<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">F1000Research</journal-id>
            <journal-title-group>
                <journal-title>F1000Research</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2046-1402</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/f1000research.175421.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Research Article</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Cybersecurity Awareness as a Mediating Variable in the Relationship between ICS and AIS in Iraqi State Banks</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: 1 approved, 2 approved with reservations]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Ahmed Al-Mohammedi</surname>
                        <given-names>Younis</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Project Administration</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>S. Tarkh</surname>
                        <given-names>Ahmed</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>N. Al-Jumaili</surname>
                        <given-names>Hamzah</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <uri content-type="orcid">https://orcid.org/0000-0002-2886-3268</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a2">2</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Aziz Mahdi</surname>
                        <given-names>Nedhal</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Software</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="aff" rid="a3">3</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>College of Management and Economics - Department of Accounting, University of Fallujah, Al-Fallujah, Al Anbar Governorate, 31002, Iraq</aff>
                <aff id="a2">
                    <label>2</label>Internal Audit and Control Department, University of Fallujah, Al-Fallujah, Al Anbar Governorate, 31002, Iraq</aff>
                <aff id="a3">
                    <label>3</label>College of Administration and Economics, Gilgamesh University, Baghdad, Baghdad, Iraq, 10045, Iraq</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:hamza.nahid.a@uofallujah.edu.iq">hamza.nahid.a@uofallujah.edu.iq</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>18</day>
                <month>2</month>
                <year>2026</year>
            </pub-date>
            <pub-date pub-type="collection">
                <year>2026</year>
            </pub-date>
            <volume>15</volume>
            <elocation-id>294</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>4</day>
                    <month>2</month>
                    <year>2026</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 Ahmed Al-Mohammedi Y et al.</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://f1000research.com/articles/15-294/pdf"/>
            <abstract>
                <sec>
                    <title>Research Objective</title>
                    <p>This research aims to study the relationship between internal control and accounting information security, while exploring the role of cybersecurity awareness as a mediating variable that can contribute to strengthening this relationship.</p>
                </sec>
                <sec>
                    <title>Research Significance</title>
                    <p>This research gains its significance from bridging the knowledge gap in accounting literature concerning the integration of internal control systems with information security in the face of cyber challenges.</p>
                </sec>
                <sec>
                    <title>Research Methodology and Tools</title>
                    <p>Considering the nature of the problem and the research objectives, this study follows the steps of the descriptive-analytical method. The aim is to determine the role of cybersecurity awareness as a mediating variable in strengthening the relationship between internal control systems and accounting information security. This includes analyzing data and information related to enhancing the importance of cybersecurity awareness in the local environment, both theoretically and empirically. The analysis was conducted through a survey examining the relationship between internal control systems and accounting information security, mediated by cybersecurity awareness among employees at different administrative levels in the banks included in the study sample. The PLS Smart software was used to process and analyze data.</p>
                </sec>
                <sec>
                    <title>Key Findings</title>
                    <p>The study concluded that internal control systems contribute to enhancing accounting information security when cybersecurity awareness acts as a mediating variable. This demonstrates the crucial and positive role of control in protecting data when cybersecurity awareness is raised.</p>
                </sec>
                <sec>
                    <title>Recommendations</title>
                    <p>The researchers recommend that banks adopt best practices for information security protection and implement strong and clear policies and procedures for cybersecurity awareness.</p>
                </sec>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Cybersecurity awareness</kwd>
                <kwd>internal control</kwd>
                <kwd>accounting information security</kwd>
                <kwd>Iraqi government banks.</kwd>
            </kwd-group>
            <funding-group>
                <funding-statement>The author(s) declared that no grants were involved in supporting this work.</funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec id="sec6" sec-type="intro">
            <title>1. Introduction</title>
            <p>Information systems, evidence bases, and communication systems have become the main vein of the world of knowledge, industry, finance, business and other sectors, and the security of information and accounting data. Also, its protection from increasing cyber threats has become crucial considering the digital transformations and a significant expansion in the use of accounting information systems, which can lead to substantial losses if ignored. Security, which justifies the need to understand the factors that enhance the effectiveness of ICS by providing adequate data protection. Despite the Department&#x2019;s keenness and efforts to implement ICS systems (ICS), the increasing cyberattacks and exploitation of technical gaps have shown a gap in the AIS necessitating the extent for which cybersecurity awareness has an effect on strengthening the relationship between ICS and data security, contributing to designing and developing more effective accounting data security policies in organizations.</p>
            <p>In this context, cybersecurity awareness has gained special importance. It is considered a variable that may contribute to strengthening the ICS relationship to AIS, through its active role in enabling employees in banking institutions to identify risks and adopt policies that are understood in accordance with sound security practices. The research relies on data collection by designing a questionnaire addressed to the specialized staff and analyzing it to reveal the relationship between the study variables, in a way that contributes to providing scientific and practical recommendations to enhance the AIS from the risks and security gaps in the contemporary environment.</p>
            <sec id="sec7">
                <title>1.1 Research problem</title>
                <p>The use of public networks such as the Internet is one of the main trends of banking institutions in recent times, which has caused a qualitative leap in the financial and banking services, but it is hardly without discomforts. These institutions have confirmed that the benefits and services that come to them because of the use of the Internet include many risks represented in the growing incidence of financial fraud cases because of the weakness and absence of effective standards and principles that can be relied on for the verification of the identity of customers and customers. Also, they have a steady increase in the Cases of privacy violation in electronic financial and banking operations because these processes involve multiple stages of repeated collection and transmission of information and data. For the foregoing, banking institutions should attach great importance to the AIS to ensure the protection of information from internal and external threats and risks protecting and maintain confidentiality and privacy from the expected risks because of the spread of hacking and hacking methods and tools on public networks, and to counter and combat information attacks activities.</p>
                <p>ICS are important tools enhancing the security of the information that organizations rely on in the face of the threats they are exposed to. Also, the effectiveness of these systems is not enough to face various threats unless their employees have sufficient cybersecurity awareness.</p>
                <p>The ICS relationship to AIS has emerged, while exploring the role of cybersecurity awareness as an intermediate variable that can contribute to strengthening this relationship. According to the literature, employees in organizations are the weakest link in the AIS system, even in the presence of effective ICS unless their employees have sufficient awareness and knowledge of cybersecurity risks and methods, protection and prevention. Hence, the main problem of the research emerges, which is represented in the following question:</p>
                <p>How does cybersecurity awareness and ICS help in the protection of the AIS among employees of banking institutions in Anbar province? This main question includes:
                    <list list-type="order">
                        <list-item>
                            <label>1.</label>
                            <p>How big is cybersecurity awareness among employees of government banks in Anbar province?</p>
                        </list-item>
                        <list-item>
                            <label>2.</label>
                            <p>How effective is the ICS applied in these banks?</p>
                        </list-item>
                        <list-item>
                            <label>3.</label>
                            <p>How efficient is the AIS in these banks?</p>
                        </list-item>
                        <list-item>
                            <label>4.</label>
                            <p>What does cybersecurity awareness relate to AIS among employees of these banks?</p>
                        </list-item>
                        <list-item>
                            <label>5.</label>
                            <p>What is the relationship between the ICS and AIS?</p>
                        </list-item>
                        <list-item>
                            <label>6.</label>
                            <p>Does cybersecurity awareness contribute to enhancing the effectiveness of the ICS to protect the AIS?</p>
                        </list-item>
                        <list-item>
                            <label>7.</label>
                            <p>What is the complementary role of both cybersecurity awareness and ICS in protecting AIS?</p>
                        </list-item>
                    </list>
                </p>
            </sec>
            <sec id="sec8">
                <title>1.2 The study importance</title>
                <p>The study is important because of its effective contribution to bridging the knowledge gap in the accounting literature related to the integration of ICS with information security considering cyber challenges. It highlights the role of cybersecurity awareness as an intermediate variable, an aspect that has rarely been addressed in previous studies in the government context. The research also provides a theoretical framework that can be used in future studies dealing with cybersecurity in the public sector. The research also addresses a real problem facing government banking institutions, namely the weak protection of accounting information because of weak control or the absence of security culture. It helps decision-makers design effective control and awareness policies to protect financial data from cyber threats.</p>
            </sec>
            <sec id="sec9">
                <title>1.3 Research objectives</title>
                <p>Considering the nature of the problem that the researchers seek to address the main aspects of it to show the role played by cybersecurity awareness as an intermediate variable in the ICS relationship to AIS, the following secondary objectives emerge from this main goal:
                    <list list-type="order">
                        <list-item>
                            <label>1.</label>
                            <p>Identifying the level of cybersecurity awareness among employees of bank branches of Al-Rashid Bank in the cities of Fallujah and Ramadi.</p>
                        </list-item>
                        <list-item>
                            <label>2.</label>
                            <p>Measuring the ICS effectiveness in those banks.</p>
                        </list-item>
                        <list-item>
                            <label>3.</label>
                            <p>Assess AIS in these banks.</p>
                        </list-item>
                        <list-item>
                            <label>4.</label>
                            <p>Analyze the cybersecurity awareness relation to AIS among employees of these banks.</p>
                        </list-item>
                        <list-item>
                            <label>5.</label>
                            <p>Study the ICS relationship with AIS.</p>
                        </list-item>
                        <list-item>
                            <label>6.</label>
                            <p>Reveal the extent to which cybersecurity awareness contributes to enhancing the effectiveness of the ICS to protect the AIS.</p>
                        </list-item>
                        <list-item>
                            <label>7.</label>
                            <p>Identify the complementary role of both cybersecurity awareness and ICS in protecting the AIS among employees in banking institutions in the study sample.</p>
                        </list-item>
                    </list>
                </p>
            </sec>
        </sec>
        <sec id="sec10">
            <title>2. Second topic/Theoretical aspect of the research</title>
            <sec id="sec11">
                <title>2.1 First: Components and elements of the ICS system</title>
                <p>&#x201c;ICS is designing activities and procedures by the board, management and employees of an entity&#x201d;. It aims to provide a reasonable degree of certainty as to gain the organization&#x2019;s aims related to asset protection and operational efficiency, the preparation and accuracy of reports, and compliance with the relevant laws and regulations through the procedures and policies adopted for this purpose (
                    <xref ref-type="bibr" rid="ref29">COSO, 2013</xref>).</p>
                <p>According to 
                    <xref ref-type="bibr" rid="ref2">Abdullah (2007</xref>, 229), ICS is the organizational plan, means of coordination and measures designed by the bank&#x2019;s management to protect its assets, controlling and auditing accounting data, ensuring its accuracy and reliability, raising productivity efficiency, and encouraging employees for the adherence to the set management policies.</p>
                <p>According to 
                    <xref ref-type="bibr" rid="ref21">Ryabov (2021)</xref>, the ICS is an integrated system that includes organizational plans designed by the economic unit, which implicitly includes the methods to protect its assets, test the accuracy of its data. It improves its operations and encourages adherence to the administrative policies set by it.</p>
                <p>So, ICS ensures that banking institutions gain their strategic aims by carrying out their financial and operational operations efficiently and effectively, in addition to contributing to preserving the resources available to the economic unit from damage, loss, misuse and other non-ideal conditions that may occur and affect those units.</p>
                <p>In order for the ICS to be effective, it should be strengthened by a set of elements and elements, including but not limited to the existence of a flexible and clear organizational plan that is clearly understood and applied, and the bank&#x2019;s accounting system has to be sound, clear and simple to ensure effective ICS at all stages of the banking business, by making the accounting cycle and ways of documenting it clear. It must also be ensured that tasks should be distributed and segregated among employees to reduce the likelihood of intentional and unintentional deviations and irregularities affecting financial reporting. It is essential to select qualified and experienced staff, especially those in charge of the ICS system, to ensure that performance is controlled. Also, all levels of staff from top to bottom are obliged to follow the set goals and plans, and to avoid deviations at all levels. Thus, mechanisms should be put in place to address deviations if they occur by checking them and acting Corrective Appropriateness (
                    <xref ref-type="bibr" rid="ref20">Qourin et al., 2019</xref>).</p>
                <p>Banks in government institutions must provide protection against any type of cyber-attacks that they are expected to face during the implementation of their operations, so they are in dire need of cybersecurity (
                    <xref ref-type="bibr" rid="ref14">Goutam &amp; Verman: 2015</xref>) involving functions related to the management of cyber risks related to the cyber environment. It also aims to provide the optimal basic requirements and in accordance with the standards and practices set for this purpose, whether those related to the confidentiality of information or those related to ensuring the integrity and integrity of information for reducing cyber risks to technological and information assets for all organizations, whether the threats are exposed to them are internal or external.</p>
                <p>
                    <xref ref-type="bibr" rid="ref28">Wolden et al. (2015)</xref> believed that cybersecurity goals are achieved through key axes for maintaining information security:
                    <list list-type="order">
                        <list-item>
                            <label>1-</label>
                            <p>Technology: This axis includes all the tools and techniques used to protect programs from potential cyber threats, such as using protection software to support and enhance the security of electronic systems against cyber threats.</p>
                        </list-item>
                        <list-item>
                            <label>2-</label>
                            <p>Organizations and Individuals: This axis includes all entities and individuals using information and electronic systems, as information security requires collective cooperation by all members of the organization.</p>
                        </list-item>
                        <list-item>
                            <label>3-</label>
                            <p>Activities and Operations: This theme includes the methods used by government banks in employing personnel and technologies that limit or prevent cyberattacks. Through it, the ICS relationship to cybersecurity is manifested.</p>
                        </list-item>
                    </list>
                </p>
                <p>According to 
                    <xref ref-type="bibr" rid="ref10">Bozkus &amp; Caliyurt (2018)</xref>, ICS and cybersecurity determine banking environment, as institutions in general, and banks in particular, have depended on electronic technologies and applications in using their various activities and processes. This increased adoption has led to their high exposure to breaches and security. An ICS is also essential to a cybersecurity strategy to verify the availability of security and protection in the system contributing to identifying vulnerabilities in systems and applications by estimating security risks, discovering vulnerabilities and flaws in system settings. It ensures that these vulnerabilities are addressed appropriately. In addition, it detects cyber-attacks to determine whether the system has been compromised or has been exposed to previous breaches and attacks and an ICS to analyze system logs and identify any unauthorized intrusions or exploits.</p>
                <p>The ICS also contributes to raising awareness and self-security among bank employees, as it highlights existing security vulnerabilities and identifies the necessary actions to avoid them and minimize their effects. This, in turn, enhances the ability of employees to monitor, detect, and prevent cyber threats (
                    <xref ref-type="bibr" rid="ref24">Stevens et al., 2020</xref>).</p>
                <p>The ICS is one of the essential measures that contribute to enhancing cybersecurity in banking operations, by helping to detect and protect sensitive data and financial and personal information of customers within the bank, by monitoring security threats and cyber breaches through systems monitoring and data analysis. It also contributes to assessing the implementation of security policies and procedures and ensuring their compliance with relevant local and international standards and legislation.</p>
                <p>Furthermore, the ICS ensures the Bank&#x2019;s compliance with cybersecurity regulations by examining various records and reports, especially those related to the implementation of Cloud ERP Systems, where it plays a key role in identifying weaknesses in the system and recommending the required corrective actions This will enhance the cybersecurity of the bank, which helps in making the appropriate decisions within the specified timings to support and enhance the security of banking operations (
                    <xref ref-type="bibr" rid="ref15">Huseynov et al., 2020</xref>; 
                    <xref ref-type="bibr" rid="ref22">Shamsuddin et al., 2018</xref>).</p>
            </sec>
            <sec id="sec12">
                <title>2.2 Second: The concept, benefits and motivations of spreading the culture of cybersecurity awareness</title>
                <p>Cybersecurity is a critical factor in ensuring the integrity of cloud ERP systems and protecting them from multiple cyber threats, through the development of security procedures and policies (
                    <xref ref-type="bibr" rid="ref16">Jamm&#x2019;e and Alash, 2021</xref>). The adoption of specialized protection systems, and the implementation of various technologies are directly related to encryption and advanced protection, and periodic updates (
                    <xref ref-type="bibr" rid="ref9">Ben Alqama and Saahi, 2019</xref>). Other requirements are also required related to strengthening collaborative relationships between technical service providers, government entities, security institutions, and banks to reduce cyber risks and ensure the security of accounting data. It also emphasizes promoting and raising awareness among users of the need to follow appropriate security measures to protect their financial and personal data, and to provide bank employees with the elements of competence and technical knowledge in the field of information technology to enhance and improve cybersecurity (
                    <xref ref-type="bibr" rid="ref12">Despotovi&#x0107; et al., 2023</xref>).</p>
                <p>As the online world becomes more interconnected, enhancing cybersecurity awareness has become a necessity for every user, cybersecurity awareness is the cornerstone of having the right defenses against increasingly complex and pervasive cyber threats (
                    <xref ref-type="bibr" rid="ref13">George, George, &amp; Baskar, 2023</xref>). People armed with information security awareness understand the importance of data security Whatever their nature, including financial, personal, and corporate data. They are also less likely to fall victim to fraud or inadvertent innuendo and disclosure of important information about the organization.</p>
                <p>Having cybersecurity awareness helps to identify potential risks such as malware, phishing, and social engineering fraud early (
                    <xref ref-type="bibr" rid="ref23">Sharma &amp; Thapa, 2023</xref>). Conscious behavior also plays a pivotal role in early detection of risks and timely preventive measures, which significantly enhances the overall cybersecurity posture.</p>
                <p>Cybersecurity practices represent the preventive and proactive methods adopted to protect the unit&#x2019;s assets, focusing on identifying expected risks and potential threats and seeking to minimize their effects (
                    <xref ref-type="bibr" rid="ref25">Stransact, n.d.</xref>).</p>
                <p>This approach is essential to counter complex threats to organizations, emphasize the confidentiality of information, and enhance organizational resilience in the face of the ever-changing environment of cyber threats. Effective cybersecurity practices enable organizations and individuals to remain vigilant and always ready for the purpose of making strategic and critical decisions as well as adopting measures that reduce the risk of cyber-attacks. The magnitude of the growing cyber risks and threats (
                    <xref ref-type="bibr" rid="ref27">Thakur, 2024</xref>; Efijemue et al., n.d).</p>
                <p>The main objective of promoting cybersecurity awareness and practice in organizations is to train other employees on its importance and to consolidate the organization&#x2019;s commitment to protecting sensitive information among its employees. The growth and increase in cybersecurity awareness enhances employees&#x2019; skills and provides them with the knowledge necessary to address security challenges, including the initiation phase of incident response processes, followed by communication with relevant parties. This is followed by the process of promoting and supporting recovery efforts (
                    <xref ref-type="bibr" rid="ref3">Al-Hawamleh, 2024</xref>).</p>
                <p>The importance of training employees on cybersecurity awareness in banking institutions cannot be underestimated. In a world where cyber risks and threats are constantly growing in complexity and pervasive, it is imperative that organizations equip their employees with the knowledge and skills necessary to recognize and respond to anticipated risks. This training aims to empower years in organizations to become a firewall against cyberattacks, protecting both their interests and customers&#x2019; trust in them.</p>
                <p>The benefits of cybersecurity awareness training are not limited to just preventing data breaches and attacks but extend beyond that. Those who are informed and vigilant can foster and spread a culture of security awareness within the organization. Those who can understand potential risks and have sufficient qualifications to follow best practices have a greater ability to make sound decisions when dealing with sensitive information. They organization&#x2019;s devices, reducing potential accidents and limiting anticipated losses, legal liabilities and reputational damage.</p>
                <p>The need to train employees on cybersecurity awareness has become even greater as companies embrace digital transformation and implement remote work policies, as employees access the organization&#x2019;s data and systems from multiple locations and devices, the cybercriminals&#x2019; attack space expands. Well-designed training programs can enhance the knowledge of employees of organizations about the specific risks of remote work. Providing them with all the necessary knowledge to secure their networks and home devices effectively and efficiently.</p>
                <p>Cybersecurity awareness training is an initiative-taking and necessary investment for organizations that aim to protect their digital assets and maintain their competitive advantage in today&#x2019;s era. By equipping employees with the knowledge and skills that help identify and respond to cyber threats, organizations can reduce or reduce the likelihood of successful fraudulent attacks and protect their resources and maintain their reputation in the competitive market.</p>
            </sec>
            <sec id="sec13">
                <title>2.3 Third: The concept and relationship between AIS and cybersecurity awareness</title>
                <p>A study submitted by (
                    <xref ref-type="bibr" rid="ref8">ASIF, 2023</xref>) for information security refers to the strategic methods and techniques used by the organization aimed at protecting and securing confidential information from unauthorized access by hackers who engage in activities of criminal nature online or carry out acts of sabotage or illegal weakening. Also, information security can be described as practices aimed at Enhance information security and stand up to unauthorized access.</p>
                <p>As information is one of the key assets of organizations, it requires the concerted efforts of all through the participation of diverse groups of stakeholders such as ICT experts, information security professionals, management, staff, and office managers who are the lifeblood and custodians of information in the organization.</p>
                <p>Lack of awareness of cyber risks and required security practices is a major factor that leads to vulnerabilities. Hence, ongoing security awareness training plays a big role in educating workers about common and potential risks such as phishing and social engineering attacks, resulting in a reduced likelihood of occurrence Human errors that lead to security breaches (
                    <xref ref-type="bibr" rid="ref7">Andersson, Bjursell, &amp; Palm, 2023</xref>).</p>
                <p>While organizations invest significant resources in advanced tools and technologies that enhance cybersecurity, they alone are not enough to provide comprehensive protection against threats. Workers are often the weakest link in the information security chain and may fall victim to social engineering tact ICS, opening malicious mail attachments, or disclosing and publishing Unintentionally sensitive information. Therefore, it is essential to add to their security strategies that organizations prioritize cybersecurity awareness training.</p>
                <p>As detailed above, security risks cannot be completely eliminated even with the use and adoption of control and preventive measures and procedures, but they can be significantly reduced and scaled down through the creation and updating of targeted plans for the purpose of responding to incidents and confronting breaches or data leaks quickly and effectively.</p>
                <p>In the context of cybersecurity awareness and information security, there is an integral relationship between them in organizational processes and activities. The more attention employees pay to cybersecurity and its practices, the safer the organization&#x2019;s environment becomes. In turn, a culture of cybersecurity awareness can be promoted and disseminated through effective information security processes. Therefore, there is a mutually beneficial relationship between the awareness and practices of office managers in the field of cybersecurity and information security, where they contribute These measures promote a culture of cybersecurity awareness, while workers&#x2019; interest in cybersecurity promotes building a safer work environment. Therefore, the two years should have a firm awareness of cybersecurity considering the escalating risks and threats of cybercrime and the digital transformation that the contemporary environment is witnessing, with the aim of protecting sensitive data in organizations.</p>
            </sec>
        </sec>
        <sec id="sec14">
            <title>3. Methodology</title>
            <sec id="sec15">
                <title>3.1 Literature review and hypothesis development</title>
                <p>

