Skip to Content
  • Review
  • Open Access

9 September 2026

Threats, Defences, and Governance in Cyber–Physical Systems Security: A Structured Review of the 2020–2026 Literature

and
Automation Department, Technical University of Cluj-Napoca, 400114 Cluj-Napoca, Romania
*
Author to whom correspondence should be addressed.

Abstract

When a water treatment plant, power grid, or pipeline is compromised, the consequences extend beyond data loss: a manipulated sensor reading can trigger physical damage, and a disabled safety interlock can endanger lives. Cyber–physical systems (CPSs) sit at this intersection of digital control and physical process, yet existing security reviews treat threats and defences in separate silos, leaving practitioners without a clear picture of which defences fail against which attacks, and why. This paper fills that gap with a structured narrative review of 82 sources (70 from the primary window January 2020 to April 2026, plus 12 foundational pre-2020 works), organised through the CPS Defence-Gap Taxonomy (CPS-DGT)—a framework that classifies 14 attack mechanisms by architectural layer and physical impact, evaluates six defensive technology categories against documented failure modes, and maps five governance dimensions to the institutional conditions required for deployment. Across five intrusion detection system (IDS) studies that differ in dataset, attack selection, training regime and evaluation scope, reported F1 scores lie between 0.796 and 0.969 under each study’s own standard conditions; these values are not a controlled comparison and are reported descriptively. For the one architecture evaluated under adversarial evasion, F1 falls by 37.4 percentage points in absolute terms, a relative reduction of 38.6%. The defence-gap matrix identifies seven entries with insufficient coverage. Five of the 14 attack mechanisms are uncovered: A03, A09, A10, A11 and A14. Two further mechanisms, A01 and A12, have only partial defences. Adversarial evasion of learned detectors is reported separately as a transversal failure mode of one defensive category rather than as an attack mechanism. The uncovered mechanisms cluster at the cyber–physical boundary and in supply-chain channels. We conclude with five concrete research challenges, each with a direct path from the identified gap to a tractable research agenda.

1. Introduction

Unlike a breach of an enterprise network—where the consequences are bounded by what an adversary can accomplish with access to data and computing resources—a successful intrusion into an industrial control system (ICS), water treatment facility, or power distribution network can translate identical access privileges into manipulated sensor readings, altered control setpoints, or disabled safety interlocks. Cyber–physical systems (CPSs) embody this qualitative difference: their tight coupling between digital control and physical process means that a compromised historian server can lead operators to misread the physical state, and a manipulated physical process can conceal its own deviation from expected measurements [1,2]. Standard enterprise security frameworks were not designed to address this; their threat models, control architectures, and response procedures all assume that the physical world remains outside the scope of a cyber incident.
The 2020–2026 period produced a series of incidents that gave concrete form to these concerns. An important precedent was set earlier: the 2014 German steel mill cyber-attack, in which adversaries manipulated blast furnace control logic to cause structural damage [3], established that cyber intrusions could produce physical consequences before operational security was widely prioritised. The 2021 ransomware-driven shutdown of a major US fuel pipeline demonstrated that financially motivated adversaries can produce significant physical consequences—a five-day production halt—through IT-layer attacks alone, without ever compromising operational technology (OT) systems [4]. The 2015 attack on Ukrainian electricity distribution showed that state-aligned actors had developed the operational capability to translate digital intrusions into wide-area physical outages [5]; the 2016 attack, which deployed the Industroyer (CrashOverride) malware to directly manipulate substation switches and circuit breakers, demonstrated further operational maturation [6]. The 2017 Triton campaign against Schneider Electric safety controllers set a further threshold: an attack designed not to destroy but to disable the safety instrumented systems (SISs) that form the last automated barrier against catastrophic outcomes [7]. Peer-reviewed reconstructions of specific campaigns support the same reading: Salazar et al. [8] compare the two Industroyer attacks on the Ukrainian grid in detail, and Kumar et al. [9] analyse three advanced persistent threat campaigns against control systems, both documenting the progression from enterprise IT access to physical consequence that the layer codes of CPS-DGT are intended to capture. More recent industry analysis confirms an escalation in adversarial maturity: the Dragos 2026 OT/ICS Cybersecurity Year in Review documents a 49% year-over-year surge in ransomware against industrial organisations and the emergence of threat groups that have progressed from access and surveillance to actively mapping control loops inside operational environments, developing an understanding of where commands originate and where physical effects can be induced [10].
The research community has responded along several concurrent trajectories. Machine learning approaches to ICS intrusion detection have advanced from early proofs of concept on individual datasets to systematic comparative evaluation using standardised benchmarks [11,12,13]. Zero-trust architectures have moved from conceptual frameworks to early deployment experiments in OT contexts, though significant compatibility barriers with real-time control requirements persist [14,15]. At the governance level, the EU NIS2 Directive extended mandatory security obligations across eighteen critical infrastructure sectors [16], NIST released Cybersecurity Framework 2.0 with expanded OT-specific guidance [17], and CISA published the first joint federal guidance for applying zero-trust principles specifically to OT environments [18].
Despite this progress, the literature suffers a structural gap. Humayed et al. [1], one of the most widely cited CPS security surveys, organises threats by attack surface but does not evaluate defensive effectiveness or identify governance barriers to deployment. Giraldo et al. [11] provide a thorough treatment of physics-based attack detection but do not address ransomware, supply-chain threats, or the governance conditions for deploying the methods they review. Iturbe et al. [19] survey anomaly detection for heterogeneous industrial networks but do not connect detection performance to the physical consequences of missed attacks. More broadly, reviews of intrusion detection report accuracy on standard datasets without connecting those metrics to the attacks that produce the most consequential physical outcomes in practice [11,19]. Reviews of zero trust assess access control benefits without addressing the real-time compatibility constraints of industrial control protocols [14,20]. Governance analyses catalogue regulatory requirements without specifying which technical gaps each requirement is intended to close [16,17]. None of these reviews provides the cross-cutting map from attack mechanism to defensive failure mode to governance prerequisite that would allow a practitioner to identify, for a specific operational context, which combination of technical investment and institutional change would reduce residual risk most efficiently. This paper introduces CPS-DGT to fill that gap. The remainder of this paper is organised as follows. Section 2 describes the review methodology, including the search strategy, inclusion and exclusion criteria, and the relationship between the iterative development of CPS-DGT and the literature selection process. Section 3 presents the CPS-DGT framework with its three analytical dimensions—the 14 attack mechanisms, the six defensive technology categories, and the five governance dimensions. Section 4, Section 5, Section 6, Section 7 and Section 8 present the thematic review: the threat landscape and attack mechanisms (Section 4), ML-based intrusion detection (Section 5), zero-trust architectures and access control (Section 6), supply-chain security (Section 7), and governance frameworks (Section 8). Section 9 synthesises the thematic findings into the defence-gap matrix, which maps each attack mechanism against each defensive category and identifies the seven entries with insufficient coverage. Section 10 derives five concrete research challenges from the gaps identified in Section 9. Section 11 discusses the structural patterns and the limitations of the review. Section 12 concludes with the principal findings and directions for future work.
This paper introduces the CPS Defence-Gap Taxonomy (CPS-DGT) as an organising framework for a structured review of 82 sources published between January 2020 and April 2026. The principal contributions are: the CPS-DGT framework itself, offered as a reusable analytical tool; a defence-gap matrix identifying seven entries with insufficient coverage in the reviewed literature, including five attack mechanisms for which no effective countermeasure was identified (A03, A09, A10, A11, A14) and two mechanisms with only partial defences (A01, A12), with adversarial machine learning evasion reported separately as a transversal failure mode of learned detection; a quantitative synthesis of ML-based intrusion detection performance under both standard and adversarial evaluation conditions; and an explicit mapping of the governance prerequisites for each defensive technology category, explaining why technically available solutions are often absent from operational deployments.

2. Review Methodology

The review was conducted using a structured narrative methodology with systematic literature selection. This review is classified as a review rather than a scoping review. The literature selection flow depicted in Figure 1 follows the spirit of PRISMA reporting standards as a matter of transparency. Full PRISMA compliance is not claimed, and a formal PRISMA checklist is therefore not required under JCP guidelines. Four databases were searched: IEEE Xplore, ACM Digital Library, Web of Science, and Scopus. Search queries combined two groups of terms. The first identified the domain: cyber–physical systems security, industrial control systems cybersecurity, critical infrastructure protection, SCADA security, and operational technology security. The second was technology-specific and corresponded to the five attack-mechanism layers and six defensive technology categories defined in CPS-DGT, including physics-informed intrusion detection, zero trust in OT, ICS ransomware, ICS supply-chain attack, adversarial machine learning in ICSs, and OT governance. The primary search window was January 2020 to April 2026. A supplementary backward search retrieved foundational pre-2020 works. These were works cited by three or more included papers as establishing the methods, datasets or theoretical foundations on which 2020–2026 contributions build.
Figure 1. Literature selection and screening process (PRISMA-inspired), with exclusion counts and reasons at each stage and the annual distribution of primary sources inset. The six sources added by the targeted supplementary search described in Section 2 are shown as a separate branch and were not part of the original screening. The protocol and its limitations can be found in Section 2.
The initial corpus of approximately 860 candidate papers was reduced to 312 after title and abstract screening for relevance to CPS or critical infrastructure security. Full-text eligibility required a paper to present original empirical or experimental results applicable to CPS security, to propose or evaluate a defence mechanism with direct CPS application, or to contribute a governance framework specifically applicable to critical infrastructure cybersecurity. Purely theoretical work without empirical grounding and grey literature without peer review were excluded, with the specific exceptions of regulatory documents (NIS2 [16], NIST CSF 2.0 [17], ISO/IEC 62443 [21]), incident reports (CISA advisories, Dragos annual reports), and benchmark dataset papers (SWaT, BATADAL, HAI) that constitute the empirical basis of reviewed studies. The process yielded 82 included sources—70 primary papers from 2020 to 2026 and 12 supplementary foundational pre-2020 works—whose selection is shown in Figure 1 and thematic distribution in Figure 2. The corpus is heterogeneous by design: it comprises peer-reviewed studies, regulatory instruments and standards, vendor and agency incident reports, and benchmark dataset papers. The term “sources” is used throughout when the whole corpus is intended, and “studies” is reserved for peer-reviewed research contributions reporting original results. Of the 82 sources, 7 are standards or regulatory instruments, 8 are incident or threat reports, 3 are benchmark dataset papers, and the remaining 64 are peer-reviewed studies and books. This review departs from full PRISMA compliance in three respects that are appropriate for its purpose and scope. First, no review protocol was pre-registered, because the CPS-DGT analytical framework was developed iteratively alongside the literature review rather than specified in advance; pre-registration is most valuable when the review question and inclusion criteria are fixed prior to the search, which was not the case here. Second, the synthesis is narrative rather than meta-analytic: the heterogeneity of methods, datasets, and outcome measures across the reviewed papers precludes statistical pooling, and a structured narrative synthesis better serves the goal of identifying cross-cutting gaps. Third, the supplementary backward search does not conform to PRISMA’s requirement for systematic coverage, as it was intentionally restricted to works cited by three or more included papers rather than conducted exhaustively. These deviations may limit the completeness of coverage in fast-moving sub-areas and introduce a degree of selectivity bias toward higher-cited foundational works. These deviations are inherent to the structured review methodology. They may affect the completeness of the corpus. That in turn affects the confidence that can be placed in the defence-gap analysis, which rests on the subset of the literature meeting the eligibility criteria.
Figure 2. Distribution of the 82 included sources across the six thematic categories (a) and by publication period (b). Category counts sum to 82.
This review is reported as a structured narrative review rather than as a systematic review, and it is not reproducible in the sense required of a systematic review. The reporting of the search protocol is incomplete in three respects, and these limit the reproducibility of the selection process. First, the searches were executed against the four databases named above, using queries that combined the domain identifiers with the technology-specific terms listed earlier in this section. The details needed to repeat them were not recorded in a form that permits exact replication: the full Boolean expression used for each database, the database-specific field restrictions, the final execution date of each search, and the language and document-type filters applied. Second, the figure of approximately 860 candidate records is an aggregate count and is reported as approximate: the exact per-database counts, and the number of records removed as duplicates, were not retained. Third, screening at the title/abstract and full-text stages was performed by both authors, but no formal screening form was used and exclusion reasons were recorded at the level of the stage rather than the individual record. A targeted supplementary search of the openly indexed literature was nevertheless carried out during revision in order to test whether the corpus was missing work central to the questions this review addresses. The search concentrated on the evaluation of machine learning-based industrial intrusion detection and on peer-reviewed analyses of multi-stage attack campaigns, these being the areas in which an incomplete search would most affect the conclusions reported here. It identified six qualifying sources that were not in the original corpus, and all six were added: Kus et al. [22] and Lamberts et al. [23] on the evaluation of machine learning-based industrial intrusion detection; Ike et al. [24] on cross-layer detection; Salazar et al. [8] and Kumar et al. [9] on multi-stage campaigns against control systems; and Kim and Park [25], a recent systematic review of AI-based anomaly detection whose scope is complementary to this one. Two of these, [22] and [23], bear directly on the principal quantitative finding reported in Section 5, and their absence from the original corpus is a concrete illustration of the limitation described above. The scope of this supplementary search is stated so that a reader can judge what it covered. Five topics were searched: the evaluation methodology of machine learning-based industrial intrusion detection; the generalisation of such detectors to attack categories withheld from training; peer-reviewed reconstructions of multi-stage attack campaigns against control systems; cross-layer correlation between SCADA and process behaviour; and recent surveys of the field. These were chosen because they are the areas in which an incomplete corpus would most directly affect the findings reported in Section 4, Section 5 and Section 9. The search was targeted rather than systematic. It was not conducted under a documented protocol, it did not use the CPS-DGT category labels as search terms, it covered the five topics above rather than the full scope of the review, and it therefore establishes neither the reproducibility of the original search nor the completeness of the corpus. Documenting a supplementary search to a standard that would make it independently auditable would require executing it under a recorded protocol against named bibliographic databases, which we have not done and do not claim to have done. What it shows is narrower and still worth stating: at least six relevant sources were missing, two of them material to the central finding, and the corpus reported here is the corrected set. A reader cannot therefore reconstruct the corpus exactly from the information given here. The consequence is stated directly and applies throughout the manuscript: no claim of systematic or exhaustive coverage of the CPS security literature is made or implied, and every finding reported below is a finding within the reviewed corpus rather than a statement about the field as a whole. The synthesis should be read as a structured narrative review whose selection process is documented in outline but not reproducible in detail.

Use of Generative AI Tools

A generative AI assistant (Claude, Anthropic) was used during the preparation and revision of this manuscript. The authors conceived the research question, defined the CPS-DGT taxonomy and its three analytical dimensions, assigned every rating in the defence-gap matrix, and drew the conclusions. They take full responsibility for the content of this paper, including all material produced with AI assistance.
Three uses fall within the publisher’s disclosure policy. The figures were rendered from data supplied or verified by the authors, so they present the authors’ classifications rather than generated content. The structure and initial text of several tables were drafted from material already present in the manuscript and in the reviewed sources, then checked and corrected by the authors. The randomised smoothing theorem and the detectability condition of Pasqualetti et al. were restated with assistance and verified by the authors against the original publications. Routine text editing—numbering, sentence division and terminological consistency—falls outside the policy and is not itemised here.
Two further uses affected substance rather than presentation and are therefore stated separately. The supplementary search reported earlier in this section, which identified six sources absent from the original corpus, was conducted with AI assistance; the authors verified each source against its publisher record and assessed its eligibility before inclusion. The taxonomy-independent check reported in Section 3 was conducted in the same way, and the three resulting candidate categories were assessed by the authors against the taxonomy definitions.
The tool was not used to generate the taxonomy, assign matrix ratings, produce the sensitivity analysis, or write the conclusions. No text, data or citation produced with AI assistance was included without author verification against a primary source, and every reference added during revision was checked against its DOI record.

