Emerging Technologies and Cybersecurity in Critical Information Infrastructure and Industrial Control Systems: An Integrated Cyber Risk Pathway Model
Abstract
The digital transformation of Critical Information Infrastructure (CII) and Industrial Control Systems (ICS) through Industry 4.0 technologies introduces significant cybersecurity challenges. While existing research examines technologies individually, little attention has been given to how their combined adoption reshapes the overall threat landscape. This study presents a Multivocal Literature Review, synthesising evidence from 41 academic and industry sources (January 2010–June 2026) and proposes an Integrated Cyber Risk Pathway Model that traces how technology adoption introduces interconnected vulnerabilities, expands threat actor capabilities, produces cyber-physical impacts, and ultimately defines resilience requirements. Three findings emerge: 1) emerging technologies play a dual role, enhancing operational capability while expanding the attack surface; 2) cyber-attacks have evolved from specialist ICS operations to ecosystem-level compromises exploiting supply chains and shared platforms; 3) the resulting vulnerabilities are systemically interconnected, creating risks that prevention-focused cybersecurity alone cannot fully address. The study argues that protecting modern critical infrastructure requires a shift to resilience-centred strategies supported by governance, secure system design and cross-sector collaboration.