align="left" valign="top" colspan="2">Sex</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Male</td><td align="left" valign="top" colspan="2">58 (72.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Female</td><td align="left" valign="top" colspan="2">22 (27.5)</td></tr><tr><td align="left" valign="top" colspan="2">Age range (years)</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>21&#x2010;30</td><td align="left" valign="top" colspan="2">14 (17.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>31&#x2010;40</td><td align="left" valign="top" colspan="2">23 (28.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>41&#x2010;50</td><td align="left" valign="top" colspan="2">18 (22.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>51&#x2010;60</td><td align="left" valign="top" colspan="2">16 (20.0)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><italic>&#x003E;</italic>60</td><td align="left" valign="top" colspan="2">9 (11.3)</td></tr><tr><td align="left" valign="top" colspan="2">Position</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Administrator</td><td align="left" valign="top" colspan="2">6 (7.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Nurse</td><td align="left" valign="top" colspan="2">40 (50.0)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Doctor</td><td align="left" valign="top" colspan="2">31 (38.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Others</td><td align="left" valign="top" colspan="2">3 (3.8)</td></tr><tr><td align="left" valign="top" colspan="2">Years of experience</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>1&#x2010;5</td><td align="left" valign="top" colspan="2">9 (11.3)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>6&#x2010;10</td><td align="left" valign="top" colspan="2">19 (23.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>11&#x2010;15</td><td align="left" valign="top" colspan="2">10 (12.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>16&#x2010;20</td><td align="left" valign="top" colspan="2">13 (16.3)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content><italic>&#x003E;</italic>20</td><td align="left" valign="top" colspan="2">29 (36.3)</td></tr><tr><td align="left" valign="top" colspan="2">Knowledge of phishing attacks</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>No knowledge</td><td align="left" valign="top" colspan="2">12 (15.0)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Basic</td><td align="left" valign="top" colspan="2">23 (28.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Medium</td><td align="left" valign="top" colspan="2">26 (32.5)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>High</td><td align="left" valign="top" colspan="2">15 (18.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Very high</td><td align="left" valign="top" colspan="2">3 (3.8)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Professional</td><td align="left" valign="top" colspan="2">1 (1.3)</td></tr><tr><td align="left" valign="top" colspan="2">Opinion in cognitive dissonance</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Not available</td><td align="left" valign="top" colspan="2">40 (50.0)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Agree</td><td align="left" valign="top" colspan="2">38 (95.0)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Disagree</td><td align="left" valign="top" colspan="2">2 (5.0)</td></tr></tbody></table></table-wrap><p>Furthermore, among these participants, 72.5% (58/80) were males, while 27.5% (22/80) were females. The age group 31-40 years old had the highest proportion (23/80, 28%), while participants &#x003E;60 years old had the lowest proportion (9/80, 11.3%). Regarding the participants, primarily doctors, nurses, and administrators participated. Nurses comprised more than half of the total participants (40/80, 50%), followed by doctors (31/80, 38%) and administrators (6/80, 7.5%). In terms of years of work experience, participants with &#x003E;20 years of experience were comparatively more numerous (29/80, 36.3%), as shown in <xref ref-type="table" rid="table1">Table 1</xref>. Meanwhile, the participants also shared their phishing security practice knowledge. Most of them (26/80, 32.5%) had medium knowledge, 28% (23/80) had basic knowledge, and 15% (12/80) reported no knowledge of phishing security practices. Additionally, participants in the experiment group shared their opinion on the treatment effect of CD. Out of the 40 participants in the experiment group, 38 (95%) agreed with the effectiveness of the treatment measure. To control for these confounding variables, the randomization approach [<xref ref-type="bibr" rid="ref55">55</xref>] was used to assign participants to the 2 groups in this study.</p><p>As shown in <xref ref-type="table" rid="table2">Table 2</xref>, descriptive statistics were computed for all dependent variables across study groups. Overall, mean values for security practice measures were generally higher in the control group than in the experimental group. Box&#x2019;s test of equality of covariance matrices was conducted to assess the assumption that the covariance matrices of the dependent variables were equivalent across groups. The test yielded a Box&#x2019;s mean value of 153.081 with a nonsignificant <italic>P</italic> value (<italic>P</italic>=.24), indicating no evidence of heterogeneity in covariance matrices. Consistent with established guidelines [<xref ref-type="bibr" rid="ref56">56</xref>], the null hypothesis of equal covariance matrices was therefore retained.</p><table-wrap id="t2" position="float"><label>Table 2.</label><caption><p>Descriptive statistics of dependent variables across groups.</p></caption><table id="table2" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom" colspan="2">Construct (n)</td><td align="left" valign="bottom" colspan="2">Mean (SD)</td></tr></thead><tbody><tr><td align="left" valign="top" colspan="2">Actual behavior (AB)</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">3.93 (1.799)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">2.75 (2.016)</td></tr><tr><td align="left" valign="top" colspan="2">Knowledge (K)</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.82 (0.412)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.81 (0.494)</td></tr><tr><td align="left" valign="top" colspan="2">Attitude (A)</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.79 (0.338)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.62 (0.541)</td></tr><tr><td align="left" valign="top" colspan="2">Intended behavior (IB)</td><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.92 (0.371)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.73 (0.463)</td></tr><tr><td align="left" valign="top">Perceived vulnerability (PV)</td><td align="left" valign="top"/><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">2.09 (0.711)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.85 (0.871)</td></tr><tr><td align="left" valign="top" colspan="2">Perceived severity (PS)</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">2.07 (0.719)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.41 (0.534)</td></tr><tr><td align="left" valign="top" colspan="2">Perceived self-efficacy (SE)</td><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">2.75 (0.65)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">2.45 (0.672)</td></tr><tr><td align="left" valign="top">Perceived response efficacy (RE)</td><td align="left" valign="top"/><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.4 (0.395)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.41 (0.534)</td></tr><tr><td align="left" valign="top" colspan="2">Perceived barrier (PB)</td><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">3.35 (0.842)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">3.34 (0.689)</td></tr><tr><td align="left" valign="top" colspan="2">Perceived cues to action (CA)</td><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">2.98 (0.517)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">2.55 (0.787)</td></tr><tr><td align="left" valign="top" colspan="2">Password</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.82 (0.482)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.67 (0.59)</td></tr><tr><td align="left" valign="top" colspan="2">Incident</td><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">2.39 (0.708)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">2.07 (0.766)</td></tr><tr><td align="left" valign="top">Email</td><td align="left" valign="top"/><td align="left" valign="top"/><td align="left" valign="top"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.6 (0.43)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.49 (0.523)</td></tr><tr><td align="left" valign="top" colspan="2">Mobile</td><td align="left" valign="top" colspan="2"/></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Control (30)</td><td align="left" valign="top" colspan="2">1.65 (0.355)</td></tr><tr><td align="left" valign="top" colspan="2"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Experiment (32)</td><td align="left" valign="top" colspan="2">1.65 (0.471)</td></tr></tbody></table></table-wrap></sec><sec id="s3-3"><title>Reliability, Validity, and Assumption Assessment</title><p><xref ref-type="table" rid="table3">Table 3</xref> presents internal consistency estimates for the study constructs. Cronbach &#x03B1; values ranged from 0.256 for CA to 0.792 for incident reporting. While several constructs demonstrated acceptable internal consistency, most notably CA (<italic>&#x03B1;</italic>=0.256), password practices (<italic>&#x03B1;</italic>=0.349), and PBs (<italic>&#x03B1;</italic>=0.476) exhibited poor internal consistency. These variables were therefore retained solely as exploratory indicators and were not used to support confirmatory inference or substantive theoretical claims.</p><table-wrap id="t3" position="float"><label>Table 3.</label><caption><p>Reliability statistics.</p></caption><table id="table3" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Number</td><td align="left" valign="bottom">Construct</td><td align="left" valign="bottom">Cronbach &#x03B1;</td><td align="left" valign="bottom">Number of items (n)</td></tr></thead><tbody><tr><td align="char" char="." valign="top">1</td><td align="left" valign="top">Knowledge (K)</td><td align="char" char="." valign="top">0.660</td><td align="char" char="." valign="top">13</td></tr><tr><td align="char" char="." valign="top">2</td><td align="left" valign="top">Attitude (A)</td><td align="char" char="." valign="top">0.53</td><td align="char" char="." valign="top">9</td></tr><tr><td align="char" char="." valign="top">3</td><td align="left" valign="top">Behavior (B)</td><td align="char" char="." valign="top">0.648</td><td align="char" char="." valign="top">16</td></tr><tr><td align="char" char="." valign="top">4</td><td align="left" valign="top">Perceived vulnerability (PV)</td><td align="char" char="." valign="top">0.654</td><td align="char" char="." valign="top">3</td></tr><tr><td align="char" char="." valign="top">5</td><td align="left" valign="top">Perceived severity (PS)</td><td align="char" char="." valign="top">0.540</td><td align="char" char="." valign="top">3</td></tr><tr><td align="char" char="." valign="top">6</td><td align="left" valign="top">Perceived self-efficacy (SE)</td><td align="char" char="." valign="top">0.655</td><td align="char" char="." valign="top">6</td></tr><tr><td align="char" char="." valign="top">6</td><td align="left" valign="top">Perceived response efficacy (RE)</td><td align="char" char="." valign="top">0.717</td><td align="char" char="." valign="top">3</td></tr><tr><td align="char" char="." valign="top">8</td><td align="left" valign="top">Perceived barriers (PB)</td><td align="char" char="." valign="top">0.476</td><td align="char" char="." valign="top">4</td></tr><tr><td align="char" char="." valign="top">9</td><td align="left" valign="top">Cues to action (CA)</td><td align="char" char="." valign="top">0.256</td><td align="char" char="." valign="top">2</td></tr><tr><td align="char" char="." valign="top">10</td><td align="left" valign="top">Password</td><td align="char" char="." valign="top">0.349</td><td align="char" char="." valign="top">6</td></tr><tr><td align="char" char="." valign="top">11</td><td align="left" valign="top">Incident</td><td align="char" char="." valign="top">0.792</td><td align="char" char="." valign="top">9</td></tr><tr><td align="char" char="." valign="top">12</td><td align="left" valign="top">Email</td><td align="char" char="." valign="top">0.554</td><td align="char" char="." valign="top">7</td></tr><tr><td align="char" char="." valign="top">13</td><td align="left" valign="top">Mobile</td><td align="char" char="." valign="top">0.65</td><td align="char" char="." valign="top">12</td></tr></tbody></table></table-wrap></sec><sec id="s3-4"><title>Phishing Click Behavior With Chi-Square Test</title><p>Phishing susceptibility was evaluated using an omnibus chi-square test of independence comparing link-click behavior across 3 groups, including control (n=34), CD-primed (n=32), and neutral nonresponders (n=753). Observed click rates were 65% (22/34) in the control group, 44% (14/32) in the CD-primed group, and 53% (396/753) in the neutral group (<xref ref-type="table" rid="table4">Table 4</xref>; <xref ref-type="fig" rid="figure4">Figure 4</xref>). The corresponding 95% CIs (Wilson method) were 0.48&#x2010;0.79, 0.28&#x2010;0.61, and 0.49&#x2010;0.56, respectively.