Submitted:
28 August 2026
Posted:
31 August 2026
You are already at the latest version
Abstract
The growing integration of cyber, physical, and operational security functions has created a need for assessment approaches that evaluate security convergence as an organisational capability rather than as a set of isolated controls. This article proposes the Converged Security Maturity Index (CSMI), a conceptual maturity model designed to assess the level of integration among cybersecurity, physical security, and operational security within organisations. The model is developed using a design science research approach grounded in a structured review of converged security literature, cyber-physical system security, and existing maturity frameworks. CSMI comprises five progressive maturity levels—Fragmented, Coordinated, Integrated, Unified, and Optimised—and evaluates organisational capabilities across four dimensions: governance and strategy, processes and incident management, technology and infrastructure integration, and human factors and security culture. The article describes the architecture of the model, the rationale for each maturity level and dimension, and outlines how the framework could be applied in practice through a structured questionnaire in future work. The proposed framework aims to support organisational self-assessment, benchmarking, and identification of convergence gaps across different sectors.
Keywords:
1. Introduction
2. Literature Review
2.1. Cyber-Physical Integration Research
2.2. Operational Security and Organisational Resilience
2.3. Maturity Models and Their Limitations
2.4. Summary of Research Gap
2.5. Research Hypotheses
- H1: Organisations demonstrate significantly higher maturity in cybersecurity than in physical–cyber convergence.
- H2: Organisations with formal cross-domain governance structures show higher overall CSMI scores.
- H3: Security incident response performance correlates positively with CSMI maturity level.
- H4: Organisational culture (e.g., cross-team communication) is a stronger predictor of convergence maturity than technology deployments.
- H5: CSMI provides a more accurate representation of integrated security capability than single-domain maturity models.
3. Methods
3.1. Research Design
- Conceptual model development, based on a structured literature review of converged security, cyber-physical systems, and organisational maturity models.
- Operationalisation of maturity dimensions, transforming abstract convergence principles into measurable assessment criteria.
- Questionnaire-based maturity assessment, enabling standardised data collection across organisations.
- Index construction and interpretation, resulting in a composite Converged Security Maturity Index (CSMI).
3.2. Structure of the Converged Security Maturity Index
- Level 1 – Fragmented: Security domains operate independently with minimal coordination.
- Level 2 – Coordinated: Informal cooperation exists, primarily during incidents.
- Level 3 – Integrated: Formal processes and shared technologies are partially implemented.
- Level 4 – Unified: Centralised governance, joint risk management, and unified operations.
- Level 5 – Optimised: Continuous improvement supported by metrics, automation, and predictive analytics.
- Governance and Strategy(leadership structures, policies, accountability, funding alignment)
- Processes and Incident Management(joint procedures, escalation paths, crisis coordination)
- Technology and Infrastructure Integration(SIEM–PSIM integration, identity convergence, cyber-physical visibility)
- Human Factors and Organisational Culture(training, communication, shared situational awareness)
- This multidimensional structure ensures that convergence is assessed not merely as a technical phenomenon, but as an organisational capability.
3.3. Questionnaire Instrument Design
- 1 = strongly disagree / not implemented
- 5 = strongly agree / fully implemented
- “Cybersecurity and physical security share a unified risk management framework.”
- “Incident response teams operate under a single command structure regardless of incident type.”
- “Security metrics are consolidated and reported at the executive level.”
3.4. Scoring Model and Index Construction
- Item scores are averaged per dimension.
- Dimension scores are normalised to a 0–100 scale.
- The overall CSMI score is calculated as the arithmetic mean of all four dimensions.
- assignment of an organisation to a maturity level,
- benchmarking across sectors,
- identification of convergence gaps between domains.
3.5. Validity and Reliability Considerations
- Design of questionaries with Likert scale,
- Cronbach’s alpha for internal consistency,
- factor analysis to confirm dimensional structure,
- inter-rater reliability testing across respondent roles.
