<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">jsea</journal-id>
      <journal-title-group>
        <journal-title>Journal of Software Engineering and Applications</journal-title>
      </journal-title-group>
      <issn pub-type="epub">1945-3124</issn>
      <issn pub-type="ppub">1945-3116</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/jsea.2026.195009</article-id>
      <article-id pub-id-type="publisher-id">jsea-151142</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>A Conceptual Framework to Illustrate Cybersecurity Workforce Gaps and the Resilience of Critical Digital Infrastructure— A Multi-Sector Case Study</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Osarenkhoe</surname>
            <given-names>Samuel-Noah</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-0477-855X</contrib-id>
          <name name-style="western">
            <surname>Osarenkhoe</surname>
            <given-names>Aihie</given-names>
          </name>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="fn" rid="fn-equal">†</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Global Partners LP, Waltham, MA, USA </aff>
      <aff id="aff2"><label>2</label> Department of Business &amp; Economic Studies, University of Gävle, Gävle, Sweden </aff>
      <author-notes>
        <fn fn-type="equal" id="fn-equal">
          <p>These authors contributed equally to this work.</p>
        </fn>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The authors declare no financial or organizational conflicts related to the content of this manuscript.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>06</day>
        <month>05</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>05</month>
        <year>2026</year>
      </pub-date>
      <volume>19</volume>
      <issue>05</issue>
      <fpage>171</fpage>
      <lpage>203</lpage>
      <history>
        <date date-type="received">
          <day>21</day>
          <month>03</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>03</day>
          <month>05</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>06</day>
          <month>05</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/jsea.2026.195009">https://doi.org/10.4236/jsea.2026.195009</self-uri>
      <abstract>
        <p>This study examines how cybersecurity workforce shortages undermine the resilience of critical digital infrastructure, with emphasis on the energy sector and comparisons to finance, transportation, and telecommunications. It reframes the skills gap as a systemic risk that weakens organizations’ capacity to prevent, manage, and recover from cyber incidents. Using a two‑phase qualitative approach—a PRISMA-guided literature review (n = 70) and multi‑sector case studies (n = 5) based on 22 interviews—the analysis draws on socio‑technical systems theory. Findings show that resilience is limited less by missing technical controls than by a lack of hybrid professionals who can bridge Information Technology (IT), Operational Technology (OT) and Artificial Intelligence domains. Shortages slow incident response, impede risk communication, and reduce coordination. The study concludes that workforce capability is central to infrastructure resilience, requiring sector-aligned training, interdisciplinary collaboration, and continuous upskilling. Policy measures should support cross‑sector training and educational reform. Limitations include the small qualitative sample, suggesting future global and AI‑human studies.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Cybersecurity Workforce Shortage</kwd>
        <kwd>Critical Infrastructure Resilience</kwd>
        <kwd>Socio-Technical Systems</kwd>
        <kwd>Operational Technology</kwd>
        <kwd>Hybrid-Skilled Professionals</kwd>
        <kwd>PRISMA Systematic Literature Review</kwd>
        <kwd>Multi-Sector Case Study</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction and Background to the Research Problem</title>
      <p>The accelerating digitization of critical infrastructure sectors—including energy, finance, transportation, and telecommunications—has intensified reliance on complex, interconnected cyber-physical systems [<xref ref-type="bibr" rid="B1">1</xref>]-[<xref ref-type="bibr" rid="B3">3</xref>]. While this transformation enhances operational efficiency and system integration, it simultaneously expands the cyber threat landscape, exposing essential services to risks that extend beyond technical disruption to include national security, economic stability, and public trust [<xref ref-type="bibr" rid="B4">4</xref>]-[<xref ref-type="bibr" rid="B6">6</xref>].</p>
      <p>In this evolving context, cybersecurity challenges are increasingly understood as socio-technical in nature, arising from the interaction of people, technologies, organizational processes, and regulatory environments [<xref ref-type="bibr" rid="B7">7</xref>][<xref ref-type="bibr" rid="B8">8</xref>]. The convergence of Information Technology (IT), Operational Technology (OT), and emerging domains such as Artificial Intelligence (AI) has further intensified system complexity, requiring coordinated expertise that spans technical, operational, and strategic domains [<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B9">9</xref>][<xref ref-type="bibr" rid="B10">10</xref>]. As a result, cybersecurity effectiveness is no longer determined solely by technological sophistication, but by the capacity of organizations to align human and technical components within complex operational settings.</p>
      <p>A persistent and critical constraint across these sectors is the global shortage of cybersecurity professionals. Although demand for cybersecurity expertise continues to grow, the available workforce remains insufficient in both scale and capability [<xref ref-type="bibr" rid="B11">11</xref>][<xref ref-type="bibr" rid="B12">12</xref>]. Importantly, this shortage reflects not only a numerical deficit but also a qualitative gap in hybrid-skilled professionals capable of bridging IT, OT, AI, and organizational functions [<xref ref-type="bibr" rid="B13">13</xref>][<xref ref-type="bibr" rid="B14">14</xref>]. Without such integrative expertise, even well-designed cybersecurity frameworks and advanced tools cannot be effectively operationalized in real-world environments [<xref ref-type="bibr" rid="B4">4</xref>][<xref ref-type="bibr" rid="B15">15</xref>].</p>
      <p>The implications of this workforce gap are particularly pronounced in the energy sector, where legacy operational technologies, safety-critical processes, and strict regulatory environments create uniquely complex cybersecurity challenges [<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B16">16</xref>]. In such contexts, cybersecurity decisions must balance risk mitigation with the continuity of essential services, such as electricity and fuel supply. However, similar workforce-related constraints—such as delayed incident response, coordination failures, and skill mismatches—have also been observed in other critical sectors, including transportation [<xref ref-type="bibr" rid="B6">6</xref>], finance [<xref ref-type="bibr" rid="B5">5</xref>], healthcare [<xref ref-type="bibr" rid="B17">17</xref>], and telecommunications [<xref ref-type="bibr" rid="B18">18</xref>]. These recurring patterns suggest that workforce capability may represent a systemic determinant of resilience across sectors, rather than a context-specific issue.</p>
      <p>Despite growing awareness of cybersecurity workforce shortages, existing research has largely focused on technical controls, policy frameworks, or generalized workforce metrics [<xref ref-type="bibr" rid="B1">1</xref>][<xref ref-type="bibr" rid="B2">2</xref>][<xref ref-type="bibr" rid="B14">14</xref>]. There remains limited empirical understanding of how workforce capability shapes the operational resilience of cybersecurity practices, particularly in high-risk, regulated environments such as energy. Furthermore, cross-sector comparative research remains underdeveloped, leaving unclear which workforce-related challenges are systemic and which are shaped by sector-specific socio-technical conditions.</p>
      <p>To address this gap, this study adopts a Socio-Technical Systems (STS) perspective [<xref ref-type="bibr" rid="B7">7</xref>][<xref ref-type="bibr" rid="B19">19</xref>] and employs a multi-method qualitative design combining a PRISMA-guided systematic literature review with empirical case studies across the energy, transportation, finance, and telecommunications sectors. While maintaining a primary analytical focus on the energy sector, the inclusion of non-energy cases serves a deliberate comparative purpose. These cases function as analytical contrasts and parallels, enabling the identification of recurring cross-sector mechanisms—such as hybrid skill shortages, coordination breakdowns, and delayed incident response—while clarifying how the energy sector’s distinctive characteristics amplify or reshape these dynamics.</p>
      <p>Through this comparative approach, the study reframes the cybersecurity workforce gap not merely as a staffing issue, but as a systemic socio-technical constraint on infrastructure resilience, affecting how organizations anticipate, manage, and recover from cyber incidents across critical sectors.</p>
      <p><italic><bold>Research</bold></italic><italic><bold>Question</bold></italic></p>
      <p>In response to the identified research gap, this study is guided by the following overarching research question:</p>
      <p>RQ: How do cybersecurity workforce shortages affect the resilience of critical digital infrastructure across sectors, and how are these effects shaped by the socio-technical characteristics of the energy sector?</p>
      <p>This question reflects the need to understand cybersecurity workforce capability as a systemic factor influencing resilience across diverse operational environments [<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B14">14</xref>][<xref ref-type="bibr" rid="B20">20</xref>]. It also recognizes that while workforce-related challenges may exhibit common patterns across sectors, their manifestation is mediated by sector-specific conditions, such as regulatory frameworks, technological architectures, and operational priorities [<xref ref-type="bibr" rid="B4">4</xref>][<xref ref-type="bibr" rid="B16">16</xref>].</p>
      <p>To address this question, the study adopts a comparative multi-sector design. Cases from transportation, finance, and telecommunications are used to identify cross-sector patterns of workforce-related constraints, including hybrid skill shortages, communication breakdowns, and delays in incident detection and response [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B6">6</xref>][<xref ref-type="bibr" rid="B18">18</xref>]. These patterns serve as a comparative baseline, enabling the study to distinguish between systemic challenges and those that are uniquely intensified within the energy sector, where legacy OT systems, safety-critical operations, and risk-averse regulatory cultures shape cybersecurity practice [<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B16">16</xref>].</p>
      <p><italic><bold>Research</bold></italic><italic><bold>Objectives</bold></italic></p>
      <p>To systematically synthesize the literature on cybersecurity workforce gaps and their implications for infrastructure resilience using a PRISMA-based methodology [<xref ref-type="bibr" rid="B14">14</xref>][<xref ref-type="bibr" rid="B21">21</xref>]. To analyze how cybersecurity workforce shortages affect operational cybersecurity practices across multiple critical infrastructure sectors, including energy, transportation, finance, and telecommunications. To identify both cross-sector patterns and sector-specific dynamics - particularly in the energy sector—that shape the relationship between workforce capability and resilience. To develop a socio-technical conceptual framework illustrating how cybersecurity workforce capability underpins resilient critical digital infrastructure [<xref ref-type="bibr" rid="B7">7</xref>][<xref ref-type="bibr" rid="B8">8</xref>].</p>
      <p><bold>Table 1</bold> highlights that, while prior work addresses frameworks and technical tools [<xref ref-type="bibr" rid="B1">1</xref>]-[<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B14">14</xref>], it often overlooks how workforce gaps disrupt operational cybersecurity in critical sectors. This study fills this gap by offering empirical evidence of these disruptions in energy, transportation, finance, and telecommunications.</p>
      <p><bold>Table 1</bold><bold>.</bold> A synopsis of contributions and gaps filled in this study.</p>
      <table-wrap id="tbl1">
        <label>Table 1</label>
        <table>
          <tbody>
            <tr>
              <td>
                <bold>ASPECT</bold>
              </td>
              <td>
                <bold>DETAILS</bold>
              </td>
            </tr>
            <tr>
              <td>
                <bold>Research</bold>
                <bold>Gap</bold>
                <bold>Filled</bold>
              </td>
              <td>
                Addresses the lack of empirical research on how workforce shortages disrupt cybersecurity operations in critical infrastructure [
                <xref ref-type="bibr" rid="B14">14</xref>
                ][
                <xref ref-type="bibr" rid="B22">22</xref>
                ][
                <xref ref-type="bibr" rid="B23">23</xref>
                ].Fills the void in cross-sectoral analysis of hybrid skill needs and operational resilience [
                <xref ref-type="bibr" rid="B9">9</xref>
                ][
                <xref ref-type="bibr" rid="B10">10</xref>
                ].Extends beyond existing literature that focuses on technical tools or generic workforce metrics by integrating sector-specific, operational, and human factors [
                <xref ref-type="bibr" rid="B1">1</xref>
                ][
                <xref ref-type="bibr" rid="B2">2</xref>
                ].Responds to calls for context-aware, interdisciplinary approaches to cybersecurity capability [
                <xref ref-type="bibr" rid="B3">3</xref>
                ][
                <xref ref-type="bibr" rid="B12">12</xref>
                ][
                <xref ref-type="bibr" rid="B20">20</xref>
                ].