3. The CPS Defence-Gap Taxonomy (CPS-DGT)

CPS-DGT organises the review across three analytical dimensions, derived from a structured reading of the reviewed literature. The first asks what attacks exist and how they reach physical consequences. The second asks what defensive technologies are available and under what conditions they fail. The third asks what institutional conditions prevent available defences from being deployed. The taxonomy was developed inductively and has not been independently validated. A first-pass open coding of the 76 sources included at that stage produced a preliminary set of attack mechanism categories. These were then consolidated iteratively: mechanisms sharing the same entry vector and physical consequence were merged into a single code, and mechanisms producing materially different defensive requirements were split into distinct codes. The process converged at 14 attack mechanisms after three consolidation rounds; the resulting codes were then checked for internal consistency by confirming that every attack documented in the reviewed incident reports could be assigned to exactly one mechanism without ambiguity. This is a consistency check applied by the authors, not an independent validation of the taxonomy. Existing frameworks address one dimension at a time—MITRE ATT&CK for ICS catalogues attack techniques, NIST CSF specifies defensive functions, and regulatory documents such as NIS2 define governance obligations—but none maps the relationships among them in a structure that makes gaps analytically visible. CPS-DGT is constructed precisely for that mapping purpose. The relationship between the taxonomy and the literature review deserves explicit clarification. CPS-DGT was not developed prior to the review as a fixed analytical instrument, nor did it emerge purely inductively from a blank-slate reading of the papers. The development followed an iterative, abductive process. A preliminary coding framework identifying three analytical dimensions (attack mechanisms, defensive categories, governance prerequisites) and a provisional set of attack layer codes (L1–L5) was defined on the basis of a prior reading of landmark CPS security papers including Humayed et al. [1], Giraldo et al. [11], and Lee et al. [3]. This preliminary framework guided the initial search terms and the first round of paper screening. That is why Section 2 describes the search terms as corresponding to the attack-mechanism layers and defensive technology categories defined in CPS-DGT. During the full-text reading, the preliminary codes were revised through three consolidation rounds. Categories were merged when they shared the same entry vector and physical consequence, and split when they produced materially different defensive requirements. The final 14-mechanism taxonomy emerged from this process and was cross-checked against the reviewed incidents by confirming that every documented attack could be assigned to exactly one code. Two aspects of the coding procedure merit explicit clarification. First, regarding inter-coder validation: the consolidation rounds were conducted jointly by both authors, with disagreements in code assignment resolved through discussion until consensus was reached; the mutual exclusivity criterion (each attack mechanism assignable to exactly one code) served as an internal consistency check. Second, regarding multi-stage incidents: CPS-DGT assigns each attack mechanism a single primary code based on its intended physical consequence and principal entry vector. Multi-stage incidents—such as a campaign that combines identity exploitation (A04: L2, I2) to gain access, LOTL exfiltration (A02: L1, I2) for reconnaissance, and false data injection (A12: L5, I3) for physical effect—are represented in the taxonomy as sequences of single-coded mechanisms rather than as multi-label entries. This design choice facilitates cell-by-cell analysis in the defence-gap matrix but means that the defensive coverage analysis addresses each mechanism independently; cross-mechanism interactions are discussed qualitatively in the threat landscape section. The iterative co-development of a coding framework and a literature review is methodologically standard in grounded theory and qualitative synthesis; it does not invalidate either the taxonomy or the review, but it does mean that CPS-DGT should be understood as a synthesis product refined through the review rather than as an a priori classification scheme independently applied to the literature.
The reliability of the coding procedure requires separate reporting. The consolidation rounds described above were conducted jointly by the two authors, with disagreements resolved by discussion until consensus was reached. Joint coding of this kind establishes consistency of application but does not measure inter-coder reliability, because the coders were not independent. No independent coding of a sample was carried out and no inter-coder agreement statistic, such as Cohen’s kappa or Krippendorff’s alpha, was computed. The reliability of the taxonomy codes is therefore unquantified. The mutual exclusivity check described above provides a weaker form of validation: it establishes that every attack documented in the reviewed incident reports could be assigned to exactly one code, but it does not establish that a second, independent coder would have produced the same assignments. Nor was a formal codebook maintained during the consolidation rounds, so the decision rules applied at each round and the candidate categories considered and rejected are not available as an audit trail. No claim is made anywhere in this manuscript that CPS-DGT has been validated. Readers should treat it as a synthesis proposed by the authors rather than as a coding instrument whose reliability has been demonstrated, and independent coding of the taxonomy is identified as necessary future work. The same consideration applies to the risk of circularity between taxonomy construction and retrieval: because the preliminary categories informed the search terms, evidence fitting those categories was more likely to be retrieved. Neither a held-out validation subset nor an external expert panel was available for this review. The partial safeguard actually applied is the evidence-quality sensitivity analysis reported in Section 9, which tests whether the principal finding survives restriction to high-confidence sources; it addresses the strength of the evidence behind each rating but not the possibility that a differently framed search would have surfaced categories absent from CPS-DGT altogether. That possibility remains open and is the reason the taxonomy is presented as a synthesis of the reviewed corpus rather than as a general classification of CPS attacks.
A taxonomy-independent check was carried out to address this concern directly rather than by inference. Broad CPS-security queries were used that deliberately avoided the CPS-DGT category labels, and a sample of the retrieved literature was examined for attack mechanisms, defence classes or cross-cutting categories that the existing taxonomy cannot represent. The result is reported here in full, including the part that is unfavourable to the taxonomy: three candidate categories were identified that CPS-DGT does not represent without extension.
First, analogue and transduction attacks on sensors: these manipulate a sensor through the physical medium—acoustic, electromagnetic or optical injection—without traversing any network path. CPS-DGT codes false data injection as A12, but A12 presumes falsified values substituted on a data channel, and all five layer codes L1–L5 describe cyber-entry points. An attack whose entry vector is physical rather than cyber has no layer code, so the mechanism cannot be placed in the matrix at all.
Second, poisoning of operational machine learning components: this review treats adversarial machine learning as a transversal failure mode of defensive category D1; that is, as something done to a detector. An adversary who corrupts the training data or model of a machine learning component embedded in the control or optimisation loop is not attacking a detector but the process itself, and that is an attack mechanism rather than a defensive failure mode. CPS-DGT has no code for it.
Third, the insider as a distinct entry vector: A03 covers AI-enabled social engineering, in which an outsider obtains credentials from a legitimate user, but a privileged insider acting deliberately has neither an external entry vector nor the same defensive profile, and several classification schemes in the retrieved literature treat the human element as a layer in its own right.
Two qualifications apply. The check was limited in scale and was conducted by the authors, so it establishes the existence of these gaps rather than the absence of others. And none of the three candidates invalidates the analysis reported here: the defence-gap matrix describes the mechanisms it contains, and the conclusions drawn from it concern those mechanisms. What the check does establish is that CPS-DGT is not complete as a classification of CPS attacks. Its scope is the cyber-entry, physically consequential attack mechanisms documented in the reviewed corpus, and the taxonomy should be read with that boundary in mind. Extending it to physical-layer entry vectors, to attacks on embedded learning components, and to the insider is identified as necessary future work in Section 10.
The attack classification dimension assigns each mechanism two independent codes. The layer code captures the architectural locus of the attack: L1 (enterprise IT) covers attacks entering through corporate networks, email, and cloud services; L2 (identity infrastructure) covers exploitation of Active Directory, cloud IAM platforms, and authentication systems; L3 (OT/ICS/SCADA) covers direct attacks on programmable logic controllers (PLCs), distributed control systems, and industrial network devices; L4 (supply chain) covers attacks introduced before deployment through software build pipelines, firmware distribution, or hardware procurement; and L5 (Cyber–Physical Coupling Interface) covers attacks targeting the sensors, actuators, and state estimators that link the digital control layer to the physical process. The impact code captures the intended operational consequence: I1 (availability disruption), I2 (cyber-state data integrity), I3 (physical state manipulation), I4 (safety system bypass), and I5 (persistent capability installation). Together these codes give each attack mechanism a precise position in the analytical space—ransomware is (L1, I1), false data injection is (L5, I3), and safety system bypass is (L5, I4)—enabling systematic comparison with defensive coverage.
Table 1 enumerates all 14 attack mechanisms classified in CPS-DGT. Each mechanism is assigned a unique code (A01–A14), a layer code specifying its architectural locus, and an impact code capturing its intended operational consequence. The codification follows a structured reading of the reviewed sources, with each mechanism representing a distinct combination of an entry vector and physical consequence that appears as a coherent pattern across multiple reviewed incidents or studies. The 14 mechanisms are not exhaustive of all possible attack types against CPSs but are representative of the principal threat patterns documented in the 2020–2026 literature and are sufficient to expose the structural asymmetry between defensive investment and adversarial coverage that motivates this review.
Table 1. The 14 attack mechanisms classified in CPS-DGT, with layer code (L1–L5), impact code (I1–I5) and representative supporting references. Coverage is assessed in Section 9.
Although no independent coding experiment was conducted, the decision rules that were in fact applied during the consolidation rounds have been reconstructed and are set out in Table 2 as a formal codebook. The codebook is presented so that a subsequent independent coding study can be conducted against a documented instrument rather than against the authors’ recollection; it does not substitute for such a study, and the reliability of the codes remains unquantified.
Table 2. Codebook for the attack mechanism dimension. For each of the three coding decisions the table gives the operational rule that was applied, the criteria for inclusion and exclusion, and a borderline case together with its resolution. The rules were reconstructed from the consolidation rounds after the fact and were not applied prospectively.
The defensive technology dimension characterises six categories—D1 deep learning-based IDS, D2 physics-informed detection, D3 zero-trust architecture, D4 secure controller design, D5 supply-chain provenance, and D6 resilience engineering—on two properties: coverage scope, meaning the set of attack codes against which the technology provides meaningful protection, and documented failure mode, meaning the conditions under which the primary literature evidence shows the defence to be unreliable. Explicitly characterising failure modes, rather than cataloguing capabilities alone, is the mechanism through which defence gaps are identified: a gap exists wherever the failure mode of every available defence is triggered by the characteristics of a given attack mechanism. The three-level rating scale applied in the defence-gap matrix is defined as follows. A defence is rated ‘effective’ when the primary literature provides evidence of reliable protection under conditions representative of operational deployment, with no documented failure mode that an adaptive adversary can systematically exploit. A defence is rated ‘partial’ when the literature provides meaningful protection under benign conditions but also documents a specific failure mode—such as adversarial evasion, model inaccuracy, or latency incompatibility—that a well-resourced adversary can trigger. A defence is rated ‘insufficient evidence’ (symbol: ✕) when the defence type is in principle applicable to the attack category but no reviewed paper demonstrates meaningful protection against the mechanism in question. This rating records the absence of demonstrated protection within the reviewed corpus. It is not itself evidence that the defence fails, and it is therefore reported as insufficient evidence rather than as ineffectiveness, except where a reviewed study documents failure directly. A ‘not applicable’ rating (symbol: ○) is used when the defence type operates on a different architectural layer than the attack, making it structurally irrelevant rather than deficient. An ‘insufficient evidence’ rating signals a research gap; a ‘not applicable’ rating signals a scope boundary. The evidence supporting each cell in the matrix is cited in Section 5, Section 6, Section 7 and Section 8.
The framework intentionally focuses on defensive effectiveness under the documented conditions of the reviewed literature rather than on deployment economics. However, this scope choice has practical implications that warrant explicit acknowledgement. Each of the six defensive categories carries deployment barriers that extend beyond technical efficacy. D1 (deep learning IDS) requires labelled training data from the target environment, GPU infrastructure for inference, and ongoing model maintenance as process baselines drift. D2 (physics-informed detection) requires accurate, continuously updated process models, whose calibration cost can exceed the cost of the detection system itself. D3 (zero trust in OT) requires identity infrastructure—directory services, certificate authorities and policy engines—that most OT environments do not currently operate. D4 (secure controller design) requires hardware replacement or re-certification, with the associated production downtime. D5 (supply-chain provenance) requires contractual and tooling changes across entire multi-tier vendor networks. D6 (resilience engineering) requires quantitative recovery-time objectives and tested runbooks calibrated to physical process restart constraints. These deployment barriers are distinct from technical gaps: a defence that is effective in a laboratory benchmark may be impractical in an operational ICS environment because of cost, latency, or qualification requirements not captured in the reviewed papers. Addressing this economic and operational dimension is identified as a cross-cutting prerequisite for translating research findings into industrial practice and is reflected in the governance gaps G1–G5 analysed in Section 8.
The governance dimension captures the institutional prerequisites for each defensive technology to function as intended in operational environments. Five categories are identified: G1 regulatory compliance, specifying the external obligations that create incentives for deployment; G2 shared responsibility frameworks, allocating specific security obligations across the multi-party supply chains typical of CPS environments; G3 identity–authority governance, mapping digital identities to the physical authority they are permitted to exercise; G4 incident response governance, establishing CPS-specific playbooks and escalation criteria calibrated to physical risk; and G5 resilience metric governance, specifying verifiable outcome measures for cyber–physical resilience. Automated cyber-attack evaluation frameworks such as HARMer [42] provide tooling for populating such taxonomies systematically; the taxonomy nonetheless differs from adversary-technique catalogues such as MITRE ATT&CK for ICS in that its purpose is to identify gaps rather than to enumerate capabilities, and it places governance conditions on equal analytical footing with technical defences.
A critical property of CPS-DGT is the asymmetric role of the governance dimension relative to the technical dimensions. Governance conditions are necessary but not sufficient for effective defensive deployment: an absent governance condition—such as the lack of an identity–authority model (G3)—can prevent a technically capable defence from being deployed at all, but the presence of a governance condition cannot substitute for a missing technical solution. This asymmetry has practical implications for prioritisation: where both a technical gap and a governance gap exist for the same attack mechanism, the technical gap requires research investment and the governance gap requires institutional action, and neither can substitute for the other. The seven insufficiently covered mechanisms identified in Section 9 all exhibit this dual structure. A recent systematic review by Kim and Park [25] covers AI-based anomaly detection for ICSs and CPSs over 2021–2025 and classifies the literature by data modality. Its scope is complementary rather than overlapping: it examines detection techniques in depth, whereas CPS-DGT maps attack mechanisms against the full defensive repertoire and against the governance conditions for deployment, and it does not assess which mechanisms remain uncovered. CPS-DGT adds to existing frameworks in four specific ways that merit explicit comparison. MITRE ATT&CK for ICS catalogues adversary techniques observed in ICS environments, organised by tactic and mapped to mitigations. CPS-DGT differs in purpose: where ATT&CK enumerates techniques, CPS-DGT maps gaps between attack mechanisms and available defences, placing governance prerequisites on equal analytical footing with technical controls. ATT&CK does not evaluate which techniques remain uncovered by the available defensive repertoire—precisely the question CPS-DGT addresses. NIST CSF 2.0 [17] specifies six defensive functions but does not classify attacks by mechanism or connect attack characteristics to the failure modes of specific defensive technologies. Humayed et al. [1], the most widely cited CPS security taxonomy, classifies attacks by attack surface but does not evaluate defences or identify governance barriers to deployment. CPS-DGT unifies these perspectives through a three-dimensional structure that enables the systematic identification of gaps—cells in the defence-gap matrix where no defence achieves even partial coverage—and anchors each gap to the governance condition whose absence prevents closure by available technical means.
To make the comparison auditable rather than narrative, Table 3 compares CPS-DGT with the closest frameworks and reviews along seven fixed dimensions. The dimensions were fixed before the comparison was populated, and each entry records what the framework provides rather than a score.
Table 3. Comparison of CPS-DGT with the closest existing frameworks and reviews along seven fixed dimensions. Entries describe what each framework provides; ‘—’ indicates that the dimension is outside the framework’s stated purpose.
The governance dimension requires the same operational treatment as the attack dimension. Table 4 gives, for each of the five governance conditions, the operational definition applied, the rule for deciding that the condition is absent, and a positive and a borderline example drawn from the reviewed sources. Two caveats apply. First, the five dimensions were derived from the regulatory and standards material in the corpus and are not claimed to be exhaustive of CPS governance: they are the conditions whose absence was observed to block deployment of a technical defence in the reviewed material. Second, no independent coding of governance sources was performed, so the mutual distinguishability of G1–G5 is argued from the definitions below rather than demonstrated empirically.
Table 4. Operational definitions of the five governance dimensions, with the rule applied for judging a condition absent, and illustrative positive and borderline cases from the reviewed corpus.
The five governance dimensions were derived from the reviewed corpus, and their relation to established external frameworks therefore requires explicit statement. Table 5 maps G1–G5 against the governance and control concepts of the three instruments most frequently invoked in this domain: NIST CSF 2.0, IEC 62443 and the NIS2 Directive. The mapping was constructed by reading each framework’s governance provisions against the operational definitions in Table 4 and recording which provisions each dimension captures. Three observations follow. First, every G-dimension corresponds to identifiable provisions in at least two of the three frameworks, which supports their relevance but not their exhaustiveness. Second, G3 is the dimension with the weakest external correspondence: all three frameworks govern authentication and access, but none governs the authority to issue a specific class of control action, which is the condition G3 names. Third, and importantly for the limits of this taxonomy, the frameworks contain governance concepts that fall outside G1–G5 altogether: workforce competence and training, third-party assurance and audit, asset inventory and configuration management, and risk-assessment methodology are all substantial governance provisions that CPS-DGT does not represent, because none of them appeared in the reviewed corpus as the condition whose absence blocked deployment of a technical defence. G1–G5 are therefore governance conditions identified within the reviewed corpus, not an exhaustive governance taxonomy, and the final column of Table 5 records this directly.
Table 5. Crosswalk between the five CPS-DGT governance dimensions and the governance provisions of NIST CSF 2.0, IEC 62443 and the NIS2 Directive. The final row lists governance concepts present in these frameworks that fall outside G1–G5. The mapping was constructed by the authors and has not been independently verified.
Because several of the terms used in the defence-gap analysis are closely related, Table 6 fixes the meaning of each and states the term that is used consistently throughout the abstract, the tables, the figures, the results and the conclusions.
Table 6. Terminology used in the defence-gap analysis. Each concept is assigned one term, which is used consistently throughout the manuscript; the alternative expressions listed in the final column are not used interchangeably with the preferred term.

