
Cyber deception can produce high-confidence evidence of unauthorized activity in industrial control systems (ICS) and operational technology (OT), but practitioners must consider the technology useful, safe, understandable, and supported before they will use it. This study reports a secondary quantitative analysis of a deidentified survey of United States-based ICS and OT professionals to determine whether psychological and instructional factors predict adoption readiness and effective utilization beyond education, experience, and sector. Hierarchical ordinary least squares regression with HC3 robust standard errors was conducted on 262 complete cases. The demographics-only model was not significant and explained 2.8 percent of outcome variance. Adding performance expectancy, self-efficacy, direct experience, social influence, instructional support, and security trust increased the explained variance to 64.3 percent. Self-efficacy and direct experience were the strongest unique predictors, followed by instructional support, performance expectancy, and security trust. Social influence was positive in bivariate analysis but was not significant in the full model. The findings indicate that credentials and general experience alone should not be treated as evidence of readiness to use cyber deception in safety-sensitive environments. Cybersecurity programs and workforce initiatives should emphasize hands-on deception laboratories, alert interpretation, role-specific playbooks, and tabletop exercises. Because several constructs were measured with only one or two items and the sample was concentrated in manufacturing, the findings should be interpreted as exploratory and validated with broader-sector samples and multi-item measures.
Recent attacks on America's critical infrastructure have drawn increased attention on securing industrial control systems and operational technology in power plants, utility companies, and other sectors providing public services. Attack detection and mitigation strategies on these systems have shown promising results using machine learning and other statistical baselining techniques, mostly using supervised learning and classification. Unsupervised learning using cluster analysis and other techniques remain mostly unexplored. In this paper, we propose multi-layered feature extraction and hybrid clustering framework to detect fine-grained nested attack patterns in Modbus-over-TCP traffic. Operating under the assumption of known number of distinct network categories, our approach achieves traffic segregation without label training. The results are validated using MITRE ATT&CK framework and serve as threat interpretation for industrial control systems environments. We provide a comprehensive analysis by calculating silhouette scores for each clustering stage, achieving a global macro-cluster separation score of 0.411 and localized sub-cluster semantic consistency. The results demonstrate that pipeline successfully distills pure, unidirectional attack vectors from operational baselines and show promising results for further research in this area.
Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven risk management [1]-[3], [13], [15]. Manual System Security Plan (SSP) updates, spreadsheet-based Plan of Action and Milestones (POA&M) tracking, and disconnected assessment evidence create governance latency: the delay between operational security events and authorization-ready governance response. This paper presents OpenGRCRMF, a proposed open, vendor-neutral reference framework that models RMF lifecycle activities as workflow states, treats authorization artifacts as structured governance objects, and maps DevSecOps and Zero Trust telemetry into authorization-relevant evidence. Using Design Science Research, the study develops the OpenGRCRMF architecture, formalizes its data and risk model, and evaluates expected governance effects through a synthetic simulation of 1,500 findings across 180 assets and 320 controls [9]. OpenGRCRMF is evaluated as a reference framework rather than a production platform using a self-contained simulation specification and sensitivity analysis. In the simulation, the OpenGRCRMF-enabled workflow reduced modeled governance processing time by 36.8 percent, increased modeled evidence completeness by 41.5 percent, and increased modeled control-to-evidence traceability by 52.7 percent compared with a document-centric baseline. These results are modeled outcomes under stated assumptions, not production deployment proof. The paper contributes a governance object model, governance latency construct, reproducibility-oriented simulation design, threat-to-validity analysis, and education-oriented framework for teaching how operational telemetry becomes authorization evidence.