                    <bold>1. Internal Control and Accounting Information Security</bold>
                </p>
                <p>
                    <xref ref-type="bibr" rid="ref18">Mishra and Dhillon (2008)</xref> aimed to show the role of ICS in the effectiveness of AIS in general. The study provided a theoretical framework for the basic objectives and means of ICS in the light of AIS Evidence were gathered through in-depth interviews with 52 IT managers that included questions about their assessment of ICS. The study identified 68 objectives, organized into 25 groups, the findings of which serve as a basis for providing more theoretical frameworks in the field of information security governance. The objectives also help define initiatives and policies related to governance.</p>
                <p>
                    <xref ref-type="bibr" rid="ref6">Al-Sorihi et al. (2025)</xref> examined and tested ICS as a mediating variable between IT risks and AIS in telecommunications companies in the Arab Republic. To achieve study aim, the comprehensive survey method was used using the questionnaire as a data collection tool, and 356 questionnaires were distributed, of which 218 questionnaires were used to analyze the data. It was concluded that information technology risks have a negatively effect on the AIS systems by 47.6% before the mediation of internal control, and that technology risks have a negative impact on the AIS systems after ICS mediation by 25.3%, where part of the impact is transmitted through internal control. Constantly updating them, paying attention to integrity, confidentiality, and information, keeping pace with technological developments, and effectively monitoring the implementation of the security policy contributes to raising the information security level and reducing the negative impact of information technology risks.</p>
                <p>
                    <xref ref-type="bibr" rid="ref1">Abdel-Jaber (2013)</xref> identified the validity of ICS procedures in Jordanian industrial companies by the electronic accounting information systems in the reduction of their information security risks. In addition, the obstacles impact this effectiveness by the identification of three types of risks that threaten the AIS systems, such as network hacking risks, social engineering risks, and malware risks. For the achievement of the study objectives, a questionnaire was given to the study sample consisting of thirty industrial companies operating in the Hashemite Kingdom of Jordan using accounting information systems. For the data analysis, the statistical methods represented by arithmetic averages, standard deviations, Kruskal Wallace test, Mann and Wintney test, and the test was used. The ICS procedures provided information security in Jordanian industrial companies through its prevention, detection, and correction, the researcher recommended the need for the department to carry out ICS activities on information security through the provision of qualified cadres, and motivating employees&#x2019; industrial companies for obtaining relevant professional certificates.</p>
                <p>Based on the results of previous studies, the following hypothesis was developed:
                    <statement id="state1">
                        <label>H1:</label>
                        <p>There is no statistically significant effect of internal control on accounting information security in government banks in Anbar Governorate.</p>
                    </statement>
                </p>
                <p>

