Cybersecurity Risk in Industrial Control Systems in Industry 4.0
Abstract
1. Introduction
2. Related Works
2.1. Risk in Digitally Connected Systems
2.2. Industry 4.0 and Cyber-Physical Systems
2.3. Product-Service Systems and System Complexity
2.4. Prior Work on the ICS-CERT Vulnerability Dataset
2.5. Research Gap
3. Materials and Methods
3.1. Data
3.2. Preprocessing
3.3. Variable Construction
3.4. Analytical Strategy
4. Results
4.1. Descriptive Landscape
4.2. Severity Determinants (Model 1)
4.3. Temporal Trajectory (Model 2)
4.4. Concentration
4.5. Robustness (Model 4)
5. Discussion
5.1. Risk as System Structure
5.2. Cross-Vendor Dependencies and Risk Propagation
5.3. Implications for Product-Service Systems
5.4. Digital Transformation Restructures Risk
5.5. Limitations
6. Conclusions
6.1. Findings
6.2. Theoretical Contribution
6.3. Methodological Contribution
6.4. Practical Implications
6.5. System-Level Implication
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Xu, L.D.; Xu, E.L.; Li, L. Industry 4.0: State of the art and future trends. Int. J. Prod. Res. 2018, 56, 2941–2962. [Google Scholar] [CrossRef] [Scilit]
- Frank, A.G.; Dalenogare, L.S.; Ayala, N.F. Industry 4.0 technologies: Implementation patterns in manufacturing companies. Int. J. Prod. Econ. 2019, 210, 15–26. [Google Scholar] [CrossRef] [Scilit]
- Urciuoli, L.; Männistö, T.; Hintsa, J.; Khan, T. Supply chain cyber security—Potential threats. Inf. Secur. 2013, 29, 51–68. [Google Scholar] [CrossRef] [Scilit]
- Böhme, R.; Kataria, G. Models and measures for correlation in cyber-insurance. In Proceedings of the Workshop on the Economics of Information Security, Cambridge, UK, 26–28 June 2006. [Google Scholar]
- Tukker, A. Product services for a resource-efficient and circular economy—A review. J. Clean. Prod. 2015, 97, 76–91. [Google Scholar] [CrossRef] [Scilit]
- Baines, T.; Bigdeli, A.Z.; Bustinza, O.F.; Shi, V.G.; Baldwin, J.; Ridgway, K. Servitization: Revisiting the state-of-the-art and research priorities. Int. J. Oper. Prod. Manag. 2017, 37, 256–278. [Google Scholar] [CrossRef] [Scilit]
- Coreynen, W.; Matthyssens, P.; Van Bockhaven, W. Boosting servitization through digitization: Pathways and dynamic resource configurations for manufacturers. Ind. Mark. Manag. 2017, 60, 42–53. [Google Scholar] [CrossRef] [Scilit]
- Ardolino, M.; Rapaccini, M.; Saccani, N.; Gaiardelli, P.; Crespi, G.; Ruggeri, C. The role of digital technologies for the service transformation of industrial companies. Int. J. Prod. Res. 2018, 56, 2116–2132. [Google Scholar] [CrossRef] [Scilit]
- Knowles, W.; Prince, D.; Hutchison, D.; Disso, J.F.P.; Jones, K. A survey of cyber security management in industrial control systems. Int. J. Crit. Infrastruct. Prot. 2015, 9, 52–80. [Google Scholar] [CrossRef] [Scilit]
- Green, B.; Krotofil, M.; Abbasi, A. On the significance of process comprehension for conducting targeted ICS attacks. In Proceedings of the ACM Workshop on Cyber-Physical Systems Security and Privacy, Dallas, TX, USA, 3 November 2017; pp. 5–6. [Google Scholar]
- Eling, M.; Wirfs, J. What are the actual costs of cyber risk events? Eur. J. Oper. Res. 2019, 22, 1109–1119. [Google Scholar] [CrossRef] [Scilit]