              </td>
            </tr>
            <tr>
              <td>
                <bold>Contribution</bold>
              </td>
              <td>
                Reframes the cybersecurity workforce gap as a socio-technical resilience issue, not just a staffing problem [
                <xref ref-type="bibr" rid="B3">3</xref>
                ][
                <xref ref-type="bibr" rid="B14">14</xref>
                ].Develops a conceptual framework grounded in Socio-Technical Systems (STS) theory to illustrate how workforce capability underpins infrastructure resilience [
                <xref ref-type="bibr" rid="B8">8</xref>
                ][
                <xref ref-type="bibr" rid="B15">15</xref>
                ][
                <xref ref-type="bibr" rid="B24">24</xref>
                ].Provides empirical evidence from five critical sectors (energy, transport, finance, telecom) showing how hybrid skill shortages disrupt incident response and operational continuity [
                <xref ref-type="bibr" rid="B4">4</xref>
                ][
                <xref ref-type="bibr" rid="B22">22</xref>
                ].Offers policy-relevant insights through a causal impact pathway linking workforce shortages to systemic vulnerabilities [
                <xref ref-type="bibr" rid="B12">12</xref>
                ].
              </td>
            </tr>
          </tbody>
        </table>
      </table-wrap>
      <p>It integrates technical, organizational, and human dimensions into a unified framework, addressing calls for more context-aware interdisciplinary approaches to cybersecurity [<xref ref-type="bibr" rid="B12">12</xref>][<xref ref-type="bibr" rid="B22">22</xref>]. By reconceptualizing the cybersecurity workforce gap as an issue of resilience, this study emphasizes the need for hybrid professionals who can bridge cybersecurity expertise with sector-specific knowledge.</p>
      <p>Consequently, this research advances the field by demonstrating that workforce capacity is not a peripheral concern, but a foundational element of cybersecurity resilience in critical infrastructure systems.</p>
    </sec>
    <sec id="sec2">
      <title>2. Theoretical Background and Literature Review</title>
      <p><italic><bold>Socio</bold></italic><bold>-</bold><italic><bold>Technical</bold></italic><italic><bold>Systems</bold></italic><italic><bold>Theory</bold></italic></p>
      <p>Sociotechnical Systems (STS) theory offers a valuable foundation for understanding how human and technical factors interact in cybersecurity. Developed by Trist and Emery and expanded through various applications [<xref ref-type="bibr" rid="B7">7</xref>][<xref ref-type="bibr" rid="B19">19</xref>], STS emphasizes that complex systems, such as those supporting critical digital infrastructures, comprise interconnected social and technical elements functioning within broader environments.</p>
      <p>In cybersecurity, STS frames organizations not as purely technical entities but as integrated socio-technical systems in which people, processes, tools, and environmental factors collectively influence outcomes. The joint optimization principle, a core of STS, states that neither social nor technical components alone can achieve optimal results; both must evolve together. Optimizing one dimension (e.g., technology alone) may yield local benefits, but can leave the broader system suboptimal or exposed, creating a socio-technical gap [<xref ref-type="bibr" rid="B8">8</xref>].</p>
      <p>STS also explains why persistent cybersecurity skill shortages are more common than hiring or training problems. Capabilities arise from alignment across skilled personnel, technology, organizational structure, and external conditions, such as regulation, culture, and policy. Critical infrastructure-from energy to finance and transportation-depends on this alignment to confront increasingly adaptive and intelligent threats.</p>
      <p>From an STS perspective, developing a conceptual framework to analyze organizational practices across the social, technical, and environmental domains is highly applicable [<xref ref-type="bibr" rid="B3">3</xref>]. Cybersecurity professionals must possess not only technical expertise but also the ability to work across functions, align with organizational objectives, and integrate controls into broader mission-critical operations [<xref ref-type="bibr" rid="B14">14</xref>][<xref ref-type="bibr" rid="B25">25</xref>].</p>
      <p><italic><bold>Relevance</bold></italic><italic><bold>of</bold></italic><italic><bold>Socio</bold></italic><bold>-</bold><italic><bold>Technical</bold></italic><italic><bold>Theory</bold></italic><italic><bold>to</bold></italic><italic><bold>This</bold></italic><italic><bold>Study</bold></italic></p>
      <p>This study adopts the STS lens to examine how cybersecurity workforce shortages affect digital infrastructure resilience. The theory is particularly relevant to the energy sector—and, by extension, other critical sectors-where legacy systems, regulatory complexity, and emerging technologies intersect. STS provides a framework for assessing how workforce gaps disrupt not just technical tasks but also the broader socio-technical system needed for resilient cybersecurity.</p>
      <sec id="sec2dot1">
        <title>Literature Review</title>
        <p><italic><bold>Resilience</bold></italic><italic><bold>and</bold></italic><italic><bold>the</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>Skills</bold></italic><italic><bold>Gap</bold></italic></p>
        <p>Resilience in critical digital infrastructure, particularly energy, is increasingly threatened by a persistent shortage of cybersecurity professionals. This gap is more than a technical deficit; it is a systemic risk to cybersecurity frameworks [<xref ref-type="bibr" rid="B3">3</xref>][<xref ref-type="bibr" rid="B26">26</xref>]. Cybersecurity is not solely a technical concern, but also a managerial and economic concern [<xref ref-type="bibr" rid="B4">4</xref>][<xref ref-type="bibr" rid="B5">5</xref>]. </p>
        <p>NIST [<xref ref-type="bibr" rid="B27">27</xref>] emphasizes managerial controls and staff awareness [<xref ref-type="bibr" rid="B23">23</xref>], while ongoing threat evolution necessitates continuous updates to skills and policies [<xref ref-type="bibr" rid="B28">28</xref>]. The NIST “Information Security Handbook” supports agency managers in implementing effective security programmes [<xref ref-type="bibr" rid="B28">28</xref>]. Furthermore, human behavior and perception influence effectiveness [<xref ref-type="bibr" rid="B17">17</xref>], indicating that a sociotechnical approach is essential. Skill shortages across sectors limit efforts to operationalize frameworks, especially in highly regulated and high-risk contexts, such as energy [<xref ref-type="bibr" rid="B20">20</xref>].</p>
        <p><italic><bold>Cybersecurity</bold></italic><italic><bold>Workforce</bold></italic><italic><bold>Capability</bold></italic></p>
        <p>Workforce capability is central to infrastructure resilience. Malatji <italic>et al</italic>. [<xref ref-type="bibr" rid="B3">3</xref>] presented a 29-domain model based on NIST [<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B29">29</xref>], covering areas such as cloud, IoT, and industrial cybersecurity [<xref ref-type="bibr" rid="B24">24</xref>], but noted critical gaps in practical applications. Khaw <italic>et al</italic>. [<xref ref-type="bibr" rid="B14">14</xref>] identified four capability pillars—individual, organizational, technological, and governmental—that form an interacting ecosystem rather than isolated skill sets.</p>
        <p>Otoom <italic>et al</italic>. [<xref ref-type="bibr" rid="B30">30</xref>] promoted EduCERT, a collaborative educational framework for cross-sector knowledge exchanges. Security culture is also vital, yet is often overlooked in training [<xref ref-type="bibr" rid="B31">31</xref>]. Haney and Lutters [<xref ref-type="bibr" rid="B13">13</xref>][<xref ref-type="bibr" rid="B26">26</xref>] highlighted the importance of cybersecurity advocates who require soft skills, such as communication and persuasion, which are underrepresented in traditional curricula.</p>
        <p>Due to the ever-evolving nature of cybersecurity [<xref ref-type="bibr" rid="B14">14</xref>][<xref ref-type="bibr" rid="B32">32</xref>], adaptability and continuous learning are critical. Economic incentives should also be considered to support talent retention and development [<xref ref-type="bibr" rid="B33">33</xref>]. Thus, workforce capability encompasses not only technical knowledge, but also culture, attitude, and economic sustainability.</p>
        <p><italic><bold>Sector</bold></italic><bold>-</bold><italic><bold>Specific</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>Needs</bold></italic></p>
        <p>Cybersecurity needs differ significantly by sector owing to varying industrial, technological, and regulatory contexts. In the energy sector, convergence between Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA), and the IoT introduces complex vulnerabilities [<xref ref-type="bibr" rid="B3">3</xref>]. SCADA is a type of Industrial Control System (ICS) used to monitor and control infrastructure and facility-based processes. These systems are essential for sectors such as energy, water, transportation, and manufacturing. An ICS is a broader term that includes both SCADA and Distributed Control Systems (DCSs). While SCADA involves centralized control with remote sensors and operator terminals, DCS distributes control functions across processors located near the instruments or devices that collect the data. Both play a critical role in monitoring and managing infrastructure systems [<xref ref-type="bibr" rid="B28">28</xref>].</p>
        <p>Thomas and Sule [<xref ref-type="bibr" rid="B4">4</xref>] argued that technical skills alone cannot address these complexities. Thus, holistic frameworks that integrate compliance, safety, and risk management are required. Yeboah-Ofori and Opoku-Boateng [<xref ref-type="bibr" rid="B34">34</xref>] noted that multivendor environments further complicate workforce requirements, demanding expertise in interoperability and contracts.</p>
        <p>The other sectors face parallel challenges. Healthcare contends with electronic health record systems vulnerabilities, similar to SCADA systems or issues [<xref ref-type="bibr" rid="B35">35</xref>]. Thus, Electronic Health Records (EHR) are digital patient records. Finance suffers from high staff turnover, which disrupts privacy and compliance [<xref ref-type="bibr" rid="B5">5</xref>]. Railways depend on workforce awareness to secure transport systems [<xref ref-type="bibr" rid="B6">6</xref>], while in e-government, skill gaps delay secure service provision [<xref ref-type="bibr" rid="B28">28</xref>].</p>
        <p>Cultural perceptions are also important. Trust and user values shape adoption [<xref ref-type="bibr" rid="B24">24</xref>][<xref ref-type="bibr" rid="B36">36</xref>], and robust frameworks can fail without management support [<xref ref-type="bibr" rid="B23">23</xref>]. Thus, sector-specific needs combine the technological, human, cultural, and regulatory components.</p>
        <p><italic><bold>Operationalizing</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>in</bold></italic><italic><bold>High</bold></italic><bold>-</bold><italic><bold>Risk</bold></italic><italic><bold>Environments</bold></italic></p>
        <p>High-risk regulated sectors face difficulties in translating frameworks into operational practices. Although standards exist [<xref ref-type="bibr" rid="B4">4</xref>], workforce shortages hamper consistent implementation. Legacy systems complicate staff efforts to apply compliance controls [<xref ref-type="bibr" rid="B3">3</xref>]. Orji and U-Dominic [<xref ref-type="bibr" rid="B24">24</xref>] underscored the need for cyber risk management in 3PLs to support social sustainability in supply chains. However, persistent challenges continue to impede cyber-security. These barriers are worth exploring further.</p>
        <p>Friday <italic>et al</italic>. [<xref ref-type="bibr" rid="B18">18</xref>] emphasize that resilience depends on inter-firm coordination, especially as infrastructure supply chains become more integrated. Bechara and Schuch [<xref ref-type="bibr" rid="B15">15</xref>] show that international frameworks work only if the staff can adapt them locally. Managerial practices are essential [<xref ref-type="bibr" rid="B23">23</xref>], and ongoing reassessment is required to address shifting threats [<xref ref-type="bibr" rid="B32">32</xref>]. Behavioral factors also matter; user perceptions directly influence success [<xref ref-type="bibr" rid="B36">36</xref>]. Effective cybersecurity in such settings requires technical, managerial, and cultural alignments.</p>