</p><table-wrap id="t4" position="float"><label>Table 4.</label><caption><p>Observed contingency table for phishing click behavior.</p></caption><table id="table4" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Outcome</td><td align="left" valign="bottom">Control (n=34)</td><td align="left" valign="bottom">CD-Primed (n=32)</td><td align="left" valign="bottom">Neutral (n=753)</td></tr></thead><tbody><tr><td align="left" valign="top">Clicked (n)</td><td align="left" valign="top">22</td><td align="left" valign="top">14</td><td align="left" valign="top">396</td></tr><tr><td align="left" valign="top">Not clicked (n)</td><td align="left" valign="top">12</td><td align="left" valign="top">18</td><td align="left" valign="top">357</td></tr><tr><td align="left" valign="top">Total (n)</td><td align="left" valign="top">34</td><td align="left" valign="top">32</td><td align="left" valign="top">753</td></tr></tbody></table></table-wrap><p>The omnibus chi-square test did not detect a statistically significant association between group membership and click behavior, (<italic>&#x03C7;</italic>&#x00B2;<sub>2</sub>=3.00; n=819=; <italic>P</italic>=.22). The effect size was small (Cram&#x00E9;r V=0.060; approximately 95% CI 0.00&#x2010;0.12), indicating that differences in click behavior across groups were modest and consistent with sampling variability.</p><p>To contextualize the observed pattern within the randomized subset, exploratory descriptive comparisons were computed between the CD-primed and control groups. The CD-primed group exhibited a lower observed click rate than the control group (44% vs 65%), corresponding to an absolute risk difference of &#x2212;0.21 (95% CI &#x2212;0.45 to 0.03), a relative risk of 0.68 (95% CI 0.42&#x2010;1.08), and an odds ratio of 0.42 (95% CI 0.16-1.14). These estimates are imprecise due to small group sizes and are reported descriptively without confirmatory inference.</p><p>Because the Neutral group was not randomized and consists of nonresponders, comparisons involving the Neutral group are observational and may reflect selection bias or baseline differences rather than intervention effects. Overall, the behavioral results indicate, at most, a directional but statistically nonsignificant association between CD exposure and immediate phishing click behavior under real-world conditions.</p><p>A post hoc power assessment based on the observed effect size (W=0.060) indicated limited sensitivity to detect effects of this magnitude (power &#x2248;0.32) and is reported descriptively only.</p></sec><sec id="s3-5"><title>Assumption Checks</title><p>Normality of the dependent variables was assessed using the Shapiro-Wilk test [<xref ref-type="bibr" rid="ref57">57</xref>]. As shown in <xref ref-type="table" rid="table5">Table 5</xref>, several variables deviated from normality, which informed the selection of robust and nonparametric analytical approaches.</p><table-wrap id="t5" position="float"><label>Table 5.</label><caption><p>Normality test (Shapiro-Wilk).</p></caption><table id="table5" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Construct</td><td align="left" valign="bottom">-Shapiro-Wilk statistic, W (df)</td><td align="left" valign="bottom"><italic>P</italic> value</td></tr></thead><tbody><tr><td align="left" valign="top">Actual behavior (AB)</td><td align="left" valign="top">0.627 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Knowledge (K)</td><td align="left" valign="top">0.969 (62)</td><td align="left" valign="top">.11</td></tr><tr><td align="left" valign="top">Attitude (A)</td><td align="left" valign="top">0.954 (62)</td><td align="left" valign="top">.02</td></tr><tr><td align="left" valign="top">Intended behavior (IB)</td><td align="left" valign="top">0.968 (62)</td><td align="left" valign="top">.11</td></tr><tr><td align="left" valign="top">Perceived vulnerability (PV)</td><td align="left" valign="top">0.917 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Perceived severity (PS)</td><td align="left" valign="top">0.884 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Perceived self-efficacy (SE)</td><td align="left" valign="top">0.981 (62)</td><td align="left" valign="top">.43</td></tr><tr><td align="left" valign="top">Perceived response efficacy (RE)</td><td align="left" valign="top">0.814 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Perceived barriers (PB)</td><td align="left" valign="top">0.966 (62)</td><td align="left" valign="top">.08</td></tr><tr><td align="left" valign="top">Cues to action (CA)</td><td align="left" valign="top">0.828 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Password</td><td align="left" valign="top">0.951 (62)</td><td align="left" valign="top">.01</td></tr><tr><td align="left" valign="top">Incident</td><td align="left" valign="top">0.960 (62)</td><td align="left" valign="top">.04</td></tr><tr><td align="left" valign="top">Email</td><td align="left" valign="top">0.887 (62)</td><td align="left" valign="top">&#x003C;.001</td></tr><tr><td align="left" valign="top">Mobile</td><td align="left" valign="top">0.931 (62)</td><td align="left" valign="top">.002</td></tr></tbody></table></table-wrap></sec><sec id="s3-6"><title>Exploratory Multivariate Analyses</title><p>Subsequently, a one-way MANOVA was performed to examine whether group membership was associated with differences in the combined set of dependent variables, including mobile device and SMS use and incident reporting, as shown in <xref ref-type="table" rid="table6">Table 6</xref>. Statistical significance was evaluated at an ɑ level of .05.</p><table-wrap id="t6" position="float"><label>Table 6.</label><caption><p>Correlation (n=62).</p></caption><table id="table6" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Variable</td><td align="left" valign="bottom">AB<sup><xref ref-type="table-fn" rid="table6fn1">a</xref></sup></td><td align="left" valign="bottom">Knowledge</td><td align="left" valign="bottom">Attitude</td><td align="left" valign="bottom">IB<sup><xref ref-type="table-fn" rid="table6fn2">b</xref></sup></td><td align="left" valign="bottom">PV<sup><xref ref-type="table-fn" rid="table6fn3">c</xref></sup></td><td align="left" valign="bottom">PS<sup><xref ref-type="table-fn" rid="table6fn4">d</xref></sup></td><td align="left" valign="bottom">SE<sup><xref ref-type="table-fn" rid="table6fn5">e</xref></sup></td><td align="left" valign="bottom">RE<sup><xref ref-type="table-fn" rid="table6fn6">f</xref></sup></td><td align="left" valign="bottom">PB<sup><xref ref-type="table-fn" rid="table6fn7">g</xref></sup></td><td align="left" valign="bottom">CA<sup><xref ref-type="table-fn" rid="table6fn8">h</xref></sup></td><td align="left" valign="bottom">Password</td><td align="left" valign="bottom">IR</td><td align="left" valign="bottom">Email use</td><td align="left" valign="bottom">Mobile</td></tr></thead><tbody><tr><td align="left" valign="top">AB</td><td align="left" valign="top">&#x2014;<sup><xref ref-type="table-fn" rid="table6fn9">i</xref></sup></td><td align="left" valign="top">&#x2013;0.371<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.021</td><td align="char" char="." valign="top">&#x2013;0.050</td><td align="char" char="." valign="top">0.010</td><td align="char" char="." valign="top">0.227</td><td align="char" char="." valign="top">0.090</td><td align="char" char="." valign="top">&#x2013;0.090</td><td align="char" char="." valign="top">0.113</td><td align="char" char="." valign="top">0.041</td><td align="char" char="." valign="top">0.041</td><td align="char" char="." valign="top">&#x2013;0.175</td><td align="char" char="." valign="top">&#x2013;0.027</td><td align="char" char="." valign="top">&#x2013;0.208</td></tr><tr><td align="left" valign="top">Knowledge</td><td align="left" valign="top">&#x2013;0.371<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.500<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.515<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.133</td><td align="char" char="." valign="top">&#x2013;0.159</td><td align="left" valign="top">0.440<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.336<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2013;0.328<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.149</td><td align="left" valign="top">0.390<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.495<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.538<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.683<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">Attitude</td><td align="char" char="." valign="top">&#x2013;0.021</td><td align="left" valign="top">0.500<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.468<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.261<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.213</td><td align="char" char="." valign="top">0.067</td><td align="left" valign="top">0.257<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.209</td><td align="char" char="." valign="top">0.074</td><td align="left" valign="top">0.394<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.658<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.402<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.382<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">IB</td><td align="char" char="." valign="top">&#x2013;0.050</td><td align="left" valign="top">0.515<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.468<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.293<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.297<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.432<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.407<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2013;0.401<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.337<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.642<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.637<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.655<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.479<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">PV</td><td align="char" char="." valign="top">0.010</td><td align="char" char="." valign="top">0.133</td><td align="left" valign="top">0.261<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">0.293<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.383<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.030</td><td align="left" valign="top">0.319<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.147</td><td align="char" char="." valign="top">0.126</td><td align="char" char="." valign="top">0.217</td><td align="left" valign="top">0.291<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.076</td><td align="char" char="." valign="top">0.050</td></tr><tr><td align="left" valign="top">PS</td><td align="char" char="." valign="top">0.227</td><td align="char" char="." valign="top">&#x2212;0.159</td><td align="char" char="." valign="top">0.213</td><td align="left" valign="top">0.297<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.383<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="char" char="." valign="top">0.062</td><td align="char" char="." valign="top">0.148</td><td