- Cenfetelli, R.T.; Benbasat, I.; Al-Natour, S. Addressing the what and how of online services: Positioning supporting-services functionality and service quality for business-to-consumer success. Inf. Syst. Res. 2008, 19, 161–181. [Google Scholar] [CrossRef] [Scilit]
- Allodi, L.; Massacci, F. Security events and vulnerability data for cybersecurity risk estimation. Risk Anal. 2017, 37, 1606–1627. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Eling, M.; Schnell, W. What do we know about cyber risk and cyber risk insurance? J. Risk Financ. 2016, 17, 474–491. [Google Scholar] [CrossRef] [Scilit]
- Biener, C.; Eling, M.; Wirfs, J.H. Insurability of cyber risk: An empirical analysis. Geneva Pap. Risk Insur. Issues Pract. 2015, 40, 131–158. [Google Scholar] [CrossRef] [Scilit]
- Bharadwaj, A.; El Sawy, O.A.; Pavlou, P.A.; Venkatraman, N. Digital business strategy: Toward a next generation of insights. MIS Q. 2013, 37, 471–482. [Google Scholar] [CrossRef] [Scilit]
- Mithas, S.; Rust, R.T. How information technology strategy and investments influence firm performance: Conjecture and empirical evidence. MIS Q. 2016, 40, 223–245. [Google Scholar] [CrossRef] [Scilit]
- Banker, R.D.; Hu, N.; Pavlou, P.A.; Luftman, J. CIO reporting structure, strategic positioning, and firm performance. MIS Q. 2011, 35, 487–504. [Google Scholar] [CrossRef] [Scilit]
- Tanriverdi, H.; Rai, A.; Venkatraman, N. Research commentary: Reframing the dominant quests of information systems strategy research for complex adaptive business systems. Inf. Syst. Res. 2010, 21, 822–834. [Google Scholar] [CrossRef] [Scilit]
- Xue, L.; Ray, G.; Gu, B. Environmental uncertainty and IT infrastructure governance: A curvilinear relationship. Inf. Syst. Res. 2011, 22, 389–399. [Google Scholar] [CrossRef] [Scilit]
- Kwon, J.; Johnson, M.E. Proactive versus reactive security investments in the healthcare sector. MIS Q. 2014, 38, 451–471. [Google Scholar] [CrossRef] [Scilit]
- D’Arcy, J.; Herath, T.; Shoss, M.K. Understanding employee responses to stressful information security requirements: A coping perspective. J. Manag. Inf. Syst. 2014, 31, 285–318. [Google Scholar] [CrossRef] [Scilit]
- Kagermann, H.; Wahlster, W.; Helbig, J. Recommendations for Implementing the Strategic Initiative Industrie 4.0; National Academy of Science and Engineering: Frankfurt, Germany, 2013. [Google Scholar]
- Zheng, T.; Ardolino, M.; Bacchetti, A.; Perona, M. The applications of Industry 4.0 technologies in manufacturing context: A systematic literature review. Int. J. Prod. Res. 2021, 59, 1922–1954. [Google Scholar] [CrossRef] [Scilit]
- Amin, S.; Litrico, X.; Sastry, S.S.; Bayen, A.M. Cyber security of water SCADA systems—Part I: Analysis and experimentation of stealthy deception attacks. IEEE Trans. Control Syst. Technol. 2013, 21, 1963–1970. [Google Scholar] [CrossRef] [Scilit]
- Humayed, A.; Lin, J.; Li, F.; Luo, B. Cyber-physical systems security: A survey. IEEE Internet Things J. 2017, 4, 1802–1831. [Google Scholar] [CrossRef] [Scilit]
- Hemsley, K.E.; Fisher, R.E. History of Industrial Control System Cyber Incidents; INLCON-18-44411; Idaho National Laboratory: Idaho Falls, ID, USA, 2018.
- Stouffer, K.; Lightman, S.; Pillitteri, V.; Abrams, M.; Hahn, A. Guide to Industrial Control Systems Security; NIST SP 800-82 Rev. 2; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2015.