        <p><italic><bold>Emerging</bold></italic><italic><bold>Themes</bold></italic><bold>:</bold><italic><bold>AI</bold></italic><bold>,</bold><italic><bold>Industry</bold></italic><italic><bold>4</bold></italic><bold>.</bold><italic><bold>0</bold></italic><bold>,</bold><italic><bold>and</bold></italic><italic><bold>Cyber</bold></italic><bold>-</bold><italic><bold>Physical</bold></italic><italic><bold>Convergence</bold></italic></p>
        <p>New technologies have increased workforce demand. Graham [<xref ref-type="bibr" rid="B9">9</xref>] notes that AI-driven security requires skills in machine learning, ethics, and data science. Industry 4.0 calls for professionals who combine cybersecurity and engineering expertise [<xref ref-type="bibr" rid="B16">16</xref>]. Lifelong learning must be embedded in order to keep pace [<xref ref-type="bibr" rid="B10">10</xref>][<xref ref-type="bibr" rid="B26">26</xref>].</p>
        <p>The energy sector’s shift to smart grids reflects broader trends in cyber-physical convergence in smart cities [<xref ref-type="bibr" rid="B37">37</xref>] and medical IoT [<xref ref-type="bibr" rid="B17">17</xref>], where more connected systems create greater vulnerabilities. Skills must be constantly renewed [<xref ref-type="bibr" rid="B32">32</xref>] and policies must support long-term learning [<xref ref-type="bibr" rid="B26">26</xref>]. NIST frameworks [<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B29">29</xref>] provide guidance, but depend on an agile, well-trained workforce.</p>
        <p><italic><bold>Cross</bold></italic><bold>-</bold><italic><bold>Sector</bold></italic><italic><bold>Insights</bold></italic><italic><bold>and</bold></italic><italic><bold>Workforce</bold></italic><italic><bold>Stress</bold></italic></p>
        <p>Workforce stress is an underappreciated vulnerability. Singh <italic>et al</italic>. [<xref ref-type="bibr" rid="B22">22</xref>] showed that pressure-filled environments degrade performance and cause attrition, exacerbating skill shortage. Spruit [<xref ref-type="bibr" rid="B12">12</xref>] suggests standardized frameworks, such as European e-Competence Framework (European e-CF), to align expectations and reduce overload. The European e-Competence Framework (e-CF) is a standardized reference that defines 40 Information Communication Technology (ICT) professional competences, helping to align roles and responsibilities across organizations and countries. It supports HR processes, such as recruitment, training, and career development, while also reducing role ambiguity by clearly outlining expectations.</p>
        <p>Kour and Karim [<xref ref-type="bibr" rid="B6">6</xref>] found that railway staff are overwhelmed by compliance burdens, impacting morale. Chen and Zahedi [<xref ref-type="bibr" rid="B36">36</xref>] stressed that perceptions and attitudes shape stress outcomes. Lawelai <italic>et al</italic>. [<xref ref-type="bibr" rid="B26">26</xref>] proposed economic support for mental health, whereas Asbaş and Tuzlukaya [<xref ref-type="bibr" rid="B32">32</xref>] emphasized adaptable training to reduce burnout. Managerial commitment is crucial for creating supportive environments [<xref ref-type="bibr" rid="B17">17</xref>]. Addressing well-being is essential to address technical proficiency.</p>
        <p><italic><bold>Implications</bold></italic><italic><bold>from</bold></italic><italic><bold>Extant</bold></italic><italic><bold>Literature</bold></italic><italic><bold>for</bold></italic><italic><bold>Resilience</bold></italic><italic><bold>and</bold></italic><italic><bold>Policy</bold></italic></p>
        <p>The literature has consistently shown that cybersecurity workforce shortages erode infrastructure resilience. Insufficient staffing delays threat detection and recovery [<xref ref-type="bibr" rid="B16">16</xref>], undermines compliance [<xref ref-type="bibr" rid="B4">4</xref>], and reduces public trust [<xref ref-type="bibr" rid="B38">38</xref>]. Skill gaps also hinder the adoption of advanced tools such as AI [<xref ref-type="bibr" rid="B9">9</xref>].</p>
        <p>Policies alone are not sufficient. Managerial practices must align with regulatory goals [<xref ref-type="bibr" rid="B33">33</xref>], and financial and legislative support is necessary for workforce Orji and U-Dominic [<xref ref-type="bibr" rid="B24">24</xref>] advocated for policies attentive to culture and user perception. Lawelai <italic>et al</italic>. [<xref ref-type="bibr" rid="B26">26</xref>] underscored the importance of dynamic and evolving policies. Ultimately, policies should prioritize skill development, mental health, and workforce resilience to ensure secure, uninterrupted critical services.</p>
        <p><bold>Table 2</bold> presents a synthesized overview of the existing research, highlighting various viewpoints on the capabilities of the cybersecurity workforce and their influence on the resilience of critical infrastructure.</p>
        <p><bold>Table 2</bold><bold>.</bold> Summary of key literature insights.</p>
        <table-wrap id="tbl2">
          <label>Table 2</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Extant</bold>
                  <bold>Literature</bold>
                </td>
                <td>
                  <bold>Main</bold>
                  <bold>Focus</bold>
                </td>
                <td>
                  <bold>Key</bold>
                  <bold>Findings</bold>
                </td>
              </tr>
              <tr>
                <td>
                  Malatji
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B3">3</xref>
                  ], Cybersecurity capabilities for critical infrastructure resilience
                </td>
                <td>Capability frameworks for critical infrastructure</td>
                <td>Identify 29 domains adapted from NIST but note skills shortage</td>
              </tr>
              <tr>
                <td>
                  Khaw
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B14">14</xref>
                  ], Systematic review of cybersecurity frameworks
                </td>
                <td>Cybersecurity capability pillars</td>
                <td>Highlight individual, organizational, technological, and governmental capability</td>
              </tr>
              <tr>
                <td>
                  Haney &amp; Lutters [
                  <xref ref-type="bibr" rid="B13">13</xref>
                  ], Cybersecurity advocates in practice
                </td>
                <td>Human factors in cybersecurity</td>
                <td>Importance of advocates with communication skills</td>
              </tr>
              <tr>
                <td>
                  Thomas &amp; Sule [
                  <xref ref-type="bibr" rid="B4">4</xref>
                  ], Service lens on cybersecurity continuity
                </td>
                <td>Service-based approaches</td>
                <td>Link resilience to continuity management</td>
              </tr>
              <tr>
                <td>
                  Graham [
                  <xref ref-type="bibr" rid="B9">9</xref>
                  ], AI in cybersecurity workforce
                </td>
                <td>AI skills in cybersecurity</td>
                <td>AI integration requires new workforce competencies</td>
              </tr>
              <tr>
                <td>
                  Kour &amp; Karim [
                  <xref ref-type="bibr" rid="B6">6</xref>
                  ], Railway cybersecurity maturity
                </td>
                <td>Cybersecurity maturity in transport</td>
                <td>Workforce maturity is critical to protecting transport systems</td>
              </tr>
              <tr>
                <td>
                  Otoom
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B30">30</xref>
                  ], EduCERT framework
                </td>
                <td>Cybersecurity education ecosystems</td>
                <td>Collaborative higher education models to build workforce skills</td>
              </tr>
              <tr>
                <td>
                  Bechara &amp; Schuch [
                  <xref ref-type="bibr" rid="B15">15</xref>
                  ], Global frameworks for cybersecurity resilience
                </td>
                <td>Global policy frameworks</td>
                <td>Need for local skills to implement international standards</td>
              </tr>
              <tr>
                <td>
                  Yeboah-Ofori &amp;Opoku-Boateng [
                  <xref ref-type="bibr" rid="B34">34</xref>
                  ], Cybercrime in evolving environments
                </td>
                <td>Cybercrime frameworks</td>
                <td>Skills needed to manage evolving energy cybercrime risk</td>
              </tr>
              <tr>
                <td>
                  Lawelai
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B26">26</xref>
                  ], Smart city cybersecurity policy
                </td>
                <td>Cybersecurity in smart cities</td>
                <td>Challenge in policy and skills alignment</td>
              </tr>
              <tr>
                <td>
                  Mwogosi &amp; Simba [
                  <xref ref-type="bibr" rid="B35">35</xref>
                  ], Health EHR cybersecurity
                </td>
                <td>Health sector cybersecurity</td>
                <td>Electronic health records have parallel skills gaps</td>
              </tr>
              <tr>
                <td>
                  Singh
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B22">22</xref>
                  ], Cybersecurity workforce stress
                </td>
                <td>Workforce well-being</td>
                <td>High stress impacts retention and resilience</td>
              </tr>
              <tr>
                <td>
                  Bowen
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B23">23</xref>
                  ], NIST [
                  <xref ref-type="bibr" rid="B27">27</xref>
                  ][
                  <xref ref-type="bibr" rid="B29">29</xref>
                  ]
                </td>
                <td>Managerial cybersecurity controls</td>
                <td>Management support is essential for workforce effectiveness</td>
              </tr>
              <tr>
                <td>
                  Anderson &amp; Moore [
                  <xref ref-type="bibr" rid="B39">39</xref>
                  ], Economics of information security
                </td>
                <td>Economics of cybersecurity</td>
                <td>Incentives and costs shape workforce development</td>
              </tr>
              <tr>
                <td>
                  Chen &amp; Zahedi [
                  <xref ref-type="bibr" rid="B36">36</xref>
                  ], Security perceptions and behavior
                </td>
                <td>Human perceptions</td>
                <td>Perceptions of security influence adoption of practices</td>
              </tr>
              <tr>
                <td>
                  Spruit [
                  <xref ref-type="bibr" rid="B12">12</xref>
                  ], Competence frameworks in cybersecurity
                </td>
                <td>Cybersecurity education</td>
                <td>Proposes standardized frameworks to harmonize skills and reduce stress</td>
              </tr>
              <tr>
                <td>
                  Lnenicka
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B37">37</xref>
                  ], Cybersecurity in smart cities
                </td>
                <td>Smart infrastructure security</td>
                <td>Highlights governance and cross-sector collaboration</td>
              </tr>
              <tr>
                <td>
                  Xenakis
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B20">20</xref>
                  ], Addressing cybersecurity literacy
                </td>
                <td>Workforce literacy programs</td>
                <td>Recommends policy for critical infrastructure literacy skills</td>
              </tr>
              <tr>
                <td>
                  Stavrou &amp; Piki [
                  <xref ref-type="bibr" rid="B10">10</xref>
                  ], Lifelong learning for cybersecurity skills
                </td>
                <td>Continuous learning</td>
                <td>Emphasizes upskilling and workforce adaptability</td>
              </tr>
              <tr>
                <td>
                  Kandpal
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B5">5</xref>
                  ], Cybersecurity in digital finance
                </td>
                <td>Financial sector security</td>
                <td>Underscores privacy and workforce skills gaps in fintech environments</td>