3.6. Ethical and Practical Considerations
4. CSMI Model Architecture
- Security domains layer
- Security convergence layer
- Maturity dimensions layer
- Assessment instrument layer
- Data processing and validation layer
- Index calculation layer
- Maturity classification layer
4.1. Security Domains Layer
4.2. Security Convergence Layer
- unified security governance structures
- shared risk management processes
- integrated monitoring and detection technologies
- coordinated incident response procedures
- cross-disciplinary collaboration between security teams
4.3. Maturity Dimensions
4.3.1. Governance and Strategy
4.3.2. Processes and Incident Management
4.3.3. Technology and Infrastructure Integration
4.3.4. Human Factors and Security Culture
4.4. Assessment Instrument Layer
4.5. Data Processing and Validation
4.6. Index Calculation Layer
4.7. Maturity Classification
5. Discussion
5.1. Implications
5.2. Limitations
6. Conclusions
Supplementary Materials
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| ASIS | American Society for Industrial Security |
| CISO | Chief Information Security Officer |
| CMMI | Capability Maturity Model Integration |
| COBIT | Control Objectives for Information and Related Technologies |
| CPS | Cyber-Physical System |
| CSMI | Converged Security Maturity Index |
| DSR | Design Science Research |
| ISO | International Organization for Standardization |
| IT | Information Technology |
| IoT | Internet of Things |
| NIST CSF | National Institute of Standards and Technology Cybersecurity Framework |
| PSIM | Physical Security Information Management |
| SIEM | Security Information and Event Management |
References
- Beck, D. The State of Security Convergence in the United States, Europe, and India . ASIS Foundation. 2021. Available online: https://www.asisonline.org/globalassets/foundation/documents/convergence.pdf.
- Alguliyev, R.; Imamverdiyev, Y.; Sukhostat, L. Cyber-physical systems and their security issues. Comput. Ind. 2018, 100, 212–223. [Google Scholar] [CrossRef]
- Tyson, D. Security Convergence: Managing Enterprise Security Risk; Butterworth-Heinemann: Boston, MA, USA, 2007. [Google Scholar]
- Cybersecurity and Infrastructure Security Agency (CISA). Cybersecurity and Physical Security Convergence . CISA: Washington, DC, USA, 2021. Available online: https://www.cisa.gov/sites/default/files/publications/Cybersecurity%2520and%2520Physical%2520Security%2520Convergence_508_01.05.2021.pdf.
- Salahdine, F.; Kaabouch, N. Social Engineering Attacks: A Survey. Future Internet 2019, 11, 89. [Google Scholar] [CrossRef]
- Akeiber, H.J. The Evolution of Social Engineering Attacks: A Cybersecurity Engineering Perspective. Al-Rafidain J. Eng. Sci. 2025, 3, 294–316. [Google Scholar] [CrossRef]
- Anti, E.; Rousi, R. Mitigating Insider Threats in Cybersecurity: A Design Thinking Approach. Proceedings of TKTP 2025: Annual Doctoral Symposium of Computer Science CEUR Workshop Proceedings, Helsinki, Finland, 2–3 June 2025; Vol. 4181. Available online: https://ceur-ws.org/Vol-4181/paper11.pdf.
- Riskhan, B.; Raufi, A.M.; Usmani, M.H. Physical Security to Cybersecurity (Challenges and Implications in the Modern Digital Landscape). J. Electr. Syst. 2024, 20, 692–702. [Google Scholar] [CrossRef]
- Ingelbrecht, N.; Bangurah, I. Emerging Trend: Convergence of Cyber and Physical Security—Harnessing the Disruption Opportunity . Gartner. 2025. Available online: https://www.gartner.com/en/documents/6335579.
