Cyber Security and Digital Forensics—3rd Edition

A Special Issue of Journal of Cybersecurity and Privacy (ISSN 2624-800X) belonging to the section "Security Engineering & Applications".

Deadline for manuscript submissions: 30 October 2026 | Viewed by 12808

Editors


E-Mail Website
Guest Editor
School of Technology and Management, Polytechnic of Leiria, 2411-901 Leiria, Portugal
Interests: cyber security; digital forensics; cyberawareness; information security; cyber situational awareness; computer networking security; machine learning
Special Issues, Collections and Topics in MDPI journals

E-Mail Website
Guest Editor
Computer Science Engineering Department, Superior School of Technology and Management, Polytechnic of Leiria, 2411-901 Leiria, Portugal
Interests: information and networks security; information security management systems; security incident response systems for Industry 4.0; next generation networks and services; wireless networks
Special Issues, Collections and Topics in MDPI journals

Special Issue Information

Dear Colleagues,

We are setting up the Special Issue on “Cyber Security and Digital Forensics—3rd Edition” in the Journal of Cybersecurity and Privacy, which aims to attract original, pertinent, and innovative contributions on a wide set of topics related to cybersecurity, information security, and digital forensics. Information security and cybersecurity play a key role in the management of organizations in general, as they deal with the confidentiality, privacy, integrity, and availability of one of their most valuable resources: data and information. When a cyberattack takes place in the enterprise information system, the analysis and collection of digital artifacts is crucial to understand the origins, motivations, and impact of the malicious activities. To deal with the amount of assets being protected and their high variety and heterogeneity, organizations have adopted a wide set of techniques, tools, and methodologies to implement cybersecurity and digital forensics processes. The quality of these techniques and tools may dictate the speed and efficiency of the security of the assets, the improvement of availability of IT infrastructure, and, consequently, business continuity. The Special Issue “Cyber Security and Digital Forensics—3rd Edition” welcomes articles (reviews, communications, original studies, technical reports, and case reports) that focus on the various topics that are under the cybersecurity and digital forensic umbrella.

Prof. Dr. Mario Antunes
Prof. Dr. Carlos Rabadão
Guest Editors

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Journal of Cybersecurity and Privacy is an international peer-reviewed open access semimonthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 1200 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • information security
  • cybersecurity auditing
  • cybersecurity and information security compliance
  • cybersecurity governance and regulations
  • cyber situational awareness
  • digital forensics for cybersecurity
  • digital forensics incident response
  • digital forensics automation

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Related Special Issues

Published Papers (12 papers)

Order results
Result details
Select all
Export citation of selected articles as:

Research

Jump to: Other

30 pages, 490 KB  
Article
Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework
by Victor Manuel González-Gorrín and Josep Prieto-Blázquez
J. Cybersecur. Priv. 2026, 6(5), 164; https://doi.org/10.3390/jcp6050164 - 17 Sep 2026
Viewed by 68
Abstract
Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We propose MetaGNN-Sec, a [...] Read more.
Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We propose MetaGNN-Sec, a graph-augmented neural framework that detects metamorphic malware from program structure rather than surface bytes. The framework composes four components, each addressing a distinct facet of the problem: (i) control-flow graph (CFG) extraction with semantic opcode embeddings; (ii) a heterogeneous graph neural network (hGNN) operating over program-dependence graphs that capture mutation-stable control- and data-flow invariants; (iii) an adversarial training loop derived from the Wasserstein generative adversarial network (WGAN) that hardens the classifier against adaptive evasion mutations; and (iv) a quantum-kernel anomaly layer implemented in PennyLane for separation of heavily obfuscated outliers in a high-dimensional feature space. Results: Experiments are conducted on two public corpora—VirusShare 2024 and a SOREL-20M subset—comprising 200,175 binary samples in total (155,175 malware and 45,000 benign), in agreement with the corpus totals reported in Datasets Section of this paper. MetaGNN-Sec achieves a detection rate of 97.83%, a false-positive rate of 0.41%, and an F1 score of 0.978 on held-out metamorphic families, exceeding the next-best baseline (MalConv+) by 4.6 percentage points on clean data and degrading by only 5.4 points under adaptive adversarial evasion (versus 17–31 points for the baselines). The quantum-kernel module contributes a further 1.2 pp reduction in false-negative rate, concentrated on the most heavily mutated families. Conclusions: The framework provides a heterogeneous PDG representation with a conditional score-shift bound under graph-edit-bounded mutations, a WGAN hardening loop that delivers measurable adversarial robustness, a quantum-kernel pre-filter with an explicit cost/benefit characterization, and a reproducible, near-real-time pipeline suitable for enterprise endpoint deployment. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