align="char" char="." valign="top">&#x2013;0.128</td><td align="char" char="." valign="top">0.173</td><td align="left" valign="top">0.243<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">0.272<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.150</td><td align="char" char="." valign="top">&#x2013;0.019</td></tr><tr><td align="left" valign="top">SE</td><td align="char" char="." valign="top">0.090</td><td align="left" valign="top">0.440<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.067</td><td align="left" valign="top">0.432<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.030</td><td align="char" char="." valign="top">0.062</td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.366<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2013;0.323<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.537<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.158</td><td align="char" char="." valign="top">0.156</td><td align="left" valign="top">0.431<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.505<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">RE</td><td align="char" char="." valign="top">&#x2013;0.090</td><td align="left" valign="top">0.336<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.257<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">0.407<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.319<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.148</td><td align="left" valign="top">0.366<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="char" char="." valign="top">&#x2013;0.108</td><td align="char" char="." valign="top">0.146</td><td align="char" char="." valign="top">0.172</td><td align="left" valign="top">0.232<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">0.356<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.350<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">PB</td><td align="char" char="." valign="top">0.113</td><td align="left" valign="top">&#x2013;0.328<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.209</td><td align="left" valign="top">&#x2013;0.401<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.147</td><td align="char" char="." valign="top">&#x2013;0.128</td><td align="left" valign="top">&#x2013;0.323<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">&#x2013;0.108</td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">&#x2013;0.336<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2013;0.264<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">&#x2013;0.330<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.236<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.148</td></tr><tr><td align="left" valign="top">CA</td><td align="char" char="." valign="top">0.041</td><td align="char" char="." valign="top">0.149</td><td align="char" char="." valign="top">0.074</td><td align="left" valign="top">0.337<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.126</td><td align="char" char="." valign="top">0.173</td><td align="left" valign="top">0.537<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.146</td><td align="left" valign="top">&#x2013;0.336<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="char" char="." valign="top">0.133</td><td align="char" char="." valign="top">0.182</td><td align="char" char="." valign="top">0.204</td><td align="left" valign="top">0.362<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">Password</td><td align="char" char="." valign="top">0.041</td><td align="left" valign="top">0.390<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.394<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.642<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.217</td><td align="left" valign="top">0.243<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.158</td><td align="char" char="." valign="top">0.172</td><td align="left" valign="top">&#x2013;0.264<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.133</td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.383<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.353<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.210</td></tr><tr><td align="left" valign="top">IR</td><td align="char" char="." valign="top">&#x2013;0.175</td><td align="left" valign="top">0.495<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.658<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.637<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.291<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.272<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.156</td><td align="left" valign="top">0.232<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="left" valign="top">&#x2013;0.330<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.182</td><td align="left" valign="top">0.383<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.335<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.133</td></tr><tr><td align="left" valign="top">Email use</td><td align="char" char="." valign="top">&#x2013;0.027</td><td align="left" valign="top">0.538<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.402<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.655<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.076</td><td align="char" char="." valign="top">0.150</td><td align="left" valign="top">0.431<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.356<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.236<sup><xref ref-type="table-fn" rid="table6fn11">k</xref></sup></td><td align="char" char="." valign="top">0.204</td><td align="left" valign="top">0.353<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.335<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td><td align="left" valign="top">0.463<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td></tr><tr><td align="left" valign="top">Mobile</td><td align="char" char="." valign="top">&#x2013;0.208</td><td align="left" valign="top">0.683<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.382<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.479<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.050</td><td align="char" char="." valign="top">&#x2013;0.019</td><td align="left" valign="top">0.505<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">0.350<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.148</td><td align="left" valign="top">0.362<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="char" char="." valign="top">0.210</td><td align="char" char="." valign="top">0.133</td><td align="left" valign="top">0.463<sup><xref ref-type="table-fn" rid="table6fn10">j</xref></sup></td><td align="left" valign="top">&#x2014;</td></tr></tbody></table><table-wrap-foot><fn id="table6fn1"><p><sup>a</sup>AB: actual behavior.</p></fn><fn id="table6fn2"><p><sup>b</sup>IB: intended behavior.</p></fn><fn id="table6fn3"><p><sup>c</sup>PV: perceived vulnerability.</p></fn><fn id="table6fn4"><p><sup>d</sup>PS: perceived severity.</p></fn><fn id="table6fn5"><p><sup>e</sup>SE: self-efficacy.</p></fn><fn id="table6fn6"><p><sup>f</sup>RE: response efficacy.</p></fn><fn id="table6fn7"><p><sup>g</sup>PB: perceived barrier.</p></fn><fn id="table6fn8"><p><sup>h</sup>CA: cues to action.</p></fn><fn id="table6fn9"><p><sup>i</sup>Not available.</p></fn><fn id="table6fn10"><p><sup>j</sup>Correlation is significant at the 0.01 level (2-tailed).</p></fn><fn id="table6fn11"><p><sup>k</sup>Correlation is significant at the 0.05 level (2-tailed).</p></fn></table-wrap-foot></table-wrap><p>Given the inclusion of constructs with low internal consistency, MANOVA is interpreted strictly as a descriptive screening of group differentiation rather than as inferential evidence of multivariate effects. A multivariate effect was observed in the MANOVA. Pillai&#x2019;s Trace was used for the omnibus multivariate test. The analysis yielded a Pillai&#x2019;s Trace of 0.442, <italic>F</italic><sub>14, 47</sub>=2.660; <italic>P</italic>=.006, indicating overall group differences across the combined set of dependent variables. Given the heterogeneous reliability of the included constructs and the limited survey sample size, this result is interpreted as an omnibus, exploratory indication of group differentiation rather than evidence of specific construct-level effects.</p><p>The estimated multivariate effect size suggests that approximately 44.2% of the variance in the linear combination of dependent variables was associated with group membership. Assumptions for follow-up univariate analyses were assessed using Levene test across all 14 dependent variables [<xref ref-type="bibr" rid="ref58">58</xref>]. Although AB and CA showed statistically significant Levene results (<italic>P</italic>&#x003C;.05), inspection of group standard deviations (<xref ref-type="table" rid="table2">Table 2</xref>) revealed no substantial imbalance in variance, supporting the robustness of subsequent ANOVA analyses. The CA exhibited very low internal consistency (Cronbach <italic>&#x03B1;</italic>=0.256) and were therefore retained solely as an exploratory indicator, without supporting confirmatory inference.</p><p>Follow-up one-way ANOVA tests indicated statistically significant group differences for AB, PS, and CA (<xref ref-type="table" rid="table7">Table 7</xref>). Findings for constructs with acceptable reliability are interpreted with greater confidence, whereas results involving CA, PBs, and password practices are treated as exploratory, with emphasis placed on effect sizes rather than <italic>P</italic> values. In particular, although statistical differences were observed for CA, this finding is interpreted cautiously due to very low internal consistency and is reported only as an exploratory pattern rather than a substantive effect.</p><table-wrap id="t7" position="float"><label>Table 7.</label><caption><p>ANOVA results.</p></caption><table id="table7" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">*Construct*</td><td align="left" valign="bottom">Sum of Squares</td><td align="left" valign="bottom">df</td><td align="left" valign="bottom">Mean Square</td><td align="left" valign="bottom">F</td><td align="left" valign="bottom"><italic>P</italic> value</td><td align="left" valign="bottom">Partial eta squared</td><td align="left" valign="bottom">Noncentrality<break/>parameter</td><td align="left" valign="bottom">Observed power</td></tr></thead><tbody><tr><td align="left" valign="top">Actual behavior (AB)</td><td align="left" valign="top">21.682</td><td align="left" valign="top">1</td><td align="left" valign="top">21.682</td><td align="left" valign="top">5.917</td><td align="left" valign="top">.02</td><td align="left" valign="top">0.090</td><td align="left" valign="top">5.917</td><td align="left" valign="top">0.668</td></tr><tr><td align="left" valign="top">Knowledge (K)</td><td align="left" valign="top">0.003</td><td align="left" valign="top">1</td><td align="left" valign="top">0.003</td><td align="left" valign="top">0.013</td><td align="left" valign="top">.91</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.013</td><td align="left" valign="top">0.051</td></tr><tr><td align="left" valign="top">Attitude (A)</td><td align="left" valign="top">0.452</td><td align="left" valign="top">1</td><td align="left" valign="top">0.452</td><td align="left" valign="top">2.186</td><td align="left" valign="top">.14</td><td align="left" valign="top">0.035</td><td align="left" valign="top">2.186</td><td align="left" valign="top">0.307</td></tr><tr><td align="left" valign="top">Intended behavior (IB)</td><td align="left" valign="top">0.572</td><td align="left" valign="top">1</td><td align="left" valign="top">0.572</td><td align="left" valign="top">3.223</td><td align="left" valign="top">.08</td><td align="left" valign="top">0.051</td><td align="left" valign="top">3.223</td><td align="left" valign="top">0.423</td></tr><tr><td align="left" valign="top">Perceived vulnerability (PV)</td><td align="left" valign="top">0.853</td><td align="left" valign="top">1</td><td align="left" valign="top">0.853</td><td align="left" valign="top">1.340</td><td align="left" valign="top">.25</td><td align="left" valign="top">0.022</td><td align="left" valign="top">1.340</td><td align="left" valign="top">0.207</td></tr><tr><td align="left" valign="top">Perceived severity (PS)</td><td align="left" valign="top">6.753</td><td align="left" valign="top">1</td><td