- Dalenogare, L.S.; Benitez, G.B.; Ayala, N.F.; Frank, A.G. The expected contribution of Industry 4.0 technologies for industrial performance. Int. J. Prod. Econ. 2018, 204, 383–394. [Google Scholar] [CrossRef] [Scilit]
- Sjödin, D.; Parida, V.; Leksell, M.; Petrovic, A. Smart factory implementation and process innovation. Res.-Technol. Manag. 2018, 61, 22–31. [Google Scholar] [CrossRef] [Scilit]
- Kohtamäki, M.; Parida, V.; Oghazi, P.; Gebauer, H.; Baines, T. Digital servitization business models in ecosystems: A theory of the firm. J. Bus. Res. 2019, 104, 380–392. [Google Scholar] [CrossRef] [Scilit]
- Müller, J.M.; Kiel, D.; Voigt, K.I. What drives the implementation of Industry 4.0? The Role of Opportunities and Challenges in the Context of Sustainability. Sustainability 2018, 10, 247. [Google Scholar] [CrossRef] [Scilit]
- Tortorella, G.L.; Fettermann, D. Implementation of Industry 4.0 and lean production in Brazilian manufacturing companies. Int. J. Prod. Res. 2018, 56, 2975–2987. [Google Scholar] [CrossRef] [Scilit]
- Lasi, H.; Fettke, P.; Kemper, H.G.; Feld, T.; Hoffmann, M. Industry 4.0. Bus. Inf. Syst. Eng. 2014, 6, 239–242. [Google Scholar] [CrossRef] [Scilit]
- Samtani, S.; Yu, S.; Zhu, H.; Chen, H. Identifying SCADA vulnerabilities using passive and active vulnerability assessment techniques. In Proceedings of the IEEE Intelligence and Security Informatics, Miami, FL, USA, 8–10 November 2018; pp. 25–30. [Google Scholar]
- Hassanzadeh, A.; Rasekh, A.; Galelli, S.; Aber, M.; Ostfeld, A.; Banks, M.K.; Taormina, R. A review of cybersecurity incidents in the water sector. J. Environ. Eng. 2020, 146, 03120003. [Google Scholar] [CrossRef] [Scilit]
- Mont, O. Clarifying the concept of product-service system. J. Clean. Prod. 2002, 10, 237–245. [Google Scholar] [CrossRef] [Scilit]
- Reim, W.; Parida, V.; Örtqvist, D. Product-service systems business models and tactics: A systematic literature review. J. Clean. Prod. 2015, 97, 61–75. [Google Scholar] [CrossRef] [Scilit]
- Lightfoot, H.; Baines, T.; Smart, P. The servitization of manufacturing: A systematic literature review of interdependent trends. Int. J. Oper. Prod. Manag. 2013, 33, 1408–1434. [Google Scholar] [CrossRef] [Scilit]
- Kowalkowski, C.; Gebauer, H.; Kamp, B.; Parry, G. Servitization and deservitization: Overview, concepts, and definitions. Ind. Mark. Manag. 2017, 60, 4–10. [Google Scholar] [CrossRef] [Scilit]
- Vendrell-Herrero, F.; Bustinza, O.F.; Parry, G.; Georgantzis, N. Servitization, digitization and supply chain interdependency. Ind. Mark. Manag. 2017, 60, 69–81. [Google Scholar] [CrossRef] [Scilit]
- Xu, L. An assessment of randomized inventory policy in supply chains under multimodal demand distribution. J. Model. Manag. 2026, 21, 1352–1376. [Google Scholar] [CrossRef] [Scilit]
- Parida, V.; Sjödin, D.R.; Reim, W. Reviewing literature on digitalization, business model innovation, and sustainable industry: Past achievements and future promises. Sustainability 2019, 11, 391. [Google Scholar] [CrossRef] [Scilit]
- Suppatvech, C.; Godsell, J.; Day, S. The roles of internet of things technology in enabling servitized business models: A systematic literature review. Ind. Mark. Manag. 2019, 82, 70–86. [Google Scholar] [CrossRef] [Scilit]