                    <bold>2. Internal Control and Cybersecurity Awareness</bold>
                </p>
                <p>
                    <xref ref-type="bibr" rid="ref19">Mohamed (2024)</xref> shed light on the role played by SAIs in evaluating information systems and cybersecurity, with a focus on the challenges facing audit institutions and their importance in enhancing governance and transparency. The researcher adopted the inductive analytical method, where a theoretical framework was presented for the evaluation of information systems and cybersecurity, the study found out an importance for a comprehensive understanding of the basic concepts of information systems control and cybersecurity and the identification of the main objectives of information technology audit. The study also found that strengthening control aspects of information systems and cybersecurity not only contributes to achieving transparency and efficiency but also contributes to enhancing trust between the public and institutions making sure the business continuity and protection of the sensitive data from cyber-attacks.</p>
                <p>
                    <xref ref-type="bibr" rid="ref17">Mansour (2021)</xref> Showed that cybersecurity is important through its effect on ICS and the economic unit value by the adoption of the Information Technology Governance Framework, (COBIT5). The descriptive-analytical approach was used in the data collection along with a questionnaire that included a set of questions divided into eight axes that reflect the research requirements, using Google Forms, and Steven&#x2019;s equation. Thompson was adopted in determining the size of the sample (98 auditors and accountants) working in higher education and scientific research. There was and general agreement on the relationship between the dimensions and requirements of cybersecurity on the modern frameworks of ICS COBIT5 and the value of economic unity. There was a need for the economic unit to adopt effective means of continuous evaluation of ICS to maintain information security by adopting COBIT5 by integrating procedures and characteristic ICS according to modern frameworks for avoiding the means of penetrating electronic systems and manipulating their information.</p>
                <p>Based on the results of previous studies, the following hypothesis was developed:
                    <statement id="state2">
                        <label>H2:</label>
                        <p>There is no statistically significant effect of internal control on cybersecurity awareness in government banks in Anbar Governorate.</p>
                    </statement>
                </p>
                <p>

                    <bold>3. Internal control, cybersecurity awareness, and accounting information security</bold>
                </p>
                <p>
                    <xref ref-type="bibr" rid="ref5">Al-Qusayr (2024)</xref> designed and developed an information technology governance model to reduce cyber risks and enhance the AIS in Libyan public institutions. The researcher followed the descriptive-analytical approach by reviewing previous studies, reports, models, best practices and related literature, and the study reached a conclusion that the most important pillars of the proposed model were: governance, the Information Technology Governance Committee and its mechanisms, and the independence of the internal auditor, with an emphasis on risk management, active and continuous control, transparency and accountability.</p>
                <p>Based on the results of previous studies, the following hypothesis was developed:
                    <statement id="state3">
                        <label>H3:</label>
                        <p>There is no statistically significant effect of cybersecurity awareness on accounting information security in government banks in Anbar Governorate.</p>
                    </statement>

                    <statement id="state4">
                        <label>H4:</label>
                        <p>There is no statistically significant effect of internal control on accounting information security when cybersecurity awareness is present as a mediating variable.</p>
                    </statement>
                </p>
            </sec>
            <sec id="sec16">
                <title>3.2 Informed consent</title>
                <p>All survey participants were adults of sound mind and legal capacity; no minors were included. They are employees in various administrative positions at Al-Rasheed Bank and provided their voluntary verbal consent before participating. This was due to the nature of the study, the limited risks involved, and the fact that the research procedures did not pertain to health or medical issues. The participants&#x2019; social and cultural context was also taken into consideration. They were informed of the study&#x2019;s purpose and nature and assured that their responses did not include personal information or any statements related to racial discrimination. Instead, they provided data related to cybersecurity, the protection of accounting information, and internal controls.</p>
            </sec>
            <sec id="sec17">
                <title>3.3 Ethical considerations</title>
                <p>The information contained in this research is complete and accurate and does not violate internationally recognized laws and ethics, as approved by the Research Ethics Committee at the University of Fallujah. This research has received approval from the Research Ethics Committee of the College of Administration and Economics at the University of Fallujah, under number [UOF.HUM.2025.001].</p>
            </sec>
            <sec id="sec18">
                <title>3.4 Population and sampling procedure</title>
                <p>The research included a community represented by the government banking sector (Rashid Bank), where a sample was chosen from this community represented by employees and workers in the departments related to the nature of the studied variables, especially the accounts and financial affairs departments and the departments related to information security in this bank in its branches in the cities of Fallujah and Ramadi.</p>
                <p>