align="left" valign="top">6.753</td><td align="left" valign="top">17.020</td><td align="left" valign="top">&#x003C;.001</td><td align="left" valign="top">0.221</td><td align="left" valign="top">17.020</td><td align="left" valign="top">0.982</td></tr><tr><td align="left" valign="top">Perceived self-efficacy (SE)</td><td align="left" valign="top">1.365</td><td align="left" valign="top">1</td><td align="left" valign="top">1.365</td><td align="left" valign="top">3.116</td><td align="left" valign="top">.08</td><td align="left" valign="top">0.049</td><td align="left" valign="top">3.116</td><td align="left" valign="top">0.412</td></tr><tr><td align="left" valign="top">Perceived response efficacy (RE)</td><td align="left" valign="top">0.001</td><td align="left" valign="top">1</td><td align="left" valign="top">0.001</td><td align="left" valign="top">0.003</td><td align="left" valign="top">.96</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.003</td><td align="left" valign="top">0.050</td></tr><tr><td align="left" valign="top">Perceived barrier (PB)</td><td align="left" valign="top">0.003</td><td align="left" valign="top">1</td><td align="left" valign="top">0.003</td><td align="left" valign="top">0.005</td><td align="left" valign="top">.94</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.005</td><td align="left" valign="top">0.051</td></tr><tr><td align="left" valign="top">Perceived cues to action (CA)</td><td align="left" valign="top">2.950</td><td align="left" valign="top">1</td><td align="left" valign="top">2.950</td><td align="left" valign="top">6.574</td><td align="left" valign="top">.01</td><td align="left" valign="top">0.099</td><td align="left" valign="top">6.574</td><td align="left" valign="top">0.713</td></tr><tr><td align="left" valign="top">Password</td><td align="left" valign="top">0.325</td><td align="left" valign="top">1</td><td align="left" valign="top">0.325</td><td align="left" valign="top">1.110</td><td align="left" valign="top">.30</td><td align="left" valign="top">0.018</td><td align="left" valign="top">1.110</td><td align="left" valign="top">0.179</td></tr><tr><td align="left" valign="top">Incident</td><td align="left" valign="top">1.652</td><td align="left" valign="top">1</td><td align="left" valign="top">1.652</td><td align="left" valign="top">3.028</td><td align="left" valign="top">.09</td><td align="left" valign="top">0.048</td><td align="left" valign="top">3.028</td><td align="left" valign="top">0.402</td></tr><tr><td align="left" valign="top">Email</td><td align="left" valign="top">0.183</td><td align="left" valign="top">1</td><td align="left" valign="top">0.183</td><td align="left" valign="top">0.792</td><td align="left" valign="top">.38</td><td align="left" valign="top">0.013</td><td align="left" valign="top">0.792</td><td align="left" valign="top">0.141</td></tr><tr><td align="left" valign="top">Mobile</td><td align="left" valign="top">0.000</td><td align="left" valign="top">1</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.000</td><td align="left" valign="top">.99</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.000</td><td align="left" valign="top">0.050</td></tr></tbody></table></table-wrap><p>Post-hoc power analysis indicated that the survey-based MANOVA and ANOVA models achieved approximately 40% power to detect medium-sized effects, confirming that these analyses were underpowered. Consequently, survey-based multivariate and univariate results are interpreted as exploratory. In contrast, the behavioral click-rate analysis, based on the full sample, was sufficiently powered.</p></sec></sec><sec id="s4" sec-type="discussion"><title>Discussion</title><sec id="s4-1"><title>Principal Findings</title><p>Despite substantial investment in technical email filtering and security awareness training, health care staff continue to demonstrate high susceptibility to socially engineered emails under real operational conditions [<xref ref-type="bibr" rid="ref11">11</xref>]. Evidence from field-based phishing simulations suggests that many existing interventions show limited or inconsistent effectiveness when evaluated using objective behavioral outcomes rather than self-reported intentions [<xref ref-type="bibr" rid="ref52">52</xref>,<xref ref-type="bibr" rid="ref53">53</xref>]. This limitation has prompted increasing interest in behavioral and psychologically grounded approaches that aim to influence decision-making at the moment of threat exposure, particularly those capable of producing measurable short-term changes in actual user behavior.</p><p>In light of this gap, the present study examined whether a brief CD-based priming intervention, delivered immediately prior to a real-world phishing simulation, was associated with differences in phishing-related outcomes among health care staff. The analytical framework comprised one confirmatory behavioral hypothesis and 2 exploratory research questions. The primary and confirmatory hypothesis (hypothesis 1) evaluated whether exposure to the CD prompt was associated with reduced observed phishing susceptibility, operationalized as objective link-click behavior during an in-the-wild phishing simulation. This behavioral outcome served as the study&#x2019;s primary endpoint and was assessed using an omnibus analysis across all staff. Two exploratory research questions (RQ1 and RQ2) examined whether CD exposure was associated with directional differences in theory-driven security perception constructs derived from the HBM and PMT, as well as with self-reported security practices related to password management, incident reporting, email handling, and mobile-device security.</p><p>Given the limited sample size and variable construct reliability, the findings for RQ1 and RQ2 are interpreted as exploratory and hypothesis-generating rather than confirmatory. Accordingly, the discussion first addresses the confirmatory behavioral findings (hypothesis 1), followed by a cautious interpretation of exploratory construct-level and self-reported outcomes.</p></sec><sec id="s4-2"><title>Primary Study Finding (Hypothesis 1): Confirmatory Behavioral Outcome</title><p>The primary outcome of this study was objective phishing click behavior observed during an in-the-wild simulation [<xref ref-type="bibr" rid="ref29">29</xref>,<xref ref-type="bibr" rid="ref59">59</xref>,<xref ref-type="bibr" rid="ref60">60</xref>]. Although the CD-primed group exhibited a lower observed click-through rate than the control group (44% vs 65%), the prespecified omnibus chi-square test did not detect a statistically significant association between group membership and click behavior. The estimated effect size was small, and CIs were wide, reflecting limited precision due to the modest size of the randomized experimental groups.</p><p>Accordingly, the findings do not provide confirmatory statistical support for hypothesis 1. Rather, they indicate a directional, but statistically nonsignificant, association between brief CD-based priming and immediate phishing-click behavior under real-world conditions. This cautious interpretation is warranted because only a subset of participants was randomized to receive the CD prompt, while the neutral group comprised nonresponders and was not assigned to any experimental condition. As such, causal inference is limited to comparisons within the randomized subset, whereas comparisons involving the neutral group are observational and may reflect baseline or selection differences.</p><p>When situated within the broader cybersecurity and health informatics literature, the modest magnitude of the observed effect is consistent with prior studies examining behavioral phishing outcomes, which frequently report small and heterogeneous effects following brief or one-time interventions (eg, [<xref ref-type="bibr" rid="ref61">61</xref>-<xref ref-type="bibr" rid="ref63">63</xref>]). These findings contrast with studies reporting stronger effects from sustained educational or motivational interventions, which typically target knowledge, risk appraisal, or SE rather than rapid, heuristic-driven decision-making.</p><p>This distinction highlights the inherent difficulty of influencing immediate phishing behavior using brief psychological cues alone. From an applied perspective, the present results suggest that CD-based prompts may function as a situational nudge, introducing momentary cognitive friction prior to exposure, rather than as a standalone behavioral control. Their potential value, therefore, lies in complementing existing phishing simulations, awareness training, and technical safeguards within a layered defense strategy.</p><p>A notable pattern in the findings is the disconnect between observed phishing behavior and self-reported security perceptions. Although phishing susceptibility was measured using an objective behavioral outcome (link-clicking), effect estimates were imprecise because the randomized comparison groups were small. At the same time, several survey-based constructs showed low internal consistency, limiting confidence in construct-level interpretation. Together, these results are consistent with prior evidence that self-reported security perceptions and intentions do not reliably predict real-world phishing behavior, particularly in high-pressure health care settings.</p></sec><sec id="s4-3"><title>Construct-Level Findings With Limited Power: Exploratory Evidence (RQ1-RQ2)</title><p>In contrast to the confirmatory behavioral outcome (hypothesis 1), analyses addressing the exploratory research questions (RQ1-RQ2) focused on self-reported psychological perceptions and security practices and are interpreted as hypothesis-generating rather than confirmatory. Although the multivariate analysis indicated an overall group effect (Pillai Trace=0.442; <italic>F</italic><sub>14,47</sub>=2.66; <italic>P</italic>=.006), this result was derived from a substantially smaller survey subsample (control n=30; CD-primed n=32) and involved multiple dependent variables, thereby limiting statistical sensitivity for reliable construct-level inference.</p><p>Follow-up univariate analyses revealed nonsignificant or marginal effects for most perception and practice constructs, including PV, SE, RE, incident-reporting intentions, password management, email handling, mobile device security practices, and self-reported knowledge, attitudes, and intended behavior (<italic>P</italic>=.08-.30). Several constructs, most notably CA, PBs, and password practices, also exhibited low internal consistency, further constraining interpretability and precluding confirmatory conclusions.</p><p>While some variables displayed directional or near-significant trends, these patterns do not provide evidence of causal mechanisms nor establish that the CD prompt directly influenced underlying psychological processes [<xref ref-type="bibr" rid="ref64">64</xref>,<xref ref-type="bibr" rid="ref65">65</xref>]. Rather, the observed divergence between modest behavioral effects and weak or inconsistent construct-level changes is consistent with prior health care and organizational security research documenting limited correspondence between self-reported perceptions or intentions and objectively observed security behavior [<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref18">18</xref>]. Accordingly, the construct-level findings are best viewed as exploratory signals that motivate future research by using larger and more balanced samples, improved psychometric validation, and analytical designs capable of formally testing mediation or mechanism-based pathways.</p></sec><sec id="s4-4"><title>Contextual Factors, Baseline Susceptibility, Implications of the Study</title><p>Across all study groups, phishing susceptibility remained high, with observed click rates exceeding 50%. This pattern reinforces prior evidence that health care organizations are particularly vulnerable to social engineering attacks, even in settings with established technical defenses, policies, and awareness programs [<xref ref-type="bibr" rid="ref6">6</xref>,<xref ref-type="bibr" rid="ref66">66</xref>]. The phishing message deployed in this study leveraged a contemporaneous geopolitical crisis, a strategy commonly observed in real-world phishing campaigns to heighten emotional salience, urgency, and perceived legitimacy [<xref ref-type="bibr" rid="ref55">55</xref>]. While this design choice enhances ecological validity, it also underscores the context-dependent nature of phishing susceptibility and limits direct generalization beyond comparable threat scenarios.