Realistic, hands-on cybersecurity training has traditionally depended on fixed infrastructure such as dedicated lab hardware, cloud subscriptions, or permanent network connectivity, limiting where and how often it can be delivered. This paper presents the design and implementation of a portable, scenario-based cybersecurity training platform housed in a single travel case and built from commodity hardware, type-1 hypervisor virtualization, containerized service orchestration, and software-defined networking. The platform clones, isolates, and resets complete lab environments on demand, allowing the same physical system to support repeated classroom, workshop, or field deployments with minimal manual reconfiguration. Training scenarios are grounded in generated organizational profiles that define sector, size, roles, assets, services, and network structure, situating exercises within a realistic operational context rather than as isolated technical tasks. Network and vulnerability placement are aligned with publicly documented adversary tactics and techniques drawn from government and industry guidance, so constructed attack paths reflect plausible, observable adversary behavior rather than artificial shortcuts. A representative lab walkthrough demonstrates the platform supporting both offensive and defensive training within a single bounded scenario. Early use suggests this approach can substantially reduce the infrastructure cost and setup overhead of realistic, adversary-aligned cybersecurity instruction, though systematic measurement of learning outcomes remains future work.
The rapid expansion of digital public services in Mozambique—including e-government platforms, digital health systems, and electronic tax administration—has outpaced the development of a coherent legal framework for cybersecurity. While Law No. 3/2017 (Electronic Transactions Law) of 9 January 2017 introduced foundational data-protection principles, Mozambique long lacked a dedicated cybersecurity regulatory authority, mandatory security standards, and formal incident-notification mechanisms. This regulatory vacuum exposed critical public services to escalating cyber risks as digital transformation was actively promoted as a development priority. This article examines the legal and institutional gaps in Mozambique's cybersecurity governance framework prior to the 2026 Cybersecurity and Cybercrime Laws, situating the analysis within the broader pattern of regulatory lag in developing countries. Drawing on regional experiences—South Africa, Rwanda, and Kenya—and continental instruments such as the Malabo Convention, the study identifies structural weaknesses in Mozambique's pre-2026 legal architecture and their implications for the resilience of digital public services. The article argues that closing this gap requires not merely new legislation, but enforceable institutional capacity, sector-specific security requirements, and alignment with international cybersecurity governance standards. The 2026 legislative reforms represent a decisive step; their effective operationalization will determine whether the vacuum is closed in practice. Policy recommendations are offered to guide a proportionate implementation pathway.
Abstract—This conceptual/theoretical paper explores how personal authenticity might promote generative learning in introductory cybersecurity courses. Generative learning transfers confidently to future educational, professional, personal, and testing situations. This cycle of design-based research addresses the concern that more typical professionally authentic contexts (e.g., hospitals, banks, etc.) may be alien and overwhelming to many students, particularly those in introductory courses and/or from non-professional families and communities. If so, this leads to “inert” knowledge that does not transfer. Personal authenticity is rooted in expansive framing, a modern theory of learning transfer. We reframe expansive framing as personal authenticity to make it more accessible and to highlight the contrast with professional authenticity. The paper offers two design cases of personally authentic cybersecurity instruction (one actual and one hypothetical). The paper then uses these examples to shed light on five theoretical explanations of why such personally authentic and expansively framed instruction might transfer more readily than professionally authentic instruction or traditional “direct” instruction (where contexts are introduced after the “basics” have been mastered). The paper’s ultimate goals are to (a) encourage cybersecurity and computing educators to explore personal authenticity, (b) introduce a theoretical framework and assessment strategies for studying personal authenticity, and (c) help cybersecurity and computing educators and educational researchers understand the implications of newer “situated” theories of cognition.
The cybersecurity workforce gap in the United States is estimated at several hundred thousand unfilled positions, and the rapid integration of artificial intelligence into adversary tradecraft and federal cyber operations is widening that gap qualitatively as well as quantitatively, threatening national security and the operational readiness of graduates entering the field. This perspective article synthesizes the principal arguments advanced by five federal and academic speakers at the 2026 CAE Cybersecurity Community Symposium, using verbatim session transcripts, a structured thematic extraction process, and triangulation against published workforce policy and peer-reviewed literature. Findings document a unified speaker thesis that artificial intelligence now functions as a replacement technology requiring a redefinition of graduate employability around tasks that neither humans nor machines can perform alone. The article concludes that an emerging federal-academic compact requires reciprocal commitments to curricular redesign, capstone transformation, and work-role alignment, and it provides a phased implementation roadmap, a competency-to-curriculum mapping, and governance mechanisms for institutions acting within the next academic cycle.