4. Threat Landscape

4.1. Overview of Reviewed Threat Studies

Conti et al. [47] conducted a thorough survey of ICS testbeds and datasets for security research, cataloguing publicly available test environments and establishing the SWaT [12] and BATADAL [13] benchmarks as the most widely used platforms for reproducible evaluation. The SWaT testbed was the basis for a systematic attack study by Adepu and Mathur [48,49]; the benchmark dataset introduced by Goh et al. [12] documents 36 distinct attack scenarios spanning multiple process stages that laid the experimental groundwork for the IDS evaluation literature reviewed in Section 5. The ENISA Threat Landscape 2025 (building on earlier editions including [50]), analysing 4875 incidents across the EU from July 2024 to June 2025, found that OT-related incidents now account for 18.2% of all identified threat categories [51]—a marked increase that reflects the growing connectivity of traditionally isolated industrial networks. The WEF Global Cybersecurity Outlook 2026 (extending the 2025 edition [52]), drawing on responses from 804 leaders across 92 countries, found that 94% identified artificial intelligence as the most significant driver of cybersecurity change, with AI-enabled attack tools accelerating reconnaissance, social engineering, and malware development at a pace that current governance frameworks cannot absorb [53]. Segovia-Ferreira et al. [54] reviewed 73 cyber-resilience proposals for CPSs, finding no consensus definition of CPS cyber-resilience and noting that the overwhelming majority of proposals addressed single attack vectors rather than the multi-stage, cross-layer campaigns documented in recorded incidents.
The reviewed threat studies reflect two distinct methodological traditions. Incident-based analyses—represented by the CISA and Dragos reports, Lindsay [55], and Liang et al. [5]—derive threat models from documented attacks and provide the highest-fidelity evidence about adversarial objectives and operational capabilities, but are limited by the selection bias of disclosed incidents, which systematically underrepresent successful intrusions that were never detected. Dataset-based analyses—represented by the SWaT [12], BATADAL [13], and HAI [56] benchmark studies—support reproducible quantitative evaluation but reflect idealised attack conditions that may not correspond to adversary behaviour against real operational infrastructure. The synthesis challenge, which motivates the CPS-DGT approach, is to integrate insights from both traditions without treating the quantitative results as representative of operational security and without treating incident reports as sufficient grounds for generalising about the full attack space.

4.2. Financially Motivated and AI-Enabled Threats

Ransomware targeting industrial environments (A01: L1, I1) has matured substantially since 2020. Cartwright et al. [57] showed through game-theoretic modelling, and the broader attack economy analysis by Huang et al. [26] provides supporting context, that operational downtime losses create payment incentives even when technical recovery is feasible, which helps explain the persistent effectiveness of ransomware against infrastructure operators. Current campaigns involve extended pre-deployment reconnaissance to identify critical production systems, deliberate timing relative to operational schedules, and selective encryption calibrated to maximise disruption while preserving enough access for ransom negotiations. The Colonial Pipeline incident demonstrated the model: an IT-layer infection caused a five-day operational shutdown through precautionary management decisions, without any documented OT compromise [4]. The Dragos 2026 Report documents a 49% year-over-year increase in ransomware against industrial organisations in 2025, affecting 3300 organisations globally ([8], Executive Summary, p. 4). Living-off-the-land (LOTL) techniques compound the challenge: by operating exclusively through legitimate system utilities such as PowerShell and Windows Management Instrumentation (WMI), adversaries leave no malware artefacts detectable by signature-based systems, requiring behavioural baseline analysis that most IT-OT boundary environments do not systematically maintain [4,10]. AI-enabled social engineering (A03: L1, I1) further reduces the unit cost of targeted intrusion by enabling the generation of contextually convincing phishing and synthetic media at scale [27,28]. The AI-driven threat surface extends, however, beyond deepfake-based social engineering. Three additional AI-enabled threat categories are documented or credibly anticipated in the 2020–2026 literature. First, AI-generated malicious payloads: large language models have been shown to generate functionally novel shellcode and exploit scripts from natural language specifications, reducing the reverse-engineering skill threshold required for custom payload development [53]. Second, automated vulnerability mining: AI-assisted fuzzing and program analysis tools accelerate the discovery of zero-day vulnerabilities in ICS firmware and protocol implementations, compressing the window between vulnerability existence and adversarial exploitation; the WEF 2026 report [53] identifies this acceleration as one of the three principal AI-enabled risk amplifiers. Third, adaptive adversarial sample generation: beyond the evasion of ML-based IDS evaluated by Erba et al. [58], AI-driven adversarial sample generation can be applied to any learned defensive model in the CPS environment, including anomaly detectors trained on SCADA historian data and physics-informed models trained on sensor time series. The common thread across these three extensions is that AI lowers the skill, time, and cost barriers to attacks that previously required either significant technical expertise or prolonged manual effort. Within CPS-DGT, these AI-amplified threat patterns are not classified as separate A-codes because they represent amplification of existing attack categories (A01–A14) rather than new entry vectors or physical consequences; they do, however, worsen the failure modes of all D-dimension defences that rely on pattern recognition under the assumption of non-adaptive adversaries.
The technical progression of a targeted industrial ransomware campaign follows a recognisable pattern documented across multiple incident analyses. Initial access is typically achieved through valid account credentials obtained via phishing or credential stuffing, or through exploitation of internet-facing management interfaces such as Remote Desktop Protocol (RDP) or virtual private network (VPN) concentrators with known vulnerabilities [4,10]. A dwell period of weeks to months follows, during which adversaries conduct internal reconnaissance—mapping domain trusts, identifying backup infrastructure, locating critical process controllers and historian servers, and establishing persistent access through scheduled tasks, service installation, or firmware implants. Ransomware detonation is timed for maximum operational impact: outside business hours on a Friday or before a major production run to maximise time before the disruption is fully recognised. The IT-OT boundary represents both a propagation barrier and a strategic lever: operators who shut down OT environments as a precaution—as occurred at Colonial Pipeline [4]—produce physical consequences from an attack that never technically crossed into OT. This dynamic is consistent with the adversarial economics documented by Huang et al. [26]: disrupting production by proxy, without needing ICS-specific technical capability, is incentive-compatible from the adversary’s perspective.

4.3. State-Aligned and OT-Targeted Threats

The Dragos 2026 Report [10] identifies three newly documented threat groups whose activity illustrates the current state of adversarial capability against OT environments. AZURITE, with OT-layer technical overlaps with the Flax Typhoon cluster, focuses on OT engineering workstations, exfiltrating network diagrams, alarm histories, and process information apparently intended to support the development of ICS-specific malware. PYROXENE, aligned with Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command, uses multi-year supply-chain campaigns and social engineering against operational personnel to establish footholds in IT environments and pivot into OT networks; the group deployed destructive wiper malware against critical infrastructure during regional conflict in June 2025. SYLVANITE operates primarily as an initial-access broker, exploiting edge device vulnerabilities to establish footholds that are subsequently handed off to VOLTZITE for deeper OT operations. The academic foundations for understanding the strategic motivations behind such campaigns are provided by Lindsay [55], Langner [34] (whose Stuxnet analysis established the concept of cyber weapons designed for physical effect), and Rid and Buchanan [59], while Pasqualetti et al. [2] establish a theoretical bound on detection: for a linear time-invariant process model, an attack sequence is undetectable precisely when it is an output-nulling input of the system, a condition governed by the invariant zeros of the model rather than by the choice of detection algorithm. The exact statement of the theorem, its assumptions and the sense in which a dimensional condition on attack inputs and monitored outputs is sufficient are given in Section 4.4.
The adversarial capability progression described by the Dragos 2026 Report [10] can be mapped onto the two-stage ICS Cyber Kill Chain framework, which distinguishes Stage 1 (intrusion, development, and reconnaissance in the IT and OT-adjacent environment) from Stage 2 (the development and execution of ICS-specific attack capabilities that produce physical effects). The framework, developed from the analysis of Stuxnet and subsequent ICS-targeting campaigns including BlackEnergy, Industroyer, and Triton, establishes that the transition from Stage 1 to Stage 2 requires adversaries to acquire process-specific knowledge—understanding of control logic, setpoint constraints, process dependencies, and safety system interactions. AZURITE’s documented focus on exfiltrating network diagrams and alarm data indicates sustained Stage 1 activity oriented toward enabling future Stage 2 operations: the value of process documentation to an adversary lies entirely in its utility for developing attack tools that will produce the intended physical effect without triggering safety systems prematurely. Langner’s analysis of Stuxnet [34] documented that the development of the centrifuge manipulation payload required detailed process knowledge that adversaries had clearly obtained in advance, establishing a pattern that subsequent ICS campaign analysis has consistently confirmed.

4.4. Cyber–Physical Coupling Attack Mechanisms

False data injection (A12: L5, I3) is the archetypal cyber–physical attack: it substitutes falsified sensor values for real process measurements, causing state estimators and controllers to operate on a distorted representation of the physical environment while the actual process state diverges undetected [2,11,33,41]. Urbina et al. [33] demonstrated experimentally on the SWaT testbed that FDI attacks can be designed to remain below the detection thresholds of statistical anomaly detectors while progressively steering the physical process toward an unsafe or targeted state—a result with direct implications for the reliability of any purely statistical defence. The 2015 Ukrainian power grid attack, in which attackers simultaneously compromised substations across multiple distribution companies, illustrates the physical consequence potential of coordinated IT–OT intrusions [5]. Safety instrumented system bypass (A14: L5, I4) operates at the highest consequence level in the taxonomy, targeting the protective mechanisms—emergency shutdowns, high-pressure interlocks, temperature safety limits—designed to prevent catastrophic physical outcomes when the controlled process reaches unsafe conditions. The 2017 Triton campaign targeted Triconex SIS controllers in a petrochemical facility with the apparent objective of disabling this last automated barrier [7]. Of all fourteen mechanisms classified in CPS-DGT, A14 is the one for which the defence-gap analysis reveals the most complete absence of effective countermeasures.
The formal stealthiness condition for FDI attacks was established by Pasqualetti et al. [2] through a state-space analysis of linear time-invariant process models, and is stated here once, with its assumptions, as the reference form used throughout this review. Consider a discrete-time LTI system x(k + 1) = Ax(k) + Bu(k) + B_a a(k), y(k) = Cx(k), where a(k) ∈ R^p denotes the attack input entering through the attack matrix B_a, y(k) ∈ R^m denotes the monitored outputs, and the following assumptions hold: the matrices A, B_a and C are known and time-invariant; the adversary has full knowledge of the model and can inject an arbitrary sequence a(k) through the fixed columns of B_a; the defender observes only y(k); and no process or measurement noise is considered, so that any nonzero residual is attributable to the attack. Under these assumptions, an attack sequence is undetectable if and only if it is an output-nulling input of the system: it lies in the kernel of the map from attack inputs to monitored outputs over all time, which is determined by the invariant zeros of the triple (A, B_a, C) and the associated output-nulling subspace. Undetectability is therefore a property of the model and of sensor placement, not of the detection algorithm. For systems without invariant zeros in the closed unit disc, no stealthy attack exists. In the practically relevant case where the system does have invariant zeros (i.e., where the transfer matrix from attack to output is not full column rank for all frequencies), a stealthy attack can always be constructed. The condition does not reduce simply to the rank of C: the system dynamics A enter through the invariant zero condition, and adding sensors (increasing the row dimension of C) closes the gap only if the enlarged system loses its output-nulling subspace, which depends on both the system dynamics and the sensor placement. A dimensional condition of the form p ≥ m—more attack inputs than monitored outputs—is sometimes quoted as a shorthand. It is a sufficient condition for the existence of a nontrivial output-nulling subspace only under the additional assumption that the transfer matrix from a to y is generic in the sense of losing full column rank whenever p ≥ m, and it is not necessary: systems with p < m may still admit stealthy attacks if they possess invariant zeros in the relevant region. This review uses the invariant-zero statement above as the operative condition and treats the dimensional form only as a sufficient condition under its stated assumptions. The implication for detection design is significant: increasing the statistical sophistication of the detector cannot close this gap; only increasing measurement redundancy—adding sensors such that the rank condition is no longer satisfied by the adversary’s available attack inputs—can provide a theoretical guarantee. In realistic water treatment, power grid, and chemical process environments, the number of potential attack injection points typically exceeds the number of independently monitored sensors, placing the system in the regime where stealthy attacks exist by construction. Physics-informed detection provides a partial mitigation by tightening the admissible perturbation set to physically realisable values [2,60], but cannot eliminate the fundamental limitation identified by Pasqualetti et al. when the rank condition is violated. A caveat on the generalisation of this condition is warranted: the result holds formally for linear time-invariant (LTI) systems with static attack and measurement matrices, and its extension to nonlinear dynamics, time-varying operating conditions, and sensor or actuator placement constraints requires additional analysis. In practice, detectability also depends on the system observability structure, the correlation between attacked and monitored channels, and the fidelity of the process model used by the detector. Physics-informed detectors that incorporate these system-specific constraints—as demonstrated by Lin et al. [60] using probabilistic timed automata and by Taormina and Galelli [61] using hydraulic simulation models—can reduce the set of feasible stealthy attacks below the theoretical bound, even when the rank condition is not fully satisfied. The Pasqualetti et al. condition should therefore be understood as an upper bound on attacker capability under idealised assumptions, not as a precise characterisation of the detectability frontier in any specific operational system. With the principal threat mechanisms characterised, the following three sections review the defensive landscape. Section 5 examines the intrusion detection approaches that represent the dominant defensive investment of the 2020–2026 period, assessing both their capabilities under standard conditions and their robustness under adversarial evaluation.