- Martinez, V.; Neely, A.; Velu, C.; Ber, S.; Bisessar, D. Exploring the journey to services. Int. J. Prod. Econ. 2017, 192, 66–80. [Google Scholar] [CrossRef] [Scilit]
- Gebauer, H.; Paiola, M.; Saccani, N.; Rapaccini, M. Digital servitization: Crossing the perspectives of digitization and servitization. Ind. Mark. Manag. 2021, 93, 382–388. [Google Scholar] [CrossRef] [Scilit]
- Tukker, A. Eight types of product-service system: Eight ways to sustainability? Experiences from SusProNet. Bus. Strategy Environ. 2004, 13, 246–260. [Google Scholar] [CrossRef] [Scilit]
- Rabetino, R.; Harmsen, W.; Kohtamäki, M.; Sihvonen, J. Structuring servitization-related research. Int. J. Oper. Prod. Manag. 2018, 38, 350–371. [Google Scholar] [CrossRef] [Scilit]
- Story, V.M.; Raddats, C.; Burton, J.; Zolkiewski, J.; Baines, T. Capabilities for advanced services: A multi-actor perspective. Ind. Mark. Manag. 2017, 60, 54–68. [Google Scholar] [CrossRef] [Scilit]
- Bustinza, O.F.; Bigdeli, A.Z.; Baines, T.; Elliot, C. Servitization and competitive advantage: The importance of organizational structure and value chain position. Res.-Technol. Manag. 2015, 58, 53–60. [Google Scholar] [CrossRef] [Scilit]
- Paschou, T.; Rapaccini, M.; Adrodegari, F.; Saccani, N. Digital servitization in manufacturing: A systematic literature review and research agenda. Ind. Mark. Manag. 2020, 89, 278–292. [Google Scholar] [CrossRef] [Scilit]
- Grubic, T. Remote monitoring technology and servitization: Exploring the relationship. Comput. Ind. 2018, 100, 148–158. [Google Scholar] [CrossRef] [Scilit]
- Sklyar, A.; Kowalkowski, C.; Tronvoll, B.; Sörhammar, D. Organizing for digital servitization: A service ecosystem perspective. J. Bus. Res. 2019, 104, 450–460. [Google Scholar] [CrossRef] [Scilit]
- Sjödin, D.; Parida, V.; Kohtamäki, M.; Wincent, J. An agile co-creation process for digital servitization: A micro-service innovation approach. J. Bus. Res. 2020, 112, 478–491. [Google Scholar] [CrossRef] [Scilit]
- Samtani, S.; Yu, S.; Zhu, H.; Patton, M.; Matherly, J.; Chen, H. Identifying SCADA systems and their vulnerabilities on the Internet of Things: A text-mining approach. IEEE Intell. Syst. 2018, 33, 63–73. [Google Scholar] [CrossRef] [Scilit]
- Zolanvari, M.; Teixeira, M.A.; Gupta, L.; Khan, K.M.; Jain, R. Machine learning-based network vulnerability analysis of industrial internet of things. IEEE Internet Things J. 2019, 6, 6822–6834. [Google Scholar] [CrossRef] [Scilit]
- Ivanov, D.; Dolgui, A.; Sokolov, B. The impact of digital technology and Industry 4.0 on the ripple effect and supply chain risk analytics. Int. J. Prod. Res. 2019, 57, 829–846. [Google Scholar] [CrossRef] [Scilit]
- Holmström, J.; Holweg, M.; Lawson, B.; Pil, F.K.; Wagner, S.M. The digitalization of operations and supply chain management: Theoretical and methodological implications. J. Oper. Manag. 2019, 65, 28–34. [Google Scholar] [CrossRef] [Scilit]
- Liao, Y.; Deschamps, F.; Loures, E.F.R.; Ramos, L.F.P. Past, present and future of Industry 4.0: A systematic literature review and research agenda proposal. Int. J. Prod. Res. 2017, 55, 3609–3629. [Google Scholar] [CrossRef] [Scilit]
- Acharya, V.V.; Pedersen, L.H.; Philippon, T.; Richardson, M. Measuring systemic risk. Rev. Financ. Stud. 2017, 30, 2–47. [Google Scholar] [CrossRef] [Scilit]