The growing reliance on cybersecurity certifications has increased the financial and professional stakes associated with certification decision-making for cybersecurity professionals. Despite their widespread use in hiring and career advancement, there is limited objective guidance available to help individuals evaluate the return on investment (ROI) of specific certifications. This gap has created uncertainty regarding which credentials provide the greatest value relative to their cost and market impact. This study presents a data-driven, design science–based tool that supports cybersecurity professionals in evaluating certification ROI using practitioner survey data combined with certification cost and labor-market demand indicators. The paper also demonstrates how such a tool can improve transparency and support more informed, evidence-based certification planning within cybersecurity education and workforce development contexts.
Phishing remains one of the most persistent cybersecurity threats facing higher education institutions, where diverse user populations and highly connected digital environments increase exposure to social engineering attacks. Although cybersecurity awareness initiatives are widely implemented, high awareness does not always translate into secure behavior. This study examined phishing awareness, phishing-related practices, phishing susceptibility, and phishing experiences among college students, teaching faculty, and administrative staff in a private higher education institution in the Philippines. Using a quantitative cross-sectional design, data were collected from 553 respondents through a validated survey instrument and analyzed using descriptive statistics, one-way analysis of variance, Tukey's honestly significant difference test, and Pearson correlation. The findings revealed very high phishing awareness across all stakeholder groups but significant differences in cybersecurity practices and phishing susceptibility. Administrative staff demonstrated lower cybersecurity practices and greater susceptibility than students and faculty members. While phishing awareness was positively associated with cybersecurity practices and negatively associated with phishing susceptibility, cybersecurity practices showed the strongest relationship with reduced susceptibility, highlighting the gap between knowing and consistently practicing secure behavior. Based on these findings, the study proposes the Cybersecurity Awareness, Reporting, and Education (C.A.R.E.) Framework, a role-based institutional training framework designed to align established security education strategies with empirically identified behavioral risk profiles. The study contributes evidence that effective phishing resilience in higher education requires targeted, behavior-focused interventions rather than uniform awareness campaigns, providing a practical framework for strengthening institutional cybersecurity.
In this research work, we explored the effectiveness of gamification in improving cybersecurity awareness and training users on targeted social engineering attacks. Traditional cybersecurity training focuses on lectures and videos. These training methods may not actively engage employees, which reduces their knowledge retention and ability to recognize social engineering attacks. This lack of involvement is a concern, as social engineering continues to be one of the most prevalent attack methods faced by end-users. A gamified training program, Escaping the Cyberstorm, was developed using the Godot game engine to address key challenges in spreading cybersecurity awareness. The game includes real-life scenarios of four social engineering attacks: phishing, deepfakes, shoulder surfing, and baiting. During a single academic semester pilot study conducted for a local organization, the training program was implemented on ten employees, including cybersecurity professionals, human resources staff, and general employees. The employees were selected based on their prior vulnerability to social engineering attacks. We evaluated the training program using pre-game and post-game surveys, as well as in-game performance metrics, such as scenario-based scores and total game score. Results show a noticeable increase in user engagement and self-reported confidence in identifying and responding to different social engineering attacks. These results provide promising pilot evidence indicating that gamification can be used as a cybersecurity training and education tool, though these results should be tested on a larger scale.
In today’s rapidly evolving technological landscape, cyberattacks pose increasing threats, yet a global shortage of cybersecurity and digital forensics professionals leaves industries vulnerable, similar to having too few law enforcement officers in a densely populated city. The judicial system faces rising digital crimes and fraud cases, further strained by the lack of experts to analyze and extract digital evidence. Despite high demand, millions of positions remain unfilled. This paper identifies the root causes of the cybersecurity workforce shortage and proposes a targeted solution: a curriculum for Grades 7–12 designed to foster cybersecurity awareness and interest. The methodology included a comprehensive literature review, expert consultations, curriculum mapping, and a pilot survey of 137 students across four private schools. Survey results revealed that 77% of students were aware of cybersecurity concepts, 89% recognized its future importance, and 67% advocated for hands-on cybersecurity labs in schools. This adaptable program can be integrated into educational institutions to equip students with foundational skills and encourage early career exploration in cybersecurity. The initiative addresses the skills gap and aims to cultivate a workforce prepared for the future.