27 pages, 1644 KB  
Article
Risk-Driven Deployment and Forensic Readiness Framework for AI-Enabled Security Operations Centers
by Olga Torstensson, Dmytro Prokopovych-Tkachenko, Alona Desiatko, Zoriana Hbur and Igor Britchenko
J. Cybersecur. Priv. 2026, 6(5), 149; https://doi.org/10.3390/jcp6050149 - 1 Sep 2026
Viewed by 399
Abstract
Security Operations Centers increasingly use artificial intelligence to rank alerts, summarize evidence, and automate repetitive response actions. However, AI-enabled security operations can also create new risks for incident response and digital forensic reliability, including false-negative prioritization, model drift, hallucinated explanations, prompt injection, automation [...] Read more.
Security Operations Centers increasingly use artificial intelligence to rank alerts, summarize evidence, and automate repetitive response actions. However, AI-enabled security operations can also create new risks for incident response and digital forensic reliability, including false-negative prioritization, model drift, hallucinated explanations, prompt injection, automation bias, unsafe SOAR actions, and evidence contamination. This article proposes a risk-driven deployment and forensic readiness framework for AI-enabled Security Operations Centers. The framework combines Monte Carlo loss simulation, detector threshold analysis, analyst queueing, model-drift monitoring, and evidence-preserving governance controls. It explicitly separates evidence, recommendation, and action so that AI can accelerate triage while preserving source artifacts, provenance, audit trails, and chain-of-custody information needed for incident reconstruction. Illustrative simulation results show a mean annualized loss expectancy of USD 1.70 M, a 95% Value-at-Risk of USD 3.85 M and a 99% Value-at-Risk of USD 6.29 M, a detector ROC-AUC of 0.942 and PR-AUC of 0.750 with precision 0.719, recall 0.650 and F1 0.683 at the selected decision threshold of 1.873, a manual triage workload reduction of about 38%, and a reduction in mean time to respond (MTTR, defined throughout as mean time to respond rather than mean time to resolution) from about 44 to 26 min under controlled assumptions. The results are demonstration outputs rather than universal benchmarks. The main contribution is a reproducible governance method for deciding when AI reduces SOC risk, when it transfers risk, and when forensic readiness requires human approval, evidence preservation, or automation rollback. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

26 pages, 1561 KB  
Article
A Hardware-Software Complex for the Reconstruction of Unmanned Aerial Vehicle Digital Traces Under Logical Data Damage Using LSTM-Based Telemetry Recovery and Multi-Source Confidence Scoring
by Azamat Baibussinov, Madi Shayakhmetov, Leila Rzayeva and Kaisarbek Yesbergenov
J. Cybersecur. Priv. 2026, 6(4), 123; https://doi.org/10.3390/jcp6040123 - 13 Jul 2026
Viewed by 504
Abstract
(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and [...] Read more.
(1) Background: The digital traces of unmanned aerial vehicles (UAVs) are becoming increasingly important in criminal incidents, the violation of airspace and in military operations, thus making the reconstruction of the digital traces a critical task. But, current tools like DatCon, Autopsy and GRYPHON cannot recover telemetry when the flight logs are logically damaged, fragmented or partially deleted and don’t offer any quantitative measurement of the confidence of the recovered information. (2) Methods: A unified hardware-software complex, including a forensic workstation, a hardware write-blocker and SD/microSD/eMMC adapters; a set of software modules for extracting artifacts from files, structural parsing of DAT/BIN/CSV log, neural network reconstruction of missing telemetry using a two-layer LSTM architecture; a multi-source correlation module that combines flight logs, telemetry, media metadata and controller artifacts; a module, Confidence Score (CS), that computes a reliability measure in [0,1]; and a visualization module to generate a reconstructed trajectory on an electronic map. (3) Results: The complex has been tested on 105 flights on 10 different UAVs, 492 flight logs were gathered, 10,435 were the media item files and 624 GB was the amount of storage during acquisition. The carving stage recovers 98.7% of artifacts across the eight signature classes, the LSTM module recovers all five telemetry parameters with R2>0.99 and a single-step horizontal position error of 6.8 m, which is reduced to 4.7 m after multi-source correlation (below the 5 m operational target consistent with consumer-GNSS precision); the dependence on gap length is described by the empirical growth law εhoriz4.84·G1.44 m; 46.8% of recovered records fall within the high-confidence band of CS0.8; and the complex outperforms DatCon, Autopsy + DJI Analyzer and GRYPHON by 22–35 percentage points in end-to-end record recovery and by a factor of ∼2.6 in mean horizontal error (4.7 m vs. 12.4–18.7 m). (4) Conclusions: The combined write-blocked hardware acquisition, neural reconstruction of telemetry, and quantitative confidence index provides a forensically structured pipeline that fills an existing gap in UAV digital forensics; we note that technical reconstruction accuracy does not by itself confer legal admissibility, which remains a function of jurisdiction-specific evidentiary standards discussed in the Conclusions. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