5. Intrusion Detection for Cyber–Physical Systems

5.1. Deep Learning-Based Detection

Ike et al. [24] correlate SCADA-layer behaviour with physical-process behaviour, detecting attacks that appear legitimate when either layer is examined alone. Kravchik and Shabtai [62] established an important performance baseline: a relatively compact 1D convolutional neural network (CNN) architecture achieves an F1 score of 0.969 across 36 attack scenarios on the SWaT dataset, outperforming earlier approaches and showing that temporal receptive field size and network depth matter more than raw parameter count for anomaly detection in ICS time series. A semi-supervised long short-term memory (LSTM) autoencoder approach by Goh et al. [63] achieves F1 = 0.796 on the first process stage of SWaT using only normal-operation data for training, which is practically relevant because labelled attack data is rarely available in operational environments; the lower F1 relative to supervised methods reflects both the unsupervised training constraint and the evaluation being limited to one of the six SWaT process stages. He et al. [64] applied a deep belief network architecture to capture temporal behaviour patterns of false data injection attacks in a smart grid dataset, obtaining an F1 of 0.925. Although this work pre-dates the 2020–2026 primary review window, it is included in the quantitative synthesis because it is the only published study applying a DBN architecture to FDI detection on a CPS dataset and is cited as a methodological baseline by multiple post-2020 papers in the reviewed corpus; its inclusion is consistent with the supplementary foundational-work criterion stated in Section 2. Wolsing et al. [65] addressed the protocol heterogeneity characteristic of real industrial installations through the Industrial Protocol Abstraction Layer (IPAL) normalisation framework, translating Modbus, DNP3, IEC 104, and OPC UA traffic into a common representation and achieving F1 = 0.860 on the BATADAL water distribution dataset [13]. Shin et al. [56,66] introduced and extended the HAI hardware-in-the-loop benchmark with more realistic process dynamics, finding that statistical methods trained under one set of operating conditions degrade substantially when conditions change. Earlier dataset-level work by Junejo and Goh [67] on the same SWaT environment established the class of behaviour-based detection methods that subsequent deep learning approaches refined.
The performance differences among architectures on the SWaT dataset reflect identifiable design choices. Kravchik and Shabtai [62] show that convolutional architectures outperform LSTM-based approaches on the SWaT benchmark for short-duration attacks, because the CNN’s fixed receptive field captures the relevant temporal context without the gradient vanishing problems that affect LSTM training on imbalanced datasets where attack samples are rare. The deep belief network approach of He et al. [64] captures temporal behavioural features of FDI attacks that simpler classifiers miss: by learning hierarchical representations of normal and attack traffic patterns, the model identifies subtle deviations in measurement sequences that do not trigger threshold-based detectors. Wolsing et al. [65] demonstrate a third dimension of variation: detection effectiveness is strongly protocol-dependent when models are trained on single-protocol datasets and tested on multi-protocol environments, motivating normalisation approaches that abstract over protocol specifics before training. These architectural differences have direct implications for deployment: no single architecture dominates across all process types, attack durations, and protocol configurations, which suggests that ensemble approaches combining complementary architectures may offer more robust operational coverage than any individual model [62,65].

5.2. Physics-Informed Detection

Physics-informed detection approaches validate sensor measurements against constraints derived from the physical process—conservation laws, thermodynamic bounds, control-loop invariants—that the system must satisfy regardless of what the digital layer reports [2,11,20,68]. The structural advantage over purely statistical methods is robustness against adversarial manipulation: an adversary bound by physical laws has a smaller perturbation space, and an injection that is statistically plausible but physically impossible will be flagged by a physics-aware detector where a statistical one will not. Lin et al. [60] demonstrated a physics-grounded alternative through TABOR, a graphical model that encodes process invariants as probabilistic timed automata learned from normal-operation data on SWaT; the model achieves superior precision over SVM and deep neural network baselines and provides interpretable explanations of why a given observation is flagged—a property that purely statistical detectors lack. Taormina and Galelli [61] quantified the practical failure mode of physics-based detection: on water distribution systems, physically grounded detection substantially outperforms statistical approaches on localised attack scenarios, but the fidelity of any physics-based component is bounded by the accuracy of the underlying process model. Pasqualetti et al. [2] provide the theoretical ceiling stated in Section 4.4: undetectability is governed by the invariant zeros of the process model, so no increase in the statistical sophistication of the detector can close the gap, which motivates complementary investment in sensor placement and measurement redundancy.
The complementary failure modes of D1 and D2 create a natural motivation for hybrid architectures. Statistical anomaly detection (D1) fails against adversarially crafted inputs that remain within the learned statistical distribution but violate physical laws; physics-informed detection (D2) fails when the process model is inaccurate but is inherently robust against the statistical evasion strategies that defeat D1. A hybrid detector that passes inputs through both a statistical and a physics-based filter captures the advantages of each: statistically anomalous but physically plausible inputs are caught by D1, while statistically plausible but physically impossible inputs are caught by D2. Raissi et al. [68] provide the foundational architecture for embedding physical constraints into neural network training through physics-informed loss functions, though their application to ICS anomaly detection remains an open research problem: the process models available in industrial environments are typically partial, approximate, and incompletely documented, which limits the fidelity of any physics-based component in the same way documented by Taormina and Galelli [61]. The practical question is not whether hybrid approaches outperform pure methods in ideal conditions—they do, by construction—but whether the improvement persists under the model inaccuracies, operating condition changes, and adversarial evasion strategies characteristic of real deployments. A candid assessment of the current state of hybrid D1 + D2 evaluation is warranted. The reviewed literature does not contain a controlled study that directly compares a hybrid statistical–physics architecture against either its component detectors on the same dataset and under the same adversarial conditions. The closest comparisons available are: (a) Lin et al. [60], whose TABOR graphical model integrates learned process invariants with statistical detection and reports superior precision over SVM and deep neural network baselines on SWaT, but does not evaluate under adversarial evasion; (b) Taormina and Galelli [61], whose physics-based hydraulic model outperforms statistical methods on localised FDI scenarios but does not include a hybrid architecture; and (c) Erba et al. [58], who demonstrate adversarial evasion against the 1D-CNN baseline but do not evaluate whether a physics-based component would have caught the adversarial samples. A standardised hybrid evaluation protocol—fixing the dataset (SWaT or BATADAL), the adversarial threat model (white-box, black-box transfer, or physically constrained), and the performance metrics—does not yet exist in the reviewed literature. Establishing such a protocol is identified in Section 10 as a prerequisite for comparing hybrid architectures against the single-modality baselines in Table 7 and for making deployment recommendations.
Table 7. Reported detection performance of five primary studies on standard ICS evaluation datasets, with the final row giving the 1D-CNN under adversarial evasion. Evaluation conditions differ across studies; see Section 5.4. Sources: [58,62,63,64,65,69]. 1 Process stage 1 of SWaT only.

5.3. Adversarial Robustness

Erba et al. [58] demonstrated the extent to which standard evaluation conditions overstate the practical security value of ML-based IDS: by constructing adversarial inputs that keep all process measurements within the model-accepted statistical range, they reduced the F1 score of the 1D-CNN baseline from 0.969 to 0.595. This is a reduction of 37.4 percentage points in absolute terms, corresponding to a relative reduction of 38.6% from the baseline F1. All percentages reported in this manuscript state explicitly whether they are absolute percentage-point reductions or relative percentage reductions. Critically, white-box model access is not required: black-box adversarial examples constructed against a substitute model transfer to a different deployed model with measurable F1 degradation [58,70], meaning the attack is practical without prior knowledge of the target architecture. Biggio and Roli [70] provide the theoretical basis: the defender–attacker relationship in adversarial ML is a sequential game in which the attacker observes and adapts to the defence, and no purely statistical detector can certify robustness against a sufficiently informed adversary. Apruzzese et al. [71] surveyed the empirical evidence across multiple ICS detection architectures and found systematic evasion in every case, with no architecture demonstrating certified bounds. The practical implication is that F1 scores obtained under standard evaluation do not represent the security guarantee provided against an adversary who studies and targets the deployed system.
The adversarial ML literature offers two broad approaches to addressing this limitation: empirical defences, which modify training or inference procedures to reduce observed vulnerability without formal guarantees; and certified defences, which provide provable bounds on performance degradation under bounded perturbations. Randomised smoothing [70,71], the most practically scalable certified defence, constructs a smoothed classifier by evaluating the base classifier on Gaussian-perturbed inputs. The theorem of Cohen et al. is stated as follows. Let f map inputs to a label set C, let ϵ ~ N(0, σ2I) be isotropic Gaussian noise, and let the smoothed classifier be g(x) = argmax_{c ∈ C} P(f(x + ϵ) = c). Suppose a class c_A and probability bounds p_A and p_B satisfy P(f(x + ϵ) = c_A) ≥ p_A ≥ p_B ≥ max_{c ≠ c_A} P(f(x + ϵ) = c). Then g(x + δ) = c_A for every perturbation δ with ‖δ‖2 < R, where R = (σ/2)·[Φ−1(p_A) − Φ−1(p_B)] and Φ−1 is the inverse of the standard Gaussian cumulative distribution function. The certified radius therefore depends on both the lower bound for the top-class probability and the upper bound for the runner-up class probability. The simplified form R = σ·Φ−1(p_A) is recovered only in the binary case under the additional assumption p_B = 1 − p_A, which does not hold in general for multi-class ICS detection. In practice p_A and p_B are estimated by Monte Carlo sampling, so the certified radius holds at a stated confidence level that must be reported alongside it. In ICS process data, however, the certified radius depends on the data dimensionality and the noise distribution, both of which differ fundamentally from the image classification setting for which most certified methods were designed. The structured, low-dimensional, physically constrained nature of ICS sensor time series creates an opportunity: the physically admissible perturbation set is much smaller than the Euclidean ball used in standard certified robustness analysis, which means that tighter, physically motivated robustness certificates should in principle be achievable. Translating this theoretical opportunity into practical certified ICS detectors requires formalising the physical admissibility constraints, characterising the adversary’s knowledge about those constraints, and designing training procedures that exploit the constraints to achieve certification—each of which remains an open research problem [70,71].

5.4. Quantitative Performance Synthesis

Table 7 collates detection performance from the five primary studies meeting the inclusion criteria for standardised comparison: all evaluate on the SWaT water treatment or BATADAL water distribution datasets, report precision, recall, and F1 under specified experimental conditions, and provide sufficient methodological detail for reproducible evaluation. Figure 3 illustrates the results and shows the F1 degradation observed when the same models operate against adversarially crafted inputs. The comparison should be interpreted as illustrative rather than as a definitive ranking of methods: the five studies differ in dataset (SWaT, BATADAL, or smart-grid), attack scenario selection, training regime (supervised versus unsupervised), evaluation scope (full dataset versus single process stage), and the specific attack types targeted. F1 differences between methods may reflect these design choices as much as intrinsic architectural capability. The ordering in Table 7 by F1 score under standard conditions is intended to orient the reader within the literature, not to establish a definitive performance hierarchy.
Figure 3. Detection performance of the five primary studies under standard conditions, grouped by dataset (a), and the effect of adversarial evasion on the 1D-CNN (b). The studies shown are Kravchik and Shabtai [62], Ahmed et al. [69], Goh et al. [12], Wolsing et al. [65] and He et al. [64]; the adversarial evaluation in panel (b) follows Erba et al. [58]. Data from Table 7; interpretation can be found in Section 5.4.
Because the five studies are frequently read as a ranking, the dimensions along which they are not comparable are set out explicitly in Table 8. Entries marked “not reported” are not omissions in this review: the source study does not state the value. The extent of these entries is itself the finding. No two of the five studies share a common dataset, attack selection, evaluation split and averaging convention, so no pair of reported F1 values is a controlled comparison, and the range 0.796–0.969 should be read as the spread of values reported under five different protocols rather than as a performance ordering.
Table 8. Comparability of the five primary IDS studies. “Not reported” indicates that the source study does not state the value; no imputation has been performed.

6. Access Control and Zero-Trust Architectures

NIST Special Publication 800-207, authored by Rose et al. [14] and published in 2020, defines zero trust as the elimination of implicit trust based on network location and its replacement with continuous verification of identity, device posture, and contextual risk for every access request. The companion NIST SP 800-82 guide to operational technology security [35] provides the OT-specific context that 800-207 does not cover, including operational constraints on authentication mechanisms that are incompatible with legacy industrial control hardware. Behavioural biometrics such as keystroke dynamics and network access patterns have been proposed as low-overhead continuous authentication signals for IoT environments [72], and their potential applicability to OT timing constraints is noted in the access control literature, though no deployment on real industrial hardware has been demonstrated. SP 800-207 acknowledges the particular challenges of OT environments—legacy communication protocols without authentication capability, real-time deterministic control requirements, and safety-critical operational constraints—without providing OT-specific guidance for resolving them. That gap was partially addressed on 29 April 2026 when CISA, the Department of War, the Department of Energy, the FBI, and the Department of State published the first joint interagency guidance for applying zero-trust principles specifically to OT environments [18]. The document is candid about the limits of direct translation: blanket application of IT-focused zero-trust capabilities to OT is described as neither reasonable nor feasible, and the guidance recommends compensating controls—enhanced passive monitoring, strict access policies, network segmentation—for environments where modern security features cannot be deployed on legacy hardware. Syed et al. [15], in a comprehensive survey of zero-trust architecture (ZTA), found that only a small minority of surveyed studies addressed OT environments and none demonstrated deployment in safety-critical real-time control systems, confirming that the academic literature had not yet resolved the underlying compatibility barriers.
Feng and Hu [20] made the most direct contribution to resolving these barriers, proposing a cyber–physical ZTA framework that extends the standard policy decision point with a physical-state monitoring module, enabling access control decisions to account for current process operating conditions. Their framework addresses the identity–authority mapping problem that this review identifies as governance gap G3: in most current OT deployments, no systematic model exists specifying which digital identities are authorised to exercise which physical authority under which operational conditions. The evaluation is limited to simulation, and no hardware-in-the-loop or live deployment results have been reported. The principal technical failure mode of D3 in OT contexts is latency: the network round-trip required for policy decision point evaluation is incompatible with the scan-cycle timing of PLC control loops, which typically range from 10 to 100 milliseconds. A secondary failure mode is safety conflict: automated access revocation, a core mechanism for containing compromise, can itself trigger unsafe conditions if it interrupts a safety-critical control function mid-execution [20,36]. Cheminod et al. [31] and Nicholson et al. [32] documented the baseline condition that motivates these concerns: Modbus, DNP3, and most legacy SCADA protocols implement no packet-level authentication, and this remains unchanged across the reviewed period; Homoliak et al. [29] identify access control misconfiguration as the most common enabler of insider incidents across surveyed organisations, a finding that confirms the urgency of identity-aware controls.
The identity–authority governance prerequisite for zero-trust deployment in OT environments (G3 in CPS-DGT) has no established solution in the reviewed literature. Enterprise identity governance frameworks model access in terms of subject, object, and permission: a user with a given role is permitted or denied access to a given resource. In a CPS environment, the corresponding model must additionally capture physical authority: a control engineer with maintenance permissions on a specific PLC may be authorised to modify setpoints within their operating range during a scheduled maintenance window but not during a live production run at peak load, and not at all if the associated safety interlock is in an alarm state. This operational-context dependency has no equivalent in enterprise identity models, which treat resource access as a binary permission rather than a context-qualified authority. Developing a formal model of CPS identity–authority that captures the role, process state, temporal context, and safety conditions is identified here as a prerequisite for zero-trust policy specification in OT environments; without it, ZTA policy engines cannot be configured to enforce appropriate access control for the most sensitive control operations. Feng and Hu [20] gesture toward this model in their cyber–physical ZTA proposal, but their process-state monitoring module captures continuous variables rather than the discrete authority model that policy specification requires. A formal definition of the CPS identity–authority model required to close the G3 gap can be stated as follows. Let Σ denote the set of principals (human operators, automated processes, and remote access sessions), Π the set of physical process states (a finite discretisation of the continuous process variable space into operationally meaningful operating modes), Θ the set of temporal contexts (shift schedules, maintenance windows, emergency states), and Φ the set of safety interlock states. A CPS identity–authority model is a function A: Σ × Π × Θ × Φ → 2^C, mapping each tuple of (principal, process state, temporal context, safety state) to the set of authorised control actions C that the principal may execute under those conditions. This generalises enterprise role-based access control (RBAC), in which A: Σ × R → 2^C with R a static role set, by introducing the process-state, temporal, and safety dimensions that are absent from enterprise models. A policy engine implementing this model can, for example, permit a control engineer to modify pump setpoints within a normal operating range during a scheduled maintenance window (σ ∈ control engineers, π = normal operation, θ = maintenance window, φ = no alarms), while denying the same action during a safety alarm state (φ = SIL-1 alarm active) regardless of the engineer’s role. The four-tuple (principal, process state, temporal context, safety state) corresponds directly to the four-component authority prerequisite identified in the G3 governance gap: the absence of a formalised model of this type is the proximate reason why ZTA policy engines cannot be configured for CPS environments without significant custom engineering effort for each installation.