Abstract -This conceptual essay addresses the need for systemic and systematic transdisciplinary analytical techniques within cybersecurity and technical security. This conceptual essay is contingent upon recognition that cybersecurity is not simply technical in nature, it does not need an adversary, and more importantly it is based upon systems engineering and systems thinking. The essay contributes a socio-technical attribution chain and field-specific ontology/taxonomy which distinguish user-triggered events from root causes, latent conditions, technical debt, validation failures, governance failures, and attribution bias before assigning responsibility to end users. It systematically defines an ontology inclusive of developer technical debt, organizational debt arising from policy and procedural failures, and emergent cybersecurity ecosystem properties. It further defines technocentric mythos bias as a possible blinder causality for cybersecurity and technical security professionals who might otherwise be unable to or improperly trained to attribute incident causality as systemic. It explains why the end-user becomes the most heuristically available failure explanation, simply because of visibility. This attribution fails to account for organizational and systemic conditions which set the stage for end-user blaming, instead using availability bias for causality attribution. It recommends training considerations to improve the systemic identification of causality in accordance with systems engineering and industry’s best practices.
The rapid deployment of Industrial Internet of Things (IIoT) systems across Sub-Saharan Africa's extractive, energy, logistics, and agro-industrial sectors has introduced a cybersecurity challenge of growing urgency: industrial networks that were designed for operational efficiency are increasingly exposed to cyber threats for which neither the organizations nor the regulatory frameworks are adequately prepared. This article examines the cybersecurity governance of IIoT systems in a developing African economy, using Mozambique as a primary case study and drawing comparative lessons from South Africa, Rwanda, and Kenya. Through an integrative literature review and documentary analysis of national digital, cybersecurity, and industrial policies, the study identifies five critical cybersecurity governance gaps: the absence of IIoT-specific cybersecurity policy, lack of industrial data governance legislation, fragmented radioelectric spectrum regulation for IoT technologies, workforce skill deficits in operational technology security, and the absence of mandatory security-by-design requirements for industrial IoT deployments. The article maps the specific threat landscape facing IIoT systems in Mozambique's priority industrial sectors — including sensor tampering in remote mining infrastructure, ransomware targeting operational technology networks, man-in-the-middle attacks on logistics tracking systems, and supply chain compromises in agro-industrial IoT deployments — and proposes a structured cybersecurity governance framework calibrated to the resource constraints and industrialization priorities of developing economies. The findings contribute to the growing body of literature on cybersecurity policy in the Global South and offer actionable recommendations for policymakers, regulators, and security practitioners operating in similar developmental contexts.
This study presents a PRISMA-based systematic review of 412 cybersecurity education intervention studies, coding assessment methods, evidence types, claimed outcomes, use of established assessment instruments, and artifact availability. Despite frequent claims of skill development and workforce preparation, 45.4% of studies reported no identifiable assessment. Knowledge tests appeared in 11.4% of studies, while performance assessments appeared in 10.2%. From 2015 to 2025, assessment practices remained dominated by post-only designs or no assessment, with no statistically detectable increase in pre/post-capable designs. Use of established assessment instruments was rare, with 94.2% of assessed studies using ad hoc measures or not identifying an established instrument. Among implementation-based interventions such as labs, ranges, and CTFs, only 22.5% provided publicly accessible artifacts for reuse. Overall, the findings indicate that the field prioritizes intervention development over empirical evaluation. As cybersecurity education continues to mature, stronger assessment practices and greater accessibility of educational artifacts can help identify effective interventions, support broader adoption, and provide clearer evidence of cybersecurity skill development.