23 pages, 300 KB  
Article
Encryption Failure in Portable Device Storage: Technical-Operational Analysis of the Veterans Affairs Data Breach
by Pedro A. R. S. Costa, Antonio Goncalves and Mario Monteiro Marques
J. Cybersecur. Priv. 2026, 6(4), 120; https://doi.org/10.3390/jcp6040120 - 7 Jul 2026
Viewed by 588
Abstract
This case study examines an encryption failure incident involving the exposure of sensitive personal data within a governmental information system environment. The analysis is based on the well-documented data breach that occurred within the U.S. Department of Veterans Affairs, in which a government [...] Read more.
This case study examines an encryption failure incident involving the exposure of sensitive personal data within a governmental information system environment. The analysis is based on the well-documented data breach that occurred within the U.S. Department of Veterans Affairs, in which a government employee stored a large dataset containing veterans’ personal information on a portable laptop device that lacked adequate encryption protection. Following the theft of the device from the employee’s residence, the personal records of approximately 26.5 million individuals were placed at risk of unauthorized exposure. Rather than interpreting the incident as an isolated technical failure, this study analyzes it through the Swiss cheese model, proposed by James Reason, and formalizes them as Portable Device Data Exposure Chain (PDDEC), showing that the breach resulted from the alignment of weaknesses across multiple layers of defense. The model is compared with two post-2010 endpoint-loss incidents to provide a limited historical back-test and is positioned against data-lifecycle, defense-in-depth, and Zero Trust approaches. The analysis shows that full-disk encryption is now a baseline control rather than a sufficient or novel solution. Hardware-backed key protection, verified boot, endpoint compliance, data-loss prevention, continuous monitoring, and controls for data in use are also required because encryption can be weakened by poor recovery-key governance, authenticated malware, sleep-state memory exposure, cold-boot attacks, and direct-memory-access attacks. The study contributes a reproducible control-point model for analyzing how sensitive data becomes exposed when it is moved beyond centrally managed environments, while explicitly limiting its generalizability to analytically comparable endpoint-loss scenarios. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Graphical abstract

28 pages, 921 KB  
Article
Digitalized Quality Management for Cybersecurity Conformity Assessment: ISO/IEC 17025-Based Automated Workflows, Evidence Analytics, and EN 18031 Readiness for the Radio Equipment Directive
by Aymen Gatri, David Lübeck and Mukayil Kilic
J. Cybersecur. Priv. 2026, 6(4), 113; https://doi.org/10.3390/jcp6040113 - 30 Jun 2026
Viewed by 614
Abstract
Cybersecurity conformity assessment is increasingly shaped by the Radio Equipment Directive (RED) delegated act, the EN 18031 harmonized standards, the Cyber Resilience Act, and industrial standards such as International Electrotechnical Commission (IEC) 62443. ISO/IEC 17025:2017 provides a general laboratory competence framework, but its [...] Read more.
Cybersecurity conformity assessment is increasingly shaped by the Radio Equipment Directive (RED) delegated act, the EN 18031 harmonized standards, the Cyber Resilience Act, and industrial standards such as International Electrotechnical Commission (IEC) 62443. ISO/IEC 17025:2017 provides a general laboratory competence framework, but its application to qualitative cybersecurity testing, rapidly changing toolchains, and automation-assisted evidence workflows remains under-specified. This paper proposes a digitalized quality-management framework that translates ISO/IEC 17025 clauses into cybersecurity-native controls for scope definition, method governance, toolchain control, evidence traceability, decision rules, technical review, and corrective-action feedback. An accreditation-style single-laboratory case study integrates a European Telecommunications Standards Institute (ETSI) TS 103 701 assessment workbook, an IEC 62443 corrective-action dataset, ISO/IEC 17025 internal audit findings, and laboratory governance records. In the ETSI workbook, the Conformity Statement Ambiguity Index (CSAI) decreases from 0.976 in the draft state to 0.050 after review, with 37 previously inconclusive provisions moving to PASS. This result is interpreted as improved determinability within the assessed workflow, not as cross-laboratory validation. The study contributes a clause-to-workflow operationalization of ISO/IEC 17025, an analytic design for heterogeneous assurance artefacts, and an EN 18031 evidence-mapping approach for Radio Equipment Directive readiness. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