              </tr>
              <tr>
                <td>
                  Younies &amp; Al‑Tawil [
                  <xref ref-type="bibr" rid="B40">40</xref>
                  ], Effect of cybercrime laws in UAE
                </td>
                <td>Cyber legislation and operational readiness</td>
                <td>Shows that legal frameworks require skilled enforcement personnel to be effective.</td>
              </tr>
              <tr>
                <td>
                  Radanliev
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B41">41</xref>
                  ], Artificial intelligence in cybersecurity
                </td>
                <td>AI-driven cybersecurity challenges</td>
                <td>Finds emerging AI skills are essential but significantly lacking in current workforce profiles.</td>
              </tr>
              <tr>
                <td>
                  Rangarajan
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B42">42</xref>
                  ], A roadmap to address burnout in cybersecurity profession
                </td>
                <td>Workforce well-being</td>
                <td>Offers multidimensional strategies to combat burnout and retain talent</td>
              </tr>
              <tr>
                <td>
                  Tallam [
                  <xref ref-type="bibr" rid="B43">43</xref>
                  ], The Cyber Immune System
                </td>
                <td>Adaptive cyber defense &amp; resilience</td>
                <td>Proposes adversarial testing as a mechanism to reinforce resilience—underscoring new skill paradigms</td>
              </tr>
              <tr>
                <td>
                  Walendy
                  <italic>et al</italic>
                  . [
                  <xref ref-type="bibr" rid="B44">44</xref>
                  ], Curriculum initiative for hardware reverse engineering (HRE)
                </td>
                <td>Hardware supply chain security</td>
                <td>Advocates integrating HRE education into cybersecurity curricula to secure infrastructure</td>
              </tr>
              <tr>
                <td>
                  Alevizos [
                  <xref ref-type="bibr" rid="B45">45</xref>
                  ], Complexity-informed cyber defenses
                </td>
                <td>Organizational complexity and defense optimization</td>
                <td>Introduces a model linking workforce planning and analytics to reduce defense complexity</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>Malatji <italic>et al</italic>. [<xref ref-type="bibr" rid="B3">3</xref>] and Khaw <italic>et al</italic>. [<xref ref-type="bibr" rid="B14">14</xref>] proposed comprehensive frameworks outlining the multidomain skills required to meet evolving cybersecurity challenges. Haney and Lutters [<xref ref-type="bibr" rid="B13">13</xref>] emphasized the importance of soft skills and human factors, while Graham [<xref ref-type="bibr" rid="B9">9</xref>] and Stavrou and Piki [<xref ref-type="bibr" rid="B10">10</xref>] highlighted competencies related to artificial intelligence and lifelong learning.</p>
        <p>Sector-specific studies such as Kour and Karim [<xref ref-type="bibr" rid="B6">6</xref>] in the railway sector and Mwogosi and Simba [<xref ref-type="bibr" rid="B35">35</xref>] in healthcare illustrate how workforce gaps are tied to the operational context of each domain. These findings challenge generic workforce models and suggest that tailored development strategies are necessary. Similarly, Lawelai <italic>et al</italic>. [<xref ref-type="bibr" rid="B26">26</xref>] and Lnenicka <italic>et al</italic>. [<xref ref-type="bibr" rid="B37">37</xref>] explored smart cities and demonstrated how governance and policy must be aligned with evolving workforce needs.</p>
        <p>This table also includes research on psychological well-being and stress among cybersecurity professionals. Singh <italic>et al</italic>. [<xref ref-type="bibr" rid="B22">22</xref>] and Spruit [<xref ref-type="bibr" rid="B12">12</xref>] showed that retention and mental health are integral to resilience, broadening the conventional focus on technical skills to encompass organizational culture and staff support. </p>
        <p>Policies and governance are central to this process. Bowen <italic>et al</italic>. [<xref ref-type="bibr" rid="B23">23</xref>] and Bechara and Schuch [<xref ref-type="bibr" rid="B15">15</xref>] argue that international frameworks and managerial practices are effective only when paired with capable and well-supported personnel. Anderson and Moore [<xref ref-type="bibr" rid="B39">39</xref>] added an economic lens, noting how incentives and cost structures influence recruitment, training, and retention.</p>
        <p>Collectively, <bold>Table 2</bold> underscores that addressing workforce gaps requires a holistic strategy that spans technical skills, sector-specific expertise, organizational well-being, and supportive policy infrastructure. A resilient cybersecurity ecosystem depends on a trained, motivated, and context-aware workforce that is supported both technically and psychologically.</p>
        <p><italic><bold>Synthesis</bold></italic><italic><bold>of</bold></italic><italic><bold>Literature</bold></italic><italic><bold>and</bold></italic><italic><bold>Research</bold></italic><italic><bold>Gaps</bold></italic></p>
        <p>The literature review highlights a multidimensional challenge linking cybersecurity skills gaps to infrastructure resilience. Evidence from the energy, health, finance, and transportation sectors confirms that workforce capability is central to cybersecurity effectiveness. However, this capability remains inconsistently developed across sectors, weakening the overall resilience. The convergence of IT and OT, the growth of Industry 4.0, and AI adoption amplify the demand for specialized skills. However, outdated training models, fragmented educational pipelines, and weak cross-sector collaboration have hindered workforce development. Additionally, psychological strain among cybersecurity staff increases burnout and attrition risk. Policy frameworks alone cannot secure infrastructure without a skilled workforce to implement them.</p>
        <p>Organizational and sectoral variations also prevent universal solutions. For instance, the energy sector relies on long-life cycle industrial control systems, creating mismatches with modern tools. Financial services face intense compliance and high staff turnover, and healthcare must secure systems without compromising patient care. These examples highlight the importance of sector-specific strategies.</p>
        <p>The skills gap also interacts with supply chain risk. Many energy organizations outsource IT services but lack in-house cybersecurity expertise to assess contractor practices and compound vulnerabilities. Supplier weaknesses can become entry points for attackers, as in other sectors.</p>
        <p>Finally, there is a lack of empirical research on how workforce shortages directly disrupt daily cybersecurity functions such as patching, scanning, detection, and response, especially in energy environments. Field studies and mixed-methods research can illuminate how technical deficits and human factors intersect in real-world settings.</p>
        <p>In a nutshell, cybersecurity workforce capability is a crucial and under-explored component of infrastructure resilience. Future research should develop sector-specific training models, investigate educational and career pathways, and address workforce well-being and policy mechanisms to build a sustainable and adaptive cybersecurity labor force.</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Methodology</title>
      <p><italic><bold>Research</bold></italic><italic><bold>Approach</bold></italic><italic><bold>and</bold></italic><italic><bold>Strategy</bold></italic></p>
      <p>This study used a multi-method qualitative approach to examine how cybersecurity workforce shortages affect operational resilience in critical digital infrastructure sectors. The research was conducted in two phases: a Systematic Literature Review (SLR) to identify knowledge gaps, followed by empirical fieldwork, including semi-structured interviews and documentary analysis to build detailed case studies.</p>
      <p>Adopts a structured iterative approach that enables the study to move beyond surface-level observations. This revealed deeper insights into how cybersecurity workforce shortages disrupt resilience in energy, transportation, and financial infrastructure. The integration of rigorous Systematic Literature Review (SLR) with empirical case studies allowed for the development of a context-sensitive understanding of the mechanisms through which staffing gaps, skill mismatches, and organizational structures shape cybersecurity outcomes.</p>
      <p><italic><bold>Systematic</bold></italic><italic><bold>Literature</bold></italic><italic><bold>Review</bold></italic></p>
      <p>A systematic literature review was carried out to map the current academic discourse on cybersecurity workforce shortages and their operational impacts. The review adhered to the PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) framework to ensure transparency and replicability. PRISMA flow diagram illustrating the study selection process is shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>.</p>
      <fig id="fig1">
        <label>Figure 1</label>
        <graphic xlink:href="https://html.scirp.org/file/9303497-rId17.jpeg?20260506025707" />
      </fig>
      <p><bold>Figure 1</bold><bold>.</bold> Conceptual framework showing how cybersecurity workforce capability interacts with sectoral demands, operational contexts, and emerging technologies to strengthen resilience in critical infrastructure.</p>
      <p><italic><bold>Search</bold></italic><italic><bold>Strategy</bold></italic><italic><bold>and</bold></italic><italic><bold>Inclusion</bold></italic><italic><bold>Criteria</bold></italic></p>
      <p>Databases searched included Scopus, IEEE Xplore, SpringerLink, and Emerald Insight. Articles published in English between 2015 and 2025 were eligible if they addressed the following:</p>
      <p>Cybersecurity workforce challenges in operational settings;Skill shortages or hybrid skill requirements (e.g., IT/OT convergence and AI/Machine Learning security);Cyber resilience or incident response in digital infrastructure.</p>
      <p>Exclusion criteria included conceptual papers without empirical data, articles that did not focus on workforce issues, and duplicates.</p>
      <p><italic><bold>Screening</bold></italic><italic><bold>and</bold></italic><italic><bold>Synthesis</bold></italic></p>
      <p>After removing duplicates, a three-stage screening process was followed: title/abstract review, full-text assessment, and risk-of-bias appraisal using adapted CASP (Critical Appraisal Skills Programme) criteria. Articles were evaluated for methodological rigor, including research design, clarity of aims, and robustness of the findings. Studies with substantial flaws or with weak evidence were excluded. </p>
      <p>The screening process yielded 70 articles. Three key patterns emerged:</p>
      <p>Workforce shortages delay incident detection and response.The demand for hybrid skills (e.g., cybersecurity + operational tech/data science) is increasing.There is limited empirical research on how shortages disrupt frontline operations.</p>
      <p>These insights informed the second phase: fieldwork exploring real-world workforce dynamics.</p>
      <p><italic><bold>PRISMA</bold></italic><italic><bold>Flow</bold></italic><italic><bold>Description</bold></italic></p>
      <p>To ensure transparency and replicability, the study followed the PRISMA (Preferred Reporting Items for Systematic Reviews and Meta-Analyses) guidelines. The selection process is summarized below:</p>
      <p>A total of <bold>120</bold><bold>records</bold> were initially identified across four databases (Scopus, IEEE Xplore, SpringerLink, and Emerald Insight). After removing duplicates, <bold>95</bold><bold>records</bold> remained for title and abstract screening. During this stage, <bold>15</bold><bold>studies</bold> were excluded because they were not directly related to cybersecurity workforce challenges, did not focus on critical infrastructure, or were purely conceptual without empirical evidence.</p>
      <p>Records screened (title/abstract) (n = 95).</p>
      <p>Records excluded (n = 15).</p>
      <p>Reasons: Not related to workforce (n = 6); Not critical infrastructure (n = 5); Conceptual only /no empirical data (n = 4). </p>