</p><p>From an applied perspective, the findings suggest that brief, lightweight psychological prompts may complement existing security awareness and simulation programs by influencing immediate decision-making at the point of exposure. Importantly, the evidence supports this implication only for short-term, observed behavioral responses. The present study does not establish the durability of the observed effects, their transferability across organizational contexts or attack types, or the specific psychological mechanisms through which CD prompting may operate. These limitations highlight the need for longitudinal and replication studies before such interventions can be considered as standalone or broadly generalizable mitigation strategies.</p></sec><sec id="s4-5"><title>Conclusion</title><p>This study examined whether a brief CD-based priming intervention, delivered immediately prior to a real-world phishing simulation, was associated with differences in phishing susceptibility among health care staff. The primary behavioral analysis indicated a directional but statistically nonsignificant association, with lower observed click rates in the CD-primed group; however, effect estimates were small and imprecise due to limited randomized group sizes. Accordingly, causal inference is restricted to the randomized comparison, while differences involving the neutral group are observational.</p><p>Survey-based analyses of security perceptions and self-reported practices were conducted on a smaller subsample, and several constructs exhibited low internal consistency. These findings are therefore considered exploratory and do not support conclusions about psychological mechanisms. Overall, the results suggest that CD-based prompts may function as a lightweight, short-term behavioral nudge under real-world conditions but do not establish a reliable effect.</p><p>Larger, fully randomized, and longitudinal studies with improved psychometric validation are needed before such interventions can be considered reliable complements to established cybersecurity controls.</p></sec></sec></body><back><ack><p>No generative AI was used.</p></ack><notes><sec><title>Funding</title><p>No funding source to declare.</p></sec></notes><fn-group><fn fn-type="conflict"><p>None declared.</p></fn></fn-group><glossary><title>Abbreviations</title><def-list><def-item><term id="abb1">AB</term><def><p>actual behavior</p></def></def-item><def-item><term id="abb2">CA</term><def><p>cues to action</p></def></def-item><def-item><term id="abb3">CD</term><def><p>cognitive dissonance</p></def></def-item><def-item><term id="abb4">CONSORT</term><def><p>Consolidated Standards of Reporting Trials</p></def></def-item><def-item><term id="abb5">HBM</term><def><p>Health Belief Model</p></def></def-item><def-item><term id="abb6">KAB</term><def><p>knowledge, attitude, and behavior</p></def></def-item><def-item><term id="abb7">MANOVA </term><def><p>multivariate analysis of variance</p></def></def-item><def-item><term id="abb8">NSD</term><def><p>Norwegian Center for Research Data</p></def></def-item><def-item><term id="abb9">PB</term><def><p>perceived barrier</p></def></def-item><def-item><term id="abb10">PMT</term><def><p>Protection Motivation Theory</p></def></def-item><def-item><term id="abb11">PS</term><def><p>perceived severity</p></def></def-item><def-item><term id="abb12">PV</term><def><p>perceived vulnerability</p></def></def-item><def-item><term id="abb13">RE</term><def><p>response efficacy</p></def></def-item><def-item><term id="abb14">REK</term><def><p>Regional Committees for Medical and Health Research Ethics of Norway</p></def></def-item><def-item><term id="abb15">RQ</term><def><p>research question</p></def></def-item><def-item><term id="abb16">SE</term><def><p>self-efficacy</p></def></def-item><def-item><term id="abb17">STROBE</term><def><p>Strengthening the Reporting of Observational Studies in Epidemiology</p></def></def-item></def-list></glossary><ref-list><title>References</title><ref id="ref1"><label>1</label><nlm-citation citation-type="web"><article-title>The state of healthcare cybersecurity 2025</article-title><source>Veriti</source><access-date>2026-04-15</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://veriti.ai/wp-content/uploads/2024/12/The-State-of-Healthcare-Cybersecurity-2025-_-A-Veriti-Research-Report.pdf">https://veriti.ai/wp-content/uploads/2024/12/The-State-of-Healthcare-Cybersecurity-2025-_-A-Veriti-Research-Report.pdf</ext-link></comment></nlm-citation></ref><ref id="ref2"><label>2</label><nlm-citation citation-type="web"><article-title>Cost of a data breach: the healthcare industry</article-title><source>IBM</source><access-date>2025-12-10</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry">https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry</ext-link></comment></nlm-citation></ref><ref id="ref3"><label>3</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Keller</surname><given-names>T</given-names> </name><name name-style="western"><surname>Warwas</surname><given-names>JI</given-names> </name><name name-style="western"><surname>Klein</surname><given-names>J</given-names> </name><name name-style="western"><surname>Henkenjohann</surname><given-names>R</given-names> </name><name name-style="western"><surname>Trenz</surname><given-names>M</given-names> </name><name name-style="western"><surname>Trang</surname><given-names>STN</given-names> </name></person-group><article-title>Motivational framing strategies in health care information security training: randomized controlled trial</article-title><source>JMIR Med Educ</source><year>2025</year><month>11</month><day>7</day><volume>11</volume><issue>1</issue><fpage>e73245</fpage><pub-id pub-id-type="doi">10.2196/73245</pub-id><pub-id pub-id-type="medline">41202283</pub-id></nlm-citation></ref><ref id="ref4"><label>4</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Yeng</surname><given-names>PK</given-names> </name><name name-style="western"><surname>Fauzi</surname><given-names>MA</given-names> </name><name name-style="western"><surname>Yang</surname><given-names>B</given-names> </name><name name-style="western"><surname>Nimbe</surname><given-names>P</given-names> </name></person-group><article-title>Investigation into phishing risk behaviour among healthcare staff</article-title><source>Information</source><year>2022</year><month>08</month><volume>13</volume><issue>8</issue><fpage>392</fpage><pub-id pub-id-type="doi">10.3390/info13080392</pub-id></nlm-citation></ref><ref id="ref5"><label>5</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Abdelhamid</surname><given-names>M</given-names> </name></person-group><article-title>The role of health concerns in phishing susceptibility: survey design study</article-title><source>J Med Internet Res</source><year>2020</year><month>05</month><day>4</day><volume>22</volume><issue>5</issue><fpage>e18394</fpage><pub-id pub-id-type="doi">10.2196/18394</pub-id><pub-id pub-id-type="medline">32364511</pub-id></nlm-citation></ref><ref id="ref6"><label>6</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Jalali</surname><given-names>MS</given-names> </name><name name-style="western"><surname>Bruckes</surname><given-names>M</given-names> </name><name name-style="western"><surname>Westmattelmann</surname><given-names>D</given-names> </name><name name-style="western"><surname>Schewe</surname><given-names>G</given-names> </name></person-group><article-title>Why employees (still) click on phishing links: investigation in hospitals</article-title><source>J Med Internet Res</source><year>2020</year><month>01</month><day>23</day><volume>22</volume><issue>1</issue><fpage>e16775</fpage><pub-id pub-id-type="doi">10.2196/16775</pub-id><pub-id pub-id-type="medline">32012071</pub-id></nlm-citation></ref><ref id="ref7"><label>7</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Donalds</surname><given-names>C</given-names> </name><name name-style="western"><surname>Osei-Bryson</surname><given-names>KM</given-names> </name></person-group><article-title>Cybersecurity compliance behavior: exploring the influences of individual decision style and other antecedents</article-title><source>Int J Inf Manage</source><year>2020</year><month>04</month><volume>51</volume><fpage>102056</fpage><pub-id pub-id-type="doi">10.1016/j.ijinfomgt.2019.102056</pub-id></nlm-citation></ref><ref id="ref8"><label>8</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ewoh</surname><given-names>P</given-names> </name><name name-style="western"><surname>Vartiainen</surname><given-names>T</given-names> </name></person-group><article-title>Vulnerability to cyberattacks and sociotechnical solutions for health care systems: systematic review</article-title><source>J Med Internet Res</source><year>2024</year><month>05</month><day>31</day><volume>26</volume><issue>1</issue><fpage>e46904</fpage><pub-id pub-id-type="doi">10.2196/46904</pub-id><pub-id pub-id-type="medline">38820579</pub-id></nlm-citation></ref><ref id="ref9"><label>9</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ewoh</surname><given-names>P</given-names> </name><name name-style="western"><surname>Vartiainen</surname><given-names>T</given-names> </name><name name-style="western"><surname>Mantere</surname><given-names>T</given-names> </name></person-group><article-title>Sociotechnical cybersecurity framework for securing health care from vulnerabilities and cyberattacks: scoping review</article-title><source>J Med Internet Res</source><year>2025</year><month>10</month><day>15</day><volume>27</volume><issue>1</issue><fpage>e75584</fpage><pub-id pub-id-type="doi">10.2196/75584</pub-id><pub-id pub-id-type="medline">40838797</pub-id></nlm-citation></ref><ref id="ref10"><label>10</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Yeng</surname><given-names>PK</given-names> </name><name name-style="western"><surname>Szekeres</surname><given-names>A</given-names> </name><name name-style="western"><surname>Yang</surname><given-names>B</given-names> </name><name name-style="western"><surname>Snekkenes</surname><given-names>EA</given-names> </name></person-group><article-title>Mapping the psychosocialcultural aspects of healthcare professionals&#x2019; information security practices: systematic mapping study</article-title><source>JMIR Hum Factors</source><year>2021</year><month>06</month><day>9</day><volume>8</volume><issue>2</issue><fpage>e17604</fpage><pub-id pub-id-type="doi">10.2196/17604</pub-id><pub-id pub-id-type="medline">34106077</pub-id></nlm-citation></ref><ref id="ref11"><label>11</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Rizzoni</surname><given-names>F</given-names> </name><name name-style="western"><surname>Magalini</surname><given-names>S</given-names> </name><name name-style="western"><surname>Casaroli</surname><given-names>A</given-names> </name><name name-style="western"><surname>Mari</surname><given-names>P</given-names> </name><name name-style="western"><surname>Dixon</surname><given-names>M</given-names> </name><name name-style="western"><surname>Coventry</surname><given-names>L</given-names> </name></person-group><article-title>Phishing simulation exercise in a large hospital: a case study</article-title><source>Digit Health</source><year>2022</year><volume>8</volume><fpage>20552076221081716</fpage><pub-id pub-id-type="doi">10.1177/20552076221081716</pub-id><pub-id pub-id-type="medline">35321019</pub-id></nlm-citation></ref><ref id="ref12"><label>12</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Mou</surname><given-names>J</given-names> </name><name name-style="western"><surname>Cohen</surname><given-names>J</given-names> </name><name name-style="western"><surname>Bhattacherjee</surname><given-names>A</given-names> </name><etal/></person-group><article-title>A test of protection motivation theory in the information security literature: a meta-analytic structural equation modeling approach in search advertising</article-title><source>J Assoc Inf Syst</source><year>2022</year><month>01</month><volume>23</volume><issue>1</issue><fpage>196</fpage><lpage>236</lpage><pub-id pub-id-type="doi">10.17705/1jais.00723</pub-id></nlm-citation></ref><ref id="ref13"><label>13</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Herath</surname><given-names>T</given-names> </name><name name-style="western"><surname>Rao</surname><given-names>HR</given-names> </name></person-group><article-title>Encouraging information security behaviors in organizations: role of penalties, pressures and perceived effectiveness</article-title><source>Decis Support Syst</source><year>2009</year><month>05</month><volume>47</volume><issue>2</issue><fpage>154</fpage><lpage>165</lpage><pub-id pub-id-type="doi">10.1016/j.dss.2009.02.005</pub-id></nlm-citation></ref><ref id="ref14"><label>14</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Gordon</surname><given-names>WJ</given-names> </name><name name-style="western"><surname>Wright</surname><given-names>A</given-names> </name><name name-style="western"><surname>Glynn</surname><given-names>RJ</given-names> </name><etal/></person-group><article-title>Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system</article-title><source>J Am Med Inform Assoc</source><year>2019</year><month>06</month><day>1</day><volume>26</volume><issue>6</issue><fpage>547</fpage><lpage>552</lpage><pub-id pub-id-type="doi">10.1093/jamia/ocz005</pub-id><pub-id pub-id-type="medline">30861069</pub-id></nlm-citation></ref><ref id="ref15"><label>15</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Chen</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Ramamurthy</surname><given-names>K</given-names> </name><name name-style="western"><surname>Wen</surname><given-names>KW</given-names> </name></person-group><article-title>Organizations&#x2019; information security policy compliance: stick or carrot approach?