Abstract
Standalone traditional cybersecurity solutions and tools often fall short in covering the lifecycle of critical assets, conducting vulnerability identification, and correlating cyber incidents with adversary knowledge bases. This limitation can lead to fragmented incident response (IR) strategies. Security-enhancing digital twins (SEDTs) can act as complementary security solutions alongside existing solutions to support various IR lifecycle phases in cyber–physical systems (CPSs). In this work, we propose a framework that can serve as a guide for plant operators on how to design, develop, deploy, and manage SEDT-based IR solutions across four key phases, including prerequisites, design-and-engineering, operation-and-maintenance, and end-of-life. With the automotive manufacturing industry as a cyber–physical production system (CPPS) use case, we thoroughly examine the applicability of the proposed framework. Furthermore, we evaluate the proposed framework in both industry and academic settings, covering various aspects, including the design and operation requirements of SEDTs. This evaluation helps identify gaps between academic findings and practical industry solutions, such as in SEDT objectives, architecture, integration with existing security solutions, and lifecycle.
Original language | English |
---|---|
Article number | 101547 |
Number of pages | 30 |
Journal | Internet of Things |
Volume | 31 |
Early online date | 28 Feb 2025 |
DOIs | |
Publication status | Published - May 2025 |
Keywords
- cyber incident
- cyber incident response
- security-enhancing digital twin s
- cyber–physical systems