- Anderson, R.; Moore, T. The economics of information security. Science 2006, 314, 610–613. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Ng, I.C.L.; Ding, D.X.; Yip, N. Outcome-based contracts as a new business model: The role of partnership and value-driven relational assets. Ind. Mark. Manag. 2013, 42, 730–743. [Google Scholar] [CrossRef] [Scilit]
- Verhoef, P.C.; Broekhuizen, T.; Bart, Y.; Bhattacharya, A.; Dong, J.Q.; Fabian, N.; Haenlein, M. Digital transformation: A multidisciplinary reflection and research agenda. J. Bus. Res. 2021, 122, 889–901. [Google Scholar] [CrossRef] [Scilit]
- Perrow, C. Normal Accidents: Living with High-Risk Technologies, Updated ed.; Princeton University Press: Princeton, NJ, USA, 2011. [Google Scholar]
- Tronvoll, B.; Sklyar, A.; Sörhammar, D.; Kowalkowski, C. Transformational shifts through digital servitization. Ind. Mark. Manag. 2020, 89, 293–305. [Google Scholar] [CrossRef] [Scilit]
- Eloranta, V.; Turunen, T. Platforms in service-driven manufacturing: Leveraging complexity by connecting, sharing, and integrating. Ind. Mark. Manag. 2016, 55, 178–186. [Google Scholar] [CrossRef] [Scilit]
- Hasselblatt, M.; Huikkola, T.; Kohtamäki, M.; Nickell, D. Modeling manufacturer’s capabilities for the Internet of Things. J. Bus. Ind. Mark. 2018, 33, 822–836. [Google Scholar] [CrossRef] [Scilit]


| Field | Level | Description |
|---|---|---|
| CVE identifier | Vulnerability | Unique Common Vulnerabilities and Exposures (CVE) reference for each disclosed flaw. |
| CPE vector | Product | Common Platform Enumeration (CPE) string identifying the affected product configuration. |
| Vendor | Product | Organisation that supplies the affected product. |
| CWE category | Vulnerability | Common Weakness Enumeration (CWE) class describing the type of flaw. |
| CVSS base score | Vulnerability | Common Vulnerability Scoring System version 3 (CVSS v3) base severity on a 0 to 10 scale. |
| CVSS exploitability sub-score | Vulnerability | Component of the score reflecting how readily the flaw can be exploited. |
| CVSS impact sub-score | Vulnerability | Component of the score reflecting the consequence of successful exploitation. |
| Severity category | Vulnerability | Ordinal band (low, medium, high, critical) derived from the base score. |
| Affected products | Vulnerability | Number of distinct products linked to the vulnerability. |
| Affected vendors | Vulnerability | Number of distinct vendors linked to the vulnerability. |
| Publication year | Record | Year the advisory was published, used for the temporal analysis over 2012 to 2019. |
| Variable | Level | Definition |
|---|---|---|
| CVSS Base Score | CVE | Overall severity rating (0–10) |
| combining exploitability and impact | ||
| Exploitability Score | CVE | Sub-score measuring ease of |
| exploitation (0–3.9 for CVSS v3) | ||
| Impact Score | CVE | Sub-score measuring consequences if |
| exploited (0–6.0) | ||
| Affected Products | CVE | Count of unique CPE entries per CVE; |
| captures cross-system exposure | ||
| Affected Vendors | CVE | Count of unique vendors affected per |
| CVE; captures supply chain breadth | ||
| Vulnerability Count | Vendor-Year | Number of unique CVEs disclosed for |
| a vendor in a given year | ||
| Mean Severity | Vendor-Year | Average CVSS base score across a |
