Preprint
Article

This version is not peer-reviewed.

Converged Security Maturity Index: A Unified Model for Cyber, Physical, and Operational Security Maturity Assessment

Submitted:

28 August 2026

Posted:

31 August 2026

You are already at the latest version

Abstract

The growing integration of cyber, physical, and operational security functions has created a need for assessment approaches that evaluate security convergence as an organisational capability rather than as a set of isolated controls. This article proposes the Converged Security Maturity Index (CSMI), a conceptual maturity model designed to assess the level of integration among cybersecurity, physical security, and operational security within organisations. The model is developed using a design science research approach grounded in a structured review of converged security literature, cyber-physical system security, and existing maturity frameworks. CSMI comprises five progressive maturity levels—Fragmented, Coordinated, Integrated, Unified, and Optimised—and evaluates organisational capabilities across four dimensions: governance and strategy, processes and incident management, technology and infrastructure integration, and human factors and security culture. The article describes the architecture of the model, the rationale for each maturity level and dimension, and outlines how the framework could be applied in practice through a structured questionnaire in future work. The proposed framework aims to support organisational self-assessment, benchmarking, and identification of convergence gaps across different sectors.

Keywords: 
;  ;  ;  ;  ;  ;  ;  ;  

1. Introduction

The security landscape has shifted toward increasingly complex threat environments in which the cyber and physical domains are interconnected [1,2]. Traditional siloed approaches are insufficient to address modern hybrid threats that leverage both digital and physical vectors simultaneously [3,4]. Examples include cyber intrusions enabling bypass of physical access controls, ransomware disrupting operational processes in healthcare or manufacturing, and insider threats combining digital credential misuse with on-site manipulation [5,6]. Research shows that organisations lacking unified governance structures experience a higher likelihood of security failures across domains [7,8].
The concept of converged security refers to the strategic and operational integration of cybersecurity, physical security, and operational resilience functions [1,9,10,11]. While the corporate security literature has highlighted the importance of convergence for over two decades, the degree of convergence across industries remains highly uneven [1,12]. Multiple studies indicate that convergence supports improved incident response, reduced redundancies, more effective risk management, and higher security ROI [4,13,14,15]. However, existing maturity models tend to focus on only one security domain, especially cybersecurity (e.g., NIST CSF or CMMI-based interpretations), while integrated models remain rare and fragmented [16,17].
This study contributes to the field by introducing the Converged Security Maturity Index (CSMI)—a unified, domain-agnostic maturity model capturing the extent of security convergence across governance, processes, technology, culture, and operational execution. The article primarily formulates hypotheses and develops an assessment framework, that will be used for future practical validation by questionaries.

2. Literature Review

Research on converged security spans several intersecting domains: cybersecurity governance, physical protection systems, enterprise resilience, and risk management integration [12,13,18,19]. The push toward convergence gained momentum in early corporate security research, notably in publications emphasising the need to unify organisational security functions to address hybrid threats [3,4]. Studies by ASIS International highlight the increasing alignment between physical and IT security teams due to the digital transformation of access control systems, IoT devices, and building automation [1,15].

2.1. Cyber-Physical Integration Research

Modern security technologies blur the boundaries between physical and cyber systems. Access control, surveillance, intrusion detection, and facility automation depend heavily on digital networks, introducing cyber vulnerabilities into previously isolated physical systems [10,20]. Multiple studies show strong empirical evidence that cyber-physical integration significantly increases the attack surface when not governed cohesively [21,22,23,24]. Research in cyber-physical system (CPS) security demonstrates that organisational maturity strongly correlates with resilience outcomes [25].

2.2. Operational Security and Organisational Resilience

Operational security, covering processes, continuity, and incident response, has become inseparable from cyber and physical systems. The resilience literature indicates that maturity in operational processes improves cross-domain response capability, especially during cascading multi-domain incidents [12,18]. Frameworks such as ISO 22301 emphasise process integration but do not explicitly address convergence maturity [19].

2.3. Maturity Models and Their Limitations

Existing maturity models, such as NIST CSF, COBIT, or sector-specific CPS models, provide structured approaches but focus on a single domain [26,27]. Research indicates that organisations often achieve maturity in cyber or physical domains independently, leading to misalignment, redundant controls, and fragmented risk assessment [26]. There is a clear research gap regarding quantitative maturity models explicitly measuring the degree of convergence between security domains [20].