The accelerating convergence of artificial intelligence (AI), the Internet of Things (IoT), cloud computing, blockchain, and quantum computing has fundamentally transformed the global threat landscape, introducing cybersecurity challenges of unprecedented complexity and scale. This systematic literature review synthesizes findings from peer-reviewed publications, institutional reports, and regulatory documents published primarily between 2020 and 2025 to provide an integrated analysis of contemporary cybersecurity challenges across five key emerging technology domains. The review identifies critical vulnerabilities inherent to each domain, documents the evolution of threat actors and attack methodologies — including AI-powered ransomware, adversarial machine learning, and harvest-now-decrypt-later quantum attacks — and evaluates emerging defensive frameworks and international regulatory responses. Key findings indicate that global cybercrime costs are projected to reach USD 10.5 trillion annually by 2025; ransomware payments reached record highs in 2024 with individual demands exceeding USD 75 million; and the post-quantum cryptography transition mandated by NIST represents an urgent systemic imperative with a 2035 deprecation deadline. The cybersecurity workforce gap — currently estimated at a 12.6% annual growth deficit — compounds these risks, particularly for developing nations and smaller institutions. The review concludes that effective cybersecurity governance in the age of emerging technologies requires multidisciplinary approaches, proactive regulatory frameworks, investment in human capital, and deep public-private collaboration spanning institutional and national boundaries.
Artificial intelligence (AI) is being adopted at an exponential rate to improve efficiency, decision-making, and cybersecurity, but its rapid integration introduces new and often poorly understood risks, including system errors, algorithmic bias, data privacy concerns, security vulnerabilities, and ethical dilemmas. This paper examines how organizations are implementing AI and evaluates the National Institute of Standards and Technology's AI Risk Management Framework (NIST AI RMF) as a tool for managing these risks. It reviews the benefits of AI adoption alongside the risks emerging from its use in business and broader society and examines the legal and ethical challenges organizations face when implementing AI risk management, including barriers specific to small and medium-sized enterprises (SMEs). Drawing on current literature and complementary regulatory frameworks, including the EU AI Act and ISO/IEC 42001, the paper situates the NIST AI RMF's four core functions, Govern, Map, Measure, and Manage, within this broader governance landscape. It finds that the primary obstacle to effective AI governance is not a lack of standards but inconsistent and incomplete organizational implementation. The paper concludes by identifying current gaps in AI governance practice and proposing future directions for improving AI risk management and security practices across organizations of varying size and maturity.
The Domain Name System (DNS) remains a critical attack vector exploited by adversaries for command-and-control (C2) communication, data exfiltration, and phishing campaigns. DNS Response Policy Zones (RPZ) have emerged as an effective defense mechanism by enabling the redirection or blocking of queries to malicious domains. However, current RPZ implementations encounter significant challenges related to scalability, adaptability, and user awareness, often resulting in static policies, delayed updates, and a high incidence of false positives. To address these limitations, this paper proposes an enhanced RPZ framework that integrates adaptive threat intelligence, machine learning-driven dynamic policy updates, and user-context-aware security controls. The proposed framework incorporates real-time ingestion of diverse threat intelligence feeds, automated scoring mechanisms to prioritize indicators based on risk attributes such as entropy, domain age, domain generation algorithm (DGA) likelihood, and reputation history, as well as machine learning techniques for continuous refinement of blocklists. Additionally, the framework presents novel methods for minimizing false positives by leveraging user behavior analytics and contextual policy enforcement across heterogeneous network environments. Experimental validation demonstrates the system’s ability to scale to large DNS traffic environments through controlled high-load tests, while effectively reducing malicious query resolutions and maintaining accurate policy adjustments. By combining automation, risk-based intelligence, and user-centric adaptability, the proposed model advances DNS security beyond static defenses and offers a proactive, scalable, and context-sensitive approach to mitigating emerging DNS threats.