7. Supply-Chain Security

Ladisa et al. [73] conducted the most comprehensive taxonomic study of software supply-chain attacks to date, identifying 116 distinct attack patterns across the full development lifecycle. Their analysis found that Software Bills of Materials (SBOMs)—the most widely adopted supply-chain defence mechanism—address fewer than 40% of the 116 documented patterns even under idealised deployment assumptions, because SBOMs describe component inventory but carry no evidence about the integrity of the build process that assembled those components. Ohm et al. [37] independently catalogued 174 documented cases of malicious package injection into npm, PyPI, and RubyGems repositories between 2015 and 2020, a more-than-fivefold increase over that period. The dependency confusion attack documented by Birsan [74] in 2021 illustrated a systematic vulnerability in multi-registry build systems: by uploading a public package sharing its name with an internal private package but carrying a higher version number, an attacker can cause automated build systems to fetch the malicious version without any explicit user action or authentication failure. This attack requires no prior knowledge of the target organisation’s internal package namespace and affected Apple, Microsoft, and dozens of other organisations before it was publicly documented.
Torres-Arias et al. [75] addressed the build process integrity gap with in-toto, a framework that defines a policy language for specifying the expected transformations at each stage of the build pipeline and cryptographically links those specifications to evidence generated at runtime. The security of CI/CD pipeline configurations was further studied by Koishybayev et al. [38], who found systematic misconfigurations in GitHub Actions workflows (GitHub Actions, GitHub Inc., San Francisco, CA, USA; platform version as deployed in 2022) that expose build artefacts to supply-chain compromise. The NCSC supply-chain guidance [76] provides complementary practitioner-oriented controls for managing third-party software and hardware suppliers. In-toto closes the gap that SBOM-based defences leave open—evidence of what was built does not substitute for evidence of how it was built—but it requires every pipeline stage to generate and sign attestation records, which is not feasible in multi-organisation supply chains where intermediaries do not have visibility into each other’s processes. Pashchenko et al. [77] documented the depth of the transitive dependency problem: the attack surface attributable to transitive dependencies is on average ten times larger than that of direct dependencies, with some production software stacks extending to fifteen dependency levels. Costin et al. [39] conducted a large-scale analysis of 32,000 embedded firmware images and found high-severity known vulnerabilities in 38% of them, with many device families sharing identical private cryptographic keys across vendors—indicative of systemic failures in the firmware distribution supply chain; subsequent work by Muench et al. [40] addressed the practical challenges of security-testing such firmware through dynamic fuzzing. The supply-chain attack taxonomy derived from these reviewed papers is illustrated in Figure 4.
Figure 4. Software supply-chain attack phases and the coverage boundary of SBOM-based defences, after Ladisa et al. [73] and Ohm et al. [37]. Discussed in Section 7.
The hardware supply-chain dimension of the D5 gap is the least addressed in the reviewed literature and the most difficult to close. Software supply-chain attacks can in principle be detected after the fact through artefact comparison and runtime monitoring, even if prevention is imperfect; hardware backdoors, once embedded in silicon or firmware at fabrication, are effectively undetectable without either physical decapping and reverse engineering of the component or hardware attestation mechanisms anchored in a root of trust that itself must be manufactured trustworthily. Physically unclonable functions (PUFs), reviewed by Maes [78], offer a hardware-based attestation mechanism exploiting manufacturing-process variation that is unique to each die and cannot be reproduced without the original silicon: a PUF-based device identity would allow a field device to prove that it is the specific silicon component that was originally provisioned, rather than a replacement device with a cloned identity. PUF deployment in industrial control hardware remains limited to prototype demonstrations, however, because the qualification and re-certification requirements for safety-rated industrial components create economic and timeline barriers that have prevented industrial uptake. The EU Cyber Resilience Act (2024) [43] introduces minimum security requirements for connected products that may create demand for hardware attestation mechanisms, but its provisions are specified at a level of abstraction that does not yet mandate PUFs or equivalent attestation for safety-critical industrial components.

8. Governance and Resilience

8.1. Regulatory Frameworks

Table 9 presents a comparative assessment of the five principal regulatory and standards frameworks applicable to CPS security: NIST Cybersecurity Framework 2.0 [17], ISO/IEC 62443 [21], the EU NIS2 Directive [16], the North American Electric Reliability Corporation (NERC) CIP standards [79], and IEC 62351 [80]. The NIS2 Directive, adopted in late 2022, is the most significant recent regulatory development, extending mandatory security obligations to organisations in 18 critical infrastructure sectors across the EU and introducing specific supply-chain security requirements that respond directly to the large-scale supply-chain attacks of 2020–2021 [16]. The EU Cyber Resilience Act (2024) [43] extended this framework to mandate cybersecurity requirements for all products with digital elements placed on the EU market, creating supply-chain security obligations that directly address the D5 provenance gap identified in the matrix. NIST CSF 2.0 adds a Govern function to the five original functions and expands OT-specific implementation guidance, though it remains principally voluntary and does not prescribe specific technical controls [17]. ISO/IEC 27001:2022 [44] provides the broader organisational information security management framework within which both CSF and ISO/IEC 62443 technical requirements are typically implemented in practice. ISO/IEC 62443 remains the technically most precise standard in the set, providing security level requirements ranging from SL1 to SL4, zone and conduit architecture prescriptions, and component-level security requirements that translate directly to implementation decisions [21]. Skopik et al. [30] and Carr [81] analysed the information-sharing dimensions of NIS-based frameworks, finding that voluntary sharing mechanisms consistently underdeliver relative to the systemic intelligence value available, and argued for structured sharing obligations as a necessary complement.
Table 9. Comparative assessment of five regulatory and standards frameworks applicable to CPS security, in order of CPS-specificity. Coverage depth reflects the degree to which each framework addresses OT/ICS-specific threat mechanisms identified in CPS-DGT.

8.2. Governance Gaps

Nurse et al. [82] documented that IoT and CPS operators overwhelmingly rely on IT-derived security risk assessment frameworks that do not account for the physical operational constraints distinguishing industrial environments—continuous operation requirements, safety interlock states, and process dependencies. Settanni et al. [83] documented that CTI frameworks prioritise information aggregation and correlation over operational timeliness, a mismatch that is particularly acute in industrial incident response where decisions must be made within control-loop timeframes. The CISA 2026 ZT-OT guidance [18] reaches the same conclusion from a policy perspective, identifying the coordination gap between IT and OT response teams as a primary barrier to effective zero-trust implementation. The Dragos 2026 Report [10] documents the adversarial exploitation of this gap: PYROXENE specifically targets operational personnel through social engineering campaigns that take advantage of the disconnect between cybersecurity procedures and control engineering practices. On resilience metrics, Linkov et al. [45,46,84], Kott and Linkov [85], Sterbenz et al. [86], and Radanliev et al. [87] provide theoretical and empirical frameworks for resilient systems, but Segovia-Ferreira et al. [54] found that none of the 73 reviewed cyber-resilience proposals for CPSs yields operationally deployable metrics that can be measured without physical testbed access or specialised laboratory conditions.
The governance gap analysis reveals a structural pattern: each of the five G-dimension gaps has the property that it cannot be closed by technical research alone but requires collective action across organisational boundaries. The G1 regulatory specificity gap requires regulators to engage with the technical details of attack mechanisms—a form of regulatory science that current staffing and mandate structures at most national cybersecurity agencies do not support. The G2 shared responsibility gap requires supply-chain contracting practices to change across entire industries, which is achievable only through coordinated regulatory pressure or industry self-governance with sufficient market power. The G3 identity–authority gap requires identity governance frameworks to be developed jointly by control engineers, cybersecurity architects, and safety engineers—a cross-disciplinary combination that rarely occurs within a single organisation. The G4 incident response gap requires cybersecurity and operational engineering communities to develop shared playbooks and training frameworks, which necessitates mutual recognition of each discipline’s constraints and priorities. The G5 resilience metric gap requires standards bodies to convene researchers, operators, and regulators around a shared measurement framework, a multi-year standards development process that has not yet been formally initiated for CPS-specific resilience. Carr [81] and Skopik et al. [30] observe that voluntary coordination mechanisms in cybersecurity consistently produce suboptimal outcomes because they lack the enforcement mechanisms that make compliance individually rational; the G-dimension gaps exhibit the same collective action problem structure.

9. Defence-Gap Synthesis: The CPS-DGT Matrix

The defence-gap matrix is presented in two complementary forms. Table 10 provides the categorical defence-coverage matrix in tabular form for reference and citation; Figure 5 presents the same matrix as a visual heat map with colour-coded layers to facilitate pattern recognition. Both are retained because the tabular form is needed for precise cell-level citation, while the figure form reveals the structural layer-wise patterns that are the primary analytical result. Table 11 summarises the resulting gaps and their associated governance prerequisites.
Table 10. CPS-DGT defence-gap matrix: coverage of the 14 classified attack mechanisms (rows) by the six defensive technology categories (columns). Symbols: ● effective; ◑ partial; ✕ insufficient evidence; ○ not applicable. Defensive categories: D1 deep learning-based IDS; D2 physics-informed detection; D3 zero-trust architecture; D4 secure controller design; D5 supply-chain provenance; D6 resilience engineering. The rules governing each rating are given in Section 3. D1 = deep learning-based IDS; D2 = physics-informed detection; D3 = zero-trust architecture; D4 = secure controller design; D5 = supply-chain provenance; D6 = resilience engineering. The basis for every one of the 84 cells is given in the cell-level evidence table below, which records for each cell the rating, the supporting reference, the section in which the evidence is discussed, and a one-sentence statement of the basis for the rating. Whether a cell is rated not applicable (○) or insufficient evidence (✕) follows from the scope of the defensive category as defined in Section 3: a cell is not applicable when the defence operates on an architectural layer at which the mechanism leaves no observable and no enforceable control point, and insufficient evidence when the defence type could in principle act on the mechanism but no reviewed study demonstrates that it does.
Figure 5. Defence-gap matrix as a heat map: 14 attack mechanisms (rows, coloured by layer) against six defensive categories (columns). Symbols and colours as in Table 10; dashed borders mark the five uncovered mechanisms. Cell-level basis given later in this section; patterns discussed in Section 9.
Table 11. The seven entries with insufficient coverage: five uncovered rows and two partial rows. A10 and A11 share one row; the fifth uncovered row is adversarial ML evasion, a transversal failure mode of D1 rather than an attack mechanism. Asterisks mark mechanisms covered only on post-2018 hardware. Counting rule and governance prerequisites are explained in Section 9.
The evidence base for the matrix requires an explicit statement of scope. The matrix contains 84 cells, formed by 14 attack mechanisms and six defensive categories. Table 12 identifies the primary supporting reference for the cells in which a defence is rated effective or partial and for which a specific study is decisive; the remaining cells are supported by the discussion in Section 4, Section 5, Section 6, Section 7 and Section 8. Table 13 gives the basis for every one of the 84 cells: the rating, the supporting reference where one exists, the section in which the evidence is discussed, and a one-sentence statement of the basis for the rating. Cells are traceable individually rather than only through the narrative. Two limitations of this evidence base should be stated. First, the quality grade is assigned to the decisive source by study type and was applied by the authors without independent verification, so it separates experimental from advisory evidence but is not a validated appraisal instrument. Second, the ratings distinguishing not applicable from insufficient evidence follow the scope rule stated above rather than an independently validated instrument. Cells for which no supporting study was identified are recorded as insufficient evidence rather than as demonstrated ineffectiveness, in accordance with the rating definitions given in Section 3, and are marked in Table 13 as ‘none identified’ rather than left blank.
Table 12. Principal supporting references for the cells in which a single study is decisive. The complete cell-level evidence is given in the following table. Rating symbols: ● effective; ◑ partial; ✕ insufficient evidence; ○ not applicable.
Table 13. Basis for every cell of the defence-gap matrix. One row is given for each of the 84 cells formed by the 14 attack mechanisms and the six defensive categories. Rating symbols: ● effective; ◑ partial; ✕ insufficient evidence; ○ not applicable; these are the same symbols used in Table 10 and Figure 5. The Reference column gives the reviewed work supporting the rating; an em dash marks a cell rated not applicable, and ‘none identified’ marks a cell where the defence type is applicable but no reviewed study demonstrates protection. The Section column locates the discussion supporting the rating, the Quality column grades the decisive source (Q1–Q4, defined in Section 9), and the final column states the basis in one sentence.
The quality of the evidence behind each rating is graded in the final column of Table 13 on a four-point scale applied to the decisive source: Q1, a controlled experiment reported in a peer-reviewed venue; Q2, peer-reviewed modelling, simulation or systematic evaluation without a controlled comparison; Q3, an incident report, standard or published guidance; and Q4, reasoning from adjacent evidence rather than from a study of the mechanism itself. Cells rated not applicable carry no grade, and cells marked ‘none identified’ have no source to grade.
Restricting the matrix to high-confidence evidence (Q1 and Q2 only) yields a sensitivity analysis with three results. First, the five uncovered mechanisms remain uncovered: A03, A09, A10, A11 and A14 have no effective rating under either evidence regime, and restricting the admissible evidence can only remove ratings, never add them. The principal finding of the review is therefore robust to the quality restriction. Second, and less comfortably, three of the six effective ratings in the matrix do not survive the restriction. All three are zero-trust ratings at the identity layer (A02, A04 and A05 against D3), and all three rest on Q3 guidance and standards rather than on experimental evaluation in an ICS setting. Under the high-confidence restriction the identity layer retains no demonstrated effective coverage, and A02, A04 and A05 join the uncovered set, raising the count from five mechanisms to eight. Third, fifteen of the partial ratings likewise rest on Q3 or Q4 evidence, concentrated in the zero-trust and resilience columns.
Two conclusions follow. The uncovered mechanisms identified in this review are not an artefact of admitting weak evidence: they would be uncovered on any evidence standard. But the covered portion of the matrix is more fragile than the symbols alone suggest, because the strongest claims about identity-layer defence rest on guidance rather than on demonstration. This asymmetry, that the negative findings are better supported than the positive ones, is a direct consequence of a literature in which defences are more often specified than evaluated, and it should be weighed when reading the matrix. Two sources added during the targeted supplementary search described in Section 2 support this reading from a different direction. Kus et al. [22] show that machine learning-based industrial intrusion detectors are commonly trained on the same categories of attack against which they are subsequently evaluated, so that reported detection rates above 99% say little about performance on attacks the detector has not seen; when attack categories are withheld from training, recall falls sharply. Lamberts et al. [23] survey evaluation practice across the field and document the same absence of a shared protocol that Table 8 records for the five studies compared here. The degradation shown in Figure 3 is therefore not an isolated result for one architecture, but one instance of a broader pattern in which evaluation design flatters the defence.
Before describing the structural patterns in the matrix, the gap counting used throughout the manuscript requires clarification. Table 11 identifies seven entries with insufficient coverage, corresponding to five rows marked uncovered (A14, A03, A09, A10 + A11 combined as one row because they share the same attestation gap, and adversarial ML evasion as a transversal failure mode of D1 rather than a 14th A-coded mechanism) plus two mechanisms with only partial countermeasures (A12 and A01). The phrase used in the Abstract, the Introduction and the Conclusions is “seven entries with insufficient coverage”, and it resolves as follows: seven matrix entries, comprising five uncovered rows and two partial rows; these seven entries correspond to six unique attack mechanisms with insufficient coverage (A03, A09, A10, A11 uncovered, together with A01 and A12 partial) plus one transversal failure mode; one row is a combined row (A10 + A11 share a single row because they share the same attestation gap); one uncovered row is adversarial ML evasion, which is a transversal failure mode of defensive category D1 and is not one of the mechanisms A01–A14; and A14 is the fifth uncovered mechanism. The phrase “seven attack mechanisms” is therefore not used anywhere in this manuscript, because the seven entries are not seven mechanisms. The “five with no effective countermeasure” refers to the five uncovered rows (noting that one row combines A10 and A11 because both share the same multi-stage attestation gap). Adversarial ML evasion is listed as a separate uncovered entry because it is a cross-cutting failure mode of a defensive category (D1) under adversarial conditions, not a discrete attack mechanism against a specific system component; it cannot be assigned a layer code and does not appear among A01–A14.
The matrix reveals several structural features of the CPS security landscape as documented in the 2020–2026 literature. The attacks least covered by available defences are concentrated at the cyber–physical boundary (L5) and in supply-chain channels (L4), whereas attacks generating detectable cyber-layer anomalies (L1–L3) have at least partial coverage. This asymmetry reflects a dominant pattern in the literature: the primary defensive investment of the post-2020 period has been in deep learning-based network anomaly detection, which provides no coverage against mechanisms that do not produce anomalies in the cyber layer. Governance deficiencies compound the picture in a specific way: several technically available defences are absent from operational deployments not for technical reasons but for institutional ones. Zero trust is constrained by the absence of identity–authority models (G3 gap); supply-chain provenance is undermined by absent multi-party attestation obligations (G2 gap); resilience engineering cannot be verified or required by regulation because quantitative metrics do not exist (G5 gap). The adversarial robustness problem, finally, is transversal: the F1 improvements documented in standard evaluation represent genuine detection capability under non-adaptive conditions, but they do not represent security guarantees against adversaries who observe and adapt to the deployed detection system.
Examining the seven insufficiently covered mechanisms individually clarifies the distinct nature of each. SIS bypass (A14: L5, I4) is uncovered because no approach identified in the reviewed literature provides a non-intrusive, low-latency mechanism for detecting logic-level modification to a safety controller without disrupting its safety function: the very properties that make SIS reliable in operation—deterministic execution, hardware separation from process networks, protection against software updates—also prevent the monitoring and attestation approaches that would enable detection. AI-enabled social engineering (A03: L1, I1) is uncovered because it defeats technical defences by operating on the human-judgement layer rather than the network or software layer; no technical control identified in the reviewed literature prevents a contextually convincing email from being acted upon by a target with legitimate network access [27,28]. Sub-OS persistence (A09: L3, I5) is covered by D4 (secure controller design) on modern hardware but is effectively uncovered for the majority of the deployed ICS base, which pre-dates secure boot and measured firmware capabilities by a decade or more, and for which the re-certification barrier means hardware security features cannot be deployed within the operational lifecycle of the equipment. Build pipeline compromise (A10: L4, I5) and firmware backdoors (A11: L4, I5) share the attestation gap identified in Section 7: both require multi-party attestation chains that are not contractually established in current supply-chain arrangements. Adversarial ML evasion is transversal—it is not a specific attack mechanism against a specific system but a failure mode of an entire defensive category under adversarial conditions—and uncovering it requires either certified robustness (the technical gap identified in Challenge 10.1) or an architectural shift away from purely statistical detection (the hybrid D1 + D2 direction).

