Skip to content
Conference

IoT-Specific Cybersecurity Awareness Training (CSAT) Framework

Jul 2026 · 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET) · pp. 1-10 · 0 citations · 27 references

Abstract

The widespread adoption of Internet of Things (IoT) and Operational Technology (OT) sys- tems in industrial environments has significantly in- creased cybersecurity exposure. Human error re- mains a leading cause of successful cyberattacks; how- ever, conventional Cybersecurity Awareness Training (CSAT) programs are typically static and poorly aligned with user roles, asset criticality, and evolving threats. This paper proposes an IoT-focused risk- adaptive CSAT framework that integrates MITRE ATT&CK-based threat modeling, CIA-aware impact analysis, machine learning-driven risk assessment, and Generative Artificial Intelligence (GenAI) for person- alized training delivery. The framework models cyber- security awareness as a continuous closed-loop process that constructs user-specific attack graphs, evaluates vulnerabilities through adaptive assessments, and com- putes local and global risk scores. Machine learning dynamically derives risk thresholds to guide training prioritization, while GenAI generates targeted training content aligned with real-world attack scenarios. Evaluation using representative industrial user profiles demonstrates consistent reductions in vulnerability and global risk levels following personalized training. The results indicate that the proposed framework has the potential to enhance human-centric security and im- prove the effectiveness of cybersecurity awareness pro- grams in industrial IoT environments.

View source

Similar papers

Review Open access Aug 2026

AI-Supported Dynamic Cyber Risk Assessment for Cyber Situational Awareness: A Cross-Sectional Survey

Small and medium-sized enterprises (SMEs) have limited resources and governance that might restrict their ability to conduct dynamic cyber risk assessment (DCRA) and maintain effective cyber situational awareness (CSA). This study investigates stakeholders’ perceptions of CSA, DCRA, and AI-enabled cybersecurity to develop a conceptual framework targeted for SMEs. The online survey was cross-sectional, and 302 completed responses were gathered. The valid sample size for the items ranged from 288 to 299. Out of 293 respondents, 54 (18.4%) indicated prior usage of CSA techniques, 21 (7.2%) reported prior use of DCRA tools, and 226 (77.1%) backed AI in the cybersecurity field. The highest rated DCRA requirements were continuous threat updates, identification of attacks and vulnerabilities, and prioritization of alerts based on risk. The highest rated implementation challenges were accuracy, relevance, and integration with current infrastructure. Four multi-item measures had good-to-outstanding internal consistency (α = 0.868–0.926; ω = 0.870–0.929), and parallel analysis supported a single factor for each. Exploratory findings suggested that Information Technology (IT) and cybersecurity professionals had greater familiarity with CSA and DCRA than did leaders and managers. There was a moderate-to-strong positive association between familiarity with CSA and DCRA (ρ = 54). The framework defines AI as a layer of analytical decision support, DCRA as the process of translating changing evidence into updated and prioritized risk information, and CSA as decision-relevant interpretation and use of that information. This framework will help SMEs to improve CSA and will help their leaders to make the right decisions when dealing with cyber threats.

Mansour Almalki, L. Nawaf, Fiona Carroll · 0 citations
Open access 2026

A Human Factors-Cyber-Safety Framework for Risk and Requirements in Critical Infrastructure

Cyber-attacks on critical infrastructure are increasing in scale and sophistication, yet cybersecurity practice remains dominated by technology-centric assessments that insufficiently represent human contributions to risk. In cyber-physical systems (CPS), non-malicious human actions -including slips, mistakes, workarounds, training gaps, and misaligned procedures- frequently create, amplify or fail to detect vulnerabilities.This paper presents an integrated socio-technical framework that combines Human Factors (HF) methods, safety analysis, and cybersecurity modelling within a Secure-by-Design approach. The framework models how human performance variability influences cyber vulnerability and safety outcomes, enabling structured, scenario-based risk assessment and the derivation of traceable engineering requirements. An illustrative application demonstrates how HF findings are translated into human error mechanisms, cyber effects, unsafe control actions, safety impacts, and prioritised Secure-by-Design controls. By operationalising HF methods as cybersecurity engineering tools, the approach reframes cybersecurity as a socio-technical reliability problem comparable to safety engineering.