      <p>Full-text assessments were conducted on the remaining <bold>80</bold><bold>articles</bold>, applying inclusion criteria related to empirical relevance, methodological rigor, and focus on operational cybersecurity or resilience. At this stage, <bold>10</bold><bold>studies</bold> were excluded due to poor methodological quality, lack of relevance to resilience or operational contexts, or insufficient focus on cybersecurity workforce issues.</p>
      <p>Full-text articles assessed (n = 80).</p>
      <p>Full-text articles excluded (n = 10).</p>
      <p>Reasons: Weak methodology/insufficient rigor (n = 4); Not addressing resilience or operations (n = 3); Not focused on cybersecurity workforce issues (n = 3) </p>
      <p>The final sample consisted of <bold>70</bold><bold>studies</bold>, which formed the basis for thematic synthesis and informed the empirical phase of the research.</p>
      <p><italic><bold>Qualitative</bold></italic><italic><bold>Data</bold></italic><italic><bold>Collection</bold></italic><italic><bold>and</bold></italic><italic><bold>Case</bold></italic><italic><bold>Design</bold></italic></p>
      <p>A multiple case study design was employed to examine socio‑technical challenges in situ. Empirical material consisted of 22 semi‑structured interviews and organizational documents related to cybersecurity incidents in the energy, transportation, and financial sectors.</p>
      <p>The interviews were distributed across five cases, with each case informed by several participants according to sectoral relevance and access. Because many participants held overlapping operational responsibilities or possessed cross-sector experience, their contributions were not confined to single cases. As a result, individual interviews often provided insight that was applicable across multiple cases.</p>
      <p>Case narratives were therefore constructed through an integration of case-specific interview data, cross-case insights, and documentary evidence. This strategy enabled analytical depth while preserving coherence with the overall sample size (n = 22).</p>
      <p><italic><bold>Case</bold></italic><italic><bold>Selection</bold></italic><italic><bold>and</bold></italic><italic><bold>Construction</bold></italic></p>
      <p>The five cases were purposively selected to capture variation across critical infrastructure sectors while maintaining analytical comparability with the study’s primary focus on energy. Two cases represent the energy sector, while three cases were drawn from transportation, finance, and telecommunications to enable cross-sector comparison. Data was collected through 22 semi-structured interviews with participants occupying roles directly involved in cybersecurity operations and decision-making, including cybersecurity analysts, Security Operations Center (SOC) personnel, engineers (IT and OT), data scientists, incident response managers, and senior operational or IT managers across the respective sectors. <bold>Table 3</bold> shows distribution of interviews across cases.</p>
      <p><bold>Table 3</bold><bold>.</bold> Distribution of interviews across cases.</p>
      <table-wrap id="tbl3">
        <label>Table 3</label>
        <table>
          <tbody>
            <tr>
              <td>
                <bold>Case</bold>
              </td>
              <td>
                <bold>Sector</bold>
              </td>
              <td>
                <bold>No</bold>
                <bold>of</bold>
                <bold>interviews</bold>
              </td>
              <td>
                <bold>Key</bold>
                <bold>Roles</bold>
                <bold>Represented</bold>
              </td>
            </tr>
            <tr>
              <td>Case 1</td>
              <td>Energy</td>
              <td>5</td>
              <td>OT engineers, analysts, technicians</td>
            </tr>
            <tr>
              <td>Case 2</td>
              <td>Energy</td>
              <td>4</td>
              <td>Cloud security, dispatch managers</td>
            </tr>
            <tr>
              <td>Case 3</td>
              <td>Transport</td>
              <td>4</td>
              <td>SOC analysts, rail engineers</td>
            </tr>
            <tr>
              <td>Case 4</td>
              <td>Finance</td>
              <td>4</td>
              <td>Fraud analysts, data scientists</td>
            </tr>
            <tr>
              <td>Case 5</td>
              <td>Telecom</td>
              <td>5</td>
              <td>Network engineers, SOC analysts</td>
            </tr>
            <tr>
              <td>
                <bold>Total</bold>
              </td>
              <td>-</td>
              <td>
                <bold>22</bold>
              </td>
              <td>-</td>
            </tr>
          </tbody>
        </table>
      </table-wrap>
      <p>In addition to interviews, documentary evidence was reviewed to support triangulation, including internal incident reports, security audit summaries, vulnerability assessments, policy and compliance documents, and post-incident review materials.</p>
      <p>Each case represents a single organizational context, with the exception that minor composite elements were introduced in limited instances to protect organizational anonymity without altering the empirical patterns to preserve confidentiality and emphasize recurring socio-technical patterns. Case narratives were constructed by integrating interview data and documentary sources into coherent incident-focused accounts, allowing the analysis to capture both frontline experiences and organizational response dynamics. This approach ensures consistency across cases while enabling comparison of sector-specific and cross-sector workforce-related challenges.</p>
      <p><italic><bold>Interview</bold></italic><italic><bold>Protocol</bold></italic></p>
      <p>Interviews were conducted over eight weeks with cybersecurity professionals, engineers, and managers. Each session lasted approximately 60 minutes and was held virtually or in person, per participant preference (see <bold>Table 3</bold>). The semi-structured guide covered the following:</p>
      <p>Role and responsibilities;Sector-specific cybersecurity challenges;Perceived staffing gaps and hybrid skill needs;Responses to recent incidents;Organizational barriers to action.</p>
      <p><italic><bold>Sample</bold></italic><italic><bold>Questions</bold></italic><italic><bold>Included</bold></italic><bold>:</bold></p>
      <p>1) Describe your role in cybersecurity. </p>
      <p>2) What challenges do you face?</p>
      <p>3) How do staff shortages affect your work?</p>
      <p>4) Describe recent incidents and responses. </p>
      <p>5) What skills are missing from your team?</p>
      <p>Interviews were recorded with consent, transcribed verbatim, anonymized, and members checked. Field notes and documents (e.g., incident reports) support triangulation.</p>
      <p><italic><bold>Ethics</bold></italic><italic><bold>and</bold></italic><italic><bold>Consent</bold></italic></p>
      <p>Ethical clearance was granted by the authors’ institution. Participants received information sheets and signed informed consent forms outlining confidentiality, voluntary participation, data use, and withdrawal rights. Ethical committee contact was provided to ensure transparency.</p>
      <p><italic><bold>Data</bold></italic><italic><bold>Analysis</bold></italic></p>
      <p>Data were analyzed using a grounded theory-inspired inductive approach. This iterative method allowed for research on surface patterns and relationships among workforce challenges, sectoral contexts, and incident response behaviors.</p>
      <p><italic><bold>Coding</bold></italic><italic><bold>process</bold></italic></p>
      <p>Initial open coding identified concepts from the transcripts, such as “burnout,” “role confusion”, or “lack of authority”. These were refined into four thematic categories through axial coding.</p>
      <p>Workforce shortages and burnout.Skill gaps and hybrid capability needs.Organizational silos and coordination issues.Cultural and regulatory influences on incident response.</p>
      <p>For instance, “unclear authority” and “siloed teams” were combined under coordination breakdowns, which emerged as a critical theme across sectors. NVivo software was used to manage coding, ensure consistency, and support synthesis across the data types.</p>
      <p><italic><bold>Cross</bold></italic><bold>-</bold><italic><bold>Case</bold></italic><italic><bold>and</bold></italic><italic><bold>Comparison</bold></italic><italic><bold>Ca</bold></italic><italic><bold>ses</bold></italic></p>
      <p>While this study maintains a primary focus on the energy sector, the inclusion of transportation, finance, and telecommunications cases serves a deliberate comparative purpose. These sectors function as analytical contrasts and parallels, enabling the study to distinguish between: 1) workforce challenges that are systemic across critical infrastructure and 2) those that are uniquely shaped by the socio-technical characteristics of the energy domain.</p>
      <p>Through this comparative design, the study identifies recurring patterns—such as hybrid skill shortages, coordination breakdowns, and delayed incident response—as cross-sector mechanisms of resilience degradation, while also highlighting how the energy sector’s reliance on legacy operational technology, safety-critical processes, and regulatory constraints intensifies these effects.</p>
      <p>Thus, the non-energy cases do not dilute the energy focus; rather, they strengthen causal explanation by providing comparative evidence that clarifies what is generalizable versus sector specific.</p>
      <p>Following within-case analysis, a cross-case synthesis identified shared patterns and sector-specific differences.</p>
      <p>In energy, fear of triggering service disruptions (e.g., power outages) inhibited the incident response.In transportation, concerns focused on passenger safety and system failure-safes.In finance, reputational damage and regulatory compliance were dominant concerns.</p>
      <p>All sectors converged on the challenge of lacking cross-disciplinary talent, which limited effective and timely incident responses.</p>
      <p><italic><bold>Validation</bold></italic><italic><bold>Strategies</bold></italic></p>
      <p>To ensure analytic trustworthiness, member checking was used after each interview, allowing participants to verify the summaries. Two independent researchers reviewed the coding framework and themes to ensure inter-coder reliability. Discrepancies were resolved through discussions to enhance credibility.</p>
    </sec>
    <sec id="sec4">
      <title>4. Empirical Findings Based on Multi-Sector Case Studies</title>
      <p>This section presents five empirical case studies of the energy, transportation, financial, and telecommunications sectors. Derived from interviews and documentary sources, they examined how cybersecurity workforce shortages disrupt incident response, coordination, and systemic resilience. Each case was interpreted through socio-technical systems theory. Pseudonyms were used where necessary. A synopsis of the case studies, presented in <bold>Table 4</bold>, serves as a prelude to the detailed presentation of the five individual cases. </p>
      <p><bold>Table 4</bold><bold>.</bold> Summary of case studies.</p>
      <table-wrap id="tbl4">
        <label>Table 4</label>
        <table>
          <tbody>
            <tr>
              <td>
                <bold>Organization/</bold>
                <bold>Sector</bold>
              </td>
              <td>
                <bold>Incident</bold>
              </td>
              <td>
                <bold>Frontline</bold>
                <bold>Perspectives</bold>
              </td>
              <td>
                <bold>Key</bold>
                <bold>Implications</bold>
              </td>
            </tr>
            <tr>
              <td>EnergyRegional energy utility (Midwest)</td>
              <td>Vendor credentials compromised via phishing, lateral movement into AMI/SCADA systems</td>
              <td>Staff described being “frozen” by uncertainty; only one hybrid OT/IT expert available; field technicians afraid to act without guidance</td>
              <td>Robust architectures ineffective without skilled cross-domain staff to coordinate incident response and avoid cascading failures</td>
            </tr>
            <tr>
              <td>Energy“EnergyCo” (anonymized)</td>
              <td>Malware on contractor laptop through trusted VPN, threatened dispatch scheduling</td>
              <td>Dispatch staff torn between keeping fuel flowing and following cybersecurity instructions; confusion on escalation</td>
              <td>Technical safeguards could not be activated under stress due to lack of hybrid cybersecurity skills and coordination bottlenecks</td>
            </tr>
            <tr>