Background and Purpose: Libraries are evolving into highly networked information ecosystems in this age of fast digital transformation, which increases their susceptibility to cybersecurity risks. The study "Cyber-Ready Libraries: Building Digital Fortresses for Tomorrow" looks into how prepared libraries are to face cyber threats and considers methods for creating information systems that are safe, robust, and ready for the future. To safeguard digital assets and user data, the study aims to assess existing cybersecurity practices in library settings and offer a roadmap for combining technological, human, and governance solutions. Design/Method: The existing literature, case studies, and policy frameworks pertaining to cybersecurity in libraries particularly in the public and academic sectors are qualitatively reviewed in this conceptual study. It offers a multifaceted cybersecurity framework for libraries by combining knowledge of threat environments, institutional policies, human-centered awareness, and collaborative governance approaches. Findings: According to research, libraries are particularly vulnerable to ransomware, phishing scams, data breaches, and illegal access as they grow their digital services and remote access capabilities. The survey also shows that many organizations frequently rely on antiquated infrastructure, underinvest in staff training, and lack official cybersecurity strategies. Proactive governance, collaborations with cybersecurity and IT companies, and ongoing education, however, can greatly lessen these difficulties. Implications: The study is unique in its holistic approach that links technology, policy, ethics, and education while focusing on the distinct information ecosystem of libraries. The implications are broad for educators, librarians, and policymakers, offering strategies to improve digital trust, data privacy, and resilience in library systems. Originality and value: This work is valuable because it promotes libraries as safe digital havens that are necessary for knowledge preservation and fair access in a world where everything is connected by technology, in addition to being informational hubs.
Supply-chain attacks (including typosquatting, dependency confusion, compromised builds, dataset poisoning, and backdoored models) pose growing threats to analytics platforms central to Information Systems (IS). While frameworks like the Secure Software Development Framework (SSDF) and Supply-chain Levels for Software Artifacts (SLSA) offer guidance, IS curricula often lack accessible, infrastructure-light modules that build practical skills for mitigating these risks. This experience report presents a two-week module embedded in a graduate Secure Coding course required for a Master’s in Applied Security and Analytics degree. The module operationalizes secure development habits across both traditional software and machine learning (ML) pipelines. The module addresses a gap in IS education: the absence of hands-on, replicable interventions that integrate supply-chain hygiene with ML provenance. Students engage in sequenced drills using deterministic Python environments, private package indexes, CI policies that prohibit public fallback, and concise Software and Model Bills of Materials (SBOM/MBOM). The module emphasizes (i) visibility of dependencies and provenance, (ii) integrity enforcement by default, and (iii) evidence-based risk triage. Qualitative analysis of student artifacts and reflections reveals improved onboarding, clearer transitive risk differentiation, stronger policy awareness, and greater fluency in stakeholder-oriented documentation. These outcomes suggest meaningful gains in workforce readiness, especially for roles requiring secure AI/ML deployment and DevSecOps fluency. Aligned with IS2020 competencies and SSDF/SLSA compliance, the module offers a scalable blueprint for IS educators. Future work includes signed attestations, objective pre/post assessments, and cross-institution replication to validate generalizability and deepen cybersecurity pedagogy.
Abstract: This paper offers a conceptual discussion of how mindfulness, understood as present moment awareness and deliberate attention regulation, can support cybersecurity professionals. Drawing on a narrative synthesis of workplace mindfulness, burnout, and high pressure decision making literature, we map plausible self regulation mechanisms to typical cyber defense tasks. Rather than presenting new empirical data, we develop an explanatory framework linking attention, reactivity, and recovery to decision quality, team communication, and adherence to incident playbooks. We focus on two connected outcomes: reducing burnout in roles with sustained cognitive and emotional demands, and improving operational effectiveness during critical situations such as incident response. We argue that brief, secular mindfulness practices can strengthen attentional control and emotion regulation, helping practitioners notice stress signals, recover after interruptions, and reduce lapses that contribute to human error. We also examine how usefulness and implementation may vary across functional profiles (security operations center monitoring, incident response, threat hunting) and operational contexts (shift work, on call, distributed teams), including 24/7 follow the sun models. Finally, we delimit the contribution as a theory informed agenda and propose comparative directions for research and implementation, emphasizing that mindfulness should complement, not replace, structural measures for workload management, tooling, and process maturity.