                    <bold>3.4.1 Sample Description and Demographic Characteristics</bold>
                </p>
                <p>The characteristics of the sample covered by this study include gender, nature of work, type of academic degree, years of professional experience, academic title, and academic qualification. 
                    <xref ref-type="table" rid="T1">
Table 1</xref> shows the detailed distribution of the demographic characteristics of the participants, which shows that most of the sample members are male, and most of them work in academic and financial fields, with a clear predominance of those with academic degrees, and a diversity in levels of experience and educational qualifications.</p>
                <table-wrap id="T1" orientation="portrait" position="float">
                    <label>
Table 1. </label>
                    <caption>
                        <title>Demographic characteristics of the sample.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Variable</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Category</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Category number of individuals</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Percentage (%)</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="6" valign="top">Age</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">30 years younger</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">20%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">31-35 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">15</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">30%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">36-40 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">18%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">41-45 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">18%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">46-50 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">6</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">12%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Over 50 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="5" valign="top">Academic qualification</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Bachelor&#x2019;s</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">24</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">48%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Higher Diploma</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">6%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Master&#x2019;s</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">16</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">32%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Doctorate</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Other (specify)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">3</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">6%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="6" valign="top">Scientific specialization</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Accounting</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">20</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">40%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Business Administration</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">16%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Economics</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Public Administration</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Financial and Banking Studies</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">18%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Other (specify)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">9</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">18%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="4" valign="top">Job title</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Department Manager</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">20%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Auditor</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">16%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Accountant</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">11</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">22%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Other (specify)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">21</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">42%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="5" valign="top">Years of experience</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Under 5 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">15</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">30%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">6-10 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">10</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">20%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">11-15 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">13</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">26%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">16-20 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">16%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Over 20 years</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8%</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Total</td>
                                <td colspan="1" rowspan="1"/>
                                <td align="left" colspan="1" rowspan="1" valign="top">50</td>
                                <td colspan="1" rowspan="1"/>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>The results of the descriptive analysis of the demographic characteristics of the research sample of 50 individuals show that the sample is characterized by young professionals with high academic qualifications. The sample was concentrated in the age group of 35 years or younger, and 80% of them hold a bachelor&#x2019;s or master&#x2019;s degree. There is also a very high concentration of financial and administrative specializations, with 40% of the sample majoring in accounting and 16% in business administration. In terms of experience, the sample exhibits a good balance between intermediate and advanced experience, with 46% of the sample having between 15 and 20 years of experience, and 24% having between 16 and 20 years of experience, creating a good balance between new and experienced talent. Job titles show great diversity, with a good distribution between technical and administrative positions, and a large &#x201c;other&#x201d; category comprising 42% of the sample.</p>
            </sec>
            <sec id="sec19">
                <title>3.5 Developing the study tool</title>
                <p>The research tool is based on a set of variables that represent the conceptual framework of the research. The research tool includes three main variables: The first variable is the independent variable, which represents internal control, which was measured through five main indicators: the control environment; control activities; follow-up; risk assessment; information and communication. This variable includes (25 items). The second variable is the dependent variable, which represents accounting information security. It was measured as a standardized variable, including (8 items). The third variable is the mediating variable, which is cybersecurity awareness. It was also measured as a standardized variable, through (8 items). Details of the variables, their dimensions, and the number of paragraphs is presented in 
                    <xref ref-type="table" rid="T2">
Table 2</xref>.</p>
                <table-wrap id="T2" orientation="portrait" position="float">
                    <label>
Table 2. </label>
                    <caption>
                        <title>Research variables.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Variable type</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Variable</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Abbreviation</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Dimensions/Components</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">No. of paragraphs</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="5" valign="top">
                                    <bold>Independent Variable</bold>
</td>
                                <td align="left" colspan="1" rowspan="5" valign="top">Internal Control</td>
                                <td align="left" colspan="1" rowspan="5" valign="top">IC</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Control Environment (CE)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Control Activities (CA)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Monitoring (MON)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Risk Assessment (RA)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Information and Communication (IC)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">5</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Dependent Variable</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Accounting Information Security</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">(As a unified concept)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>Mediating Variable</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Cybersecurity Awareness</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">CAW</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">(As a unified concept)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec20">
                <title>3.6 Data collection procedures</title>
                <p>The research relied on a questionnaire as the primary means of collecting data related to the research variables. The questionnaires were distributed directly to a group of officials and employees specializing in internal control and cybersecurity, employees working on accounting data processing, and financial report preparers at the Rashid Bank in its two branches in Fallujah and Anbar. The aim was to ensure that the respondents were aware of the nature and accuracy of the questions. A total of 50 questionnaires were distributed, all of which were returned, reflecting a high degree of seriousness and cooperation from the participants. The process of distributing and retrieving the questionnaires took a month and a half, including filtering and organizing the data until it was ready for statistical analysis.</p>
            </sec>
            <sec id="sec21">
                <title>3.7 Analytical framework (Quantitative)</title>
                <p>To test and discuss hypotheses and evaluate the relationship between variables, quantitative analysis was used, relying on the statistical software SmartPLS, which specializes in structural equation modeling (SEM). This modeling is typically used to explain multiple statistical relationships simultaneously through visualization and model validation. Complex models can be easily discussed using this technique. It is an extension of traditional linear modeling techniques, such as multiple regression analysis and analysis of variance (ANOVA), which are essential requirements for learning structural equation modeling. This modeling adopts a confirmatory approach rather than an exploratory approach. Thus, we will model the impact of internal control on accounting information security, both directly and indirectly through cybersecurity awareness.</p>
            </sec>
            <sec id="sec22">
                <title>3.8 Model specifications</title>
                <p>The mathematical model was designed to measure the effect of the independent variable, internal control (IC), on the dependent variable, accounting information security (AIS). An intermediate variable, cybersecurity awareness, was also introduced to examine whether this awareness conveys (or mediates) the effect of internal control on information security. For modeling purposes, internal control is a multidimensional variable consisting of its five components (control environment, control activities, monitoring, risk assessment, and information and communication), while the other variables include multiple indicators that serve as the basis for measuring these variables.</p>
                <p>To ensure the accuracy of the results and obtain reliable confidence intervals, the model was first tested using the PLS-SEM algorithm. The purpose is to verify the model&#x2019;s reliability and validity. Bootstrapping will then be used as the primary analysis tool within the structural equation modeling program.</p>
                <p>The structural structure of the mathematical model can be seen in 
                    <xref ref-type="fig" rid="f1">
Figure 1</xref>.</p>
                <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                    <label>
Figure 1. </label>
                    <caption>
                        <title>Conceptual model.</title>
                    </caption>
                    <graphic id="gr1" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/193402/3e0730d7-81a0-4d81-a5c0-2dab78282a61_figure1.gif"/>
                </fig>
                <p>Below is the estimation of the mathematical model based on the structured hypothetical relationships, which will be statistically examined:
                    <disp-formula id="e1">

                        <mml:math display="block">
                            <mml:mi mathvariant="bold">AIS</mml:mi>
                            <mml:mo>=</mml:mo>
                            <mml:msub>
                                <mml:mi>a</mml:mi>
                                <mml:mn>0</mml:mn>
                            </mml:msub>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>&#x03b2;</mml:mi>
                                <mml:mn>1</mml:mn>
                            </mml:msub>
                            <mml:mi mathvariant="italic">IC</mml:mi>
                            <mml:mo>+</mml:mo>
                            <mml:mi>&#x03b5;</mml:mi>
                        </mml:math>

                        <label>(1)</label>
</disp-formula>

                    <disp-formula id="e2">

                        <mml:math display="block">
                            <mml:mi mathvariant="bold-italic">CAW</mml:mi>
                            <mml:mo>=</mml:mo>
                            <mml:msub>
                                <mml:mi>a</mml:mi>
                                <mml:mn>0</mml:mn>
                            </mml:msub>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>&#x03b2;</mml:mi>
                                <mml:mn>2</mml:mn>
                            </mml:msub>
                            <mml:mi mathvariant="italic">IC</mml:mi>
                            <mml:mo>+</mml:mo>
                            <mml:mi>&#x03b5;</mml:mi>
                        </mml:math>

                        <label>(2)</label>
</disp-formula>

                    <disp-formula id="e3">

                        <mml:math display="block">
                            <mml:mi mathvariant="bold">AIS</mml:mi>
                            <mml:mo>=</mml:mo>
                            <mml:msub>
                                <mml:mi>a</mml:mi>
                                <mml:mn>0</mml:mn>
                            </mml:msub>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>&#x03b2;</mml:mi>
                                <mml:mn>1</mml:mn>
                            </mml:msub>
                            <mml:mi mathvariant="italic">IC</mml:mi>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>&#x03b2;</mml:mi>
                                <mml:mn>3</mml:mn>
                            </mml:msub>
                            <mml:mi mathvariant="italic">CAW</mml:mi>
                            <mml:mo>+</mml:mo>
                            <mml:mi>&#x03b5;</mml:mi>
                        </mml:math>

