A Survey on Cybersecurity Threats in Industrial and Information Technology Environments: Advancements and Resilience Through Network Steganographic Techniques
Aug 2026· ACM Computing Surveys· 0 citations· 116 references
TL;DR
This paper analyzes eight major IT/OT threats in the view of their empowerment via steganography to anticipate the evolution of malicious software targeting IT/OT scenarios when endowed with advanced data hiding schemes, i.e., multi level steganography.
Abstract
The complex interplay of Operational Technology (OT) and Information Technology (IT) daily supports critical infrastructures managing energy, transportation, manufacturing, and utilities. Due to their importance, the number of attacks targeting IT/OT scenarios has increased. The most sophisticated malware relies on techniques such as encryption, obfuscation, or social engineering. An emerging trend is to use some form of information hiding, mainly to create covert communications cloaked within network traffic. This paper analyzes eight major IT/OT threats in the view of their empowerment via steganography. The goal of this work is to anticipate the evolution of malicious software targeting IT/OT scenarios when endowed with advanced data hiding schemes, i.e., multi level steganography. Our analysis clearly indicates that the ability of cloaking data within IT/OT deployments should be considered a real danger. Moreover, current mitigation techniques are only partially adequate to face such a new-wave of attacks. Hence, we provide some gaps to be filled by researchers and security experts for improving detection techniques and implementing defenses against emerging cybersecurity threats.
Cloud is the essential component for modern computer systems, offering businesses flexible scalability and on-demand resources. However, as attackers use more complex techniques to compromise cloud networks, this technological advancement has ushered in a new era of cybersecurity challenges. Wide-ranging effects, such as data loss, financial penalties, reputational harm, and legal responsibilities, can result from such breaches. In response to these challenges, a strong security framework is essential to effectively protect cloud infrastructure. Recently, several artificial intelligence (AI) techniques have been developed for cyber threat detection. Hence, to get deeper insight into this, the survey aims to analyse the role of cyber threat detection techniques and provide an overview of their applications. To achieve this, around 28 research papers from the years 2023-2026 are reviewed based on their methods, algorithms, datasets, performance metrics, and achievements. Furthermore, this work reviews different types of threats affecting the availability, confidentiality, and integrity of cloud services and resources, and examines the applications, including intrusion detection in cloud and several types of cyber threat detection systems. The core insights formulated in this review provide a comparison of analytics as well as future directions.
Pradnya Patil, J. Bakal· 2026 7th International Confe...· 0 citations
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
The quick uptake of cloud computing, artificial intelligence (AI), Internet of Things (IoT), and hybrid workplace solutions has changed the cybersecurity needs in a way that renders the traditional notion of perimeter defense inefficient in addressing sophisticated attack scenarios such as ransomware, insider threats, and advanced persistent threats (APTs). This literature review analyzes advancements in the field of Advanced Information Security and Assurance from 2016 to 2026.
Key advancements include NIST SP 800-207 published in 2020, widespread use of Zero Trust Architecture (ZTA), and incorporation of AI into security analytics. The reviewed sources show that Zero Trust drastically minimizes attack surfaces using continuous authentication, least-privilege access, and microsegmentation. Also, AI is beneficial in improving threat detection through predictive analytics, behavioral anomalies detection, and automation of the incident response process.
On the other hand, AI also poses emerging risks such as adversarial machine learning, automated API reconnaissance, AI phishing scams, and intelligent malware. Additionally, cyber resilience, explainable AI, and adaptive governance are the identified research areas important for protecting future digital infrastructures. While significant advances have been made, there are still many challenges related to complexity, interoperability, staffing shortage, privacy, and governance.
Celinne Atienza Mendez, Dr. Reagan Ricafort· International Journal of Lat...· 0 citations
In the realities of the intensive growth of cyber threats, traditional perimeter-based approaches to data protection are predictably losing their barrier function. It seems that the ability of digital ecosystems to withstand hacking has ceased to be perceived by the market as a purely technical or infrastructural task. In essence, information security has transformed into a fundamental driver of business capitalization. Meanwhile, when assessing the technological environment, pronounced contradictions are observed today. The engineering community persistently declares the need for an emergency migration of networks due to the growing "quantum threat." However, investment and venture capital institutions often operate with more "stretched" planning horizons, frequently overlooking the real transaction costs of integrating next-generation protocols. The aim of the article is to conduct an interdisciplinary analysis of the impact of advanced public key cryptography methods on the funding prospects of IT services. Based on the results of the work, it is logically argued that the architectural transition to post-quantum specifications, fully homomorphic encryption, and zero-knowledge proofs has a direct correlation with the growth of valuation multiples. By abandoning the accumulation of excessive sensitive data, regulatory risks are significantly reduced; the likelihood of compliance fines is minimized. The author's contribution is manifested in the conceptualization of the latest algorithms: complex mathematical primitives are argued to be presented as full-fledged economic tools through which long-term competitive advantage is formed. At the same time, a specific scheme for eliminating technological debt through an audit of cryptographic agility is proposed. The formulated conclusions and practical recommendations will be useful to technical directors, members of corporate boards of directors, hedge fund analysts, and specialists conducting startup audits before merger and acquisition procedures or initial public offerings.
A. A. Kvasov, Nikolay A. Kretinin· EKONOMIKA I UPRAVLENIE: PROB...· 0 citations