Zero-Trust Architecture (ZTA) has emerged as a foundational cybersecurity paradigm with wide adoption. However, assumptions made in shore-based enterprise networks pose challenges when applying zero-trust principles in maritime environments. In maritime systems, operations depend on intermittent, low-bandwidth, and often contested communications. Thus, strict zero trust enforcement can unintentionally disrupt mission-critical functions. This paper examines the benefits and limitations of applying ZTA in maritime contexts, with particular attention to safety-critical operations and military. This work outlines a maritime-adapted zero trust framework that integrates degraded-mode operation and fallback mechanisms to preserve operational continuity while maintaining security objectives and safe mission completion.
Despite growing concern about cognitive warfare targeting critical infrastructure, maritime Search and Rescue (SAR) operations have received little systematic attention as potential targets, despite being life-saving activities, constantly happening around the globe, and involving efforts from both militaries, coast guards, and NGOs. This paper presents a disruption model based on the International Aeronautical and Maritime Search and Rescue (IAMSAR) Manual—employing Observe, Orient, Decide, Act (OODA) loop phases as analytical lenses—for understanding how AI-generated deception threatens maritime SAR effectiveness.
Maritime Transportation Systems are considered critical infrastructure and systemic risk which can trigger cascade effects to impacting operations, the economy, and national security. Maritime cybersecurity systems currently face challenges, and a lack of structured frameworks to prioritize R&D investments and technological development. This study aims to systematically analyze maritime cybersecurity using a Technology Roadmapping (TRM) approach structured around the National Institute of Standards and Technology (NIST), integrating a qualitative analysis of themes from the perspectives of people, technology, and governance across six functional areas. TRM facilitates the identification of drivers, capability gaps, technologies, and R&D priorities, to address these limitations. The findings highlight that maritime cybersecurity should be treated as a system-of-systems problem that requires the integration of IT, OT, and cyber-physical systems, as well as automation and real-time capabilities supported by human-Artificial Intelligence (AI) collaboration.
Digital technologies are often described as transforming security and war, yet their strategic effects remain contested. This article argues that cyber capabilities and related digital infrastructures are better understood as recomposing the strategic field rather than inaugurating a discrete Revolution in Military Affairs. Drawing on large-N datasets of interstate cyber incidents, illustrative case studies, and policy and doctrinal documents, it traces how digital tools reshape instruments of coercion, diversify relevant actors beyond states, and blur domestic and external spaces of security. The analysis highlights governance dilemmas for deterrence, alliance coordination, and the regulation of platform power.
Managing cybersecurity risks within financial technology organisations is increasingly complex, with traditional qualitative assessments falling short in quantifying the financial implications of cyber threats. This paper presents an approach to implementing a Cybersecurity Debt Management Model, which integrates cybersecurity with financial risk management methodologies, demonstrating a structured method for operationalising the model within a FinTech IT environment. The model quantifies the financial impact of unresolved cybersecurity vulnerabilities, facilitating decision making, targeted resource allocation, and regulatory compliance. The proposed approach provides organisations with insights into managing cybersecurity debt, thereby promoting resilience and alignment of technical measures with strategic objectives.
This paper explores the use of machine learning to improve cybersecurity measures against phishing attacks targeting e-banking platforms. By analysing a comprehensive dataset of phishing and legitimate URLs, machine learning models were developed and evaluated for their effectiveness in detecting phishing threats. This study highlights the potential of using the XGBoost machine learning algorithm in the development of applications with a focus on the identification of malicious URLs. The results of the Phishing URL Detection Model (PUDM) developed in this paper using XGBoost demonstrates a significant enhancement in detection accuracy and response times. An application that includes this model for the identification of malicious URLs will support users using e-banking applications as it will reduce the chances of user's connecting to a malicious URL that will result in the stealing of their sensitive financial information. Using this algorithm in applications will provide proactive defences in the ongoing battle against cyber threats.
Societies’ increasing dependence on digitised services makes them vulnerable to cyber threats. Artificial Intelligence (AI) has been utilised in threat detection since the 1990s, and its use is expanding as the technology advances. However, the role of AI in cyber operations has not been studied systematically. This study provides a comprehensive understanding of how AI can accelerate both defensive and offensive cyber operations. Using the systematic literature review method, 22 practical use cases were identified and mapped onto different phases of cyber operations. The results indicate that cyber operations leaders’ AI acceleration has not been sufficiently researched.
This paper analyzes the cyber threat landscape posed by advanced persistent threats (APTs) attributed to China, Iran, North Korea, and Russia. It focuses on active groups and their cyber activities targeting the United States. Utilizing cyber threat intelligence data from authoritative sources such as Cybersecurity and Infrastructure Security Agency (CISA), Office of the Director of National Intelligence (ODNI), Mandiant, and MITRE, this study identifies twelve key APT groups attributed to the four adversarial nations and creates a quick profile for each nation and group. It explores the common techniques and sub-techniques employed by each nation and then across all four nations. Examination of these nations, groups, and techniques then informs a list of six actionable mitigations that will enhance cybersecurity defenses targeting these adversarial groups in an efficient manner: User Training, Restrict Web-Based Content, Privileged Account Management, Network Intrusion Prevention, Execution Prevention, and Antivirus/Antimalware.