                        <label>(3)</label>
</disp-formula>
</p>
            </sec>
        </sec>
        <sec id="sec23">
            <title>4-Evaluation of the mathematical model (Reliability and internal consistency)</title>
            <p>To evaluate reliability and internal consistency, the Loadings test, Cronbach&#x2019;s alpha coefficient and composite reliability rho_c were used. The results showed that the reliability and internal consistency analysis of the mathematical model adopted in the research showed that the measurement tools were characterized by a very high level of reliability and validity, indicating the quality of the statistical design and the integrity and validity of the data for statistical analysis. The results shown in 
                <xref ref-type="table" rid="T3">
Table 3</xref> related to the Cronbach&#x2019;s alpha test showed that the reliability values exceeded the acceptable statistical limit of (0.70) for all variables, ranging between (0.886-0.928). This indicates a high degree of internal consistency between the items of each variable, and that all items measure the same dimension with a high degree of accuracy and consistency. The results of the composite reliability test also confirmed very high values, exceeding (0.90) for all variables, which confirms that the indicators used measure and interpret the latent dimensions in a stable and consistent manner. The results of the weighted average variance (AVE) showed that all values were greater than 0.50, which is the minimum statistically acceptable value. This confirms that the model has convergent validity, meaning that the items can explain most of the variance occurring in the latent variables. This confirms that the model accurately measures what it is supposed to measure; and P-values reached 0.000, which is a strong indication that the correlation coefficients between the items and the latent variables are real and not the result of statistical chance (see 
                <xref ref-type="table" rid="T3">
Table 3</xref>).</p>
            <table-wrap id="T3" orientation="portrait" position="float">
                <label>
Table 3. </label>
                <caption>
                    <title>Reliability and internal consistency.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top"/>
                            <th align="left" colspan="1" rowspan="1" valign="top">Cronbach&#x2019;s alpha</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Composite reliability (rho_a)</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Composite reliability (rho_c)</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Average variance extracted (AVE)</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">AIS</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.925</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.932</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.939</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.658</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">CAW</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.886</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.891</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.910</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.560</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Internal control</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.928</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.931</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.946</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.778</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>The results of the outer loadings test show that all items related to the study variables had positive and significant loadings, exceeding the standard value level of 0.70 (see 
                <xref ref-type="table" rid="T4">
Table 4</xref>). This indicates that each item of the variables contributes to measuring the variable to which it belongs. Furthermore, items with loadings slightly lower than this level are still acceptable due to their high statistical significance. Thus, it can be concluded that the proposed model possesses a high degree of stability and validity, and that the research measurement tools used meet the statistical quality requirements required by partial structural equation models (PLS-SEM). These results confirm the possibility of relying on current research data to test causal relationships between variables with high confidence, giving the model explanatory power and high scientific credibility. 
                <bold>See</bold> 
                <xref ref-type="fig" rid="f2">
Figure 2</xref> To test the discriminator validity of the study model, the Heterotrait-Monotrait Ratio (HTMT) was used. The results of the discriminator validity test showed that all values fall within the statistically acceptable levels (see 
                <xref ref-type="table" rid="T5">
Table 5</xref>). All variable results fall between (0.839-0.871), which is less than the recommended maximum (0.90). These statistics confirm that each variable in the model is distinct from the other variables, meaning that there is a clear distinction between the measured concepts and no overlap between them. The results also showed that the confidence interval (2.5% - 97.5%) for all relationships did not exceed the critical value (1.00), which enhances the discriminator validity of the model and confirms that each dimension measures a different and specific aspect of the phenomenon studied. Thus, the discriminator validity of the latent model is well achieved.</p>
            <table-wrap id="T4" orientation="portrait" position="float">
                <label>
Table 4. </label>
                <caption>
                    <title>Outer loadings results.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top"/>
                            <th align="left" colspan="1" rowspan="1" valign="top">AIS</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">CAW</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Internal control</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">CA</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.907</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">CE</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.907</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">IC</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.892</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">MON</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.881</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">RA</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.821</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais1</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.794</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais2</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.857</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais3</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.749</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais4</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.720</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais5</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.864</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais6</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.836</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais7</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.843</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">ais8</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.813</td>
                            <td colspan="1" rowspan="1"/>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw1</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.695</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw2</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.792</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw3</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.805</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw4</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.810</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw5</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.682</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw6</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.852</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw7</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.646</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">caw8</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.679</td>
                            <td colspan="1" rowspan="1"/>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <fig fig-type="figure" id="f2" orientation="portrait" position="float">
                <label>
Figure 2. </label>
                <caption>
                    <title>Outer loading and R
                        <sup>2</sup> in PLS-SEM algorithm.</title>
                </caption>
                <graphic id="gr2" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/193402/3e0730d7-81a0-4d81-a5c0-2dab78282a61_figure2.gif"/>
            </fig>
            <table-wrap id="T5" orientation="portrait" position="float">
                <label>
Table 5. </label>
                <caption>
                    <title>Discriminant validity (Heterotrait-Monotrait Ratio -HTMT).</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top"/>
                            <th align="left" colspan="1" rowspan="1" valign="top">Original sample (O)</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Sample mean (M)</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Bias</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">2.5%</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
97.5%</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">CAW&lt;-&gt; AIS</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.850</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.866</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.015</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.655</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.998</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Internal control &lt;-&gt; AIS</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.839</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.844</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.005</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.738</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.908</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Internal control &lt;-&gt; CAW</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.871</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.871</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.743</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">0.943</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec24">
            <title>5- Evaluation of the structural model</title>
            <sec id="sec25">
                <title>5-1 Coefficient of determination and explanatory power of the model (R2)</title>
                <p>The results of the adjusted R
                    <sup>2</sup> indicate that the explanatory power of the developed model is large and solid, as it explains a large proportion of the variance in the dependent variables (see 
                    <xref ref-type="table" rid="T6">
Table 6</xref>). The adjusted R
                    <sup>2</sup> value for the AIS variable reached 0.676, meaning that approximately 68% of the variation in internal control in the studied government banks can be explained by the AIS variable. Similarly, for the CAW variable, the adjusted R
                    <sup>2</sup> value reached 0.624, meaning that the model explains approximately 62% of the variance in internal control due to the cyber awareness variable. The above results indicate a high explanatory power and demonstrate the effectiveness of the independent variables in explaining the variance in internal control in the studied government banks. The T-statistics results also showed values of 7.445 and 8.991, with a significance level of P = 0.000. These values confirm that the relationships between the variables are truly statistically significant and are not caused by chance. This indicates that the model has very good explanatory power, and that the variables used represent realistic and influential interactions within the theoretical framework of the research, which enhances the strength and stability of the results (see 
                    <xref ref-type="fig" rid="f2">
Figure 2</xref>).</p>
                <table-wrap id="T6" orientation="portrait" position="float">
                    <label>
Table 6. </label>
                    <caption>
                        <title>Coefficient of determination R2 adjusted.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top"/>
                                <th align="left" colspan="1" rowspan="1" valign="top">R-square
</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">R-square adjusted</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">T statistics (|O/STDEV|)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.689</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.676</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">7.445</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">CAW</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.632</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.624</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">8.991</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <p>To test for multicollinearity between the independent variables, we relied on the results of Collinearity Statistics (VIF) (see 
                    <xref ref-type="table" rid="T7">
Table 7</xref>). The VIF value for both the CAW path to AIS and the Internal Control path to AIS was approximately 2.716, which is well below the critical threshold of 5. This means that each variable contributes to explaining the dependent variable to an independent degree, without significantly affecting the other. The relationship between internal control and cyber awareness showed a VIF value of 1.000, which is completely ideal and indicates the absence of any linear correlation between them. These results indicate that the model enjoys a high degree of independence between the explanatory (independent) variables, and that the estimated causal relationships reflect the true effects of the variables without bias resulting from statistical interference, enhancing the reliability of the estimates and the quality of the results of the structural model.</p>
                <table-wrap id="T7" orientation="portrait" position="float">
                    <label>
Table 7. </label>
                    <caption>
                        <title>Inner model collinearity statistics (VIF).</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top"/>
                                <th align="left" colspan="1" rowspan="1" valign="top">Original sample (O)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Sample mean (M)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">2.5%</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
97.5%</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">CAW -&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.716</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.920</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.982</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4.230</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.716</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.920</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.982</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">4.230</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; CAW</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.000</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.000</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.000</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">1.000</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
            <sec id="sec26">
                <title>5-2 Hypothesis testing (Path analysis)</title>
                <p>In hypothesis testing, bootstrapping was used, which is the second step in model analysis using the PLS-SEM method. It is used to test the significance of paths and causal relationships between variables in the internal model. Bootstrapping was performed with a power of 5,000 samples to estimate the standard error and extract statistical values (T-values and P-values) that determine the significance of the hypothesized relationships between variables and determine the significance and strength of the relationship using paths between the studied variables.</p>
                <p>The results of the statistical analysis presented in 
                    <xref ref-type="table" rid="T8">
Tables 8</xref>-
                    <xref ref-type="table" rid="T10">10</xref> and 
                    <xref ref-type="fig" rid="f3">
Figure 3</xref> showed that all the hypothesized relationships in the statistical model achieved significant significance at the level of (0.05), which reflects the strength of the internal model and its predictive validity. When presenting the detailed results shown in Table (9) related to the direct impact between the variables, these results indicate the presence of a direct and significant positive impact of the internal control variable (IC) on accounting information security (AIS), as the original sample value reached (O = 0.786) with a high t-statistic value (T = 19.001) and a probability value (P = 0.000), which indicates that the internal control variable contributes significantly to enhancing accounting information security within government banks in Anbar Governorate. These results do not support hypothesis (H1), which states that there is no impact of internal control on accounting information security. The results also showed that internal control also has a statistically significant, positive effect at a confidence level of less than 0.005 on cybersecurity awareness (CAW), with an effect value of (O = 0.795, T = 18.447, P = 0.000). This indicates that activating internal control elements contributes to raising the level of awareness and commitment to cybersecurity among employees of the banks under study. This result does not support hypothesis (H2), which states that internal control has no effect on cybersecurity awareness. With the same result, the results showed that awareness of cybersecurity affects the security of accounting information. The results of 
                    <xref ref-type="table" rid="T9">
Table 9</xref> showed that the relationship is positive and statistically significant according to the values (O = 0.438, T = 2.206, P = 0.027). These results confirm that increasing awareness of cybersecurity leads to improving the protection of accounting systems from potential threats and breaches in the banks under study. These results do not support hypothesis (H3), which states that there is no effect of awareness of cybersecurity on the security of accounting information. The results, as shown in 
                    <xref ref-type="table" rid="T10">
Table 10</xref>, regarding the indirect effect, also showed that cybersecurity awareness plays a statistically significant mediating role in the relationship between internal control and accounting information security. The indirect effect value was (O = 0.348, T = 2.105, P = 0.035), indicating that part of the impact of internal control on accounting information security is transmitted through the level of cybersecurity awareness. This result does not support Hypothesis (H4), which states that cybersecurity awareness has no effect on the relationship between internal control and accounting information security.</p>
                <table-wrap id="T8" orientation="portrait" position="float">
                    <label>
Table 8. </label>
                    <caption>
                        <title>Total indirect effect.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top"/>
                                <th align="left" colspan="1" rowspan="1" valign="top">Original sample (O)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Sample mean (M)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Standard deviation (STDEV)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
T statistics (|O/STDEV|)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.348</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.384</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.165</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.105</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.035</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <table-wrap id="T9" orientation="portrait" position="float">
                    <label>
Table 9. </label>
                    <caption>
                        <title>Total indirect effect.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top"/>
                                <th align="left" colspan="1" rowspan="1" valign="top">Original sample (O)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Sample mean (M)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Standard deviation (STDEV)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
T statistics (|O/STDEV|)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">CAW-&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.438</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.478</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.199</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.206</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.027</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.786</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.797</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.041</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">19.001</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.008</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; CAW</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.795</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.802</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.043</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">18.447</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.000</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <table-wrap id="T10" orientation="portrait" position="float">
                    <label>
Table 10. </label>
                    <caption>
                        <title>Specific indirect effect.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top"/>
                                <th align="left" colspan="1" rowspan="1" valign="top">Original sample (O)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Sample mean (M)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Standard deviation (STDEV)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
T statistics (|O/STDEV|)</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
P values</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">Internal control -&gt; CAW -&gt; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.348</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.384</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.165</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">2.105</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">0.035</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
                <fig fig-type="figure" id="f3" orientation="portrait" position="float">
                    <label>
Figure 3. </label>
                    <caption>
                        <title>Direct and indirect effects results.</title>
                    </caption>
                    <graphic id="gr3" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/193402/3e0730d7-81a0-4d81-a5c0-2dab78282a61_figure3.gif"/>
                </fig>
                <p>The previous results related to the mediating relationship are confirmed in 
                    <xref ref-type="table" rid="T8">
Table 8</xref>, where it was shown that the estimated value of the total indirect effect of internal control on accounting information security was statistically significant and positive, reinforcing the hypothesis that cybersecurity awareness is a key factor in the hypothesized model and has a positive effect.</p>
                <p>In conclusion, it can be concluded that the structural model shown in 
                    <xref ref-type="fig" rid="f3">
Figure 3</xref> has proven highly efficient in explaining the impact relationships between the studied variables. The high values of T and low P indicate that the relationships between the studied variables in the model are not a coincidence, but rather reflect a logical and practical connection between internal control (IC), cybersecurity awareness (CAW), and accounting information security (AIS), in line with modern theoretical trends that confirm that creating a strong internal control environment and raising the level of cybersecurity awareness together help in enhancing the security of accounting information in the studied banking institutions. (See the summary of the hypothesis testing, 
                    <xref ref-type="table" rid="T11">
Table 11</xref>).</p>
                <table-wrap id="T11" orientation="portrait" position="float">
                    <label>
Table 11. </label>
                    <caption>
                        <title>Hypothesis testing summary.</title>
                    </caption>
                    <table content-type="article-table" frame="hsides">
                        <thead>
                            <tr>
                                <th align="left" colspan="1" rowspan="1" valign="top">Hyp.</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Statement</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Path tested</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">Result</th>
                                <th align="left" colspan="1" rowspan="1" valign="top">
Conclusion</th>
                            </tr>
                        </thead>
                        <tbody>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>H1</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">There is no statistically significant effect of internal control on accounting information security in government banks in Anbar Governorate.</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">IC &#x2192; AIS (Direct Effect)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">&#x03b2; = 0.786, T = 19.00, p = 0.008 (significant)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rejected</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>H2</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">There is no statistically significant effect of internal control on cybersecurity awareness in government banks in Anbar Governorate.</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">IC &#x2192; CAW</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">&#x03b2; = 0.795, T = 18.447, p = 0.000</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rejected</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>H3</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">There is no statistically significant effect of cybersecurity awareness on accounting information security in government banks in Anbar Governorate.</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">CAW &#x2192; AIS</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">&#x03b2; = 0.438, T = 2.206, p = 0.027</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rejected</td>
                            </tr>
                            <tr>
                                <td align="left" colspan="1" rowspan="1" valign="top">
                                    <bold>H4</bold>
</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">There is no statistically significant effect of internal control on accounting information security when cybersecurity awareness is present as a mediating variable.</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">IC &#x2192; CAW &#x2192; AIS (Indirect Effect)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Indirect effect = 0.348, T = 2.105, p = 0.035 (Significant positive mediation)</td>
                                <td align="left" colspan="1" rowspan="1" valign="top">Rejected</td>
                            </tr>
                        </tbody>
                    </table>
                </table-wrap>
            </sec>
        </sec>
        <sec id="sec27">
            <title>6. Discussion of results</title>
            <p>The results of the statistical analysis showed that the internal control environment in the banks under study enjoys a good level of implementation, as senior management demonstrated a clear interest in control reports and the principle of individual and collective responsibility for control. It also became clear that financial and administrative reports are effectively used as a control tool to help improve performance and identify deviations, reflecting organizational awareness of the importance of control activities in supporting the stability of banking operations. The results also showed that accounting information security is one of the most important elements of accounting system efficiency, as the bank is committed to keeping data confidential, restricting access rights, and maintaining backup copies. This enhances management&#x2019;s confidence in the accuracy of information and decision-making. Regarding cybersecurity awareness, it was found that employees have a good understanding of the nature of cyber risks and the need to adhere to security measures, such as changing passwords, not sharing them, and examining the sources of emails. However, the results indicated a need for further training courses to enhance the efficiency of employees in this field. In general, the results revealed a complementary relationship between the internal control environment, information security, and cybersecurity awareness, with each contributing to the enhancement of the other. The stronger and more effective the internal control environment, the greater the ability to protect data and information. As employees&#x2019; cybersecurity awareness increases, the effectiveness of this control increases, and the quality of the accounting system improves.</p>
        </sec>
        <sec id="sec28">
            <title>7. Conclusion and recommendation</title>
            <p>In conclusion, this research, which examined the relationship between the internal control environment, accounting information security, and cybersecurity awareness in banks, sought to clarify the vital role played by effective control systems in enhancing information security and ensuring the integrity of financial and accounting procedures. This topic is particularly important considering the accelerating digital transformation taking place in the banking sector and the accompanying cyber risks that require institutional readiness and high professional awareness among employees.</p>
            <p>The research reached a set of important findings that summarize the essence of the objectives achieved. The results of the statistical analysis showed that the internal control environment in the banks studied enjoys an acceptable level of organization and effectiveness, and that senior management pays clear attention to audit reports and the application of the principles of segregation of duties and responsibilities, which positively impacts the stability of internal operations. It also revealed that accounting information security represents a fundamental pillar of the accounting system, as banks implement precise procedures to protect data and its confidentiality and continuously update their security systems. Regarding cybersecurity awareness, the results showed that employees are aware of the importance of protecting electronic systems, despite the need for further training and awareness to address the rapid developments in this field.</p>
            <p>Based on these results, it can be said that the research clearly answered the question posed at the outset: to determine the extent to which the internal control environment, information security, and cybersecurity awareness impact the efficiency of the accounting system and the protection of its data. The results demonstrated a complementary relationship between these dimensions, with each contributing to the support of the other. This confirms that effective information protection can only be achieved through a robust control system and an institutional culture based on awareness and responsibility. From the above, several conclusions and recommendations can be drawn, the most important of which is that a strong control system represents the cornerstone of information security, and that developing the technological infrastructure is not sufficient unless accompanied by high human and professional awareness. Therefore, it is recommended to strengthen the role of internal audit units and update their policies periodically. It is also recommended to intensify training programs that enhance employees&#x2019; awareness of cyber risks, in addition to encouraging cooperation between audit, risk, and information technology departments to ensure integrated protection of financial systems.</p>
        </sec>
    </body>
    <back>
        <sec id="sec31" sec-type="data-availability">
            <title>Data availability statement</title>
            <sec id="sec32">
                <title>Underlying data</title>
                <p>

