TY - JOUR
T1 - Socio-Technical Security Modelling and Simulations in Cyber-Physical Systems
T2 - Outlook on Knowledge, Perceptions, Practices, Enablers, and Barriers
AU - Ani, Uchenna
AU - Al-Mhiqani, Mohammed
AU - Tuptuk, Nilufer
AU - Hailes, Stephen
AU - McKendrick Watson, Jeremy
N1 - Funding Information:
Funding: This work is part of the Modelling for Socio-Technical Security project supported by the PETRAS National Centre of Excellence for IoT Systems Cybersecurity, which has been funded by the UK Engineering and Physical Science Research Council (EPSRC) under grant number EP/S035362/1. The authors would like to also thank UK Department for Transport (DfT), National Cyber Security Centre (NCSC) for their invaluable support as part of this work.
Funding Information:
This work is part of the Modelling for Socio\u2010Technical Security project supported by the PETRAS National Centre of Excellence for IoT Systems Cybersecurity, which has been funded by the UK Engineering and Physical Science Research Council (EPSRC) under grant number EP/S035362/1. The authors would like to also thank UK Department for Transport (DfT), National Cyber Security Centre (NCSC) for their invaluable support as part of this work. Funding:
Publisher Copyright:
© 2025 The Author(s). IET Cyber-Physical Systems: Theory & Applications published by John Wiley & Sons Ltd on behalf of The Institution of Engineering and Technology.
PY - 2025/4/30
Y1 - 2025/4/30
N2 - Socio-Technical Security Modelling and Simulation (STSec-M&S) is a technique used for reasoning and representing security viewpoints that include both the social and technical aspects of a system. It has shown great potential for improving the cybersecurity and resilience of Critical Infrastructure (CI). This study involved a multi-methods approach, consisting of a scoping literature review and a focus group workshop, conducted with stakeholder engagement from critical infrastructure stakeholders to explore their perceptions and practices regarding the use of socio-technical security modelling and simulation. The findings suggest that the current state of knowledge regarding the use and effectiveness of STSec-M&Ss approaches is limited in CI domains. Consequently, there is little application of it in existing CI systems, regardless of its recognised benefits of enabling a better understanding of CI functionalities, security goals, early and more holistic risk identifications and selection of appropriate countermeasures. The benefits of the STSec-M&S approach can be better realised by effective cross-sector communications and collaborations, team partnerships, system and approach sophistication, and better security awareness amongst others. The potential barriers that can impede such benefits include high expense for implementing the technique, low data availability and quality, regulatory compliance, and competency gaps, etc. Helpful recommendations include exploring and using realistic data, validating system security models, and exploring new ways of reskilling and upskilling CI stakeholders in socio-technical security-thinking and M&S approaches to enhance cybersecurity and resilience of CIs.
AB - Socio-Technical Security Modelling and Simulation (STSec-M&S) is a technique used for reasoning and representing security viewpoints that include both the social and technical aspects of a system. It has shown great potential for improving the cybersecurity and resilience of Critical Infrastructure (CI). This study involved a multi-methods approach, consisting of a scoping literature review and a focus group workshop, conducted with stakeholder engagement from critical infrastructure stakeholders to explore their perceptions and practices regarding the use of socio-technical security modelling and simulation. The findings suggest that the current state of knowledge regarding the use and effectiveness of STSec-M&Ss approaches is limited in CI domains. Consequently, there is little application of it in existing CI systems, regardless of its recognised benefits of enabling a better understanding of CI functionalities, security goals, early and more holistic risk identifications and selection of appropriate countermeasures. The benefits of the STSec-M&S approach can be better realised by effective cross-sector communications and collaborations, team partnerships, system and approach sophistication, and better security awareness amongst others. The potential barriers that can impede such benefits include high expense for implementing the technique, low data availability and quality, regulatory compliance, and competency gaps, etc. Helpful recommendations include exploring and using realistic data, validating system security models, and exploring new ways of reskilling and upskilling CI stakeholders in socio-technical security-thinking and M&S approaches to enhance cybersecurity and resilience of CIs.
KW - Socio-Technical Security
KW - Cybersecurity Modelling
KW - Security Simulation
KW - Cyber-Physical Systems Security
KW - Critical Infrastructure Security
KW - computer network security
KW - cyber‐physical systems
KW - internet of things
KW - risk analysis
KW - security of data
UR - http://www.scopus.com/inward/record.url?scp=105003797040&partnerID=8YFLogxK
U2 - 10.1049/cps2.70017
DO - 10.1049/cps2.70017
M3 - Article
SN - 2398-3396
VL - 10
JO - IET Cyber-Physical Systems: Theory and Applications
JF - IET Cyber-Physical Systems: Theory and Applications
IS - 1
M1 - e70017
ER -