This study delves into the escalating cybersecurity concerns in the maritime sector as technology becomes more integrated with daily operations. Focused on the Hampton Roads region, it employs Grounded Theory to decipher the intricate dynamics of cybersecurity. Through interviews with key stakeholders and participant observation, it aims to grasp the challenges, risks, and remedies pertinent to maritime cybersecurity. Additionally, it scrutinizes existing frameworks and regulations to gauge their efficacy. Initial findings reveal resistance from organizations in complying with cybersecurity standards, hinting at pervasive vulnerabilities. The research promises to enrich scholarly dialogue and practical strategies for maritime entities, cybersecurity practitioners, and policymakers. By shedding light on the unique cybersecurity landscape of the Hampton Roads area, the study seeks to foster tailored approaches for bolstering cybersecurity resilience in maritime operations. This endeavor is crucial amid the digitalization wave, underscoring the imperative of safeguarding maritime activities for their safety, security, and sustainability.
This paper proposes a novel, beneficial application of deepfake technology in the realm of moving target obfuscation information security defence mechanisms. This defensive obfuscation technique aims to utilize generative artificial intelligence systems to synthesize honeypot datasets that mimic certain characteristics of sensitive and highly sought-after datasets by threat actors. By synthesizing and intentionally making available realistic but fake datasets within information systems, this novel technique has the potential to (1) mislead threat actors from acquiring their target data during their data breach attempts, and (2) render any corpus of breached datasets useless.
The digitization of the electric energy grid enlarges its attack surface and makes the infrastructure increasingly vulnerable to digital warfare. Therefore, national legislation is central to defending critical energy infrastructure against terrorist and nation-state attacks in cyberspace. Still, previous studies have found shortcomings in cybersecurity legislation. To support smaller countries in their policymaking, this study describes a normative ideal in the form of a consolidated security policy framework. The framework consists of 25 policies that are based on cybersecurity and privacy rules of five countries with strong cyber defence capabilities; the framework addresses five cyberattack scenarios with a very high consequence potential. This study shows that the consolidated policies provide a holistic cyber defence framework, covering strategic, tactical, and operational levels, including obligations on both authority and industry levels.
Amidst the digital revolution, cyber-enabled critical infrastructures are the foundation of societal operations. However, this interconnectivity introduces risks such as cascading failures where disruptions in the power grid affect multiple systems. Global collaboration becomes inescapable in forming holistic approaches that evolve alongside continuous technological advancements to enhance infrastructure resilience. Before these approaches can truly succeed, it is imperative to understand the decision-making processes within these environments and effectively mitigate biases that may alter priorities. This study investigates subconscious biases stemming from perceived solutions, intending to anticipate their potential impact on decision-making prioritization and enhance overall cybersecurity in critical infrastructure resilience.
Most of the influence and persuasion techniques used in social engineering have been documented across many domains, including cybersecurity, and have been shown to rely on similar effect mechanisms used in areas such as marketing, scams, and street cons. This paper shows that, while these attacks are explained in terms of the social and psychological effect mechanisms, the aspectual lens provides a more nuanced understanding of human performance variability implicated in social engineering. The aspectual lens provides a comprehensive analytical and ontological framing, and hints at aspectually informed measures for mitigating social engineering attacks and dampening the said human performance variability.
The broad applicability of the National Institute for Standards and Technology’s (NIST) Framework for Improving Critical Infrastructure Cybersecurity, commonly known as the Cybersecurity Framework (CSF), creates a utility gap for small and medium businesses (SMB) to apply and implement the framework effectively within their organizations. The purpose of this research is to explore and interpret the CSF in the context of small and medium businesses with implications of bridging the utility gap for this significant, yet vulnerable, population; specifically, this paper contributes detailed interpretations and actions of the NIST CSF that can be implemented by SMBs to help improve their cybersecurity stance.
Vulnerabilities leveraged by Advanced Persistent Threats (APTs) that ultimately allow them to gain access to critical data and unveil private information are often far removed from the portions of the security environment where initial access is gained. This paper presents a defensi- ble scholarly decomposition of the red-team process itself and discusses how traditional red-team assessments may not be the most effective solution for emulating APT threats and mitigating their impacts.
The definitive publication for the best and latest research and analysis on information warfare, information operations, and cyber crime. Available in traditional hard copy or online.
The definitive publication for the best and latest research and analysis on information warfare, information operations, and cyber crime. Available in traditional hard copy or online.