                    <bold>Repository Name:</bold> [Study data entitled: Cybersecurity Awareness as a Mediating Variable in the Relationship between Industrial Control Systems and Management Information Systems in Iraqi Government Banks] available at 
                    <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5281/zenodo.18100387">https://doi.org/10.5281/zenodo.18100387</ext-link> (
                    <xref ref-type="bibr" rid="ref4">Al-Mohammedi et al., 2025</xref>)</p>
                <p>The project contains the following Underlying data:
                    <list list-type="bullet">
                        <list-item>
                            <label>-</label>
                            <p>

                                <bold>[Questionnaire Form.doc]</bold> (This file contains a questionnaire list designed using a five-point Likert scale, including variables, indicators, and items).</p>
                        </list-item>
                        <list-item>
                            <label>-</label>
                            <p>

                                <bold>[data.xlsx]</bold> (This file contains the raw data used in the statistical analysis, which was collected from the target study sample.)</p>
                        </list-item>
                    </list>
                </p>
                <p>Data are available under the terms of the 
                    <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International license</ext-link> (CC-BY 4.0).</p>
            </sec>
        </sec>
        <ref-list>
            <title>References</title>
            <ref id="ref1">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Abdel-Jaber</surname>
                            <given-names>YK</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">The Effectiveness of Control Procedures in Providing Electronic Information Security in Jordanian Industrial Companies.</italic>
</source>
                    <publisher-loc>Jordan</publisher-loc>:
                    <publisher-name>Middle East University, Faculty of Business, Department of Accounting and Finance</publisher-name>;<year>2013</year>. Unpublished Master&#x2019;s Thesis.</mixed-citation>
            </ref>
            <ref id="ref2">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Abdullah</surname>
                            <given-names>KA</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Auditing from a Theoretical and Practical Perspective.</italic>
</source>
                    <year>2007</year>;
                    <publisher-loc>Amman</publisher-loc>:
                    <publisher-name>Dar Wael for Publishing and Distribution</publisher-name>.</mixed-citation>
            </ref>
            <ref id="ref3">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Al-Hawamleh</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>Cyber resilience framework: Strengthening defenses and enhancing continuity in business security.</article-title>
                    <source>

                        <italic toggle="yes">International Journal of Computing and Digital Systems.</italic>
</source>
                    <year>2024</year>;<volume>15</volume>(<issue>1</issue>):<fpage>1315</fpage>&#x2013;<lpage>1331</lpage>.</mixed-citation>
            </ref>
            <ref id="ref4">
                <mixed-citation publication-type="data">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Al-Mohammedi</surname>
                            <given-names>YA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Tarkh</surname>
                            <given-names>AS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Al-Jumaili</surname>
                            <given-names>HN</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <data-title>Data from the study sample titled &#x2013;Cybersecurity Awareness as a Mediating Variable in the Relationship between ICS and AIS in Iraqi State Banks.</data-title>[Data set].
                    <source>

                        <italic toggle="yes">Zenodo.</italic>
</source>
                    <year>2025</year>.
                    <pub-id pub-id-type="doi">10.5281/zenodo.18100387</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref5">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Al-Qusayr</surname>
                            <given-names>IM</given-names>
                        </name>
</person-group>:
                    <article-title>Information Technology Governance to Reduce Cyber Risks and Enhance AIS in Libyan Public Institutions &#x2013; A Proposed Model.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Academic Research (Administrative and Financial Sciences).</italic>
</source>
                    <year>2024</year>;<volume>2</volume>(<issue>28</issue>):<fpage>10</fpage>.</mixed-citation>
            </ref>
            <ref id="ref6">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Al-Sorihi</surname>
                            <given-names>SAA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alrubaidi</surname>
                            <given-names>MA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Al-Hemya</surname>
                            <given-names>NHA</given-names>
                        </name>
</person-group>:
                    <article-title>The Mediating Role of Security Controls between Information-technology Risks and the AIS Systems: A Field Study in Telecommunication Companies Operating in the Republic of Yemen.</article-title>
                    <source>

                        <italic toggle="yes">Jordan Journal of Business Administration.</italic>
</source>
                    <year>2025</year>;<volume>21</volume>(<issue>1</issue>):<fpage>2025</fpage>.
                    <pub-id pub-id-type="doi">10.35516/jjba.v21i1.270</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref7">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Andersson</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bjursell</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Palm</surname>
                            <given-names>I</given-names>
                        </name>
</person-group>:
                    <article-title>Hack the human: A qualitative research study exploring the human factor and social engineering awareness in cybersecurity and risk management among Swedish organisations.</article-title>
                    <year>2023</year>.</mixed-citation>
            </ref>
            <ref id="ref8">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Asif</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>What is information security? principles, types.</article-title>
                    <year>2023</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.knowledgehut.com/blog/security/what-is-information-security">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref9">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ben Alqama</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Saahi</surname>
                            <given-names>Y</given-names>
                        </name>
</person-group>:
                    <article-title>The role of financial technology in supporting financial and banking sectors.</article-title>
                    <source>

                        <italic toggle="yes">Al Ijtihad Journal of Legal and Economic Studies.</italic>
</source>
                    <year>2019</year>;<volume>7</volume>(<issue>3</issue>):<fpage>85</fpage>&#x2013;<lpage>107</lpage>.</mixed-citation>
            </ref>
            <ref id="ref10">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bozkus Kahyaoglu</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Caliyurt</surname>
                            <given-names>K</given-names>
                        </name>
</person-group>:
                    <article-title>Cyber security assurance process from the internal audit perspective.</article-title>
                    <source>

                        <italic toggle="yes">Manag. Audit. J.</italic>
</source>
                    <year>2018</year>;<volume>33</volume>(<issue>4</issue>):<fpage>360</fpage>&#x2013;<lpage>376</lpage>.</mixed-citation>
            </ref>
            <ref id="ref29">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <collab>Committee of Sponsoring Organizations of the Treadway (COSO)</collab>
                    </person-group>:
                    <source>

                        <italic toggle="yes">Internal control&#x2014;Integrated framework (Framework and appendices).</italic>
</source>
                    <year>2013</year>.</mixed-citation>
            </ref>
            <ref id="ref12">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Despotovi&#x0107;</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Parmakovi&#x0107;</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Miljkovi&#x0107;</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <chapter-title>Cybercrime and Cyber Security in Fintech.</chapter-title>
                    <source>

                        <italic toggle="yes">Digital Transformation of the Financial Industry: Approaches and Applications.</italic>
</source>
                    <publisher-loc>Cham</publisher-loc>:
                    <publisher-name>Springer International Publishing</publisher-name>;<year>2023</year>; pp.<fpage>255</fpage>&#x2013;<lpage>272</lpage>.</mixed-citation>
            </ref>
            <ref id="ref13">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>George</surname>
                            <given-names>AS</given-names>
                        </name>

                        <name name-style="western">
                            <surname>George</surname>
                            <given-names>AH</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Baskar</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Digitally immune systems: building robust defences in the age of cyber threats.</article-title>
                    <source>

                        <italic toggle="yes">Partners Universal International Innovation Journal.</italic>
</source>
                    <year>2023</year>;<volume>1</volume>(<issue>4</issue>):<fpage>155</fpage>&#x2013;<lpage>172</lpage>.</mixed-citation>
            </ref>
            <ref id="ref14">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Goutam</surname>
                            <given-names>RK</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Verman</surname>
                            <given-names>DK</given-names>
                        </name>
</person-group>:
                    <article-title>Top five cyber frauds.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Comput. Appl.</italic>
</source>
                    <year>2015</year>;<volume>119</volume>(<issue>7</issue>):<fpage>23</fpage>&#x2013;<lpage>25</lpage>.</mixed-citation>
            </ref>
            <ref id="ref15">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Huseynov</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mammadova</surname>
                            <given-names>U</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Aliyev</surname>
                            <given-names>E</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The impact of the transition to electronic audit on accounting behavior.</article-title>
                    <source>

                        <italic toggle="yes">Economic and Social Development: Book of Proceedings.</italic>
</source>
                    <year>2020</year>;<volume>4</volume>:<fpage>378</fpage>&#x2013;<lpage>384</lpage>.</mixed-citation>
            </ref>
            <ref id="ref16">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jamm&#x2019;e</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Alash</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <article-title>The role of financial technology in promoting Islamic finance.</article-title>
                    <source>