              <td>TransportationMetropolitan transportation authority</td>
              <td>Vulnerability in SaaS-ICS API delayed patching for 3 months</td>
              <td>Engineering staff felt unsupported; cybersecurity staff feared breaking safety protocols; legacy/modern teams failed to collaborate</td>
              <td>Without cybersecurity staff trained in secure software and transportation systems, even simple vulnerabilities remain unaddressed</td>
            </tr>
            <tr>
              <td>FinanceLarge financial institution</td>
              <td>Third-party API exploited to inject adversarial data, disrupting ML fraud detection</td>
              <td>Fraud analysts powerless to override models; cybersecurity staff lacked data science skills; delays relying on consultants</td>
              <td>Advanced ecosystems need cybersecurity staff fluent in data science; skills shortages leave critical services vulnerable</td>
            </tr>
            <tr>
              <td>TelecommunicationNational telecom provider</td>
              <td>Phishing, ransomware, and DDoS attacks disrupted services; API misconfiguration exploited viathird-party billing system</td>
              <td>Engineers overwhelmed by alert overload; analysts lacked visibility; vendor security unknown; leadership delayed escalation</td>
              <td>Telecom resilience depends on real-time, integrated visibility and hybrid-skilled teams across IT, OT, and vendor domains</td>
            </tr>
          </tbody>
        </table>
      </table-wrap>
      <sec id="sec4dot1">
        <title>4.1. Presentation of the Five Case Studies</title>
        <p><bold>Case</bold><bold>Study</bold><bold>1:</bold><bold>Third</bold><bold>-</bold><bold>Party</bold><bold>Vendor</bold><bold>Compromise</bold><bold>in</bold><bold>a</bold><bold>Regional</bold><bold>Energy</bold><bold>Utility</bold></p>
        <p>A regional utility in the U.S. Midwest initiated a modernization effort integrating Advanced Metering Infrastructure (AMI) with outdated Supervisory Control and Data Acquisition (SCADA) systems. This convergence was facilitated by a third-party Internet of Things (IoT) vendor whose technicians were granted persistent Virtual Private Network (VPN) access to critical infrastructure, a common but hazardous configuration in combined Information Technology/Operational Technology (IT/OT) environments.</p>
        <p>The incident began when a technician’s credentials were compromised during a phishing attack. An attacker uses the vendor’s VPN to pivot laterally into the utility network. Although network segmentation flagged unusual queries to the SCADA control panels, “<italic>it</italic><italic>took</italic><italic>nearly</italic><italic>two</italic><italic>days</italic><italic>to</italic><italic>isolate</italic><italic>the</italic><italic>th</italic><italic>reat</italic>”. During this window, multiple internal systems are probed, triggering an operational alarm.</p>
        <p>Interview data relating to this case indicate deep dysfunctions in incident handling. Engineers feared cutting power unintentionally by acting without a full system understanding. Analysts cannot distinguish legitimate vendor traffic from malicious activities. Only one staff member had experience in both SCADA protocols and IT security tools. This personnel shortfall left the organization vulnerable during the critical breach period.</p>
        <p>This case highlights that even sophisticated technical defenses cannot substitute for personnel capable of interpreting and managing converged systems. This event affirms Lawelai <italic>et al</italic>. [<xref ref-type="bibr" rid="B26">26</xref>], who emphasized the need for hybrid-skilled professionals in digitally modernized utilities to uphold resilience during cyber disruptions.</p>
        <p><bold>Case</bold><bold>Study</bold><bold>2:</bold><bold>Malware</bold><bold>Containment</bold><bold>Challenges</bold><bold>at</bold><bold>“</bold><bold>EnergyCo</bold><bold>”</bold></p>
        <p>“EnergyCo” (pseudonym), a leading independent fuel distributor, migrated its dispatch systems to a hybrid cloud to coordinate fuel logistics across regional terminals. This transformation was intended to enhance responsiveness and real-time visibility but introduced new risks from increased interconnectivity.</p>
        <p>The incident occurred when a contractor plugged into a personal laptop infected with malware during a VPN session. Although anomaly detection tools immediately flagged the behavior, the malware had already spread to dispatch subnets. Isolating the terminals posed a dilemma: disconnection increased the risk of halting fuel deliveries during a seasonal demand spike.</p>
        <p>Interviews with participants in this case revealed paralyzed decisions and insufficient capacity. The only cloud security expert worked over 24 h alone, with no backup. Dispatch staff hesitated, fearing systemic service outages. Analysts deferred action owing to unclear escalation paths and segmentation knowledge gaps. A contractor reported, “<italic>I</italic><italic>didn</italic>’<italic>t</italic><italic>know</italic><italic>who</italic><italic>had</italic><italic>authority</italic>—<italic>everyone</italic><italic>froze</italic>”.</p>
        <p>This case underscores that even low-sophistication malware can overwhelm organizations that lack redundancy and clear roles. Technical tools provide alerts, but skilled people are not able to interpret them under operational pressure. Delays widened the threat window and disrupted fuel supply to the entire region.</p>
        <p>These findings reinforce Thomas and Sule [<xref ref-type="bibr" rid="B4">4</xref>], who argued that resilience frameworks must be underpinned by a workforce with both technical expertise and domain-specific judgment. EnergyCo’s challenges illuminate human bottlenecks that persist even in cloud-mature environments.</p>
        <p><bold>Case</bold><bold>Study</bold><bold>3:</bold><bold>Vulnerability</bold><bold>Management</bold><bold>in</bold><bold>a</bold><bold>Metropolitan</bold><bold>Transportation</bold><bold>Authority</bold></p>
        <p>A major U.S. transit authority modernized its signaling systems, transitioning from analog infrastructure to a Communication-Based Train Control (CBTC) platform. This included integration with third-party predictive maintenance tools through Application Programming Interfaces (APIs) hosted in the cloud.</p>
        <p>During a routine audit, a critical vulnerability was found in an API bridging the Software as a Service (SaaS) platform and on-premises training systems. This flaw enabled potential command injection into a safety-critical infrastructure. Despite the urgency, patching took over three months due to a shortage of personnel skilled in both secure software development and railway operations.</p>
        <p>Interviews with participants in this case revealed a fractured organizational response. Security Operations Center (SOC) analysts were reluctant to act, fearing that they might disable the train safety mechanisms. One participant said, “<italic>This</italic><italic>wasn</italic>’<italic>t</italic><italic>a</italic><italic>standard</italic><italic>Linux</italic><italic>box</italic>—<italic>we</italic><italic>didn</italic><italic>’</italic><italic>t</italic><italic>know</italic><italic>what</italic><italic>failure</italic><italic>looked</italic><italic>like</italic><italic>here</italic>”. Conversely, rail engineers distrusted the cybersecurity team’s understanding of control systems. One commented, “<italic>They</italic><italic>approached</italic><italic>this</italic><italic>like</italic><italic>patching</italic><italic>a</italic><italic>website</italic>, <italic>not</italic><italic>operating</italic><italic>a</italic><italic>transit</italic><italic>system</italic>”. Staff burnout is also widespread. Several employees were juggled by routine incidents and this high-risk vulnerability without sufficient support. The required cross-functional collaboration never materialized because of rigid departmental boundaries and cultural mistrust.</p>
        <p>This case demonstrates that technically solvable vulnerabilities can remain dangerous if interdisciplinary cooperation fails. As Friday <italic>et al</italic>. [<xref ref-type="bibr" rid="B18">18</xref>] argued, effective cybersecurity in critical infrastructure demands shared mental models, not just advanced tooling. In this case, the socio-technical gap, not the flaw itself, posed the greatest threat to public safety.</p>
        <p><bold>Case</bold><bold>Study</bold><bold>4:</bold><bold>Adversarial</bold><bold>Machine</bold><bold>Learning</bold><bold>Attack</bold><bold>in</bold><bold>a</bold><bold>Financial</bold><bold>Institution</bold></p>
        <p>A large national bank has adopted a Machine Learning (ML) engine to detect fraud in real time across transactions processed by financial technology (fintech) partners via API integration. The system was designed to enhance precision without delaying legitimate transactions.</p>
        <p>Attackers exploit a misconfigured API key from the partner firm by injecting adversarial data into the model. This caused a spike in false positives, freezing thousands of legitimate transactions and triggering a customer service crisis. The incident marked a textbook example of model poisoning, a novel and poorly understood threat at the time.</p>
        <p>Interview data relating to this case revealed confusion and slow responses. Fraud analysts lack insight into ML behavior and cannot override their decisions. Cybersecurity personnel, unfamiliar with adversarial techniques, relied on external consultants who arrived 36 hours later. A data scientist reflected, “<italic>We</italic><italic>couldn</italic>’<italic>t</italic><italic>explain</italic><italic>model</italic><italic>behavior</italic><italic>in</italic><italic>a</italic><italic>way</italic><italic>they</italic><italic>understood</italic>. <italic>They</italic><italic>thought</italic><italic>in</italic><italic>firewalls</italic>, <italic>we</italic><italic>thought</italic><italic>in</italic><italic>tensors</italic>”. The absence of interdisciplinary fluency delayed containment and eroded trust between departments. Moreover, customer confidence was shaken by banks’ lack of transparency and control.</p>
        <p>This case underscores the need for hybrid-skilled professionals who can bridge the cybersecurity and artificial intelligence domains. This event supports Kandpal <italic>et al</italic>. [<xref ref-type="bibr" rid="B5">5</xref>], who call for a new skills architecture to support resilience in AI-driven financial systems. Without teams able to interpret, secure, and act on ML insights, the system’s sophistication becomes a liability.</p>
        <p><bold>Case</bold><bold>Study</bold><bold>5:</bold><bold>Multi</bold><bold>-</bold><bold>Vector</bold><bold>Cyberattacks</bold><bold>in</bold><bold>a</bold><bold>National</bold><bold>Telecom</bold><bold>Provider</bold></p>
        <p>A national telecommunications company embarked on a major digital transformation to accelerate its 5G rollout and consolidate billing, customer service, and Internet of Things (IoT) management through centralized cloud infrastructure. Multiple third-party vendors have managed core systems to support rapid scaling.</p>
        <p>Over a two-week period, the provider experienced coordinated cyberattacks involving phishing, ransomware, and Distributed Denial-of-Service (DDoS) techniques. A phishing email compromised the billing administrator’s credentials, enabling lateral movement into customer databases. Simultaneously, ransomware is deployed through a misconfigured API linked to a third-party billing platform. The crisis peaked when a DDoS attack took down public-facing systems, disabling mobile data in several cities.</p>
        <p>Interviews with participants in this case revealed severe breakdowns in coordination and response. The SOC teams could not correlate with different attack vectors. One network engineer said, “<italic>Everything</italic><italic>was</italic><italic>on</italic><italic>fire</italic>—<italic>email</italic><italic>servers</italic>, <italic>routers</italic>, <italic>billing</italic><italic>systems</italic>—<italic>and</italic><italic>no</italic><italic>one</italic><italic>knew</italic><italic>where</italic><italic>to</italic><italic>start</italic>”. Executive hesitation, partly due to fear of regulatory scrutiny, delayed full-scale incident response. Vendor oversight is limited. One executive admitted, “<italic>The</italic><italic>billing</italic><italic>platform</italic><italic>was</italic><italic>a</italic><italic>black</italic><italic>box</italic>—<italic>we</italic><italic>didn</italic>’<italic>t</italic><italic>know</italic><italic>its</italic><italic>vulnerabilities</italic>”.</p>