24 pages, 596 KB  
Article
Empirical Evaluation of Android Browser Forensics and Artifact Persistence
by Paraskevas Giannakopoulos, Christos Smiliotopoulos and Georgios Kambourakis
J. Cybersecur. Priv. 2026, 6(3), 78; https://doi.org/10.3390/jcp6030078 - 1 May 2026
Viewed by 2295
Abstract
The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from [...] Read more.
The widespread adoption of mobile devices has rendered mobile browsers critical repositories of sensitive personal and organizational data, making their analysis a cornerstone of modern digital forensics. This paper presents a systematic empirical evaluation of the forensic recoverability and interpretability of data from popular mobile browsers (Chrome, Firefox, Tor, DuckDuckGo, and Brave) on authentic Android 13 devices. By utilizing a rooted environment to bypass application sandboxing, we introduce a standardized scoring framework to quantify and compare the residual digital footprints left across diverse usage scenarios, including standard browsing, manual data deletion, and private/incognito modes. The study details a hybrid acquisition methodology that integrates persistent storage analysis with custom volatile memory extraction routines to capture ephemeral process data. Through a suite of controlled, realistic scenarios—encompassing form filling, virtual transactions, and anti-forensic activities—the results demonstrate that significant portions of user activity remained recoverable within the tested and evaluated experimental environment and browser configurations despite aggressive privacy-enhancing measures. Our findings reveal that while private modes effectively minimize the persistent filesystem footprint, volatile memory remains a fertile source of cleartext credentials and session identifiers. This recovery is particularly pronounced in Chromium-based browsers, whereas privacy-centric alternatives like Tor exhibit higher forensic resilience. Ultimately, this research underscores the importance of volatile memory acquisition in mobile investigations and provides an experimental systematic approach for evaluating the trade-offs between browser usability and forensic traceability in contemporary Android environments, demonstrating potential applicability to subsequent Android iterations. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

27 pages, 28194 KB  
Article
Tracking the Gaze of Secure Coders: Behavioral Insights into Attention, Transitions, and Training
by Daniel Davis and Feng Zhu
J. Cybersecur. Priv. 2026, 6(2), 75; https://doi.org/10.3390/jcp6020075 - 20 Apr 2026
Viewed by 989
Abstract
Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers’ visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments [...] Read more.
Secure coding is essential, yet the strategies developers use to detect and mitigate flaws are not well understood. We present an eye-tracking-based approach that captures developers’ visual patterns while reading, coding, and applying security tools. Our framework uses participant-editable stimuli and dynamic environments to reflect authentic coding development. By visualizing gaze transitions and attention shifts, we expose how developers allocate effort during secure coding. By leveraging techniques that reveal gaze transitions, attention levels, and pupil size changes, we are able to gain insight into their behavior. Our study provides a fine-grained, process-oriented account of behavior in CWE-based secure coding educational tasks, uncovering attentional patterns and decision timelines that traditional methods may not capture. These contributions provide a foundation for improving training and understanding developer differences. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

15 pages, 275 KB  
Article
Deciding on Cybersecurity Awareness Initiatives: Insights from the Public Sector
by Joakim Kävrestad, Erik Bergström, Rebecca Gunnarsson, Ali Mazeh and Linus Stenlund
J. Cybersecur. Priv. 2026, 6(2), 66; https://doi.org/10.3390/jcp6020066 - 6 Apr 2026
Viewed by 1413
Abstract
Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA [...] Read more.
Raising cybersecurity awareness (CSA) of employees is crucial for all modern organisations. To meet the organisational need for CSA, activities aimed at increasing CSA have been the focus of both industry and research in the past. There are, subsequently, a plethora of CSA activities for organisations to choose from. Nevertheless, research consistently reports that organisations struggle to raise CSA to an appropriate level, and a core issue lies in their ability to select CSA activities and effectively adopt them. This paper used semi-structured interviews with practitioners working on CSA adoption in public-sector organisations to identify what practitioners perceive as success factors. The interviews were analysed through a socio-technical lens and resulted in a taxonomy that groups success factors for CSA adoption in the three socio-technical dimensions: organisational, user-centric, and technical. The taxonomy outlines ten success factors and demonstrates how the participants see success of CSA activities as not only dependent on technical factors but also, and perhaps even more important, user-adaptability and organisational readiness. The results were validated in a workshop with CSA experts across Europe, who highlighted the practical usefulness of the taxonomy as both a map of potential challenges and a teaching tool for educating new CSA practitioners. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