10. Open Research Challenges

The five research challenges that follow are derived directly from the defence-gap analysis. Each addresses a gap or failure mode for which the reviewed literature provides no solution, and each is specified with sufficient precision to constitute a tractable research programme rather than a general aspiration.

10.1. Certifiable Adversarial Robustness for ICS Detection

The primary failure mode of D1 is adversarial evasion. The 1D-CNN in the quantitative synthesis degrades by 37.4 percentage points in absolute terms, a relative reduction of 38.6%, under adversarial conditions (Erba et al. [58]); Apruzzese et al. [70] found systematic evasion across all reviewed architectures without quantified per-architecture bounds, and no reviewed approach provides certified robustness under formal adversarial models for ICS process data [58,70]. Current certified robustness techniques from the broader adversarial ML literature apply to input domains that differ structurally from industrial process time series: they do not exploit the physical law constraints that bound the adversary’s perturbation space in a CPS context. The most promising near-term research direction is the combination of D1 statistical detection and D2 physics-informed validation: applying physical law constraints to adversarial robustness certification would substantially narrow the set of valid adversarial perturbations, potentially enabling much tighter robustness bounds than are achievable for unconstrained adversarial ML. Demonstrating this combination on SWaT, BATADAL, and HAI under standardised adversarial threat models would provide the empirical foundation for regulatory adoption.
A concrete research path for this challenge has the following structure. The first step is to formalise the physical admissibility constraints for the target process as a set of input perturbation constraints: for a water treatment process, for example, the flow rate through a pipe cannot exceed its physical capacity, the pressure at a junction must satisfy continuity equations, and the chemical concentration of dosing points is bounded by the dosing system capacity. The second step is to characterise the adversary’s capability relative to those constraints: a threat model that specifies which sensors the adversary can spoof, what physical constraints bound the spoofed values, and what knowledge the adversary has of the deployed detection system. The third step is to design and certify a detector whose performance guarantee is expressed relative to the physical admissibility set rather than an unconstrained Euclidean ball. Erba et al. [58] take a step toward this formulation by evaluating detectors against physically constrained adversaries, but their evaluation protocol does not produce a certified bound; it demonstrates empirically that physical constraints limit adversary capability without quantifying the resulting detection guarantee. Raissi et al. [68] provide the tools for embedding physical constraints in the learning process; the combination of their physics-informed training with formal robustness certification methodology from the adversarial ML literature represents the most direct route to closing the D1 adversarial robustness gap.

10.2. End-to-End Attestation Across Multi-Stage Supply Chains

Ladisa et al. [73] document that over 60% of supply-chain attack patterns are not addressable by SBOM-based defences even under idealised conditions. Three attestation gaps require simultaneous closure: transitive software dependencies, where the attack surface attributable to indirect dependencies is on average ten times larger than that of direct ones [77]; multi-stage firmware distribution, where handoffs between the equipment manufacturer, distribution networks, and site installation generate no consistent attestation trail [39,40]; and hardware fabricated across jurisdictions, where no shared audit framework currently exists [78]. PUF-based hardware attestation offers a technically promising route for the hardware gap but has not been demonstrated at an industrial scale. Progress on all three fronts requires not only technical research on scalable multi-party attestation protocols but governance research on the contractual and legal mechanisms that would make cross-jurisdiction attestation obligations enforceable, addressing the G2 gap that the present review identifies.
The governance component of this challenge is as significant as the technical one. Closing the transitive dependency attestation gap requires every package registry—npm, PyPI, RubyGems, and their industrial equivalents—to generate and publish attestation evidence for each package version, and every build system to verify that evidence before incorporating dependencies. This is achievable in principle but requires coordinated adoption across the global open-source ecosystem, a collective action problem that individual operators cannot solve unilaterally. The NCSC supply-chain guidance [76] and the EU Cyber Resilience Act [43] create some pressure in this direction for products sold into regulated markets, but the effectiveness of these instruments depends on enforcement mechanisms that are only beginning to be developed. For the ICS-specific firmware distribution gap, the challenge is compounded by the multi-jurisdiction structure of hardware manufacturing: a programmable logic controller sold in Europe may contain a microcontroller fabricated in Taiwan using intellectual property designed in Germany and firmware written in the United States, assembled in Mexico, and distributed through a Dutch intermediary. Each handoff in this chain is a potential attestation break point, and no cross-jurisdiction legal framework currently establishes the mutual recognition of attestation evidence that would be required for end-to-end provenance across such a chain. An emerging extension of SBOM thinking that lies at the boundary of the scope of this review concerns AI Bills of Materials (AIBOMs). As AI and machine learning components are increasingly embedded in CPS environments—for anomaly detection, predictive maintenance, and adaptive control—the supply-chain attack surface expands to include model weights, training datasets, and inference pipelines. The OWASP AIBOM initiative and the transparency and documentation obligations introduced by the EU AI Act [43] create obligations to disclose the provenance of AI components in high-risk systems, a category that encompasses many critical infrastructure applications. The attack patterns documented in the 2020–2026 literature (A10, A11) do not yet include AI-specific supply-chain attacks, reflecting the recency of AI component adoption in operational CPS environments; however, the same attestation gap that affects traditional software and firmware supply chains applies with equal force to AI supply chains. Systematic coverage of AIBOMs is left to future work that falls outside the 2020–2026 primary literature reviewed here, but the governance frameworks emerging from the EU AI Act and OWASP AIBOM will need to be integrated with CPS-specific supply-chain security requirements as AI adoption in operational technology matures.

10.3. Zero-Trust Architecture Compatible with Safety-Critical Real-Time Systems

The CISA 2026 ZT-OT guidance explicitly states that applying IT-focused ZTA wholesale to OT is infeasible [18], confirming what Syed et al. [15] established in the academic literature: the fundamental barriers of latency incompatibility and safety conflict remain unresolved. Closing this gap requires architectures that satisfy zero-trust security properties—continuous verification, least privilege, microsegmentation—while meeting the deterministic timing requirements of industrial control protocols (IEC 61784 [88], PROFINET [89], EtherNet/IP [90]) and the fail-safe requirements of functional safety standards (IEC 61508 [91]). A complete architecture satisfying all three constraint sets simultaneously has not been demonstrated, even in simulation. Standardised evaluation criteria that specify what constitutes satisfactory performance across security, timing, and safety dimensions are a prerequisite for systematic research progress, and their development requires collaboration between the control engineering, cybersecurity, and safety engineering communities.
The three constraint sets that a CPS-compatible ZTA must satisfy simultaneously—security, timing, and safety—are individually well-understood but have not been jointly formalised in the literature. Security requirements for ZTA are specified in NIST SP 800-207 [14] and operationalised in enterprise deployments. Timing requirements for industrial control systems are specified in IEC 61784 and protocol-specific standards; typical control loop frequencies of 10–100 Hz imply maximum admissible authentication latencies of 10–100 ms for full-loop participation and lower still for safety-critical paths. Safety requirements are specified in IEC 61508, which establishes functional safety integrity levels (SIL 1–4) corresponding to the probability of dangerous failure per hour thresholds; modifications to safety-related systems require re-evaluation of the SIL, creating a formal barrier to adding authentication logic to safety-critical control paths. A research programme that could advance this challenge would need to: formalise the tradeoff space among these three constraint sets with quantitative models; identify the Pareto-optimal architectures in that space; and demonstrate at least one architecture on a hardware-in-the-loop testbed with realistic process dynamics and a formal safety analysis. Feng and Hu [20] have made progress on the first objective in simulation; the second and third objectives remain open.

10.4. Quantitative Cyber–Physical Resilience Metrics

Segovia-Ferreira et al. [54] found that none of the 73 reviewed cyber-resilience proposals for CPSs provides metrics measurable from operational data under real incident conditions. The required framework must capture four properties absent from existing IT-centric and organisational resilience standards: physical process stability under attack (the degree to which the process remains within safe operating bounds throughout an incident); safety threshold proximity (the minimum margin to safety limits reached during the incident); cascading failure containment (the fraction of interconnected subsystems drawn into disruption from a locally initiated fault); and recovery integrity (whether restored operation reflects genuine physical process validity rather than superficial service availability). Linkov et al. [45,46] provide theoretical foundations on which such metrics could be built; translating those foundations into quantities measurable from ICS historian data requires structured engagement between control engineers, safety specialists, cybersecurity researchers, and sector regulators; digital twin platforms have been proposed as a simulation medium for resilience evaluation and metric testing [92,93]—a multi-disciplinary process that has not yet been formally organised for the CPS domain.
A workable CPS resilience metric framework would need to satisfy four properties that existing frameworks do not jointly provide. Measurability: each metric must be computable from data available in operational ICS historian and SCADA systems without requiring special-purpose instrumentation or simulation. Specificity: the metrics must distinguish cyber-induced process deviations from equipment faults and operational anomalies, because the resilience implications of these event types differ. Actionability: the metrics must map onto specific defensive investments such that an operator can infer, from a resilience metric deficit, what D6 investments would improve the metric. Regulatability: the metrics must be expressible in a form that a regulator can mandate and audit. Sterbenz et al. [86] and Linkov et al. [45,46,84] provide partial contributions—network resilience metrics and general complex-system resilience theory respectively—but neither addresses the physical process stability and safety threshold proximity properties that distinguish CPS resilience from IT resilience. Digital twin platforms [92,93] offer a simulation medium for testing candidate metrics against controlled attack scenarios, which could accelerate the empirical validation phase of metric development if representative twin fidelity can be achieved.

10.5. Research Design for CPS Incident Response Frameworks

The absence of CPS-specific incident response frameworks is itself a research problem: the empirical data needed to design such frameworks is inaccessible under current institutional arrangements, and resolving this access barrier requires a research programme as much as a policy decision. Nurse et al. [82] found that most CPS operators use IT-derived incident response frameworks with no CPS-specific adaptation. The framework required for CPS environments differs in three respects: it must integrate cybersecurity response with physical process control decisions through a jointly designed protocol rather than sequential handoff; it must provide escalation criteria calibrated to physical risk indicators rather than purely cyber-forensic metrics; and it must specify coordination protocols for IT teams, control engineers, safety officers, and adjacent infrastructure operators. The CISA 2026 ZT-OT guidance [18] identified the IT–OT coordination gap as a primary barrier to effective incident management, and the Dragos 2026 Report [10] documents that adversarial groups explicitly exploit its absence. The mandatory incident reporting obligations introduced by NIS2 [16] create a potential empirical foundation for framework development: anonymised incident data collected under those obligations could support the systematic analysis of CPS incident response decisions and consequences that the academic literature currently lacks.
The empirical deficit in CPS incident response research reflects a fundamental data access problem. Incident data from operational CPS environments is commercially sensitive, legally regulated, and often classified in critical infrastructure sectors; operators have strong disincentives to disclose incident details beyond the minimum required by reporting obligations. The mandatory reporting regime introduced by NIS2 [16] creates structured incident reports flowing to national Computer Security Incident Response Teams (CSIRTs) and ultimately to ENISA, but the technical specificity of these reports—what exactly was compromised, what physical process state was affected, what response actions were taken and with what effect—is not currently standardised at a level that would support the kind of response effectiveness research required to develop evidence-based CPS playbooks. Research partnerships between academic security researchers and national CSIRTs, modelled on the structured access programmes used for intelligence analysis in some jurisdictions, would provide the data foundation needed for this research without requiring public disclosure of sensitive incident details. Settanni et al. [83] propose technical infrastructure for sharing threat intelligence across organisations in a controlled manner; extending their approach to incident response data, with the appropriate legal frameworks for controlled access, represents a tractable institutional innovation that could unlock this research agenda.