</article-title><source>J Manag Inf Syst</source><year>2012</year><month>12</month><volume>29</volume><issue>3</issue><fpage>157</fpage><lpage>188</lpage><pub-id pub-id-type="doi">10.2753/MIS0742-1222290305</pub-id></nlm-citation></ref><ref id="ref16"><label>16</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Musuva</surname><given-names>PMW</given-names> </name><name name-style="western"><surname>Getao</surname><given-names>KW</given-names> </name><name name-style="western"><surname>Chepken</surname><given-names>CK</given-names> </name></person-group><article-title>A new approach to modelling the effects of cognitive processing and threat detection on phishing susceptibility</article-title><source>Comput Human Behav</source><year>2019</year><month>05</month><volume>94</volume><fpage>154</fpage><lpage>175</lpage><pub-id pub-id-type="doi">10.1016/j.chb.2018.12.036</pub-id></nlm-citation></ref><ref id="ref17"><label>17</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Pepitone</surname><given-names>A</given-names> </name></person-group><article-title>A theory of cognitive dissonance by Leon Festinger</article-title><source>Am J Psychol</source><year>1959</year><volume>72</volume><issue>1</issue><fpage>153</fpage><lpage>155</lpage><pub-id pub-id-type="doi">10.2307/1420234</pub-id></nlm-citation></ref><ref id="ref18"><label>18</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Harmon-Jones</surname><given-names>E</given-names> </name><name name-style="western"><surname>Mills</surname><given-names>J</given-names> </name></person-group><article-title>An introduction to cognitive dissonance theory and an overview of current perspectives on the theory</article-title><source>Cognitive Dissonance: Reexamining a Pivotal Theory in Psychology</source><year>2019</year><edition>2</edition><publisher-name>American Psychological Association</publisher-name><fpage>3</fpage><lpage>24</lpage><pub-id pub-id-type="doi">10.1037/0000135-001</pub-id></nlm-citation></ref><ref id="ref19"><label>19</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Harmon-Jones</surname><given-names>EE</given-names> </name></person-group><source>Cognitive Dissonance: Reexamining a Pivotal Theory in Psychology</source><access-date>2025-12-23</access-date><edition>2</edition><publisher-name>American Psychological Association</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://psycnet.apa.org/books/TOC/16109">https://psycnet.apa.org/books/TOC/16109</ext-link></comment></nlm-citation></ref><ref id="ref20"><label>20</label><nlm-citation citation-type="thesis"><person-group person-group-type="author"><name name-style="western"><surname>Altamimi</surname><given-names>S</given-names> </name></person-group><article-title>Investigating and mitigating the role of neutralisation techniques on information security policies violation in healthcare organisations</article-title><year>2022</year><publisher-name>University of Glasgow</publisher-name><pub-id pub-id-type="doi">10.5525/gla.thesis.82646</pub-id></nlm-citation></ref><ref id="ref21"><label>21</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Sykes</surname><given-names>GM</given-names> </name><name name-style="western"><surname>Matza</surname><given-names>D</given-names> </name></person-group><article-title>Techniques of neutralization: a theory of delinquency</article-title><source>Delinquency and Drift Revisited</source><year>2017</year><volume>21</volume><publisher-name>Routledge</publisher-name><pub-id pub-id-type="doi">10.4324/9780203793596</pub-id></nlm-citation></ref><ref id="ref22"><label>22</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Siponen</surname><given-names>M</given-names> </name><name name-style="western"><surname>Vance</surname><given-names>A</given-names> </name></person-group><article-title>Neutralization: new insights into the problem of employee information systems security policy violations1</article-title><source>MIS Q</source><year>2010</year><month>09</month><day>1</day><volume>34</volume><issue>3</issue><fpage>487</fpage><lpage>502</lpage><pub-id pub-id-type="doi">10.2307/25750688</pub-id></nlm-citation></ref><ref id="ref23"><label>23</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Taylor-Jackson</surname><given-names>J</given-names> </name><name name-style="western"><surname>McAlaney</surname><given-names>J</given-names> </name><name name-style="western"><surname>Foster</surname><given-names>JL</given-names> </name><name name-style="western"><surname>Bello</surname><given-names>A</given-names> </name><name name-style="western"><surname>Maurushat</surname><given-names>A</given-names> </name><name name-style="western"><surname>Dale</surname><given-names>J</given-names> </name></person-group><person-group person-group-type="editor"><name name-style="western"><surname>Bernhard</surname><given-names>M</given-names> </name><name name-style="western"><surname>Bracciali</surname><given-names>A</given-names> </name><name name-style="western"><surname>Camp</surname><given-names>LJ</given-names> </name><name name-style="western"><surname>Matsuo</surname><given-names>S</given-names> </name><name name-style="western"><surname>Maurushat</surname><given-names>A</given-names> </name><name name-style="western"><surname>R&#x00F8;nne</surname><given-names>PB</given-names> </name><name name-style="western"><surname>Sala</surname><given-names>M</given-names> </name></person-group><source>Incorporating Psychology into Cyber Security Education: A Pedagogical Approach</source><year>2020</year><publisher-name>Springer International Publishing</publisher-name><fpage>207</fpage><lpage>217</lpage><pub-id pub-id-type="doi">10.1007/978-3-030-54455-3_15</pub-id></nlm-citation></ref><ref id="ref24"><label>24</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Barlow</surname><given-names>JB</given-names> </name><name name-style="western"><surname>Warkentin</surname><given-names>M</given-names> </name><name name-style="western"><surname>Ormond</surname><given-names>D</given-names> </name><etal/></person-group><article-title>Don&#x2019;t even think about it! The effects of antineutralization, informational, and normative communication on information security compliance</article-title><source>JAIS</source><year>2018</year><volume>19</volume><issue>8</issue><fpage>689</fpage><lpage>715</lpage><pub-id pub-id-type="doi">10.17705/1jais.00506</pub-id></nlm-citation></ref><ref id="ref25"><label>25</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Cazares</surname><given-names>MF</given-names> </name><name name-style="western"><surname>Ar&#x00E9;valo</surname><given-names>D</given-names> </name><name name-style="western"><surname>Andrade</surname><given-names>RO</given-names> </name><name name-style="western"><surname>Fuertes</surname><given-names>W</given-names> </name><name name-style="western"><surname>S&#x00E1;nchez-Rubio</surname><given-names>M</given-names> </name></person-group><person-group person-group-type="editor"><name name-style="western"><surname>Nagar</surname><given-names>AK</given-names> </name><name name-style="western"><surname>Jat</surname><given-names>DS</given-names> </name><name name-style="western"><surname>Mar&#x00ED;n-Ravent&#x00F3;s</surname><given-names>G</given-names> </name><name name-style="western"><surname>Mishra</surname><given-names>DK</given-names> </name></person-group><article-title>A training web platform to improve cognitive skills for phishing attacks detection</article-title><source>Intelligent Sustainable Systems - Selected Papers of World S4 2021</source><year>2022</year><fpage>33</fpage><lpage>42</lpage><series>Lecture Notes in Networks and Systems</series><pub-id pub-id-type="doi">10.1007/978-981-16-6309-3_4</pub-id><pub-id pub-id-type="other">9789811663086</pub-id></nlm-citation></ref><ref id="ref26"><label>26</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Braun</surname><given-names>O</given-names> </name><name name-style="western"><surname>H&#x00F6;rnemann</surname><given-names>J</given-names> </name><name name-style="western"><surname>Pohlmann</surname><given-names>N</given-names> </name><name name-style="western"><surname>Urban</surname><given-names>T</given-names> </name><name name-style="western"><surname>Grosse-Kampmann</surname><given-names>M</given-names> </name></person-group><article-title>Different seas, different phishes &#x2013; large-scale analysis of phishing simulations across different industries</article-title><year>2025</year><month>08</month><day>25</day><conf-name>ASIA CCS &#x2019;25</conf-name><conf-loc>Hanoi Vietnam</conf-loc><publisher-name>Association for Computing Machinery</publisher-name><fpage>1520</fpage><lpage>1534</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://dl.acm.org/doi/proceedings/10.1145/3708821">https://dl.acm.org/doi/proceedings/10.1145/3708821</ext-link></comment><pub-id pub-id-type="doi">10.1145/3708821.3733905</pub-id></nlm-citation></ref><ref id="ref27"><label>27</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Sieber</surname><given-names>JE</given-names> </name></person-group><article-title>Deception in social research I: kinds of deception and the wrongs they may involve</article-title><source>IRB</source><year>1982</year><month>11</month><volume>4</volume><issue>9</issue><fpage>1</fpage><lpage>5</lpage><pub-id pub-id-type="doi">10.2307/3564511</pub-id><pub-id pub-id-type="medline">11649501</pub-id></nlm-citation></ref><ref id="ref28"><label>28</label><nlm-citation citation-type="web"><article-title>Open source phishing framework</article-title><source>Gophish</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://getgophish.com/">https://getgophish.com/</ext-link></comment></nlm-citation></ref><ref id="ref29"><label>29</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Marshall</surname><given-names>N</given-names> </name><name name-style="western"><surname>Sturman</surname><given-names>D</given-names> </name><name name-style="western"><surname>Auton</surname><given-names>JC</given-names> </name></person-group><article-title>Exploring the evidence for email phishing training: a scoping review</article-title><source>Comput Secur</source><year>2024</year><month>04</month><volume>139</volume><fpage>103695</fpage><pub-id pub-id-type="doi">10.1016/j.cose.2023.103695</pub-id></nlm-citation></ref><ref id="ref30"><label>30</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Hernan</surname><given-names>MA</given-names> </name></person-group><source>Causal Inference: What If</source><year>2024</year><publisher-name>Taylor &#x0026; Francis</publisher-name></nlm-citation></ref><ref id="ref31"><label>31</label><nlm-citation citation-type="book"><article-title>Chapter 61 using randomization in development economics research: a toolkit</article-title><source>Handbook of Development Economics</source><year>2007</year><volume>4</volume><publisher-name>Elsevier</publisher-name><fpage>3895</fpage><lpage>3962</lpage><pub-id pub-id-type="doi">10.1016/S1573-4471(07)04061-2</pub-id></nlm-citation></ref><ref id="ref32"><label>32</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Sparks</surname><given-names>P</given-names> </name><name name-style="western"><surname>Guthrie</surname><given-names>CA</given-names> </name><name name-style="western"><surname>Shepherd</surname><given-names>R</given-names> </name></person-group><article-title>The dimensional structure of the perceived behavioral control construct <sup>1</sup></article-title><source>J Applied Social Pyschol</source><year>1997</year><month>03</month><volume>27</volume><issue>5</issue><fpage>418</fpage><lpage>438</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://onlinelibrary.wiley.com/toc/15591816/27/5">https://onlinelibrary.wiley.com/toc/15591816/27/5</ext-link></comment><pub-id pub-id-type="doi">10.1111/j.1559-1816.1997.tb00639.x</pub-id></nlm-citation></ref><ref id="ref33"><label>33</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Thomopoulos</surname><given-names>G</given-names> </name><name name-style="western"><surname>Lyras</surname><given-names>D</given-names> </name><name name-style="western"><surname>Fidas</surname><given-names>C</given-names> </name></person-group><article-title>Methodologies and ethical considerations in phishing research: a comprehensive review</article-title><year>2023</year><month>09</month><day>27</day><conf-name>CHIGREECE 2023</conf-name><conf-loc>Athens Greece</conf-loc><publisher-name>Association for Computing Machinery</publisher-name><fpage>1</fpage><lpage>10</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://dl.acm.org/doi/proceedings/10.1145/3609987">https://dl.acm.org/doi/proceedings/10.1145/3609987</ext-link></comment><pub-id pub-id-type="doi">10.1145/3609987.3609990</pub-id></nlm-citation></ref><ref id="ref34"><label>34</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hopewell</surname><given-names>S</given-names> </name><name name-style="western"><surname>Chan</surname><given-names>AW</given-names> </name><name name-style="western"><surname>Collins</surname><given-names>GS</given-names> </name><etal/></person-group><article-title>CONSORT 2025 statement: updated guideline for reporting randomised trials</article-title><source>Lancet</source><year>2025</year><month>04</month><day>14</day><fpage>S0140</fpage><lpage>6736</lpage><pub-id pub-id-type="doi">10.1016/S0140-6736(25)00672-5</pub-id><pub-id pub-id-type="medline">40245901</pub-id></nlm-citation></ref><ref id="ref35"><label>35</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>von Elm</surname><given-names>E</given-names> </name><name name-style="western"><surname>Altman</surname><given-names>DG</given-names> </name><name name-style="western"><surname>Egger</surname><given-names>M</given-names> </name><name name-style="western"><surname>Pocock</surname><given-names>SJ</given-names> </name><name name-style="western"><surname>G&#x00F8;tzsche</surname><given-names>PC</given-names> </name><name name-style="western"><surname>Vandenbroucke</surname><given-names>JP</given-names> </name></person-group><article-title>The Strengthening the Reporting of Observational Studies in Epidemiology (STROBE) statement: guidelines for reporting observational studies</article-title><source>The Lancet</source><year>2007</year><month>10</month><volume>370</volume><issue>9596</issue><fpage>1453</fpage><lpage>1457</lpage><pub-id pub-id-type="doi">10.1016/S0140-6736(07)61602-X</pub-id></nlm-citation></ref><ref id="ref36"><label>36</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Plint</surname><given-names>AC</given-names> </name><name name-style="western"><surname>Moher</surname><given-names>D</given-names> </name><name name-style="western"><surname>Morrison</surname><given-names>A</given-names> </name><etal/></person-group><article-title>Does the CONSORT checklist improve the quality of reports of randomised controlled trials? A systematic review</article-title><source>Med J Aust</source><year>2006</year><month>09</month><day>4</day><volume>185</volume><issue>5</issue><fpage>263</fpage><lpage>267</lpage><pub-id pub-id-type="doi">10.5694/j.1326-5377.2006.tb00557.x</pub-id><pub-id pub-id-type="medline">16948622</pub-id></nlm-citation></ref><ref id="ref37"><label>37</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Green-Ajufo</surname><given-names>B</given-names> </name><name name-style="western"><surname>Chakravarty</surname><given-names>D</given-names> </name><name name-style="western"><surname>Maiorana</surname><given-names>A</given-names> </name><name name-style="western"><surname>Lightfoot</surname><given-names>M</given-names> </name><name name-style="western"><surname>Hamiga</surname><given-names>J</given-names> </name><name name-style="western"><surname>Rebchook</surname><given-names>G</given-names> </name></person-group><article-title>Acceptability and feasibility of using educational incentives for research participation to advance antiracism</article-title><source>Ethics Hum Res</source><year>2025</year><volume>47</volume><issue>4</issue><fpage>18</fpage><lpage>28</lpage><pub-id pub-id-type="doi">10.1002/eahr.60010</pub-id><pub-id pub-id-type="medline">40658773</pub-id></nlm-citation></ref><ref id="ref38"><label>38</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Sobolewski</surname><given-names>J</given-names> </name><name name-style="western"><surname>Rothschild</surname><given-names>A</given-names> </name><name name-style="western"><surname>Freeman</surname><given-names>A</given-names> </name></person-group><article-title>The impact of incentives on data collection for online surveys: social media recruitment study</article-title><source>JMIR Form Res</source><year>2024</year><month>07</month><day>4</day><volume>8</volume><issue>1</issue><fpage>e50240</fpage><pub-id pub-id-type="doi">10.2196/50240</pub-id><pub-id pub-id-type="medline">38963924</pub-id></nlm-citation></ref><ref id="ref39"><label>39</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Cohen</surname><given-names>J</given-names> </name></person-group><article-title>A power primer</article-title><source>Psychol Bull</source><year>1992</year><month>07</month><volume>112</volume><issue>1</issue><fpage>155</fpage><lpage>159</lpage><pub-id pub-id-type="doi">10.1037//0033-2909.112.1.155</pub-id><pub-id pub-id-type="medline">19565683</pub-id></nlm-citation></ref><ref id="ref40"><label>40</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Vaske</surname><given-names>JJ</given-names> </name><name name-style="western"><surname>Beaman</surname><given-names>J</given-names> </name><name name-style="western"><surname>Sponarski</surname><given-names>CC</given-names> </name></person-group><article-title>Rethinking internal consistency in Cronbach&#x2019;s alpha</article-title><source>Leis Sci</source><year>2017</year><month>03</month><day>4</day><volume>39</volume><issue>2</issue><fpage>163</fpage><lpage>173</lpage><pub-id pub-id-type="doi">10.1080/01490400.2015.1127189</pub-id></nlm-citation></ref><ref id="ref41"><label>41</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Seabold</surname><given-names>S</given-names> </name><name name-style="western"><surname>Perktold</surname><given-names>J</given-names> </name></person-group><article-title>Statsmodels: econometric and statistical modeling with Python</article-title><year>2010</year><conf-name>Python in Science Conference</conf-name><conf-loc>Austin, Texas</conf-loc><fpage>92</fpage><lpage>96</lpage><pub-id pub-id-type="doi">10.25080/Majora-92bf1922-011</pub-id></nlm-citation></ref><ref id="ref42"><label>42</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Parsons</surname><given-names>K</given-names> </name><name name-style="western"><surname>McCormac</surname><given-names>A</given-names> </name><name name-style="western"><surname>Butavicius</surname><given-names>M</given-names> </name><name name-style="western"><surname>Pattinson</surname><given-names>M</given-names> </name><name name-style="western"><surname>Jerram</surname><given-names>C</given-names> </name></person-group><article-title>The development of the human aspects of information security questionnaire (HAIS-q)</article-title><year>2013</year><conf-name>ACIS</conf-name><pub-id pub-id-type="doi">10.1016/j.cose.2013.12.003</pub-id></nlm-citation></ref><ref id="ref43"><label>43</label><nlm-citation citation-type="web"><article-title>Log in</article-title><source>Nettskjema</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://nettskjema.no">https://nettskjema.no</ext-link></comment></nlm-citation></ref><ref id="ref44"><label>44</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Huang</surname><given-names>JL</given-names> </name><name name-style="western"><surname>Bowling</surname><given-names>NA</given-names> </name><name name-style="western"><surname>Liu</surname><given-names>M</given-names> </name><name name-style="western"><surname>Li</surname><given-names>Y</given-names> </name></person-group><article-title>Detecting insufficient effort responding with an infrequency scale: evaluating validity and participant reactions</article-title><source>J Bus Psychol</source><year>2015</year><month>06</month><volume>30</volume><issue>2</issue><fpage>299</fpage><lpage>311</lpage><pub-id pub-id-type="doi">10.1007/s10869-014-9357-6</pub-id></nlm-citation></ref><ref id="ref45"><label>45</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kung</surname><given-names>FYH</given-names> </name><name name-style="western"><surname>Kwok</surname><given-names>N</given-names> </name><name name-style="western"><surname>Brown</surname><given-names>DJ</given-names> </name></person-group><article-title>Are attention check questions a threat to scale validity?</article-title><source>Applied Psychology</source><year>2018</year><month>04</month><access-date>2026-04-15</access-date><volume>67</volume><issue>2</issue><fpage>264</fpage><lpage>283</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://iaap-journals.onlinelibrary.wiley.com/toc/14640597/67/2">https://iaap-journals.onlinelibrary.wiley.com/toc/14640597/67/2</ext-link></comment><pub-id pub-id-type="doi">10.1111/apps.12108</pub-id></nlm-citation></ref><ref id="ref46"><label>46</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Ho</surname><given-names>G</given-names> </name><name name-style="western"><surname>Mirian</surname><given-names>A</given-names> </name><name name-style="western"><surname>Luo</surname><given-names>E</given-names> </name><etal/></person-group><article-title>Understanding the efficacy of phishing training in practice</article-title><year>2025</year><month>05</month><conf-name>2025 IEEE Symposium on Security and Privacy (SP)</conf-name><conf-loc>San Francisco, CA</conf-loc><fpage>37</fpage><lpage>54</lpage><pub-id pub-id-type="doi">10.1109/SP61157.2025.00076</pub-id></nlm-citation></ref><ref id="ref47"><label>47</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Zhuo</surname><given-names>S</given-names> </name><name name-style="western"><surname>Biddle</surname><given-names>R</given-names> </name><name name-style="western"><surname>Russello</surname><given-names>G</given-names> </name><name name-style="western"><surname>Lottridge</surname><given-names>D</given-names> </name></person-group><article-title>Precision email simulator for research on safety-critical phishing behaviour</article-title><year>2025</year><month>04</month><day>26</day><access-date>2026-04-15</access-date><conf-name>CHI 2025</conf-name><conf-loc>Yokohama Japan</conf-loc><publisher-name>Association for Computing Machinery</publisher-name><fpage>1</fpage><lpage>12</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://dl.acm.org/doi/proceedings/10.1145/3706598">https://dl.acm.org/doi/proceedings/10.1145/3706598</ext-link></comment><pub-id pub-id-type="doi">10.1145/3706598.3714143</pub-id></nlm-citation></ref><ref id="ref48"><label>48</label><nlm-citation citation-type="web"><person-group person-group-type="author"><name name-style="western"><surname>Marczak</surname><given-names>B</given-names> </name><name name-style="western"><surname>Scott-Railton</surname><given-names>J</given-names> </name><name name-style="western"><surname>Aljizawi</surname><given-names>N</given-names> </name><name name-style="western"><surname>Anstis</surname><given-names>S</given-names> </name><name name-style="western"><surname>Deibert</surname><given-names>R</given-names> </name></person-group><article-title>The great ipwn: journalists hacked with suspected NSO group imessage &#x2018;zero-click&#x2019; exploit</article-title><source>Citizen Lab</source><year>2020</year><month>12</month><access-date>2025-12-12</access-date><publisher-name>University of Toronto</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hacked-with-suspected-nso-group-imessage-zero-click-exploit/">https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hacked-with-suspected-nso-group-imessage-zero-click-exploit/</ext-link></comment></nlm-citation></ref><ref id="ref49"><label>49</label><nlm-citation citation-type="web"><article-title>Apple sues pegasus for spyware maker. how to check if your iphone has NSO group software</article-title><source>CNET</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.cnet.com/tech/mobile/apple-sues-pegasus-for-spyware-maker-how-to-check-if-your-iphone-has-nso-group-software/">https://www.cnet.com/tech/mobile/apple-sues-pegasus-for-spyware-maker-how-to-check-if-your-iphone-has-nso-group-software/</ext-link></comment></nlm-citation></ref><ref id="ref50"><label>50</label><nlm-citation citation-type="web"><article-title>What is zero-click malware, and how do zero-click attacks work?