- Kapoor, S.; Kumar, S.; Vardhan, H. Cyber Security of OT Networks: A Tutorial and Overview. arXiv 2025, arXiv:2502.14017. [Google Scholar] [CrossRef]
- McCreight, T.; Leece, D. Physical Security and IT Convergence: Managing the Cyber-Related Risks. J. Bus. Contin. Emerg. Plan. 2016, 10, 18–30. [Google Scholar] [CrossRef]
- Hromada, M.; Rehak, D.; Skobiej, B.; Bajer, M. Converged Security and Information Management System as a Tool for Smart City Infrastructure Resilience Assessment. Smart Cities 2023, 6, 2221–2244. [Google Scholar] [CrossRef]
- Sennewald, C.A.; Baillie, C. Convergence in Security Management. In Effective Security Management, 7th ed.; Butterworth-Heinemann: Cambridge, MA, USA, 2021; pp. 275–280. [Google Scholar] [CrossRef]
- Willison, J.; Gill, J. Security Convergence: A Unified Approach to Modern Security Challenges . Kaseware. 2025. Available online: https://info.kaseware.com/hubfs/Gated%20Assets/PDF_ALL_SecurityConvergenceGuide_2025Q1_Guide.pdf.
- Darnell, D.; Uchida, C.D.; Swatt, M.L.; Anderson, K. Security Convergence and Business Continuity: Reflecting on the Pandemic Experience . ASIS Foundation. 2022. Available online: https://www.asisonline.org/globalassets/foundation/documents/research/9-22-convergence-report-2.pdf.
- National Institute of Standards and Technology (NIST). The NIST Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper (CSWP) NIST CSWP 29; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef]
- CMMI Institute. CMMI Institute . Available online: https://cmmiinstitute.com/.
- International Organization for Standardization (ISO); International Electrotechnical Commission (IEC). ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements; ISO. Geneva, Switzerland, 2022.
- International Organization for Standardization (ISO). ISO 22301:2024 Security and Resilience—Business Continuity Management Systems—Requirements; ISO. Geneva, Switzerland, 2024.
- Javed, Y.; Felemban, M.; Shawly, T.; Kobes, J.; Ghafoor, A. A Partition-Driven Integrated Security Architecture for Cyber-Physical Systems. arXiv 2019, arXiv:1901.03018. [Google Scholar] [CrossRef]
- Lian, Z.; Shi, P.; Chen, M. A Survey on Cyber-Attacks for Cyber-Physical Systems: Modeling, Defense, and Design. IEEE Internet Things J. 2025, 12(2), 1471–1483. [Google Scholar] [CrossRef]
- Huang, S.; Poskitt, C.M.; Shar, L.K. Security Modelling for Cyber-Physical Systems: A Systematic Literature Review. arXiv 2025, arXiv:2404.07527. [Google Scholar] [CrossRef]
- Tovkun, Y.; Semerenska, V.; Adamov, A. An Overview of Cyber Attacks on Critical Cyber-Physical Systems and Government Infrastructures. Secur. Saf. 2026, 5, 2026002. [Google Scholar] [CrossRef]
- Canadian Centre for Cyber Security. Ransomware Threat Outlook 2025–2027 . Government of Canada. 2026. Available online: https://www.cyber.gc.ca/en/guidance/ransomware-threat-outlook-2025-2027.
- Büyüközkan, G.; Güler, M. Cybersecurity Maturity Model: Systematic Literature Review and a Proposed Model. Technol. Forecast. Soc. Change 2025, 213, 123996. [Google Scholar] [CrossRef]
- Aytekin, A.; Coşkun, A.; Dursun, M. Evolving Maturity Models for Electric Power System Cybersecurity: A Case-Driven Framework Gap Analysis. Appl. Sci. 2026, 16, 177. [Google Scholar] [CrossRef]
- Brezavšček, A.; Baggia, A. Recent Trends in Information and Cyber Security Maturity Assessment: A Systematic Literature Review. Systems 2025, 13, 52. [Google Scholar] [CrossRef]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.