21 pages, 3346 KB  
Article
Hybrid-Pipeline-Based Detection and Classification of HTTP Slow Denial-of-Service Attacks Using Radial Basis Function Neural Networks
by Bashaer H. Alrashid, Mazen Alwadi and Qasem Abu Al-Haija
J. Cybersecur. Priv. 2026, 6(2), 64; https://doi.org/10.3390/jcp6020064 - 2 Apr 2026
Cited by 1 | Viewed by 1138
Abstract
Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop [...] Read more.
Detecting denial of service traffic remains challenging when malicious sessions exhibit flow characteristics that closely resemble benign network behavior, particularly in low-rate attack settings. This study examines whether autoencoder-based feature compression can improve flow-based intrusion detection while maintaining a deployment-oriented design. We develop a lightweight pipeline that learns a low-dimensional latent representation of tabular flow features using an autoencoder and performs classification using Random Forest, LightGBM, and a radial basis function neural network. Using the CICIDS 2017 dataset, the best performing configurations achieve 99.43 percent accuracy with autoencoder plus Random Forest and 99.39 percent with autoencoder plus LightGBM, while autoencoder plus radial basis function neural network achieves 98.27 percent, with consistently strong precision, recall, and F1-score. The findings support practice by showing that high detection performance can be achieved using compact learned features that reduce input complexity for downstream models, which is beneficial for operational monitoring environments. The study advances knowledge by providing a reproducible evaluation of representation learning as a feature compression step for tabular intrusion detection, and by linking model performance to measurable computational considerations relevant to real-world deployment. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

34 pages, 4190 KB  
Article
Towards Effective Cybersecurity Governance: Jordan Compliance System and Self-Assessment Tools
by Iman Almomani, Shahed Mehdawi and Yazeed Allabadi
J. Cybersecur. Priv. 2026, 6(2), 60; https://doi.org/10.3390/jcp6020060 - 1 Apr 2026
Viewed by 2050
Abstract
Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations’ safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements [...] Read more.
Enforcing cybersecurity governance is no longer a choice. It has become essential to protect nations’ safety and economy. In addition to the well-known cybersecurity standards that provide guidelines for implementing security controls, many countries have introduced national cybersecurity frameworks to meet their requirements and needs. These countries also provide assessment tools to check that organizations comply with these frameworks. This research emphasizes the importance of efficient cybersecurity governance practices, highlighting the Jordanian National Cyber Security Framework (JNCSF) that was announced in 2019. We have chosen this framework because, since its launch, it has not been presented or analyzed thoroughly by any of the existing studies. Moreover, the National Cyber Security Center (NCSC) in Jordan has not announced any public self-assessment tools for organizations to evaluate their compliance with the JNCSF. Therefore, the absence of a structured and publicly available self-assessment mechanism for the JNCSF creates a challenge for organizations in objectively measuring their cybersecurity governance readiness. Accordingly, the main contributions of this paper are to provide a detailed breakdown and discussion of the JNCSF, which supports organizations in Jordan and also shares the JNCSF philosophy regionally and internationally. Additionally, this study introduces an efficient self-assessment tool (named JCCT) that can be used both offline and online. JCCT accurately measures the institution’s cybersecurity compliance against JNCSF and international standards (ISO and NIST), reflecting its current state and the potential impact on its risk profile. Moreover, this paper proposes new compliance score equations based on a comprehensive mathematical model that generally benefits any governance system. The JCCT tool offers rich, interactive, customized dashboards and automatically generates reports with recommended action plans for the organization. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