        <p>Despite previous investments in Information and Communications Technology (ICT) security, siloed teams, inadequate staffing, and fragmented monitoring have left companies vulnerable to multi-vector exploitation. Analysts have been confined to outdated threat models and lack real-time threat correlation tools.</p>
        <p>This case validates Ncube, Sishi, and Skinner [<xref ref-type="bibr" rid="B46">46</xref>], who argue that systemic resilience in telecoms hinges on sociotechnical integration. Complex infrastructures require not only digital sophistication but also unified governance, interoperable teams, and continuous organizational learning. A summary of these findings is presented in <bold>Table 3</bold>.</p>
      </sec>
      <sec id="sec4dot2">
        <title>4.2. Addendum on the Case Studies</title>
        <p>The following section presents practitioners’ insights from the energy sector, gathered during a focus group interview.</p>
        <p>A key informant working in the energy sector described how recent cybersecurity incidents, specifically vendor account compromises and cross-site attacks, have exposed significant vulnerabilities within existing organizational structures. “<italic>These</italic><italic>aren</italic>’<italic>t</italic><italic>just</italic><italic>technical</italic><italic>failures</italic>”, the informant explained, “<italic>they</italic><italic>show</italic><italic>how</italic><italic>disconnected</italic><italic>our</italic><italic>technical</italic><italic>defenses</italic><italic>are</italic><italic>from</italic><italic>the</italic><italic>rest</italic><italic>of</italic><italic>the</italic><italic>organization</italic>”.</p>
        <p>From the practitioner’s perspective, these events have clarified that a purely technical approach to cybersecurity is no longer sufficient. “<italic>We</italic><italic>need</italic><italic>people</italic><italic>who</italic><italic>understand</italic><italic>both</italic><italic>the</italic><italic>tech</italic><italic>and</italic><italic>the</italic><italic>business</italic>—<italic>who</italic><italic>can</italic><italic>translate</italic><italic>risks</italic><italic>into</italic><italic>action</italic><italic>across</italic><italic>department</italic><italic>s</italic>”, another informant emphasized. This aligns with the perspective of Haney and Lutters [<xref ref-type="bibr" rid="B13">13</xref>], who argue that cybersecurity advocates must “<italic>bridge</italic><italic>cultural</italic><italic>and</italic><italic>operational</italic><italic>divides</italic><italic>across</italic><italic>IT</italic>, <italic>security</italic>, <italic>and</italic><italic>business</italic><italic>functions</italic>”.</p>
        <p>A third participant in the focused group interview stressed that the complexity of the energy sector requires a holistic, cross-functional skill set: “<italic>You</italic><italic>can</italic><italic>have</italic><italic>the</italic><italic>best</italic><italic>tools</italic><italic>in</italic><italic>place</italic>, <italic>but</italic><italic>if</italic><italic>your</italic><italic>teams</italic><italic>don</italic>’<italic>t</italic><italic>know</italic><italic>how</italic><italic>to</italic><italic>align</italic><italic>them</italic><italic>with</italic><italic>real</italic>-<italic>world</italic><italic>operations</italic>, <italic>you</italic>’<italic>re</italic><italic>still</italic><italic>vulnerable</italic>.” Technical controls, no matter how advanced, must be coupled with strategic human expertise and embedded within organizational policies and workflows. As the informant concluded, “<italic>Cybersecurity</italic><italic>resilience</italic><italic>isn</italic>’<italic>t</italic><italic>just</italic><italic>about</italic><italic>firewalls</italic><italic>and</italic><italic>patches</italic>—<italic>it</italic>’<italic>s</italic><italic>about</italic><italic>people</italic>, <italic>process</italic>, <italic>and</italic><italic>purpose</italic>”.</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Discussion of Findings and Cross-Case Synthesis</title>
      <p>This section interprets the empirical findings through the socio-technical systems theory, drawing from five case studies across the energy, transportation, finance, and telecommunications sectors. It explores how cybersecurity workforce challenges emerge in practice, how they differ across sectors, and what they imply for resilience in a critical digital infrastructure. In a nutshell, it is pertinent to mention that the non-energy cases function as comparative benchmarks, allowing the study to isolate which workforce-related disruptions are systemic across sectors and which are amplified by the energy sector’s unique socio-technical configuration.</p>
      <p>The discussion follows four themes based on the theoretical foundation: 1) cybersecurity workforce capability in critical infrastructure, 2) sector-specific cybersecurity needs with a focus on energy, 3) operationalization of cybersecurity protocols in high-risk environments, and 4) implications of the cybersecurity skill gap for resilience. Together, these themes were extracted from the 70 studies screened during the systematic literature review process. offers a structured analysis of systemic, cultural, and contextual barriers to effective cyber defense.</p>
      <p><italic><bold>Cybersecurity</bold></italic><italic><bold>Workforce</bold></italic><italic><bold>Capability</bold></italic><italic><bold>in</bold></italic><italic><bold>Critical</bold></italic><italic><bold>Infrastructure</bold></italic></p>
      <p>Cybersecurity resilience is closely linked to workforce capability. All five case studies revealed that although organizations had invested in detection, segmentation, and response technologies, these tools underperformed owing to insufficient personnel to operationalize them. This supports the findings of Malatji <italic>et al</italic>. [<xref ref-type="bibr" rid="B3">3</xref>], Khaw <italic>et al</italic>. [<xref ref-type="bibr" rid="B14">14</xref>], and Otoom <italic>et al</italic>. [<xref ref-type="bibr" rid="B30">30</xref>], who argue that cybersecurity frameworks depend not on their design, but on those implementing them. They emphasized the role of higher education in the development of cybersecurity knowledge.</p>
      <p>The need for hybrid professionals—individuals with technical cybersecurity expertise and operational familiarity—is particularly pronounced. This includes understanding Supervisory Control and Data Acquisition (SCADA) systems in energy, signaling logic in transportation, machine-learning pipelines in finance, and distributed billing systems in telecommunications. In Case 1, the staff hesitated to isolate compromised systems due to fear of triggering power outages, while in Case 4, the inability to recognize and respond to model poisoning in fraud-detection systems exposed the limits of siloed expertise. These examples support Spruit [<xref ref-type="bibr" rid="B12">12</xref>] and Xenakis <italic>et al</italic>. [<xref ref-type="bibr" rid="B20">20</xref>], who argued that cybersecurity is a socio-technical capacity that depends on integrated knowledge and strong cybersecurity literacy.</p>
      <p>The hybrid capability involves more than cross-training. It requires professionals to operate confidently amid competing operational priorities, balancing technical fluency with risk communication, negotiation, and interdepartmental collaboration. As Anderson and Moore [<xref ref-type="bibr" rid="B39">39</xref>] and Krishna <italic>et al</italic>. [<xref ref-type="bibr" rid="B38">38</xref>] note, security failures often stem not from technical deficiencies, but from institutional distrust and communication breakdowns. Therefore, workforce development must be approached as a systems-level challenge, not just as a training issue.</p>
      <p><italic><bold>Sector</bold></italic><bold>-</bold><italic><bold>Specific</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>Needs</bold></italic><bold>:</bold><italic><bold>Focus</bold></italic><italic><bold>on</bold></italic><italic><bold>Energy</bold></italic></p>
      <p>The energy sector’s unique mix of legacy Operational Technology (OT), modern Information Technology (IT), and regulatory constraints creates complex cybersecurity challenges. Both Case 1 and Case 2 revealed that key decision-makers delayed cybersecurity actions because of fear of disrupting electricity delivery or fuel logistics. In each instance, cybersecurity teams lacked sector-specific operational knowledge to assess risk tolerances, or had their warnings overridden by leaders prioritizing continuity of service.</p>
      <p>These dynamics confirm the findings of Thomas and Sule [<xref ref-type="bibr" rid="B4">4</xref>], Malatji <italic>et al</italic>. [<xref ref-type="bibr" rid="B3">3</xref>], and Haleem <italic>et al</italic>. [<xref ref-type="bibr" rid="B16">16</xref>], who stressed that cybersecurity strategies in industrial sectors must account for safety-critical processes and real-time system performance. Additionally, reliance on external vendors introduces vulnerabilities, as seen in the credential compromise and malware infection initiated outside internal systems. Yeboah-Ofori and Opoku-Boateng [<xref ref-type="bibr" rid="B34">34</xref>] and Friday <italic>et al</italic>. [<xref ref-type="bibr" rid="B18">18</xref>] similarly highlight how third-party dependencies elevate complexity and risk, especially when trust and coordination are weak.</p>
      <p>The regulatory culture of the energy sector further complicates incident responses. Conservative risk policies often delay action until threats reach predefined thresholds that hybrid professionals are best suited to interpret. In their absence, defaulting to caution may inadvertently prolong systemic exposure. Related findings in healthcare [<xref ref-type="bibr" rid="B35">35</xref>] and smart cities [<xref ref-type="bibr" rid="B26">26</xref>][<xref ref-type="bibr" rid="B37">37</xref>] suggest that misaligned training, limited cyber literacy, and organizational silos magnify vulnerabilities in digitally dependent sectors.</p>
      <p><italic><bold>Operationalizing</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>Protocols</bold></italic><italic><bold>in</bold></italic><italic><bold>High</bold></italic><bold>-</bold><italic><bold>Risk</bold></italic><italic><bold>Environments</bold></italic></p>
      <p>Applying cybersecurity protocols in high-risk settings requires more than regulatory compliance; it depends on situational awareness, institutional trust, and seamless organizational integration. Across cases, basic actions, such as patching vulnerabilities or escalating alerts, break down due to uncertainty or procedural inertia. In Case 3, a critical API vulnerability in train signaling went unpatched for months because cybersecurity and engineering teams could not agree on an acceptable risk. In Case 5, telecom staff overwhelmed by simultaneous ransomware and Distributed Denial-of-Service (DDoS) attacks failed to coordinate because of unclear escalation procedures.</p>
      <p>These patterns echo Bechara and Schuch [<xref ref-type="bibr" rid="B15">15</xref>], who show that many incidents are not caused by detection failure, but by breakdowns in execution. As Friday <italic>et al</italic>. [<xref ref-type="bibr" rid="B18">18</xref>] emphasize, socio-technical misalignment—when systems outpace organizational readiness–creates implementation bottlenecks. Moreover, the literature underscores the importance of shared mental models and collaborative practices [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B10">10</xref>], both of which are lacking across multiple sectors in high-stakes moments.</p>
      <p>Effective operationalization also requires mutual trust between teams. In the absence of shared understanding, actions are delayed or avoided. These cases highlight that cybersecurity must be embedded into sector-specific workflows–developing playbooks, conducting simulations, and aligning terminology with operational goals. As Khaw <italic>et al</italic>. [<xref ref-type="bibr" rid="B14">14</xref>] and Al-Hawamleh [<xref ref-type="bibr" rid="B28">28</xref>] argue, integration into everyday routines matters more than technical sophistication alone does.</p>
      <p><italic><bold>Implications</bold></italic><italic><bold>of</bold></italic><italic><bold>the</bold></italic><italic><bold>Cybersecurity</bold></italic><italic><bold>Skills</bold></italic><italic><bold>Gap</bold></italic><italic><bold>on</bold></italic><italic><bold>Resilience</bold></italic></p>
      <p>A shortage of cybersecurity professionals undermines organizational resilience through delayed responses, underused technologies, fragmented workflows, and burnout. Each case revealed confusion and hesitation. Case 4 showed that the absence of ML-literate cybersecurity staff led to delays and reliance on consultants. Case 5 illustrates how reputational concerns discouraged action in the face of multi-vector attacks, particularly where the authority for escalation was unclear.</p>