11. Discussion and Limitations

The defence-gap matrix synthesises the thematic review into a cross-cutting map of where the 2020–2026 literature has concentrated defensive investment relative to the documented threat landscape. Three structural patterns are worth drawing out before the limitations are addressed. First, the uncovered mechanisms concentrate at the cyber–physical boundary (L5: A12, A13, A14) and in supply-chain channels (L4: A10, A11). This reflects a disciplinary asymmetry. The detection and provenance problems these mechanisms pose are inherently interdisciplinary, combining process control theory, cryptography and governance, whereas the bulk of the reviewed literature comes from single-discipline research programmes. Second, the adversarial robustness problem (adversarial ML evasion) is transversal—it degrades the primary defensive investment of the post-2020 period—but the literature addresses it as a research curiosity rather than an engineering requirement. Third, several gaps are governance-created: technically available defences are absent from operational deployments not because the technology fails but because the institutional conditions for deployment (identity–authority models, attestation obligations, resilience metrics) have not been established. Some gaps identified as research challenges could therefore be resolved by governance action rather than by additional technical research.
This review has four substantive limitations that bear on the interpretation of the defence-gap matrix and the research challenges derived from it, in addition to two methodological limitations stated earlier: the incomplete recording of the search protocol (Section 2) and the absence of a quantified inter-coder agreement statistic for the taxonomy codes (Section 3).
A third, the traceability of the individual matrix ratings, is addressed by the cell-level evidence given in Table 13, subject to the two qualifications stated in Section 9. First, the literature selection is necessarily incomplete: the search protocol retrieved papers available in the four databases searched, which overrepresents English-language publications and underrepresents the practitioner literature from national security agencies and sector-specific bodies that do not publish in indexed academic venues. Second, the defence-gap matrix reflects the state of published evidence as of April 2026; classified research programmes and proprietary defensive deployments that have not been publicly documented are not represented, and some gaps may have been closed by approaches not yet available in the open literature. Third, the governance analysis draws on a limited set of regulatory frameworks applicable to the EU and North America; governance structures for critical infrastructure cybersecurity differ substantially across jurisdictions, and the G-dimension gaps may be more or less severe depending on the regulatory environment of the operator. Fourth, the quantitative synthesis in Section 5 is limited to five primary studies on two benchmark datasets; performance on these benchmarks may not generalise to other process types, attack distributions, or environmental conditions. Future reviews should extend the scope in four directions: to non-English literature; to proprietary evaluation results, where these become available under disclosure agreements; to additional regulatory jurisdictions; and to the expanding set of publicly available ICS security benchmarks, including HAI [56] and the power system datasets emerging from NERC CIP compliance testing programmes.

12. Conclusions

This paper has reviewed 82 sources on CPS and critical infrastructure security (70 from the primary review window of January 2020 to April 2026, and 12 supplementary foundational pre-2020 works), applying the CPS Defence-Gap Taxonomy as the organising analytical framework. The review yields three findings that warrant direct statement.
The defence-gap matrix exposes a systematic asymmetry between defensive investment and adversarial consequence. In the five studies reviewed, each evaluated under its own experimental conditions, ML-based detection reports F1 scores between 0.796 and 0.969 against attacks that produce detectable cyber-layer anomalies; these figures are not directly comparable across studies and are reported descriptively rather than as a ranking. Within the reviewed corpus, the same body of work provides minimal or no demonstrated coverage against the mechanisms associated with the most severe documented outcomes: false data injection and safety system bypass at the cyber–physical boundary (L5), firmware backdoors and build pipeline compromise in supply-chain channels (L4), and adversarial evasion of the detection systems themselves. The dominant defensive investment of the post-2020 period has been directed precisely at the category of attacks for which coverage already exists.
The adversarial robustness problem is not a theoretical curiosity. A measured F1 reduction of 37.4 percentage points in absolute terms, corresponding to a relative reduction of 38.6%, documented under adversarial conditions for the 1D-CNN architecture [58], with Apruzzese et al. [70] finding systematic evasion across multiple architectures without quantified per-architecture figures, represents a failure mode that well-resourced adversaries will identify and exploit systematically. Within the reviewed corpus, no approach provides certified robustness against model-aware adversaries, and the performance improvements documented in standard evaluation do not translate into meaningful security guarantees against adversaries who have had the opportunity to study the deployed system.
Several of the identified gaps are governance-created. Zero-trust architectures capable of containing L2 identity-exploitation attacks exist technically but are not deployed in OT environments because the identity–authority governance models required for policy specification have not been developed (G3 gap). Supply-chain provenance mechanisms exist but leave systematic attestation gaps because multi-party attestation obligations are not contractually required across the supply chain (G2 gap). Resilience engineering investments cannot be justified, specified, or regulated because the quantitative metrics needed to verify their effectiveness do not exist (G5 gap). Closing these gaps requires action that spans technical research, governance reform, and standards development, and the escalating adversarial capability documented in the 2026 threat intelligence provides the context for why that action is urgent.

Author Contributions

Conceptualisation, P.G.U. and V.M.; methodology, P.G.U. and V.M.; investigation, P.G.U. and V.M.; writing—original draft preparation, P.G.U.; writing—review and editing, V.M.; visualisation, P.G.U.; supervision, V.M. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

No new experimental data were created in this study. The review does, however, generate reproducibility material: the codebook (Table 2), the operational definitions of the governance dimensions (Table 4), and the cell-level evidence mapping for all 84 matrix cells (Table 13). These are provided in full within the manuscript, and the cell-level evidence mapping is additionally available as a spreadsheet from the corresponding author on request. The benchmark datasets discussed are publicly available research datasets: SWaT and BATADAL are distributed by iTrust, Centre for Research in Cyber Security, Singapore University of Technology and Design (https://itrust.sutd.edu.sg/itrust-labs_datasets/, accessed on 16 August 2026); the BATADAL competition data are also available at https://www.batadal.net/data.html (accessed on 16 August 2026); and the HAI dataset is available at https://github.com/icsdataset/hai (accessed on 16 August 2026).