2.4. Summary of Research Gap

Across the reviewed literature, five key gaps emerge:
  • Absence of a single maturity model bridging cyber, physical, and operational domains [22,25,26,27].
  • Lack of quantitative metrics evaluating “convergence level” [1,12,25,27].
  • Minimal emphasis on organisational culture and interdisciplinary collaboration [3,11,13,15].
  • Insufficient practical tools for assessing converged security in small and medium-sized organisations [4,14,15,17].
  • Limited empirical datasets demonstrating converged maturity evaluation [12,15,17].
These gaps justify developing a unified, empirically testable model, such as the CSMI.

2.5. Research Hypotheses

Based on the literature, we formulate the following hypotheses:
  • H1: Organisations demonstrate significantly higher maturity in cybersecurity than in physical–cyber convergence.
  • H2: Organisations with formal cross-domain governance structures show higher overall CSMI scores.
  • H3: Security incident response performance correlates positively with CSMI maturity level.
  • H4: Organisational culture (e.g., cross-team communication) is a stronger predictor of convergence maturity than technology deployments.
  • H5: CSMI provides a more accurate representation of integrated security capability than single-domain maturity models.

3. Methods

3.1. Research Design

This study adopts a design science research (DSR) approach combined with quantitative maturity assessment methods. The objective is to design, operationalise, and preliminarily validate a maturity model capable of assessing the degree of convergence between cyber, physical, and operational security domains within organisations.
The research design consists of four sequential phases:
  • Conceptual model development, based on a structured literature review of converged security, cyber-physical systems, and organisational maturity models.
  • Operationalisation of maturity dimensions, transforming abstract convergence principles into measurable assessment criteria.
  • Questionnaire-based maturity assessment, enabling standardised data collection across organisations.
  • Index construction and interpretation, resulting in a composite Converged Security Maturity Index (CSMI).
This methodological approach aligns with established practices in security maturity modelling and organisational capability assessment [17,25,26,27].

3.2. Structure of the Converged Security Maturity Index

CSMI is structured as a five-level maturity model, reflecting progressive stages of security convergence:
  • Level 1 – Fragmented: Security domains operate independently with minimal coordination.
  • Level 2 – Coordinated: Informal cooperation exists, primarily during incidents.
  • Level 3 – Integrated: Formal processes and shared technologies are partially implemented.
  • Level 4 – Unified: Centralised governance, joint risk management, and unified operations.
  • Level 5 – Optimised: Continuous improvement supported by metrics, automation, and predictive analytics.
Each maturity level is evaluated across four core dimensions:
  • Governance and Strategy(leadership structures, policies, accountability, funding alignment)
  • Processes and Incident Management(joint procedures, escalation paths, crisis coordination)
  • Technology and Infrastructure Integration(SIEM–PSIM integration, identity convergence, cyber-physical visibility)
  • Human Factors and Organisational Culture(training, communication, shared situational awareness)
  • This multidimensional structure ensures that convergence is assessed not merely as a technical phenomenon, but as an organisational capability.

3.3. Questionnaire Instrument Design

To operationalise the CSMI model, a 48-item structured questionnaire was developed. Each item corresponds to a specific maturity indicator within one of the four dimensions.
Responses are measured using a 5-point Likert scale, where:
  • 1 = strongly disagree / not implemented
  • 5 = strongly agree / fully implemented
Examples of questionnaire items include:
  • “Cybersecurity and physical security share a unified risk management framework.”
  • “Incident response teams operate under a single command structure regardless of incident type.”
  • “Security metrics are consolidated and reported at the executive level.”
The questionnaire was designed to be role-agnostic, allowing completion by security managers, CISOs, facility security officers, or operational risk managers.

3.4. Scoring Model and Index Construction

For each organisation, responses are aggregated as follows:
  • Item scores are averaged per dimension.
  • Dimension scores are normalised to a 0–100 scale.
  • The overall CSMI score is calculated as the arithmetic mean of all four dimensions.
The resulting index enables:
  • assignment of an organisation to a maturity level,
  • benchmarking across sectors,
  • identification of convergence gaps between domains.
This composite scoring approach follows best practices used in established maturity frameworks such as NIST CSF and COBIT, while extending them toward cross-domain convergence [4,11,12,27].

3.5. Validity and Reliability Considerations

Content validity was ensured through alignment with peer-reviewed literature and industry frameworks [16,17,18,19]. Construct validity is supported by the multidimensional design, which reflects governance, processes, technology, and human factors.
Future empirical studies will apply:
  • Design of questionaries with Likert scale,
  • Cronbach’s alpha for internal consistency,
  • factor analysis to confirm dimensional structure,
  • inter-rater reliability testing across respondent roles.