Eylem Thron, Duncan Ki-Aries, Martin Freer et al. · 0 citations
Conference Jul 2026

OT Cybersecurity: From Perimeter Security to Zero Trust: An AI-Governed OT Cybersecurity Architecture for Industrial Systems

The progressive convergence of Information Technology (IT) and Operational Technology (OT) environments has introduced new cybersecurity challenges for industrial and critical infrastructure systems. This work presents a generalized OT cybersecurity architecture that combines the Purdue reference model with Zero Trust principles to enforce strict segmentation, continuous verification, and controlled information flows across IT/OT boundaries. The architecture incorporates Artificial Intelligence (AI)-driven monitoring to support anomaly detection, contextual risk assessment, and automated response mechanisms under operational constraints. Additionally, a governance and assurance layer is discussed, aligning AI-enabled security functions with recognized risk management frameworks and auditable controls to ensure trustworthiness, resilience, and operational sustainability in high-impact industrial deployments. The proposal is further contextualized with prior AI-RMFgoverned IoT-as-a-Service and OWASP ML05 middleware contributions that address AI-enabled IoT security, model protection, and governance requirements.

Yair Rivera Julio, Ángel D. Pinto-Mangones, Frank A. Ibarra et al. · 0 citations
Review Open access 2026

A Risk-Based Cybersecurity Auditing Framework for Smart Grid Infrastructure Using Explainable Artificial Intelligence (XAI)

This study suggests a framework for cybersecurity auditing of smart grid infrastructure, which is based on the concept of risk and the use of Explainable Artificial Intelligence (XAI) to produce transparent, prioritized and audit-ready security evidence. The information from public smart grid cybersecurity events was mapped to event labels, asset classes, security-control status, compliance indicators, and cyber-physical impact variables, which were then used to create audit-relevant records. Attack likelihood estimates were made using machine learning models. The attack likelihood, asset criticality, control deficiency score, compliance condition and operational impact were all added together to calculate the final audit risk score. Explainability was used as a technique to identify the most important features that affected each audit decision by applying the SHAP method. The proposed framework achieved 96.38% accuracy, 96.51% precision, 96.38% recall, 96.42% F1-score, and 0.996 ROC-AUC. The results of the ablation showed that the inclusion of the risk component and the XAI component resulted in an improvement in the risk ranking, audit traceability and explanation consistency. The framework translates the cybersecurity detection results into an understandable audit decision, enabling risk-based remediation, compliance review, and an understandable smart grid cybersecurity governance.

Udit Mamodiya, I. Kishor, Hastimal Jangid et al. · 0 citations
Review 2026

A Critical Review of Continuous Threat Exposure Management and Zero Trust Security in Cloud–IoT Ecosystems

The rise in Cloud–Internet of Things (Cloud–IoT) infrastructure has greatly increased the exposure of organizations to cyber threats, with recent studies showing that over 68% of security breaches have originated from misconfigured cloud resources. Continuous Threat Exposure Management (CTEM) and Zero Trust Security (ZTS) models have been proposed to address these challenges; however, nearly 70% of current implementations are still detection-oriented rather than exposure-predictive. This critical review statistically evaluates current research on CTEM models, Zero Trust frameworks, and artificial intelligence-based cybersecurity solutions in multi-cloud and edge environments. A review of the literature suggests that less than 35% of current solutions have combined dynamic risk scoring with automated access control, while less than 25% of current solutions have allowed real-time adaptive policy enforcement. There is a great need for improvement in predictive threat exposure modelling, autonomous security orchestration, and continuous exposure mitigation in heterogeneous cloud–IoT infrastructures. The review identifies essential research goals in the development of an AI-based adaptive cyber defence framework that is predictive, intelligent, and continuously risk-driven in a Zero-Trust security paradigm.

Koteswara Rao Damacharla, S. Kumar · 0 citations
Review Open access Jul 2026

Cybersecurity Challenges and Centralized Monitoring Solutions for e-Governance in Zambia: A Literature Review

Some operational and technical challenges that affect the adoption of effective cybersecurity prac-tices within e-government infrastructures are identified and the importance of scalable, cost-effective, and integrated monitoring infrastructures to manage cybersecurity proactively in developing countries are highlighted.

Lukumba Phiri, Steve Muwowo · 0 citations