TY - JOUR
T1 - A framework for enhancing cyber incident response with Security-Enhancing Digital Twins in Cyber–Physical Systems
AU - Suhail, Sabah
AU - Iqbal, Mubashar
AU - McLaughlin, Kieran
AU - Lee, Brian
AU - Imtiaz, Babar
N1 - Publisher Copyright:
© 2025 The Authors
PY - 2025/5
Y1 - 2025/5
N2 - Standalone traditional cybersecurity solutions and tools often fall short in covering the lifecycle of critical assets, conducting vulnerability identification, and correlating cyber incidents with adversary knowledge bases. This limitation can lead to fragmented incident response (IR) strategies. Security-enhancing digital twins (SEDTs) can act as complementary security solutions alongside existing solutions to support various IR lifecycle phases in cyber–physical systems (CPSs). In this work, we propose a framework that can serve as a guide for plant operators on how to design, develop, deploy, and manage SEDT-based IR solutions across four key phases, including prerequisites, design-and-engineering, operation-and-maintenance, and end-of-life. With the automotive manufacturing industry as a cyber–physical production system (CPPS) use case, we thoroughly examine the applicability of the proposed framework. Furthermore, we evaluate the proposed framework in both industry and academic settings, covering various aspects, including the design and operation requirements of SEDTs. This evaluation helps identify gaps between academic findings and practical industry solutions, such as in SEDT objectives, architecture, integration with existing security solutions, and lifecycle.
AB - Standalone traditional cybersecurity solutions and tools often fall short in covering the lifecycle of critical assets, conducting vulnerability identification, and correlating cyber incidents with adversary knowledge bases. This limitation can lead to fragmented incident response (IR) strategies. Security-enhancing digital twins (SEDTs) can act as complementary security solutions alongside existing solutions to support various IR lifecycle phases in cyber–physical systems (CPSs). In this work, we propose a framework that can serve as a guide for plant operators on how to design, develop, deploy, and manage SEDT-based IR solutions across four key phases, including prerequisites, design-and-engineering, operation-and-maintenance, and end-of-life. With the automotive manufacturing industry as a cyber–physical production system (CPPS) use case, we thoroughly examine the applicability of the proposed framework. Furthermore, we evaluate the proposed framework in both industry and academic settings, covering various aspects, including the design and operation requirements of SEDTs. This evaluation helps identify gaps between academic findings and practical industry solutions, such as in SEDT objectives, architecture, integration with existing security solutions, and lifecycle.
KW - Cyberattacks
KW - Cyber–Physical System (CPS)
KW - Incident Response (IR)
KW - Industry 4.0
KW - Security-Enhancing Digital Twins (SEDTs)
UR - http://www.scopus.com/inward/record.url?scp=85218908826&partnerID=8YFLogxK
U2 - 10.1016/j.iot.2025.101547
DO - 10.1016/j.iot.2025.101547
M3 - Article
AN - SCOPUS:85218908826
SN - 2542-6605
VL - 31
JO - Internet of Things (The Netherlands)
JF - Internet of Things (The Netherlands)
M1 - 101547
ER -