3.6. Ethical and Practical Considerations

The proposed assessment does not require sensitive operational details and can be conducted anonymously. The model is suitable for internal audits, benchmarking exercises, and longitudinal maturity tracking.

4. CSMI Model Architecture

CSMI architecture provides a structured analytical framework for evaluating the level of integration among cybersecurity, physical security, and operational security functions within an organisation. The architecture transforms qualitative organisational practices related to security governance and coordination into a measurable maturity indicator.
The proposed model is structured as a multilayered architecture composed of several interconnected analytical layers. Each layer represents a different stage of the maturity assessment process, beginning with the identification of core security domains and culminating in the calculation of a composite maturity index. This layered structure enables the systematic evaluation of security convergence while maintaining conceptual clarity between organisational inputs, analytical dimensions, and resulting maturity metrics.
The architecture consists of the following key components:
  • Security domains layer
  • Security convergence layer
  • Maturity dimensions layer
  • Assessment instrument layer
  • Data processing and validation layer
  • Index calculation layer
  • Maturity classification layer
Together, these components form an integrated framework that supports the measurement and interpretation of security convergence maturity within complex organisational environments.

4.1. Security Domains Layer

At the foundational level, the CSMI architecture recognises three primary security domains that traditionally operate as separate organisational functions. These domains represent the core operational environment in which security convergence occurs.
The first domain is cybersecurity, which focuses on protecting digital assets, information systems, and communication networks from unauthorised access, disruption, or compromise. Cybersecurity includes technologies and practices such as network monitoring, vulnerability management, identity and access control, and incident response capabilities.
The second domain is physical security, which addresses the protection of physical infrastructure, facilities, equipment, and personnel. Typical physical security measures include surveillance systems, access control technologies, perimeter protection, and facility monitoring systems.
The third domain is operational security, which focuses on maintaining organisational continuity and resilience during disruptive events. This domain encompasses crisis management, emergency response planning, business continuity management, and disaster recovery strategies.
Although these domains historically developed as independent organisational disciplines, the increasing digitisation of physical infrastructure and the growing reliance on interconnected systems have created significant overlaps between them. Modern security incidents frequently involve interactions between digital vulnerabilities, physical infrastructure, and operational processes. Consequently, effective risk management requires coordinated security governance across these domains.
Within the CSMI architecture, the three domains are therefore treated as the foundational input layer that defines the operational context of the maturity assessment model.

4.2. Security Convergence Layer

The second architectural layer represents the concept of security convergence, which forms the central analytical focus of the CSMI framework.
Security convergence refers to the integration of cybersecurity, physical security, and operational security functions within a unified governance and risk management structure. Rather than evaluating each domain independently, the model focuses on the degree to which these domains cooperate, share information, and coordinate their activities.
In practice, security convergence can manifest through several organisational mechanisms, including:
  • unified security governance structures
  • shared risk management processes
  • integrated monitoring and detection technologies
  • coordinated incident response procedures
  • cross-disciplinary collaboration between security teams
The convergence layer, therefore, serves as the conceptual bridge between the foundational security domains and the analytical maturity dimensions used to evaluate their level of integration.
By focusing on the interactions between security domains rather than their isolated capabilities, the CSMI model captures the organisational maturity of integrated security management.

4.3. Maturity Dimensions

The convergence layer is operationalised through four analytical maturity dimensions representing key organisational capabilities required for effective security integration.

4.3.1. Governance and Strategy

The governance and strategy dimension evaluates the degree to which security functions are coordinated at the strategic and managerial levels. This includes unified security leadership structures, integrated risk management frameworks, and coordinated security policies.
Organisations with higher maturity levels in this dimension typically exhibit centralised security governance, clearly defined responsibilities across security disciplines, and alignment between cybersecurity, physical security, and operational risk management strategies.

4.3.2. Processes and Incident Management

The processes and incident management dimension focuses on operational coordination between security functions during routine operations and incident response situations.
Key aspects evaluated in this dimension include joint incident response procedures, coordinated crisis management planning, and shared situational awareness mechanisms. Mature organisations typically maintain integrated incident response frameworks that allow security teams to collaborate effectively during complex cyber-physical incidents.

