Skip to content
Open access

A Human Factors-Cyber-Safety Framework for Risk and Requirements in Critical Infrastructure

2026 · AHFE International · Vol 208 · 0 citations

TL;DR

An integrated socio-technical framework that combines Human Factors methods, safety analysis, and cybersecurity modelling within a Secure-by-Design approach is presented, reframing cybersecurity as a socio-technical reliability problem comparable to safety engineering.

Abstract

Cyber-attacks on critical infrastructure are increasing in scale and sophistication, yet cybersecurity practice remains dominated by technology-centric assessments that insufficiently represent human contributions to risk. In cyber-physical systems (CPS), non-malicious human actions -including slips, mistakes, workarounds, training gaps, and misaligned procedures- frequently create, amplify or fail to detect vulnerabilities.This paper presents an integrated socio-technical framework that combines Human Factors (HF) methods, safety analysis, and cybersecurity modelling within a Secure-by-Design approach. The framework models how human performance variability influences cyber vulnerability and safety outcomes, enabling structured, scenario-based risk assessment and the derivation of traceable engineering requirements. An illustrative application demonstrates how HF findings are translated into human error mechanisms, cyber effects, unsafe control actions, safety impacts, and prioritised Secure-by-Design controls. By operationalising HF methods as cybersecurity engineering tools, the approach reframes cybersecurity as a socio-technical reliability problem comparable to safety engineering.

Read PDF

Similar papers

Open access Jul 2026

Security and trustworthiness challenges in cyber-physical-human systems

Cyber-physical-human systems (CPHS) integrate human inputs, behaviors, and interfaces for a more effective utilization of artificial intelligence (AI) assisted cyber and physical systems. However, the growing reliance on Agentic AI , coupled with the inherent variability of human actions, can introduce unforeseen security challenges. Studies have reported that any security compromise can result in catastrophic failures, safety hazards, and data breaches, disrupting the day-to-day operations of CPHS. Given the scale and complexity of typical CPHS, robust security measures are essential. This paper investigates the security requirements of CPHS encompassing confidentiality, integrity, availability, authentication, and authorization, in the context of CPHS. We also emphasize the role of formal verification methods to establish and guarantee the trustworthiness of agents, which are increasingly integral to these systems. Considering the inherent mutual dependency, we systematically categorize and analyze attack vectors across three dimensions: data , agents , and human actors that can impact the security and trustworthiness of CPHS. Using unmanned aerial vehicles (UAVs) in the defense sector as a prototypical CPHS engineering application, we present a typical mission scenario involving a remotely piloted Medium-Altitude, Long-Endurance (MALE) aircraft designed for Intelligence, Surveillance, Target Acquisition, and Reconnaissance (ISTAR) to conduct threat assessments. Our comprehensive analysis illustrates how these attack vectors can compromise each dimension, providing actionable insights for security engineers and system architects to design robust security measures in CPHS.

Sandeep K. S. Gupta, Maria Papaioannou, Nicola Dragoni · 0 citations
Review Open access Aug 2026

Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures

The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.

Kennedy Owino Jaramba, Samwel Oonge · 0 citations
Review Open access 2026

Emerging Technologies and Cybersecurity in Critical Information Infrastructure and Industrial Control Systems: An Integrated Cyber Risk Pathway Model

The digital transformation of Critical Information Infrastructure (CII) and Industrial Control Systems (ICS) through Industry 4.0 technologies introduces significant cybersecurity challenges. While existing research examines technologies individually, little attention has been given to how their combined adoption reshapes the overall threat landscape. This study presents a Multivocal Literature Review, synthesising evidence from 41 academic and industry sources (January 2010–June 2026) and proposes an Integrated Cyber Risk Pathway Model that traces how technology adoption introduces interconnected vulnerabilities, expands threat actor capabilities, produces cyber-physical impacts, and ultimately defines resilience requirements. Three findings emerge: 1) emerging technologies play a dual role, enhancing operational capability while expanding the attack surface; 2) cyber-attacks have evolved from specialist ICS operations to ecosystem-level compromises exploiting supply chains and shared platforms; 3) the resulting vulnerabilities are systemically interconnected, creating risks that prevention-focused cybersecurity alone cannot fully address. The study argues that protecting modern critical infrastructure requires a shift to resilience-centred strategies supported by governance, secure system design and cross-sector collaboration.

Unknown authors · 0 citations
Review Open access Jul 2026

Cyber-Physical Systems in Healthcare: Design, Interoperability and Security Challenges

Cyber-Physical Systems (CPS), a combination of embedded computing, communication networks, and physical processes, are increasingly reshaping clinical practice, pharmaceutical supply chains, and hospital infrastructure. This review covers key principles of Medical CPS design; major interoperability frameworks such as FHIR (Fast Healthcare Interoperability Resources), IEEE 11073, and DICOM; and critical cybersecurity risks that threaten patient safety and data integrity, including ransomware, man-in-the-middle, denial-of-service, and data injection attacks. A review of the literature from 2020 to the present (2025) shows that architectural fragmentation has continued, that there is a lack of harmonised security-by-design standards, and that there is a lack of regulatory guidance on real-time MCPS deployments. Some promising mitigation strategies, such as blockchain-based trust frameworks, AI-powered intrusion detection, and digital twin validation, are introduced. The papers conclusion recommends a research agenda for interoperability protocols, context-aware security models, and international regulatory convergence as essential factors for implementing safe and scalable MCPS.

Emmanuel Nkansah, M. Oladosu, M. Abah et al. · 0 citations
Review Open access Aug 2026

AI-Driven Problem Solving for Cyber-Physical Systems Security: An Assessment Framework

It is found that traditional risk assessment and testing approaches are insufficient for AI-powered CPS, and a prototype implementation and experimental evaluation are presented along with a case study of protecting a smart manufacturing plant during a ransomware attack using the proposed approach.

Vikram Kulothungan, Deepti Gupta, Raju Dhakal et al. · 0 citations
Aug 2026

Cyber-risk assessment and mitigation framework for critical information infrastructure: mixed-methods approach

Distributed Denial of Service (DDoS) attacks on critical information infrastructures (CII) cause operational disruptions and result in financial and reputational damage to organisations. Our study provides an integrated framework to assess, quantify and mitigate the cyber-risk of DDoS attacks on CII organisations in the energy and power sectors. Our model adopts a socio-technological perspective and draws on protection motivation theory (PMT) and rational choice theory (RCT). Our study adopts a mixed-method approach. In the quantitative section, we estimate the likelihood of misdetection of different DDoS attacks by using observable attackers’ strategy. These observations influence how CISOs implement the organisation’s cybersecurity posture and IT governance. Next, we compute the expected loss. Lastly, the study recommends CISO for various mitigation strategies based on the NIST Cybersecurity Framework by creating a 2×2 risk-impact heat matrix. Subsequently, Linear Programming is used to determine the priority of optimal allocation of investment across different mitigation strategies. In qualitative section, in-depth interviews with cybersecurity executives corroborate findings. The likelihood of the misdetection of DDoS attacks by the CISO of an organisation is low. Most DDoS attacks result in small financial losses, but rare, severe incidents can cause disproportionately serious damage. The study further finds that organisations must invest in technological interventions, complemented by financial tools, to mitigate DDoS attacks. The study uses a mixed-methods approach, combining quantitative analysis with executive interviews to assess the CISO's misdetection rate for DDoS attacks, compute the expected financial loss, and recommend a mitigation and investment strategy based on the NIST framework for CII organisations.

Priyanka Srivastava, Arunabha Mukhopadhyay · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.