| vendor’s annual disclosures | ||
| Mean Exploitability | Vendor-Year | Average exploitability sub-score across annual disclosures |
| Product Breadth | Vendor-Year | Count of unique products affected across annual disclosures |
| CWE Diversity | Vendor-Year | Count of unique vulnerability types (CWE classes) disclosed annually |
| System Risk Index | Vendor-Year | (Vuln Count × Mean Severity × Mean Exploitability)/10 |
| Panel A: CVE Level (n = 1678 with CVSS v3 scores) | |||||||
| Variable | Mean | SD | Min | Q1 | Median | Q3 | Max |
| CVSS Base Score | 7.76 | 1.59 | 2.50 | 6.63 | 7.80 | 8.80 | 10.00 |
| Exploitability Score | 3.00 | 0.99 | 0.30 | 2.20 | 2.80 | 3.90 | 3.90 |
| Impact Score | 4.66 | 1.43 | 1.40 | 3.60 | 5.50 | 5.90 | 6.00 |
| Affected Products | 23.2 | 171.8 | 1 | 1 | 2 | 7 | 4890 |
| Affected Vendors | 1.15 | 1.12 | 1 | 1 | 1 | 1 | 35 |
| Panel B: Vendor-Year Level (n = 444) | |||||||
| Variable | Mean | SD | Min | Q1 | Median | Q3 | Max |
| Vulnerability Count | 4.36 | 8.98 | 1 | 1 | 2 | 4 | 136 |
| Mean Severity | 7.60 | 1.34 | 3.10 | 6.63 | 7.55 | 8.60 | 10.00 |
| Mean Exploitability | 2.90 | 0.88 | 0.45 | 2.20 | 2.91 | 3.90 | 3.90 |
| Product Breadth | 30.9 | 261.4 | 1 | 1 | 2 | 10 | 5371 |
| CWE Diversity | 3.21 | 4.51 | 1 | 1 | 2 | 3 | 49 |
| System Risk Index | 10.28 | 22.82 | 0.24 | 1.82 | 3.82 | 9.58 | 346.04 |
| Panel A: Model 1, OLS: CVSS Base Score (CVE level, n = 1678) | ||||
| β | Robust SE | z | p | |
| Constant | 0.375 | 0.026 | 14.56 | <0.001 |
| Exploitability Score | 0.947 | 0.004 | 234.88 | <0.001 |
| Impact Score | 0.978 | 0.003 | 326.09 | <0.001 |
| ln(Affected Products) | −0.003 | 0.003 | −0.81 | 0.418 |
| ln(Affected Vendors) | −0.020 | 0.018 | −1.13 | 0.260 |
| R2 = 0.989 | Adj. R2 = 0.989 | F = 42,180 | ||
| Panel B: Model 3, OLS: ln(System Risk Index) (Vendor-Year level, n = 444) | ||||
| β | Robust SE | z | p | |
| Constant | −1.275 | 0.065 | −19.66 | <0.001 |
| Mean Severity | 0.090 | 0.009 | 10.01 | <0.001 |
| Mean Exploitability | 0.288 | 0.018 | 16.12 | <0.001 |
| ln(Product Breadth) | 0.056 | 0.017 | 3.20 | 0.001 |
| ln(CWE Diversity) | 1.250 | 0.025 | 50.39 | <0.001 |
| R2 = 0.911 | Adj. R2 = 0.911 | F = 1856 | ||
| β | SE | T | p | |
|---|---|---|---|---|
| Constant | 0.186 | 0.003 | 74.14 | <0.001 |
| Exploitability Score | 0.952 | 0.000 | 2317.7 | <0.001 |
| Impact Score | 1.000 | 0.000 | 3500.1 | <0.001 |
| ln(Affected Products) | 0.000 | 0.000 | 0.00 | 1.000 |
| ln(Affected Vendors) | 0.000 | 0.002 | 0.00 | 1.000 |
| Pseudo R2 = 0.944 | N = 1678 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Enang, I.; Enang, I.; Akpan, I.J. Cybersecurity Risk in Industrial Control Systems in Industry 4.0. Systems 2026, 14, 837. https://doi.org/10.3390/systems14070837
Enang I, Enang I, Akpan IJ. Cybersecurity Risk in Industrial Control Systems in Industry 4.0. Systems. 2026; 14(7):837. https://doi.org/10.3390/systems14070837
Chicago/Turabian StyleEnang, Imo, Iniobong Enang, and Ikpe Justice Akpan. 2026. "Cybersecurity Risk in Industrial Control Systems in Industry 4.0" Systems 14, no. 7: 837. https://doi.org/10.3390/systems14070837
APA StyleEnang, I., Enang, I., & Akpan, I. J. (2026). Cybersecurity Risk in Industrial Control Systems in Industry 4.0. Systems, 14(7), 837. https://doi.org/10.3390/systems14070837