4.3.3. Technology and Infrastructure Integration

The technology and infrastructure dimension assesses the level of interoperability among security technologies across different domains.
Modern organisations increasingly deploy both cybersecurity monitoring tools and physical security systems such as surveillance networks, access control platforms, and building automation systems. Effective security convergence requires these technologies to share information and support coordinated monitoring and response capabilities.
Higher maturity levels in this dimension are characterised by integrated security information platforms, centralised monitoring systems, and interoperability between cybersecurity and physical security technologies.

4.3.4. Human Factors and Security Culture

The final maturity dimension addresses the human and organisational aspects of security convergence. Even when technological and procedural integration is in place, effective convergence depends heavily on collaboration among individuals and teams responsible for different security functions.
This dimension, therefore, evaluates factors such as cross-disciplinary communication, training programs, organisational awareness of security convergence principles, and collaborative decision-making structures.
Organisations demonstrating high maturity in this dimension typically promote a shared security culture in which cybersecurity, physical security, and operational teams work together toward common risk management objectives.
Together, these four dimensions form the structural core of the CSMI architecture and provide the analytical basis for the maturity assessment model.

4.4. Assessment Instrument Layer

The maturity dimensions are operationalised through a structured assessment instrument designed to capture organisational practices related to security convergence.
The instrument consists of a questionnaire containing multiple indicators assigned to individual maturity dimensions. Each indicator represents a specific organisational capability or practice associated with integrated security management.
Respondents evaluate each indicator using a five-point Likert scale, which enables the transformation of qualitative organisational practices into quantitative measurements. The use of a standardised response scale ensures comparability of responses across organisations and supports statistical analysis of the collected data.
The questionnaire is intended to be completed by organizational stakeholders responsible for security governance, including cybersecurity managers, physical security managers, risk management professionals, and operational leadership.

4.5. Data Processing and Validation

After data collection, the responses undergo several statistical validation procedures designed to ensure the reliability and validity of the maturity assessment model.
Internal consistency of questionnaire items within each maturity dimension will be evaluated by Cronbach’s alpha, which measures the degree to which items within a dimension capture the same underlying construct.
In addition, exploratory factor analysis is applied to verify whether the empirical structure of the questionnaire corresponds to the theoretical maturity dimensions defined within the CSMI model.
To address potential differences in perception between organizational roles, inter-rater reliability analysis is also conducted. This analysis evaluates the level of agreement between responses provided by different respondents within the same organization.
These validation procedures ensure that the assessment instrument provides reliable measurements of organizational security convergence maturity.

4.6. Index Calculation Layer

Once validated, the collected data are aggregated into numerical scores representing the maturity of each analytical dimension. These dimension scores are subsequently normalized and combined to produce a single composite indicator known as the Converged Security Maturity Index (CSMI).
The index provides a quantitative measure of the level of integration between cybersecurity, physical security, and operational security functions within an organization. By aggregating multiple organizational indicators into a single metric, the CSMI index enables simplified comparison of security convergence maturity across organizations or sectors.

4.7. Maturity Classification

The final architectural layer of the model maps the calculated CSMI score onto a predefined maturity classification scale consisting of five levels.
These maturity levels represent the evolutionary stages of security convergence within organizations, ranging from fragmented security environments characterized by isolated security functions to highly integrated environments where security governance, processes, and technologies operate under unified management structures.
The classification framework enables organizations to benchmark their current maturity level and identify specific areas requiring improvement in order to achieve higher levels of security convergence.
Through this layered architecture, the CSMI framework provides a systematic approach for evaluating and interpreting the maturity of integrated security management practices.

5. Discussion

The findings underscore several salient features of converged security environments. First, governance integration appears to precede technological integration, as organizations often establish joint security committees or adopt shared policies before implementing fully integrated monitoring systems. Second, the results indicate that technological interoperability between cybersecurity and physical security systems remains a persistent barrier to convergence. Finally, the findings suggest that the proposed maturity model may serve as a useful instrument for benchmarking and for identifying convergence gaps within organizations.

5.1. Implications

The CSMI framework may be employed by organizations to assess their current stage of security convergence and to identify areas requiring further development. From a research perspective, the model provides a conceptual basis for future empirical investigations into the relationship between security convergence and organizational resilience.

5.2. Limitations

This study proposes a conceptual model rather than a large-scale empirical validation. Future research should apply the model to a sample of organizations in order to examine sector-specific patterns in security convergence maturity and validate the model.