</article-title><source>Kaspersky</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.kaspersky.com/resource-center/definitions/what-is-zero-click-malware">https://www.kaspersky.com/resource-center/definitions/what-is-zero-click-malware</ext-link></comment></nlm-citation></ref><ref id="ref51"><label>51</label><nlm-citation citation-type="web"><person-group person-group-type="author"><name name-style="western"><surname>Azrain</surname><given-names>A</given-names> </name></person-group><article-title>Multivariate analysis of variance (MANOVA)</article-title><source>Academia</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.academia.edu/7751963/Multivariate_Analysis_of_Variance_MANOVA">https://www.academia.edu/7751963/Multivariate_Analysis_of_Variance_MANOVA</ext-link></comment></nlm-citation></ref><ref id="ref52"><label>52</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Meyers</surname><given-names>LS</given-names> </name><name name-style="western"><surname>Gamst</surname><given-names>G</given-names> </name><name name-style="western"><surname>Guarino</surname><given-names>AJ</given-names> </name></person-group><source>Applied Multivariate Research: Design and Interpretation</source><year>2017</year><publisher-name>SAGE Publications</publisher-name><pub-id pub-id-type="doi">10.4135/9781071802687</pub-id></nlm-citation></ref><ref id="ref53"><label>53</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Wilson Van Voorhis</surname><given-names>CR</given-names> </name><name name-style="western"><surname>Morgan</surname><given-names>BL</given-names> </name></person-group><article-title>Understanding power and rules of thumb for determining sample Sizes</article-title><source>Tutor Quant Methods Psychol</source><year>2007</year><volume>3</volume><issue>2</issue><fpage>43</fpage><lpage>50</lpage><pub-id pub-id-type="doi">10.20982/tqmp.03.2.p043</pub-id></nlm-citation></ref><ref id="ref54"><label>54</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Tavakol</surname><given-names>M</given-names> </name><name name-style="western"><surname>Dennick</surname><given-names>R</given-names> </name></person-group><article-title>Making sense of Cronbach&#x2019;s alpha</article-title><source>Int J Med Educ</source><year>2011</year><month>06</month><day>27</day><volume>2</volume><fpage>53</fpage><lpage>55</lpage><pub-id pub-id-type="doi">10.5116/ijme.4dfb.8dfd</pub-id><pub-id pub-id-type="medline">28029643</pub-id></nlm-citation></ref><ref id="ref55"><label>55</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Jain</surname><given-names>AK</given-names> </name><name name-style="western"><surname>Gupta</surname><given-names>BB</given-names> </name></person-group><article-title>A survey of phishing attack techniques, defence mechanisms and open research challenges</article-title><source>Enterprise Information Systems</source><year>2022</year><month>04</month><day>3</day><access-date>2026-04-15</access-date><volume>16</volume><issue>4</issue><fpage>527</fpage><lpage>565</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://tinyurl.com/25vumkbv">https://tinyurl.com/25vumkbv</ext-link></comment><pub-id pub-id-type="doi">10.1080/17517575.2021.1896786</pub-id></nlm-citation></ref><ref id="ref56"><label>56</label><nlm-citation citation-type="web"><article-title>Statistical methods for psychology</article-title><source>eBook</source><access-date>2025-12-12</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://tinyurl.com/ypduhk6j">https://tinyurl.com/ypduhk6j</ext-link></comment></nlm-citation></ref><ref id="ref57"><label>57</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Pillai</surname><given-names>KCS</given-names> </name></person-group><article-title>Some new test criteria in multivariate analysis</article-title><source>Ann Math Statist</source><year>1955</year><month>03</month><volume>26</volume><issue>1</issue><fpage>117</fpage><lpage>121</lpage><pub-id pub-id-type="doi">10.1214/aoms/1177728599</pub-id></nlm-citation></ref><ref id="ref58"><label>58</label><nlm-citation citation-type="book"><article-title>Handbook of applied multivariate statistics and mathematical modeling</article-title><source>Handbook of Applied Multivariate Statistics and Mathematical Modeling</source><year>2000</year><publisher-name>Academic Press</publisher-name><fpage>3</fpage><lpage>36</lpage><pub-id pub-id-type="doi">10.1016/B978-012691360-6/50002-1</pub-id></nlm-citation></ref><ref id="ref59"><label>59</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Tolsdorf</surname><given-names>J</given-names> </name><name name-style="western"><surname>Langer</surname><given-names>D</given-names> </name><name name-style="western"><surname>Lo Iacono</surname><given-names>L</given-names> </name></person-group><article-title>Phishing susceptibility and the (in-)effectiveness of common anti-phishing interventions in a large university hospital</article-title><year>2025</year><month>11</month><day>19</day><conf-name>CCS &#x2019;25</conf-name><conf-loc>Taipei Taiwan</conf-loc><publisher-name>Association for Computing Machinery</publisher-name><fpage>4334</fpage><lpage>4348</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://dl.acm.org/doi/proceedings/10.1145/3719027">https://dl.acm.org/doi/proceedings/10.1145/3719027</ext-link></comment><pub-id pub-id-type="doi">10.1145/3719027.3765164</pub-id></nlm-citation></ref><ref id="ref60"><label>60</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Althobaiti</surname><given-names>K</given-names> </name><name name-style="western"><surname>Alsufyani</surname><given-names>N</given-names> </name></person-group><article-title>A review of organization-oriented phishing research</article-title><source>PeerJ Comput Sci</source><year>2024</year><volume>10</volume><fpage>e2487</fpage><pub-id pub-id-type="doi">10.7717/peerj-cs.2487</pub-id><pub-id pub-id-type="medline">39650535</pub-id></nlm-citation></ref><ref id="ref61"><label>61</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Canfield</surname><given-names>CI</given-names> </name><name name-style="western"><surname>Fischhoff</surname><given-names>B</given-names> </name><name name-style="western"><surname>Davis</surname><given-names>A</given-names> </name></person-group><article-title>Quantifying phishing susceptibility for detection and behavior decisions</article-title><source>Hum Factors</source><year>2016</year><month>12</month><volume>58</volume><issue>8</issue><fpage>1158</fpage><lpage>1172</lpage><pub-id pub-id-type="doi">10.1177/0018720816665025</pub-id><pub-id pub-id-type="medline">27562565</pub-id></nlm-citation></ref><ref id="ref62"><label>62</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Jansson</surname><given-names>K</given-names> </name><name name-style="western"><surname>von Solms</surname><given-names>R</given-names> </name></person-group><article-title>Phishing for phishing awareness</article-title><source>Behav Inf Technol</source><year>2013</year><month>06</month><volume>32</volume><issue>6</issue><fpage>584</fpage><lpage>593</lpage><pub-id pub-id-type="doi">10.1080/0144929X.2011.632650</pub-id></nlm-citation></ref><ref id="ref63"><label>63</label><nlm-citation citation-type="book"><article-title>Phish like a boss</article-title><source>Phishing Dark Waters</source><year>2015</year><publisher-name>John Wiley and Sons</publisher-name><fpage>179</fpage><lpage>188</lpage><pub-id pub-id-type="doi">10.1002/9781119183624</pub-id></nlm-citation></ref><ref id="ref64"><label>64</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Grosz</surname><given-names>MP</given-names> </name><name name-style="western"><surname>Rohrer</surname><given-names>JM</given-names> </name><name name-style="western"><surname>Thoemmes</surname><given-names>F</given-names> </name></person-group><article-title>The taboo against explicit causal inference in nonexperimental psychology</article-title><source>Perspect Psychol Sci</source><year>2020</year><month>09</month><volume>15</volume><issue>5</issue><fpage>1243</fpage><lpage>1255</lpage><pub-id pub-id-type="doi">10.1177/1745691620921521</pub-id><pub-id pub-id-type="medline">32727292</pub-id></nlm-citation></ref><ref id="ref65"><label>65</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Amrhein</surname><given-names>V</given-names> </name><name name-style="western"><surname>Greenland</surname><given-names>S</given-names> </name><name name-style="western"><surname>McShane</surname><given-names>B</given-names> </name></person-group><article-title>Scientists rise up against statistical significance</article-title><source>Nature New Biol</source><year>2019</year><month>03</month><volume>567</volume><issue>7748</issue><fpage>305</fpage><lpage>307</lpage><pub-id pub-id-type="doi">10.1038/d41586-019-00857-9</pub-id><pub-id pub-id-type="medline">30894741</pub-id></nlm-citation></ref><ref id="ref66"><label>66</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Priestman</surname><given-names>W</given-names> </name><name name-style="western"><surname>Anstis</surname><given-names>T</given-names> </name><name name-style="western"><surname>Sebire</surname><given-names>IG</given-names> </name><name name-style="western"><surname>Sridharan</surname><given-names>S</given-names> </name><name name-style="western"><surname>Sebire</surname><given-names>NJ</given-names> </name></person-group><article-title>Phishing in healthcare organisations: threats, mitigation and approaches</article-title><source>BMJ Health Care Inform</source><year>2019</year><month>09</month><volume>26</volume><issue>1</issue><fpage>1</fpage><pub-id pub-id-type="doi">10.1136/bmjhci-2019-100031</pub-id><pub-id pub-id-type="medline">31488498</pub-id></nlm-citation></ref></ref-list><app-group><supplementary-material id="app1"><label>Multimedia Appendix 1</label><p>Questionnaire.</p><media xlink:href="jmir_v28i1e68051_app1.docx" xlink:title="DOCX File, 17 KB"/></supplementary-material><supplementary-material id="app2"><label>Multimedia Appendix 2</label><p>Cognitive dissonance message.</p><media xlink:href="jmir_v28i1e68051_app2.docx" xlink:title="DOCX File, 14 KB"/></supplementary-material><supplementary-material id="app3"><label>Checklist 1</label><p>CONSORT (Consolidated Standards of Reporting Trials) checklist.</p><media xlink:href="jmir_v28i1e68051_app3.pdf" xlink:title="PDF File, 206 KB"/></supplementary-material><supplementary-material id="app4"><label>Checklist 2</label><p>STROBE (Strengthening the Reporting of Observational Studies in Epidemiology) checklist.</p><media xlink:href="jmir_v28i1e68051_app4.pdf" xlink:title="PDF File, 121 KB"/></supplementary-material></app-group></back></article>