Jul 2026· 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET)· pp. 1-10· 0 citations· 27 references
Abstract
The widespread adoption of Internet of Things (IoT) and Operational Technology (OT) sys- tems in industrial environments has significantly in- creased cybersecurity exposure. Human error re- mains a leading cause of successful cyberattacks; how- ever, conventional Cybersecurity Awareness Training (CSAT) programs are typically static and poorly aligned with user roles, asset criticality, and evolving threats. This paper proposes an IoT-focused risk- adaptive CSAT framework that integrates MITRE ATT&CK-based threat modeling, CIA-aware impact analysis, machine learning-driven risk assessment, and Generative Artificial Intelligence (GenAI) for person- alized training delivery. The framework models cyber- security awareness as a continuous closed-loop process that constructs user-specific attack graphs, evaluates vulnerabilities through adaptive assessments, and com- putes local and global risk scores. Machine learning dynamically derives risk thresholds to guide training prioritization, while GenAI generates targeted training content aligned with real-world attack scenarios. Evaluation using representative industrial user profiles demonstrates consistent reductions in vulnerability and global risk levels following personalized training. The results indicate that the proposed framework has the potential to enhance human-centric security and im- prove the effectiveness of cybersecurity awareness pro- grams in industrial IoT environments.
Investigating stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework to help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats suggests that Information Technology and cybersecurity professionals had greater familiarity with CSA than did leaders and managers.
Mansour Almalki, L. Nawaf, Fiona Carroll· Journal of Cybersecurity and...· 0 citations
An integrated socio-technical framework that combines Human Factors methods, safety analysis, and cybersecurity modelling within a Secure-by-Design approach is presented, reframing cybersecurity as a socio-technical reliability problem comparable to safety engineering.
Eylem Thron, Duncan Ki-Aries, Martin Freer et al.· AHFE International· 0 citations
The progressive convergence of Information Technology (IT) and Operational Technology (OT) environments has introduced new cybersecurity challenges for industrial and critical infrastructure systems. This work presents a generalized OT cybersecurity architecture that combines the Purdue reference model with Zero Trust principles to enforce strict segmentation, continuous verification, and controlled information flows across IT/OT boundaries. The architecture incorporates Artificial Intelligence (AI)-driven monitoring to support anomaly detection, contextual risk assessment, and automated response mechanisms under operational constraints. Additionally, a governance and assurance layer is discussed, aligning AI-enabled security functions with recognized risk management frameworks and auditable controls to ensure trustworthiness, resilience, and operational sustainability in high-impact industrial deployments. The proposal is further contextualized with prior AI-RMFgoverned IoT-as-a-Service and OWASP ML05 middleware contributions that address AI-enabled IoT security, model protection, and governance requirements.
Yair Rivera Julio, Ángel D. Pinto-Mangones, Frank A. Ibarra et al.· 2026 6th International Confe...· 0 citations
This study suggests a framework for cybersecurity auditing of smart grid infrastructure, which is based on the concept of risk and the use of Explainable Artificial Intelligence (XAI) to produce transparent, prioritized and audit-ready security evidence. The information from public smart grid cybersecurity events was mapped to event labels, asset classes, security-control status, compliance indicators, and cyber-physical impact variables, which were then used to create audit-relevant records. Attack likelihood estimates were made using machine learning models. The attack likelihood, asset criticality, control deficiency score, compliance condition and operational impact were all added together to calculate the final audit risk score. Explainability was used as a technique to identify the most important features that affected each audit decision by applying the SHAP method. The proposed framework achieved 96.38% accuracy, 96.51% precision, 96.38% recall, 96.42% F1-score, and 0.996 ROC-AUC. The results of the ablation showed that the inclusion of the risk component and the XAI component resulted in an improvement in the risk ranking, audit traceability and explanation consistency. The framework translates the cybersecurity detection results into an understandable audit decision, enabling risk-based remediation, compliance review, and an understandable smart grid cybersecurity governance.
Udit Mamodiya, I. Kishor, Hastimal Jangid et al.· Journal of Cyber Security an...· 0 citations
The rise in Cloud–Internet of Things (Cloud–IoT) infrastructure has greatly increased the exposure of organizations to cyber threats, with recent studies showing that over 68% of security breaches have originated from misconfigured cloud resources. Continuous Threat Exposure Management (CTEM) and Zero Trust Security (ZTS) models have been proposed to address these challenges; however, nearly 70% of current implementations are still detection-oriented rather than exposure-predictive. This critical review statistically evaluates current research on CTEM models, Zero Trust frameworks, and artificial intelligence-based cybersecurity solutions in multi-cloud and edge environments. A review of the literature suggests that less than 35% of current solutions have combined dynamic risk scoring with automated access control, while less than 25% of current solutions have allowed real-time adaptive policy enforcement. There is a great need for improvement in predictive threat exposure modelling, autonomous security orchestration, and continuous exposure mitigation in heterogeneous cloud–IoT infrastructures. The review identifies essential research goals in the development of an AI-based adaptive cyber defence framework that is predictive, intelligent, and continuously risk-driven in a Zero-Trust security paradigm.
Koteswara Rao Damacharla, S. Kumar· Journal of Information Secur...· 0 citations
Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.
Lukumba Phiri, Steve Muwowo· International Journal of Ele...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.