                        <italic toggle="yes">Al Ibtida Journal, University of Blida.</italic>
</source>
                    <year>2021</year>;<volume>11</volume>(<issue>1</issue>):<fpage>454</fpage>&#x2013;<lpage>467</lpage>.</mixed-citation>
            </ref>
            <ref id="ref17">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mansour</surname>
                            <given-names>AM</given-names>
                        </name>
</person-group>:
                    <article-title>The Impact of Cybersecurity on ICS and its Reflection on Economic Unity - An Exploratory Study of the Opinions of a Sample of Auditors and Accountants in the Ministry of Higher Education and Scientific Research.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Management and Economics in Al-Qadisiyah.</italic>
</source>
                    <year>2021</year>;<volume>46</volume>(<issue>127</issue>):<fpage>238</fpage>.</mixed-citation>
            </ref>
            <ref id="ref18">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mishra</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dhillon</surname>
                            <given-names>G</given-names>
                        </name>
</person-group>:
                    <chapter-title>Defining ICS objectives for information systems security: A value focused assessment.</chapter-title>
                    <source>

                        <italic toggle="yes">European Conference on Information Systems.</italic>
</source>
                    <year>2008</year>.</mixed-citation>
            </ref>
            <ref id="ref19">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mohamed</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Cyber Information Systems Audit - A Case Study of Cyber Information Systems Audit of the National Electricity and Gas Corporation.</italic>
</source>
                    <publisher-name>The Fourteenth Scientific Research Competition of the Arab Organization of Supreme Audit Institutions</publisher-name>;<year>2024</year>.</mixed-citation>
            </ref>
            <ref id="ref20">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Qourin</surname>
                            <given-names>HQ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Al-Siddiq</surname>
                            <given-names>AB</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Qaidwan</surname>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The role of ICS in mitigating banking risks: A case study of accredited banks in Algeria (with reference to international models).</article-title>
                    <source>

                        <italic toggle="yes">Academy for Social and Human Studies.</italic>
</source>
                    <year>2019</year>;<volume>12</volume>(<issue>1</issue>):<fpage>35</fpage>&#x2013;<lpage>45</lpage>.</mixed-citation>
            </ref>
            <ref id="ref21">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ryabov</surname>
                            <given-names>OV</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Organising Issues of Operative System of ICS in Banking Sector.</italic>
</source>
                    <publisher-loc>USA</publisher-loc>:
                    <publisher-name>Consulting company Ucom</publisher-name>;<year>2021</year>.</mixed-citation>
            </ref>
            <ref id="ref22">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shamsuddin</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Adam</surname>
                            <given-names>MA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Adnan</surname>
                            <given-names>SA</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>The effectiveness of internal audit function in managing cyber security in Malaysia&#x2019;s banking institutions.</article-title>
                    <source>

                        <italic toggle="yes">International Journal of Industrial Management.</italic>
</source>
                    <year>2018</year>;<volume>8</volume>(<issue>4</issue>).</mixed-citation>
            </ref>
            <ref id="ref23">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sharma</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Thapa</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Cybersecurity awareness, education, and behavioral change: strategies for promoting secure online practices among end users.</article-title>
                    <source>

                        <italic toggle="yes">Eigenpub Review of Science and Technology.</italic>
</source>
                    <year>2023</year>;<volume>7</volume>(<issue>1</issue>):<fpage>224</fpage>&#x2013;<lpage>238</lpage>.</mixed-citation>
            </ref>
            <ref id="ref24">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Stevens</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Dykstra</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Everette</surname>
                            <given-names>WK</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <source>

                        <italic toggle="yes">Compliance Cautions: Investigating Security Issues Associated with US Digital-Security Standards.</italic>
</source>
                    <publisher-name>NDSS</publisher-name>;<year>2020, February</year>.</mixed-citation>
            </ref>
            <ref id="ref25">
                <mixed-citation publication-type="other">
                    <collab>Stransact</collab>:
                    <article-title>Safeguarding data assets: A proactive approach to mitigate evolving cybersecurity risks.</article-title>
                    <year>n.d</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://stransact.com/en/insights/safeguarding-data-assets-a-proactive-approach-to-mitigate-evolving-cybersecurity-risks">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref27">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Thakur</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Cybersecurity threats and countermeasures in digital age.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Applied Science and Education (JASE).</italic>
</source>
                    <year>2024</year>:<fpage>1</fpage>&#x2013;<lpage>20</lpage>.</mixed-citation>
            </ref>
            <ref id="ref28">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Wolden</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Valverde</surname>
                            <given-names>R</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Talla</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>The effectiveness of COBIT 5 information security framework for reducing cyber-attacks on supply chain management system.</article-title>
                    <source>