21 pages, 2858 KB  
Article
Generation of Distances Between Feature Vectors Derived from a Siamese Neural Network for Continuous Authentication
by Sergey Davydenko, Pavel Laptev and Evgeny Kostyuchenko
J. Cybersecur. Priv. 2026, 6(2), 45; https://doi.org/10.3390/jcp6020045 - 3 Mar 2026
Viewed by 654
Abstract
Continuous authentication is a promising method for protecting computer systems in the event of compromise of primary authentication factors, such as passwords or tokens. Systems employing continuous authentication that rely on biometrics may not be restricted to a single biometric characteristic; rather, they [...] Read more.
Continuous authentication is a promising method for protecting computer systems in the event of compromise of primary authentication factors, such as passwords or tokens. Systems employing continuous authentication that rely on biometrics may not be restricted to a single biometric characteristic; rather, they can simultaneously utilize multiple characteristics and subsequently arrive at a conclusive decision based on their collective analysis outcomes. One of the significant challenges researchers encounter when investigating effective fusion in decision-making is the lack of data. At present, data generation primarily involves the creation of feature vectors or attack simulation. This paper introduces a method for directly generating distances derived from a Siamese neural network, utilizing the probability density function of an existing distribution. Through statistical analysis, we successfully generated 5000 samples that correspond to the initial distribution, which were then employed to discover the threshold values at which FAR and FRR were less than 1%. The methods developed can be further applied to identify the most efficient strategies for integrating the results of continuous authentication in systems that incorporate multiple biometric characteristics. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

Other

Jump to: Research

50 pages, 607 KB  
Systematic Review
LLM-Based Agents for Cybersecurity: A Systematic Review of Architectures, Applications, and Open Challenges
by George Fatouros, Konstantinos Mavrogiorgos, Georgios Makridis, John Soldatos and Dimosthenis Kyriazis
J. Cybersecur. Priv. 2026, 6(5), 159; https://doi.org/10.3390/jcp6050159 - 9 Sep 2026
Viewed by 687
Abstract
The rapid evolution of Large Language Models (LLMs) has opened new frontiers in cybersecurity automation, enabling intelligent agents capable of multi-step reasoning, tool invocation, and autonomous decision-making across complex security tasks. While individual applications have emerged across threat intelligence, vulnerability assessment, penetration testing, [...] Read more.
The rapid evolution of Large Language Models (LLMs) has opened new frontiers in cybersecurity automation, enabling intelligent agents capable of multi-step reasoning, tool invocation, and autonomous decision-making across complex security tasks. While individual applications have emerged across threat intelligence, vulnerability assessment, penetration testing, and security operations center (SOC) automation, a systematic understanding of the LLM-based agent paradigm in cybersecurity—encompassing both single-agent and multi-agent architectures—remains lacking. This paper presents a systematic literature review following PRISMA guidelines, identifying records through 59 structured web-search queries whose results resolve predominantly to arXiv, Semantic Scholar, the ACM Digital Library, IEEE Xplore, USENIX, MDPI, SpringerLink, and Elsevier ScienceDirect, supplemented by citation chaining, for works published between January 2022 and April 2026; the full query record is published with the paper. We applied structured inclusion and exclusion criteria and classified 59 primary studies along five dimensions: security function, agent architecture pattern, knowledge augmentation strategy, human-in-the-loop posture, and evaluation rigor. Our analysis reveals that penetration testing and threat intelligence are the most extensively studied domains, while incident response and compliance verification remain critically underrepresented. Penetration testing alone accounts for over half the corpus (50.8%). Single-agent tool-calling remains the most prevalent architecture (30.5% of studies), whereas centralized multi-agent orchestration—present in 18.6%—yields the strongest reported performance gains, up to 4.3× on zero-day exploitation; prevalence and performance therefore point in opposite directions. No included study achieves production-grade (E4) evaluation: the entire field currently rests on controlled laboratory assessments. An independent search of six bibliographic databases recovers 86.3% of the studies the primary search had surfaced (79.7% of the full corpus) while indicating a total eligible literature of roughly 400 studies, so the corpus is reported as a documented subset rather than an exhaustive census. We propose a unifying taxonomy, identify cross-cutting challenges including hallucination, prompt injection, and benchmark fragmentation, and outline open research directions with particular emphasis on multi-agent orchestration design. Financial sector applicability under DORA and the EU AI Act is treated as a documented evidence gap rather than a synthesis: the corpus’s only compliance and risk assessment study is also its only banking-specific system. Full article
(This article belongs to the Special Issue Cyber Security and Digital Forensics—3rd Edition)
Show Figures

Figure 1

Back to TopTop