Acknowledgments

During the preparation of this manuscript, the authors used Claude (Anthropic PBC, San Francisco, CA, USA; Opus model family, accessed via https://claude.ai) for the purposes of figure and table preparation from author-supplied data, restatement of two published mathematical results, and assistance with the supplementary literature search and taxonomy-independent check described in Section 2 and Section 3. Section Use of Generative AI Tools gives the details. The authors have reviewed and edited the output and take full responsibility for the content of this publication.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Humayed, A.; Lin, J.; Li, F.; Luo, B. Cyber-physical systems security—A survey. IEEE Internet Things J. 2017, 4, 1802–1831. [Google Scholar] [CrossRef] [Scilit]
  2. Pasqualetti, F.; Dörfler, F.; Bullo, F. Attack detection and identification in cyber-physical systems. IEEE Trans. Autom. Control 2013, 58, 2715–2729. [Google Scholar] [CrossRef] [Scilit]
  3. Lee, R.M.; Assante, M.J.; Conway, T. ICS CP/PE (Cyber-to-Physical or Process Effects) Case Study Paper: German Steel Mill Cyber Attack; SANS ICS: Bethesda, MD, USA, 2014; Available online: https://www.sans.org/reading-room/whitepapers/ICS/german-steel-mill-cyber-attack-36157 (accessed on 16 August 2026).
  4. Cybersecurity and Infrastructure Security Agency (CISA); FBI. DarkSide Ransomware: Best Practices; Alert AA21-131A; CISA: Arlington, VA, USA, 2021. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a (accessed on 16 August 2026).
  5. Liang, G.; Weller, S.R.; Zhao, J.; Luo, F.; Dong, Z.Y. The 2015 Ukraine blackout: Implications for false data injection attacks. IEEE Trans. Power Syst. 2017, 32, 3317–3318. [Google Scholar] [CrossRef] [Scilit]
  6. Cherepanov, A. WIN32/Industroyer: A New Threat for Industrial Control Systems; ESET: Bratislava, Slovakia, 2017; Available online: https://www.welivesecurity.com/wp-content/uploads/2017/06/Win32_Industroyer.pdf (accessed on 16 August 2026).
  7. Dragos Inc. TRISIS Malware: Analysis of Safety System Targeted Malware; Dragos: Hanover, MD, USA, 2017; Available online: https://www.dragos.com/resources/whitepaper/trisis-analyzing-safety-system-targeting-malware/ (accessed on 16 August 2026).
  8. Salazar, L.; Castro, S.R.; Lozano, J.; Koneru, K.; Zambon, E.; Huang, B.; Baldick, R.; Krotofil, M.; Rojas, A.; Cardenas, A.A. A tale of two industroyers: It was the season of darkness. In Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 19–23 May 2024; pp. 312–330. [Google Scholar] [CrossRef] [Scilit]
  9. Kumar, R.; Kela, R.; Singh, S.; Trujillo-Rasua, R. APT attacks on industrial control systems: A tale of three incidents. Int. J. Crit. Infrastruct. Prot. 2022, 37, 100521. [Google Scholar] [CrossRef] [Scilit]
  10. Dragos Inc. Dragos 2026 OT/ICS Cybersecurity Year in Review; Dragos: Hanover, MD, USA, 2026; Available online: https://www.dragos.com/ot-cybersecurity-year-in-review (accessed on 16 August 2026).
  11. Giraldo, J.; Urbina, D.; Cardenas, A.; Valente, J.; Faisal, M.; Ruths, J.; Tippenhauer, N.O.; Sandberg, H.; Candell, R. A survey of physics-based attack detection in cyber-physical systems. ACM Comput. Surv. 2018, 51, 76. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  12. Goh, J.; Adepu, S.; Junejo, K.N.; Mathur, A. A dataset to support research in the design of secure water treatment systems. In Proceedings of the 11th International Conference on Critical Information Infrastructures Security (CRITIS 2016), Paris, France, 10–12 October 2016; pp. 88–99. [Google Scholar] [CrossRef] [Scilit]
  13. Taormina, R.; Galelli, S.; Tippenhauer, N.O.; Salomons, E.; Ostfeld, A.; Eliades, D.G.; Aghashahi, M.; Sundararajan, R.; Pourahmadi, M.; Banks, M.K.; et al. The battle of the attack detection algorithms. J. Water Resour. Plan. Manag. 2018, 144, 04018048. [Google Scholar] [CrossRef] [Scilit]
  14. Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. NIST SP 800-207; Zero Trust Architecture. NIST: Gaithersburg, MD, USA, 2020. [CrossRef] [Scilit]
  15. Syed, N.F.; Shah, S.W.; Shaghaghi, A.; Anwar, A.; Baig, Z.; Doss, R. Zero trust architecture (ZTA): A comprehensive survey. IEEE Access 2022, 10, 57143–57179. [Google Scholar] [CrossRef] [Scilit]
  16. European Parliament; Council of the EU. Directive (EU) 2022/2555 (NIS2 Directive). Off. J. Eur. Union 2022, L 333, 80–152. Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555 (accessed on 16 August 2026).
  17. National Institute of Standards and Technology. NIST Cybersecurity Framework 2.0; NIST: Gaithersburg, MD, USA, 2024. Available online: https://www.nist.gov/cyberframework (accessed on 16 August 2026).
  18. Cybersecurity and Infrastructure Security Agency (CISA); Department of War; Department of Energy; FBI; Department of State. Adapting Zero Trust Principles to Operational Technology; CISA: Washington, DC, USA, 2026. Available online: https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology (accessed on 30 April 2026).
  19. Iturbe, M.; Garitano, I.; Zurutuza, U.; Uribeetxeberria, R. Towards large-scale heterogeneous anomaly detection in industrial networks: A survey. Secur. Commun. Netw. 2017, 2017, 9150965. [Google Scholar] [CrossRef] [Scilit]
  20. Feng, X.; Hu, S. Cyber-physical zero trust architecture for industrial CPS. IEEE Trans. Ind. Cyber-Phys. Syst. 2023, 1, 394–405. [Google Scholar] [CrossRef] [Scilit]
  21. ISA/IEC 62443; ISA/IEC 62443 Series: Security for Industrial Automation and Control Systems. ISA: Research Triangle Park, NC, USA; IEC: Geneva, Switzerland, 2018. Available online: https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards (accessed on 16 August 2026).
  22. Kus, D.; Wagner, E.; Pennekamp, J.; Wolsing, K.; Fink, I.B.; Dahlmanns, M.; Wehrle, K.; Henze, M. A false sense of security? Revisiting the state of machine learning-based industrial intrusion detection. In Proceedings of the 8th ACM Cyber-Physical System Security Workshop (CPSS 2022), Nagasaki, Japan, 30 May 2022; pp. 73–84. [Google Scholar] [CrossRef] [Scilit]
  23. Lamberts, O.; Wolsing, K.; Wagner, E.; Pennekamp, J.; Bauer, J.; Wehrle, K.; Henze, M. [SoK] Evaluations in industrial intrusion detection research. J. Syst. Res. 2023, 3, 1–27. [Google Scholar] [CrossRef] [Scilit]
  24. Ike, M.; Phan, K.; Sadoski, K.; Valme, R.; Lee, W. SCAPHY: Detecting modern ICS attacks by correlating behaviors in SCADA and physical. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 21–25 May 2023; pp. 20–37. [Google Scholar] [CrossRef] [Scilit]
  25. Kim, S.; Park, J. AI-based anomaly detection in industrial control and cyber–physical systems: A data-type-oriented systematic review. Electronics 2025, 15, 20. [Google Scholar] [CrossRef] [Scilit]
  26. Huang, K.; Siegel, M.; Madnick, S. Systematically understanding the cyber attack business: A survey. ACM Comput. Surv. 2018, 51, 70. [Google Scholar] [CrossRef] [Scilit]
  27. Salahdine, F.; Kaabouch, N. Social engineering attacks: A survey. Future Internet 2019, 11, 89. [Google Scholar] [CrossRef] [Scilit]
  28. Mirsky, Y.; Lee, W. The creation and detection of deepfakes: A survey. ACM Comput. Surv. 2021, 54, 7. [Google Scholar] [CrossRef] [Scilit]
  29. Homoliak, I.; Toffalini, F.; Guarnizo, J.; Elovici, Y.; Ochoa, M. Insight into insiders and IT: A survey on insider threat. ACM Comput. Surv. 2019, 52, 30. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  30. Skopik, F.; Settanni, G.; Fiedler, R. A problem shared is a problem halved: A survey on collective cyber defence. Comput. Secur. 2016, 60, 154–176. [Google Scholar] [CrossRef] [Scilit]
  31. Cheminod, M.; Durante, L.; Valenzano, A. Review of security issues in industrial networks. IEEE Trans. Ind. Inform. 2013, 9, 277–293. [Google Scholar] [CrossRef] [Scilit]
  32. Nicholson, A.; Webber, S.; Dyer, S.; Patel, T.; Janicke, H. SCADA security in the light of cyber-warfare. Comput. Secur. 2012, 31, 418–436. [Google Scholar] [CrossRef] [Scilit]
  33. Urbina, D.; Giraldo, J.; Cardenas, A.A.; Tippenhauer, N.O.; Valente, J.; Faisal, M.; Ruths, J.; Candell, R.; Sandberg, H. Limiting the impact of stealthy attacks on industrial control systems. In Proceedings of the ACM CCS 2016, Vienna, Austria, 24–28 October 2016; pp. 1092–1105. [Google Scholar] [CrossRef] [Scilit]
  34. Langner, R. Stuxnet: Dissecting a cyberweapon. IEEE Secur. Priv. 2011, 9, 49–51. [Google Scholar] [CrossRef] [Scilit]
  35. Stouffer, K.; Pease, M.; Tang, C.; Zimmerman, T.; Pillitteri, V.; Lightman, S.; Hahn, A.; Saravia, S.; Sherule, A.; Thompson, M. NIST SP 800-82r3; Guide to Operational Technology (OT) Security. NIST: Gaithersburg, MD, USA, 2023. [CrossRef] [Scilit]
  36. Colbert, E.J.M.; Kott, A. Cyber-Security of SCADA and Other Industrial Control Systems; Springer: Cham, Switzerland, 2016. [Google Scholar] [CrossRef] [Scilit]
  37. Ohm, M.; Plate, H.; Sykosch, A.; Meier, M. Backstabber’s knife collection: A review of open-source software supply-chain attacks. In Proceedings of the DIMVA 2020, Lisbon, Portugal, 24–26 June 2020; pp. 23–43. [Google Scholar] [CrossRef] [Scilit]
  38. Koishybayev, I.; Nahapetyan, A.; Zachariah, R.; Muralee, S.; Reaves, B.; Kapravelos, A.; Machiry, A. Characterizing the security of GitHub CI workflows. In Proceedings of the 31st USENIX Security Symposium, Boston, MA, USA, 10–12 August 2022; pp. 2747–2763. Available online: https://www.usenix.org/conference/usenixsecurity22/presentation/koishybayev (accessed on 16 August 2026).
  39. Costin, A.; Zaddach, J.; Francillon, A.; Balzarotti, D. A large-scale analysis of the security of embedded firmwares. In Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA, 20–22 August 2014; Available online: https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/costin (accessed on 16 August 2026).
  40. Muench, M.; Stijohann, J.; Kargl, F.; Francillon, A.; Balzarotti, D. What you corrupt is not what you crash: Challenges in fuzzing embedded devices. In Proceedings of the 25th Network and Distributed System Security Symposium (NDSS 2018), San Diego, CA, USA, 18–21 February 2018; Available online: https://www.ndss-symposium.org/wp-content/uploads/2018/02/ndss2018_01A-4_Muench_paper.pdf (accessed on 16 August 2026). [CrossRef] [Scilit]
  41. Liu, Y.; Ning, P.; Reiter, M.K. False data injection attacks against state estimation in electric power grids. In Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), Chicago, IL, USA, 9–13 November 2009; pp. 21–32. [Google Scholar] [CrossRef] [Scilit]
  42. Enoch, S.Y.; Huang, Z.; Moon, C.Y.; Lee, D.H.; Ahn, M.K.; Kim, D.S. HARMer: Cyber-attacks automation and evaluation. IEEE Access 2020, 8, 129397–129414. [Google Scholar] [CrossRef] [Scilit]
  43. European Parliament; Council of the EU. Regulation (EU) 2024/2847 on Horizontal Cybersecurity Requirements for Products with Digital Elements (Cyber Resilience Act). Off. J. Eur. Union 2024, L 2024/2847. Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847 (accessed on 16 August 2026).
  44. ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization (ISO): Geneva, Switzerland, 2022. Available online: https://www.iso.org/standard/27001 (accessed on 16 August 2026).
  45. Linkov, I.; Eisenberg, D.A.; Plourde, K.; Seager, T.P.; Allen, J.; Kott, A. Resilience metrics for cyber systems. Environ. Syst. Decis. 2013, 33, 471–476. [Google Scholar] [CrossRef] [Scilit]
  46. Linkov, I.; Eisenberg, D.A.; Bates, M.E.; Chang, D.; Convertino, M.; Allen, J.H.; Flynn, S.E.; Seager, T.P. Measurable resilience for actionable policy. Environ. Sci. Technol. 2013, 47, 10108–10110. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  47. Conti, M.; Donadel, D.; Turrin, F. A survey on ICS testbeds and datasets for security research. IEEE Commun. Surv. Tutor. 2021, 23, 2248–2294. [Google Scholar] [CrossRef] [Scilit]
  48. Adepu, S.; Mathur, A. Distributed detection of single-stage multipoint cyber attacks in a water treatment plant. In Proceedings of the 11th ACM Asia Conference on Computer and Communications Security (ASIACCS 2016), Xi’an, China, 30 May–3 June 2016; pp. 449–460. [Google Scholar] [CrossRef] [Scilit]
  49. Adepu, S.; Mathur, A. Assessing the effectiveness of attack detection at a hackfest on industrial control systems. IEEE Trans. Sustain. Comput. 2019, 6, 231–244. [Google Scholar] [CrossRef] [Scilit]
  50. European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2023; ENISA: Athens, Greece, 2023; Available online: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023 (accessed on 16 August 2026).
  51. European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025; ENISA: Athens, Greece, 2025; Available online: https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf (accessed on 16 August 2026).
  52. World Economic Forum. Global Cybersecurity Outlook 2025; WEF: Geneva, Switzerland, 2025; Available online: https://www.weforum.org/publications/global-cybersecurity-outlook-2025 (accessed on 16 August 2026).
  53. World Economic Forum; Accenture. Global Cybersecurity Outlook 2026; WEF: Geneva, Switzerland, 2026; Available online: https://www.weforum.org/publications/global-cybersecurity-outlook-2026/ (accessed on 16 August 2026).
  54. Segovia-Ferreira, M.; Rubio-Hernan, J.; Cavalli, A.R.; Garcia-Alfaro, J. A survey on cyber-resilience approaches for cyber-physical systems. ACM Comput. Surv. 2024, 56, 202. [Google Scholar] [CrossRef] [Scilit]
  55. Lindsay, J.R. Stuxnet and the limits of cyber warfare. Secur. Stud. 2013, 22, 365–404. [Google Scholar] [CrossRef] [Scilit]
  56. Shin, H.-K.; Lee, W.; Yun, J.-H.; Min, B.G. Two ICS security datasets and anomaly detection contest on the HIL-based augmented ICS testbed. In Proceedings of the 14th USENIX Workshop on Cyber Security Experimentation and Test (CSET 2021), Virtual, CA, USA, 9 August 2021; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
  57. Cartwright, E.; Hernandez Castro, J.; Cartwright, A. To pay or not: Game theoretic models of ransomware. J. Cybersecur. 2019, 5, tyz009. [Google Scholar] [CrossRef] [Scilit]
  58. Erba, A.; Taormina, R.; Galelli, S.; Pogliani, M.; Carminati, M.; Zanero, S.; Tippenhauer, N.O. Constrained concealment attacks against reconstruction-based anomaly detectors in industrial control systems. In Proceedings of the Annual Computer Security Applications Conference (ACSAC 2020), Austin, TX, USA, 7–11 December 2020; pp. 480–494. [Google Scholar] [CrossRef] [Scilit]
  59. Rid, T.; Buchanan, B. Attributing cyber attacks. J. Strateg. Stud. 2015, 38, 4–37. [Google Scholar] [CrossRef] [Scilit]
  60. Lin, Q.; Adepu, S.; Verwer, S.; Mathur, A. TABOR: A graphical model-based approach for anomaly detection in industrial control systems. In Proceedings of the 13th ACM Asia Conference on Computer and Communications Security (ASIACCS 2018), Incheon, Republic of Korea, 4–8 June 2018; pp. 525–536. [Google Scholar] [CrossRef] [Scilit]
  61. Taormina, R.; Galelli, S. Deep-learning approach to the detection and localisation of cyber-physical attacks on water distribution systems. J. Water Resour. Plan. Manag. 2018, 144, 04018065. [Google Scholar] [CrossRef] [Scilit]
  62. Kravchik, M.; Shabtai, A. Efficient cyber attack detection in ICS using lightweight neural networks and PCA. IEEE Trans. Dependable Secur. Comput. 2022, 19, 2179–2197. [Google Scholar] [CrossRef] [Scilit]
  63. Goh, J.; Adepu, S.; Tan, M.; Lee, Z.S. Anomaly detection in cyber physical systems using recurrent neural networks. In Proceedings of the 18th IEEE International Symposium on High Assurance Systems Engineering (HASE 2017), Singapore, 12–14 January 2017; pp. 140–145. [Google Scholar] [CrossRef] [Scilit]
  64. He, Y.; Mendis, G.J.; Wei, J. Real-time detection of false data injection attacks in smart grid using a deep learning architecture. IEEE Trans. Smart Grid 2017, 8, 2505–2516. [Google Scholar] [CrossRef] [Scilit]
  65. Wolsing, K.; Wagner, E.; Saillard, A.; Henze, M. IPAL: Breaking up silos of protocol-dependent and domain-specific industrial intrusion detection systems. In Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2022), Limassol, Cyprus, 26–28 October 2022; pp. 1–16. [Google Scholar] [CrossRef] [Scilit]
  66. Shin, H.-K.; Lee, W.; Yun, J.-H.; Kim, H. HAI 1.0: HIL-based augmented ICS security dataset. In Proceedings of the 13th USENIX Workshop on Cyber Security Experimentation and Test (CSET 2020), Boston, MA, USA, 10 August 2020; Available online: https://www.usenix.org/conference/cset20/presentation/shin (accessed on 16 August 2026).
  67. Junejo, K.N.; Goh, J. Behaviour-based attack detection and classification in cyber physical systems using machine learning. In Proceedings of the 2nd ACM Cyber-Physical System Security Workshop (CPSS 2016), Xi’an, China, 30 May 2016; pp. 34–43. [Google Scholar] [CrossRef] [Scilit]
  68. Raissi, M.; Perdikaris, P.; Karniadakis, G.E. Physics-informed neural networks. J. Comput. Phys. 2019, 378, 686–707. [Google Scholar] [CrossRef] [Scilit]
  69. Ahmed, C.M.; Zhou, J.; Mathur, A.P. Noise matters: Using sensor and process noise fingerprint to detect stealthy cyber attacks and authenticate sensors in CPS. In Proceedings of the 34th Annual Computer Security Applications Conference (ACSAC 2018), San Juan, PR, USA, 3–7 December 2018; pp. 566–581. [Google Scholar] [CrossRef] [Scilit]
  70. Biggio, B.; Roli, F. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognit. 2018, 84, 317–331. [Google Scholar] [CrossRef] [Scilit]
  71. Apruzzese, G.; Colajanni, M.; Ferretti, L.; Guido, A.; Marchetti, M. On the effectiveness of machine and deep learning for cyber security. In Proceedings of the 10th NATO CyCon, Tallinn, Estonia, 29 May–1 June 2018; pp. 371–390. [Google Scholar] [CrossRef] [Scilit]
  72. Liang, Y.; Samtani, S.; Guo, B.; Yu, Z. Behavioral biometrics for continuous authentication in the IoT era. IEEE Internet Things J. 2020, 7, 9128–9143. [Google Scholar] [CrossRef] [Scilit]
  73. Ladisa, P.; Plate, H.; Martinez, M.; Barais, O. SoK: Taxonomy of attacks on open-source software supply chains. In Proceedings of the 44th IEEE Symposium on Security and Privacy (IEEE S&P 2023), San Francisco, CA, USA, 21–25 May 2023; pp. 1509–1526. [Google Scholar] [CrossRef] [Scilit]
  74. Birsan, A. Dependency Confusion: How I Hacked Apple, Microsoft and Dozens of Other Companies. Medium. 2021. Available online: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610 (accessed on 16 August 2026).
  75. Torres-Arias, S.; Afzali, H.; Kuppusamy, T.K.; Curtmola, R.; Cappos, J. In-toto: Providing farm-to-table guarantees for bits and bytes. In Proceedings of the 28th USENIX Security Symposium, Santa Clara, CA, USA, 14–16 August 2019; pp. 1393–1410. Available online: https://www.usenix.org/conference/usenixsecurity19/presentation/torres-arias (accessed on 16 August 2026).
  76. National Cyber Security Centre (NCSC). Supply Chain Security Guidance; NCSC: London, UK, 2022. Available online: https://www.ncsc.gov.uk/collection/supply-chain-security (accessed on 16 August 2026).
  77. Pashchenko, I.; Plate, H.; Ponta, S.E.; Sabetta, A.; Massacci, F. Vulnerable open source dependencies: Counting those that matter. In Proceedings of the 12th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM 2018), Oulu, Finland, 11–12 October 2018. [Google Scholar] [CrossRef] [Scilit]
  78. Maes, R. Physically Unclonable Functions: Constructions, Properties and Applications; Springer: Berlin/Heidelberg, Germany, 2013; Available online: https://link.springer.com/book/10.1007/978-3-642-41395-7 (accessed on 16 August 2026). [CrossRef] [Scilit]
  79. CIP-002 to CIP-014; Critical Infrastructure Protection Reliability Standards. North American Electric Reliability Corporation (NERC): Atlanta, GA, USA, 2024.
  80. IEC 62351; Power Systems Management and Associated Information Exchange—Data and Communications Security. International Electrotechnical Commission (IEC): Geneva, Switzerland, 2020.
  81. Carr, M. Public-private partnerships in national cyber-security strategies. Int. Aff. 2016, 92, 43–62. [Google Scholar] [CrossRef] [Scilit]
  82. Nurse, J.R.C.; Creese, S.; De Roure, D. Security risk assessment in IoT systems. IT Prof. 2017, 19, 20–26. [Google Scholar] [CrossRef] [Scilit]
  83. Settanni, G.; Shovgenya, Y.; Skopik, F.; Graf, R.; Wurzenberger, M.; Fiedler, R. Acquiring cyber threat intelligence through security information correlation. In Proceedings of the 3rd IEEE International Conference on Cybernetics (CYBCONF 2017), Exeter, UK, 21–23 June 2017; pp. 1–7. [Google Scholar] [CrossRef] [Scilit]
  84. Linkov, I.; Bridges, T.; Creutzig, F.; Decker, J.; Fox-Lent, C.; Kröger, W.; Lambert, J.H.; Levermann, A.; Montreuil, B.; Nathwani, J.; et al. Changing the resilience paradigm. Nat. Clim. Change 2014, 4, 407–409. [Google Scholar] [CrossRef] [Scilit]
  85. Kott, A.; Linkov, I. Cyber Resilience of Systems and Networks; Springer: Cham, Switzerland, 2019. [Google Scholar] [CrossRef] [Scilit]
  86. Sterbenz, J.P.G.; Hutchison, D.; Çetinkaya, E.K.; Jabbar, A.; Rohrer, J.P.; Schöller, M.; Smith, P. Resilience and survivability in communication networks: Strategies, principles, and survey. Comput. Netw. 2010, 54, 1245–1265. [Google Scholar] [CrossRef] [Scilit]
  87. Radanliev, P.; De Roure, D.; Van Kleek, M.; Santos, O.; Ani, U. Artificial intelligence in cyber physical systems. AI Soc. 2021, 36, 783–796. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  88. IEC 61784; Industrial Communication Networks—Profiles. International Electrotechnical Commission (IEC): Geneva, Switzerland, 2019.
  89. IEC 61158; Industrial Communication Networks—Fieldbus Specifications (PROFINET, Type 10). International Electrotechnical Commission (IEC): Geneva, Switzerland, 2019.
  90. ODVA. The EtherNet/IP Specification, Volume 1: Common Industrial Protocol (CIP); ODVA: Ann Arbor, MI, USA, 2023. [Google Scholar]
  91. IEC 61508; Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems. International Electrotechnical Commission (IEC): Geneva, Switzerland, 2010.
  92. Eckhart, M.; Ekelhart, A. Towards security-aware virtual environments for digital twins. In Proceedings of the 4th ACM Workshop on Cyber-Physical System Security (CPSS 2018), Incheon, Republic of Korea, 4–8 June 2018; pp. 61–72. [Google Scholar] [CrossRef] [Scilit]
  93. Eckhart, M.; Ekelhart, A. A specification-based state replication approach for digital twins. In Proceedings of the 4th ACM Workshop on Cyber-Physical System Security and Privacy (CPS-SPC 2018), Toronto, ON, Canada, 15–19 October 2018; pp. 36–47. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.