                        <italic toggle="yes">IFAC- Papers Online.</italic>
</source>
                    <year>2015</year>;<volume>48</volume>(<issue>3</issue>):<fpage>1846</fpage>&#x2013;<lpage>7852</lpage>.</mixed-citation>
            </ref>
        </ref-list>
    </back>
    <sub-article article-type="reviewer-report" id="report473915">
        <front-stub>
            <article-id pub-id-type="doi">10.5256/f1000research.193402.r473915</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Rehan</surname>
                        <given-names>Hassan</given-names>
                    </name>
                    <xref ref-type="aff" rid="r473915a1">1</xref>
                    <role>Referee</role>
                    <uri content-type="orcid">https://orcid.org/0009-0003-0774-5777</uri>
                </contrib>
                <aff id="r473915a1">
                    <label>1</label>Purdue University, West Lafayette, Indiana, USA</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>15</day>
                <month>4</month>
                <year>2026</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 Rehan H</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport473915" related-article-type="peer-reviewed-article" xlink:href="10.12688/f1000research.175421.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve-with-reservations</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>This study examines cybersecurity awareness as a mediating variable in the relationship between internal control systems (ICS) and accounting information security (AIS) in Iraqi government banks, using PLS-SEM with bootstrapping on a sample of 50 employees from two branches of Al-Rashid Bank in Fallujah and Ramadi. The research question is well-motivated and contextually relevant &#x2014; the integration of internal control with information security in Arab public-sector banking remains underexplored, and cybersecurity awareness as a mediator is a theoretically defensible and practically meaningful construct to investigate. The conceptual model is grounded in COSO (2013) and supported by a coherent body of literature. The analytical execution &#x2014; measurement model evaluation, structural model testing, and mediation analysis via specific indirect effects &#x2014; follows accepted PLS-SEM conventions and is transparently reported. Open deposit of the raw dataset and questionnaire on Zenodo is commendable and enhances reproducibility.&#x00a0;</p>
            <p> </p>
            <p> Presentation and literature</p>
            <p> The manuscript contains persistent grammatical errors, awkward sentence constructions, and redundant passages throughout the introduction, literature review, and discussion sections. Several sentences are incomplete or shift register mid-paragraph. The R&#x00b2; interpretation in Section 5.1 is inverted &#x2014; the text states that 68% of variation "in internal control" is explained by "the AIS variable," when the correct reading is that AIS variance is explained by internal control. This error in direction of interpretation recurs for the CAW model and must be corrected. The literature coverage is adequate for the topic and includes recent work, though several references lack full citation details and one source is listed only as "n.d." without a retrieval date.</p>
            <p> </p>
            <p> Study design and technical soundness&#x00a0;</p>
            <p> The PLS-SEM mediation design is appropriate for the research objectives. The measurement model demonstrates acceptable reliability (Cronbach's &#x03b1; 0.886&#x2013;0.928, composite reliability &gt;0.90, AVE &gt;0.50 for all constructs) and discriminant validity (HTMT values 0.839&#x2013;0.871, all below the 0.90 threshold). Outer loadings are all statistically significant and the majority exceed 0.70, with four items (caw1, caw5, caw7, caw8) falling slightly below this threshold but remaining statistically meaningful. VIF values confirm the absence of problematic multicollinearity. Bootstrapping with 5,000 samples is appropriate for indirect effect estimation.</p>
            <p> </p>
            <p> Replication details&#x00a0;</p>
            <p> The questionnaire items are not reproduced in the manuscript body, only referenced via Zenodo. While the Zenodo deposit makes them accessible, embedding the full instrument as a supplementary appendix would substantially improve transparency and immediate replicability. The demographic table (Table 1) omits a gender column despite the text explicitly stating that most respondents are male &#x2014; this must be corrected either by adding the column or removing the claim.</p>
            <p> </p>
            <p> Statistical interpretation&#x00a0;</p>
            <p> Path analysis results are correctly reported and interpreted. All four hypotheses are rejected at p &lt; 0.05, supporting positive direct effects of IC on AIS (&#x03b2; = 0.786, T = 19.001) and on CAW (&#x03b2; = 0.795, T = 18.447), a positive effect of CAW on AIS (&#x03b2; = 0.438, T = 2.206), and a significant indirect effect through the mediator (&#x03b2; = 0.348, T = 2.105, p = 0.035). One reporting error requires correction: Tables 8 and 9 both carry the heading "Total indirect effect" &#x2014; Table 9 should be headed "Direct effects" to reflect its content accurately.</p>
            <p> </p>
            <p> Source data&#x00a0;</p>
            <p> Raw data and the questionnaire are openly deposited on Zenodo. The data availability statement contains a mismatch &#x2014; it describes the deposit as concerning "Industrial Control Systems and Management Information Systems" while the actual Zenodo record uses "ICS and AIS." This must be corrected for consistency.</p>
            <p> </p>
            <p> Support for conclusions&#x00a0;</p>
            <p> The core finding &#x2014; that cybersecurity awareness partially mediates the relationship between internal control and accounting information security &#x2014; is statistically supported within the study's scope. However, the manuscript draws conclusions about "Iraqi State Banks" and "government banks in Anbar Governorate" that substantially exceed what a convenience sample of 50 respondents from two branches of a single institution can credibly support. The title, abstract, and conclusion sections must be revised to accurately reflect the narrow institutional scope of the sample. Common-method bias is a legitimate concern in a single-source, self-report survey design and has not been tested &#x2014; at minimum, a Harman's single-factor test or full collinearity VIF assessment should be reported and the limitation acknowledged explicitly. The high path coefficients (&#x03b2; = 0.786&#x2013;0.795) combined with the small sample also warrant a caution regarding potential overfitting. Throughout the manuscript, causal language &#x2014; "contributes to," "enhances," "leads to" &#x2014; should be tempered to associational language consistent with the cross-sectional design.</p>
            <p> </p>
            <p> Required changes before approval:</p>
            <p> The R&#x00b2; directional interpretation in Section 5.1 must be corrected. The gender column must be added to Table 1 or the demographic claim removed. The duplicate table heading ("Total indirect effect" on both Tables 8 and 9) must be corrected. The data availability statement Zenodo description must be corrected to match the actual deposit title. The title, abstract, and conclusions must be revised to reflect the single-institution, two-branch scope of the sample. Causal language throughout must be softened to associational. A common-method bias test should be conducted and reported, or its absence explicitly justified and acknowledged as a limitation. A dedicated limitations section should be added covering sample size, single-institution scope, cross-sectional design, self-report bias, and the absence of common-method bias testing. The full questionnaire instrument should be embedded as a supplementary appendix. Professional English language editing is required throughout.</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Partly</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>Yes</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Yes</p>
            <p>Is the study design appropriate and is the work technically sound?</p>
            <p>Yes</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Partly</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Partly</p>
            <p>Reviewer Expertise:</p>
            <p>Machine Learning, Artificial Intelligence, Cloud Computing, Data Engineering, Data Analytics, Deep Learning, Big Data Systems, Distributed Computing, AI-driven Security Systems, Intelligent Data Processing</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above.</p>
        </body>
    </sub-article>
    <sub-article article-type="reviewer-report" id="report473923">
        <front-stub>
            <article-id pub-id-type="doi">10.5256/f1000research.193402.r473923</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>Rahmany</surname>
                        <given-names>Mostafa</given-names>
                    </name>
                    <xref ref-type="aff" rid="r473923a1">1</xref>
                    <role>Referee</role>
                    <uri content-type="orcid">https://orcid.org/0009-0005-9018-9584</uri>
                </contrib>
                <aff id="r473923a1">
                    <label>1</label>Buckinghamshire New University, High Wycombe, England, UK</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>10</day>
                <month>4</month>
                <year>2026</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 Rahmany M</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport473923" related-article-type="peer-reviewed-article" xlink:href="10.12688/f1000research.175421.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve-with-reservations</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>
                <bold>
                    <italic>Constructive assessment:</italic>
                </bold>
            </p>
            <p> This is a timely and relevant study that addresses an important gap in the accounting and cybersecurity literature, particularly in the under-researched context of Iraqi government banks. The authors correctly identify cybersecurity awareness as a potential mediator between internal control systems (ICS) and accounting information security (AIS). They develop a clear conceptual model based on COSO and relevant literature, derive four testable hypotheses, and apply PLS-SEM appropriately to test direct and indirect effects. The measurement model shows strong reliability (Cronbach&#x2019;s &#x03b1; 0.886&#x2013;0.928, composite reliability &gt;0.90, AVE &gt;0.50) and discriminant validity (HTMT &lt;0.90). Path coefficients are large and statistically significant, supporting the rejection of all null hypotheses and demonstrating a positive mediating role for cybersecurity awareness. Open sharing of the raw dataset and questionnaire on Zenodo is a major strength and promotes reproducibility.</p>
            <p> </p>
            <p> However, several limitations require attention before the work can be considered fully robust for indexing:</p>
            <p> </p>
            <p> </p>
            <p> 
                <bold>1. Sample size and generalizability (major concern):</bold> The study uses N=50 respondents from only two branches of a single institution (Al-Rashid Bank in Fallujah and Ramadi). This is a convenience sample that cannot credibly support conclusions about &#x201c;Iraqi State Banks&#x201d; or even &#x201c;government banks in Anbar Governorate.&#x201d; While PLS-SEM can function with small samples, the explanatory power claims (R&#x00b2; &#x2248; 0.68 for AIS) and very high path coefficients (&#x03b2; = 0.786&#x2013;0.795) warrant caution regarding statistical power, overfitting, and common-method bias (not tested).</p>
            <p> </p>
            <p> 
                <bold>2. Language and presentation:</bold> The manuscript contains numerous grammatical errors, awkward phrasing, sentence fragments, and repetitions that reduce clarity and readability (especially in the introduction, literature review, and discussion). Professional English editing is essential.</p>
            <p> </p>
            <p> 
                <bold>3. Minor technical and reporting issues:</bold>
            </p>
            <p> &#x00a0;&#x00a0; 
                <bold>3.1</bold> Demographic Table 1 description mentions &#x201c;most of the sample members are male,&#x201d; yet the table does not include a gender column.</p>
            <p> &#x00a0;&#x00a0; 
                <bold>3.2</bold> Table 8 and Table 9 both carry the heading &#x201c;Total indirect effect&#x201d; (copy-paste error).</p>
            <p> 
                <bold>&#x00a0;&#x00a0; 3.3</bold> The data-availability statement incorrectly describes the Zenodo deposit as concerning &#x201c;Industrial Control Systems and Management Information Systems.&#x201d; The actual Zenodo title correctly uses &#x201c;ICS and AIS&#x201d; (matching the article). This mismatch must be corrected.</p>
            <p> 
                <bold>&#x00a0;&#x00a0; 3.4</bold> Questionnaire items are not reproduced in the manuscript (only referenced to the Zenodo file), which slightly hinders immediate replication.</p>
            <p> &#x00a0;&#x00a0; 
                <bold>3.5</bold> Causal language (&#x201c;contribute to,&#x201d; &#x201c;enhancing,&#x201d; &#x201c;positive role&#x201d;) should be tempered to &#x201c;associated with&#x201d; or &#x201c;predicts&#x201d; given the cross-sectional, self-report design.</p>
            <p> </p>
            <p> 
                <bold>4. Limitations section:</bold> Currently minimal. A fuller discussion of sample limitations, self-report bias, single-institution scope, and cross-sectional nature is needed.</p>
            <p> </p>
            <p> Aspects I have not been able to assess: I did not download and re-run the raw .xlsx file from Zenodo to independently verify every bootstrap result or check for data-entry anomalies (though the reported statistics appear internally consistent and the deposit is openly accessible).</p>
            <p> </p>
            <p> 
                <bold>5. Recommendations to authors&#x00a0;</bold>
            </p>
            <p> 
                <bold>5.1 </bold>Undertake a full professional language edit.&#x00a0;</p>
            <p> 
                <bold>5.2 </bold>Explicitly acknowledge sample limitations and revise title/abstract/conclusions to reflect the narrow scope (e.g., &#x201c;in selected branches of Al-Rashid Bank, Anbar Governorate&#x201d;).&#x00a0;</p>
            <p> 
                <bold>5.3</bold> Correct the Zenodo reference and, ideally, embed the full questionnaire items (or a supplementary file) in the next version.&#x00a0;</p>
            <p> 
                <bold>5.4</bold> Expand the limitations and future-research sections.&#x00a0;</p>
            <p> 
                <bold>5.5</bold> Consider testing for common-method bias (e.g., Harman&#x2019;s single-factor test or full collinearity VIF).&#x00a0;</p>
            <p> Add a brief practical implications subsection for Iraqi banking regulators or internal-audit units.</p>
            <p> These revisions are feasible and would substantially strengthen the paper.</p>
            <p> </p>
            <p> 6. Answers to mandatory reviewer questions (Research Article)</p>
            <p> </p>
            <p> 1-Is the work clearly and accurately presented, and does it cite the current literature?&#x00a0;</p>
            <p> Partly. The literature is relevant and up to date, but language/grammar issues and the Zenodo title mismatch reduce clarity and accuracy.</p>
            <p> </p>
            <p> 2.&#x00a0;Is the study design appropriate and is the work technically sound?&#x00a0;</p>
            <p> Yes (the PLS-SEM mediation design and execution are technically sound), but the extremely narrow convenience sample limits academic merit and generalizability.</p>
            <p> </p>
            <p> 3.&#x00a0;Are sufficient details of methods and analysis provided to allow replication by others?&#x00a0;</p>
            <p> Partly, while mostly (full dataset and questionnaire are openly available; PLS-SEM parameters are reported in detail), but embedding the questionnaire items would improve transparency.</p>
            <p> 4- If applicable, is the statistical analysis and its interpretation appropriate?&#x00a0;</p>
            <p> Yes. Standard PLS-SEM procedures were followed and correctly interpreted.</p>
            <p> 5- Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p> Yes (via the Zenodo repository).</p>
            <p> </p>
            <p> 6-Are the conclusions drawn adequately supported by the results?&#x00a0;</p>
            <p> Partly, within the study&#x2019;s narrow scope, however, the authors over-generalize beyond the sampled branches.</p>
            <p> </p>
            <p> 
                <bold>Approval status:</bold>
            </p>
            <p> Approved with reservations</p>
            <p> </p>
            <p> 
                <bold>In Summary:&#x00a0;</bold>
            </p>
            <p> The paper makes a useful, context-specific contribution and the analytical work is competently executed, but the small/single-bank sample, language problems, and minor reporting inaccuracies prevent full approval in its current form. With the recommended revisions, it would be suitable for indexing.</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Partly</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>Yes</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Yes</p>
            <p>Is the study design appropriate and is the work technically sound?</p>
            <p>Yes</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Partly</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Partly</p>
            <p>Reviewer Expertise:</p>
            <p>Cybersecurity, AI &amp; ML, Network Infrastructure, Network&#x00a0;Security,&#x00a0;Information Technology, Oil &amp; Gas Industry Management, Oil &amp; Gas Cybersecurity, AI Security,&#x00a0;Healthcare Security, Healthcare Cybersecurity Framework,</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above.</p>
        </body>
    </sub-article>
    <sub-article article-type="reviewer-report" id="report465406">
        <front-stub>
            <article-id pub-id-type="doi">10.5256/f1000research.193402.r465406</article-id>
            <title-group>
                <article-title>Reviewer response for version 1</article-title>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author">
                    <name>
                        <surname>R. Jasim</surname>
                        <given-names>Muthana</given-names>
                    </name>
                    <xref ref-type="aff" rid="r465406a1">1</xref>
                    <role>Referee</role>
                </contrib>
                <aff id="r465406a1">
                    <label>1</label>College of Administration and Economics - Department of Accounting, Tikrit University, Tikrit, Saladin Governorate, Iraq</aff>
            </contrib-group>
            <author-notes>
                <fn fn-type="conflict">
                    <p>
                        <bold>Competing interests: </bold>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>23</day>
                <month>3</month>
                <year>2026</year>
            </pub-date>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 R. Jasim M</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access peer review report distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <related-article ext-link-type="doi" id="relatedArticleReport465406" related-article-type="peer-reviewed-article" xlink:href="10.12688/f1000research.175421.1"/>
            <custom-meta-group>
                <custom-meta>
                    <meta-name>recommendation</meta-name>
                    <meta-value>approve</meta-value>
                </custom-meta>
            </custom-meta-group>
        </front-stub>
        <body>
            <p>The manuscript addresses an important and timely topic&#x2014;the role of cybersecurity awareness as a mediator between internal control systems and accounting information security in public banks&#x2014;and uses PLS-SEM to test theoretically sensible hypotheses. Strengths include a clear theoretical framing, transparent reporting of reliability/validity measures, and open sharing of the underlying dataset. However, the study&#x2019;s generalizability and causal inference are limited by the small and convenience-based sample (N=50 from two branches of a single bank). I recommend the authors temper causal language, more explicitly discuss limitations related to sample size and potential self-report bias and include the survey instrument items in a manuscript appendix (or cite the Zenodo file directly). &#x00a0;Overall, the paper makes a useful contribution but would benefit from these clarifications before indexing.</p>
            <p>Is the work clearly and accurately presented and does it cite the current literature?</p>
            <p>Yes</p>
            <p>If applicable, is the statistical analysis and its interpretation appropriate?</p>
            <p>Yes</p>
            <p>Are all the source data underlying the results available to ensure full reproducibility?</p>
            <p>Partly</p>
            <p>Is the study design appropriate and is the work technically sound?</p>
            <p>Yes</p>
            <p>Are the conclusions drawn adequately supported by the results?</p>
            <p>Yes</p>
            <p>Are sufficient details of methods and analysis provided to allow replication by others?</p>
            <p>Yes</p>
            <p>Reviewer Expertise:</p>
            <p>Financial AccountantInternational Financial Reporting Standards</p>
            <p>I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard.</p>
        </body>
    </sub-article>
</article>