6. Conclusions

This paper introduced the Converged Security Maturity Index (CSMI), a structured and quantitative framework designed to assess the maturity of integrated security management across cyber, physical, and operational domains. In response to the increasing complexity of hybrid threats and the growing need for unified security governance, the proposed model addresses a significant gap in the current literature, namely the absence of a comprehensive maturity approach that captures security convergence as an organisational capability rather than as a set of isolated controls.
The CSMI framework is built on four interrelated dimensions: governance and strategy, processes and incident management, technology and infrastructure integration, and human factors and security culture. By combining these dimensions into a single maturity index, the model enables organisations to evaluate not only the existence of individual security measures, but also the extent to which these measures are coordinated, interoperable, and embedded within a shared governance structure. This makes the framework useful for benchmarking, internal self-assessment, and the identification of convergence gaps across different organisational contexts.
A further contribution of this study is the operationalisation of convergence into measurable maturity levels. The model transforms qualitative security practices into a standardised scoring approach, which can support comparative analysis and future empirical research. Although the present study is primarily conceptual, it establishes a foundation for subsequent validation using real organisational data. Future work should therefore focus on large-scale empirical testing, design and refinement of the questionnaire instrument, and statistical verification of the model’s reliability and construct validity.
Overall, the CSMI represents a step toward a more integrated and practical understanding of converged security maturity. It provides a framework that may support both academic research and organisational practice by helping decision-makers identify weak points in cross-domain security integration and prioritise improvements in governance, collaboration, and resilience.

Supplementary Materials

The following supporting information can be downloaded at the website of this paper posted on Preprints.org.

Author Contributions

Conceptualization, L.K., D.K. and D.M.; Methodology, L.K., D.K. and D.M.; Investigation, J.A., J.V. and D.M.; Writing – original draft preparation, L.K., J.A., J.V., D.K. and D.M.; Writing – review & editing, J.A.; Project administration, L.K. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Data Availability Statement

There are no research data, it is just a model proposal. Data from questionaries will be use in following research.

Acknowledgments

During the preparation of this manuscript/study, the author(s) used [Perplexity, July 2026] for the purposes of grammar check. The authors have reviewed and edited the output and take full responsibility for the content of this publication.

Conflicts of Interest

The funders had no role in the design of the study; in the collection, analyses, or interpretation of data; in the writing of the manuscript; or in the decision to publish the results.

Abbreviations

The following abbreviations are used in this manuscript:
ASIS American Society for Industrial Security
CISO Chief Information Security Officer
CMMI Capability Maturity Model Integration
COBIT Control Objectives for Information and Related Technologies
CPS Cyber-Physical System
CSMI Converged Security Maturity Index
DSR Design Science Research
ISO International Organization for Standardization
IT Information Technology
IoT Internet of Things
NIST CSF National Institute of Standards and Technology Cybersecurity Framework
PSIM Physical Security Information Management
SIEM Security Information and Event Management

References

  1. Beck, D. The State of Security Convergence in the United States, Europe, and India  . ASIS Foundation. 2021. Available online: https://www.asisonline.org/globalassets/foundation/documents/convergence.pdf.
  2. Alguliyev, R.; Imamverdiyev, Y.; Sukhostat, L. Cyber-physical systems and their security issues. Comput. Ind. 2018, 100, 212–223. [Google Scholar] [CrossRef]
  3. Tyson, D. Security Convergence: Managing Enterprise Security Risk; Butterworth-Heinemann: Boston, MA, USA, 2007. [Google Scholar]
  4. Cybersecurity and Infrastructure Security Agency (CISA). Cybersecurity and Physical Security Convergence  . CISA: Washington, DC, USA, 2021. Available online: https://www.cisa.gov/sites/default/files/publications/Cybersecurity%2520and%2520Physical%2520Security%2520Convergence_508_01.05.2021.pdf.
  5. Salahdine, F.; Kaabouch, N. Social Engineering Attacks: A Survey. Future Internet 2019, 11, 89. [Google Scholar] [CrossRef]
  6. Akeiber, H.J. The Evolution of Social Engineering Attacks: A Cybersecurity Engineering Perspective. Al-Rafidain J. Eng. Sci. 2025, 3, 294–316. [Google Scholar] [CrossRef]
  7. Anti, E.; Rousi, R. Mitigating Insider Threats in Cybersecurity: A Design Thinking Approach. Proceedings of TKTP 2025: Annual Doctoral Symposium of Computer Science CEUR Workshop Proceedings, Helsinki, Finland, 2–3 June 2025; Vol. 4181. Available online: https://ceur-ws.org/Vol-4181/paper11.pdf.
  8. Riskhan, B.; Raufi, A.M.; Usmani, M.H. Physical Security to Cybersecurity (Challenges and Implications in the Modern Digital Landscape). J. Electr. Syst. 2024, 20, 692–702. [Google Scholar] [CrossRef]
  9. Ingelbrecht, N.; Bangurah, I. Emerging Trend: Convergence of Cyber and Physical Security—Harnessing the Disruption Opportunity  . Gartner. 2025. Available online: https://www.gartner.com/en/documents/6335579.
  10. Kapoor, S.; Kumar, S.; Vardhan, H. Cyber Security of OT Networks: A Tutorial and Overview. arXiv 2025, arXiv:2502.14017. [Google Scholar] [CrossRef]
  11. McCreight, T.; Leece, D. Physical Security and IT Convergence: Managing the Cyber-Related Risks. J. Bus. Contin. Emerg. Plan. 2016, 10, 18–30. [Google Scholar] [CrossRef]
  12. Hromada, M.; Rehak, D.; Skobiej, B.; Bajer, M. Converged Security and Information Management System as a Tool for Smart City Infrastructure Resilience Assessment. Smart Cities 2023, 6, 2221–2244. [Google Scholar] [CrossRef]
  13. Sennewald, C.A.; Baillie, C. Convergence in Security Management. In Effective Security Management, 7th ed.; Butterworth-Heinemann: Cambridge, MA, USA, 2021; pp. 275–280. [Google Scholar] [CrossRef]
  14. Willison, J.; Gill, J. Security Convergence: A Unified Approach to Modern Security Challenges  . Kaseware. 2025. Available online: https://info.kaseware.com/hubfs/Gated%20Assets/PDF_ALL_SecurityConvergenceGuide_2025Q1_Guide.pdf.
  15. Darnell, D.; Uchida, C.D.; Swatt, M.L.; Anderson, K. Security Convergence and Business Continuity: Reflecting on the Pandemic Experience  . ASIS Foundation. 2022. Available online: https://www.asisonline.org/globalassets/foundation/documents/research/9-22-convergence-report-2.pdf.
  16. National Institute of Standards and Technology (NIST). The NIST Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper (CSWP) NIST CSWP 29; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef]
  17. CMMI Institute. CMMI Institute  . Available online: https://cmmiinstitute.com/.
  18. International Organization for Standardization (ISO); International Electrotechnical Commission (IEC). ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements; ISO. Geneva, Switzerland, 2022.
  19. International Organization for Standardization (ISO). ISO 22301:2024 Security and Resilience—Business Continuity Management Systems—Requirements; ISO. Geneva, Switzerland, 2024.
  20. Javed, Y.; Felemban, M.; Shawly, T.; Kobes, J.; Ghafoor, A. A Partition-Driven Integrated Security Architecture for Cyber-Physical Systems. arXiv 2019, arXiv:1901.03018. [Google Scholar] [CrossRef]
  21. Lian, Z.; Shi, P.; Chen, M. A Survey on Cyber-Attacks for Cyber-Physical Systems: Modeling, Defense, and Design. IEEE Internet Things J. 2025, 12(2), 1471–1483. [Google Scholar] [CrossRef]
  22. Huang, S.; Poskitt, C.M.; Shar, L.K. Security Modelling for Cyber-Physical Systems: A Systematic Literature Review. arXiv 2025, arXiv:2404.07527. [Google Scholar] [CrossRef]
  23. Tovkun, Y.; Semerenska, V.; Adamov, A. An Overview of Cyber Attacks on Critical Cyber-Physical Systems and Government Infrastructures. Secur. Saf. 2026, 5, 2026002. [Google Scholar] [CrossRef]
  24. Canadian Centre for Cyber Security. Ransomware Threat Outlook 2025–2027  . Government of Canada. 2026. Available online: https://www.cyber.gc.ca/en/guidance/ransomware-threat-outlook-2025-2027.
  25. Büyüközkan, G.; Güler, M. Cybersecurity Maturity Model: Systematic Literature Review and a Proposed Model. Technol. Forecast. Soc. Change 2025, 213, 123996. [Google Scholar] [CrossRef]
  26. Aytekin, A.; Coşkun, A.; Dursun, M. Evolving Maturity Models for Electric Power System Cybersecurity: A Case-Driven Framework Gap Analysis. Appl. Sci. 2026, 16, 177. [Google Scholar] [CrossRef]
  27. Brezavšček, A.; Baggia, A. Recent Trends in Information and Cyber Security Maturity Assessment: A Systematic Literature Review. Systems 2025, 13, 52. [Google Scholar] [CrossRef]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.