      <p>These symptoms reflect systemic issues beyond the staffing numbers. Singh <italic>et al</italic>. [<xref ref-type="bibr" rid="B22">22</xref>], Xenakis <italic>et al</italic>. [<xref ref-type="bibr" rid="B20">20</xref>], and Otoom <italic>et al</italic>. [<xref ref-type="bibr" rid="B30">30</xref>] highlighted how burnout, mismatches in skill deployment, and retention problems compound risk exposure. The observed hesitancy across cases often stems from ambiguity in roles and priorities, and not from a lack of will or competence. Resilience, therefore, depends not only on staffing levels, but also on the alignment of skills, authority, and situational awareness.</p>
      <p>Resilience should be understood as the emergent quality of integrated systems-people, processes, and technologies working together under pressure. Even well-trained teams struggle when organizational culture discourages cross-functional learning or conceals risks to avoid scrutiny. The findings highlight the need for leadership models that tolerate uncertainty, empower rapid decision-making, and prioritize iterative learning. As Krishna <italic>et al</italic>. [<xref ref-type="bibr" rid="B38">38</xref>] suggested, institutional trust and shared cybersecurity ethos are foundational for translating technical capacity into resilience.</p>
      <p>Ultimately, the cases show that resilience in critical sectors is not solely determined by technological maturity. It emerges from a sociotechnical alignment between people, tools, and contexts. Addressing the skill gap requires developing hybrid roles, building sector-specific fluency, and enhancing operational confidence. Cybersecurity must be embedded in core operations and must not be treated as an auxiliary IT function. Regulators and institutional leaders must treat workforce readiness as a measurable indicator of resilience, recognizing that the human layer is the linchpin of any cybersecurity strategy.</p>
    </sec>
    <sec id="sec6">
      <title>6. Conclusions</title>
      <p>This study has examined how the cybersecurity workforce gap impacts the resilience and effectiveness of cybersecurity practices across critical digital infrastructures, with an emphasis on the energy sector and comparative insights from transportation, finance, and telecommunications. Drawing on a systematic literature review and five multi-sector case studies, the findings underscore a core reality: cybersecurity resilience depends not only on technological tools but also on the human capacity to deploy, interpret, and adapt them under real-world conditions.</p>
      <p>Evidence across sectors, reinforced by existing research, reveals that the cybersecurity skills gap is not simply about insufficient headcount, but about a qualitative shortfall in hybrid capacity. As Spruit [<xref ref-type="bibr" rid="B12">12</xref>] noted, modern cybersecurity requires professionals who can integrate technical acumen with domain-specific knowledge. This includes fluency in Supervisory Control and Data Acquisition (SCADA) systems in energy [<xref ref-type="bibr" rid="B3">3</xref>], safety assurance in transportation [<xref ref-type="bibr" rid="B6">6</xref>], financial compliance [<xref ref-type="bibr" rid="B5">5</xref>], and management of vendor ecosystems in telecommunications [<xref ref-type="bibr" rid="B18">18</xref>].</p>
      <p>Case studies consistently show that failure to respond effectively to cyber incidents was less about technological shortcomings and more about the absence of personnel capable of coordinating, interpreting, and applying available tools in high-stakes operational environments [<xref ref-type="bibr" rid="B4">4</xref>][<xref ref-type="bibr" rid="B22">22</xref>]. These human-centered barriers echo sociotechnical systems research, which frames resilience as the product of well-aligned technical, human, and institutional subsystems [<xref ref-type="bibr" rid="B15">15</xref>].</p>
      <p>Institutional culture and sector-specific norms also shape response dynamics. In energy, risk aversion to service disruption delayed system isolation; in transportation, safety cultures prolonged vulnerability windows; in finance, siloed structures impeded rapid coordination; and in telecommunications, vendor fragmentation and reputational risk deterred timely escalation. These patterns reflect Stavrou and Piki [<xref ref-type="bibr" rid="B10">10</xref>], who argued that effective cybersecurity requires cohesion across cultural, operational, and technical domains.</p>
      <p>The literature further confirms that generic training approaches fall short in critical infrastructure settings. Khaw <italic>et al</italic>. [<xref ref-type="bibr" rid="B14">14</xref>], Al-Hawamleh [<xref ref-type="bibr" rid="B28">28</xref>], and Xenakis <italic>et al</italic>. [<xref ref-type="bibr" rid="B20">20</xref>] have stressed the need for cross-functional, experiential, and context-specific training models that reflect operational complexity. The inclusion of telecommunications reinforces how rapid digitalization, third-party reliance, and high public exposure intensify sector-specific workforce pressure.</p>
      <p>Thus, this study calls for systemic rethinking of cybersecurity workforce development. This is insufficient to increase the number of trained professionals. Priority must ensure the right blend of technical skills, contextual insights, and collaborative capacity. Regulatory frameworks should incorporate workforce readiness and cross-functional coordination into the resilience metrics. Academia must co-design curricula with industry, and organizations should invest in cultivating hybrid roles and interdisciplinary structures.</p>
      <p>Ultimately, no digital infrastructure—regardless of sophistication—can achieve resilience without skilled and empowered people. Without human capacity, even the most advanced technologies remain unrealized. Bridging the cybersecurity workforce gap is not just a technical or educational goal, but also a national imperative for economic stability, public safety, and strategic security. As digital threats escalate, addressing this gap has become a defining challenge in the digital era.</p>
      <sec id="sec6dot1">
        <title>6.1. Implications of This Study for Practitioners and Policymakers</title>
        <p>This study offers important insights for practitioners and policymakers to enhance the resilience of critical digital infrastructures. The acute shortage of skilled cybersecurity professionals, especially in energy, finance, and transportation, is not merely a workforce issue but a systemic operational risk with broad consequences. Addressing this risk requires moving beyond technical fixes toward greater emphasis on human capabilities, sector-specific expertise, and organizational integration.</p>
        <p>To facilitate clear traceability: data → themes → framework; and to strengthen the theoretical contribution of this study, a mapping table (<bold>Table 5</bold>) is presented below to explicitly link each empirical theme to its corresponding component in the conceptual frameworks. This makes the theoretical development more transparent and demonstrates how the frameworks are grounded in both the empirical data and the literature.</p>
        <p><bold>Table 5</bold><bold>.</bold> Mapping of empirical themes to conceptual framework components.</p>
        <table-wrap id="tbl5">
          <label>Table 5</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Empirical</bold>
                  <bold>Theme</bold>
                </td>
                <td>
                  <bold>Description</bold>
                </td>
                <td>
                  <bold>Framework</bold>
                  <bold>Component</bold>
                </td>
                <td>
                  <bold>Role</bold>
                  <bold>in</bold>
                  <bold>Framework</bold>
                </td>
              </tr>
              <tr>
                <td>Workforce shortages &amp; burnout</td>
                <td>Insufficient staffing, overload, and delayed response</td>
                <td>Cybersecurity Workforce Capability</td>
                <td>Core construct (central driver of resilience)</td>
              </tr>
              <tr>
                <td>Hybrid skill gaps</td>
                <td>Lack of IT-OT-AI integration skills</td>
                <td>Cybersecurity Workforce Capability</td>
                <td>Defines quality and effectiveness of workforce</td>
              </tr>
              <tr>
                <td>Coordination breakdowns &amp; silos</td>
                <td>Poor communication, unclear authority, fragmented teams</td>
                <td>Operationalisation Challenges</td>
                <td>Explains failure to implement security practices</td>
              </tr>
              <tr>
                <td>Cultural &amp; regulatory constraints</td>
                <td>Risk aversion, compliance pressure, sector norms</td>
                <td>Sector-Specific Needs</td>
                <td>Shapesdecision-making and response behavior</td>
              </tr>
              <tr>
                <td>Technological complexity(AI, IoT, IT/OT convergence)</td>
                <td>Evolving systems and threat landscape</td>
                <td>Emerging Technologies</td>
                <td>Creates dynamic demand for new skills</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p><italic><bold>From</bold></italic><italic><bold>Themes</bold></italic><italic><bold>to</bold></italic><italic><bold>Conceptual</bold></italic><italic><bold>Framework</bold></italic>—<italic><bold>Linking</bold></italic><italic><bold>Empirical</bold></italic><italic><bold>Themes</bold></italic><italic><bold>to</bold></italic><italic><bold>Conceptual</bold></italic><italic><bold>Framework</bold></italic><italic><bold>Development</bold></italic></p>
        <p>The conceptual frameworks presented in <xref ref-type="fig" rid="fig1">Figure 1</xref> and <xref ref-type="fig" rid="fig2">Figure 2</xref> were directly derived from the thematic analysis of the empirical data. Following axial coding, four core themes were identified: 1) workforce shortages and burnout, 2) hybrid skill gaps, 3) coordination breakdowns and organizational silos, and 4) cultural and regulatory constraints on incident response.</p>
        <fig id="fig2">
          <label>Figure 2</label>
          <graphic xlink:href="https://html.scirp.org/file/9303497-rId18.jpeg?20260506025707" />
        </fig>
        <p><bold>Figure 2</bold><bold>.</bold> Conceptual framework on cybersecurity skills gap impact pathway.</p>
        <p>These themes were systematically translated into higher-order conceptual components through an iterative abstraction process. Specifically, workforce shortages and hybrid skill gaps were integrated into the central construct of Cybersecurity Workforce Capability, representing the foundational human capacity required for resilient operations. Coordination breakdowns and organizational silos informed the component Operationalisation Challenges, capturing barriers to translating cybersecurity knowledge into effective practice. Cultural and regulatory constraints were conceptualized under Sector-Specific Needs, reflecting how institutional environments shape cybersecurity decision-making and response behavior.</p>
        <p>In addition, insights from both the literature review and empirical cases regarding rapid technological change (e.g., AI, IoT, and IT/OT convergence) were incorporated into the component Emerging Technologies, representing evolving demands on workforce capability.</p>
        <p>Together, these components were synthesized into an integrated socio-technical framework (<xref ref-type="fig" rid="fig1">Figure 1</xref>), illustrating how workforce capability interacts with sectoral context and operational conditions to produce resilience outcomes. The second framework (<xref ref-type="fig" rid="fig2">Figure 2</xref>) further extends this mapping by translating the same themes into a causal pathway, showing how workforce shortages lead to operational gaps, increased vulnerabilities, and ultimately reduced infrastructure resilience.</p>
        <p>This explicit mapping (<bold>Table 5</bold>) ensures that the conceptual frameworks are empirically grounded and analytically traceable to the underlying data.</p>
        <p><italic><bold>Unveiling</bold></italic><italic><bold>a</bold></italic><italic><bold>Conceptual</bold></italic><italic><bold>Framework</bold></italic><italic><bold>for</bold></italic><italic><bold>Infrastructure</bold></italic><italic><bold>Resilience</bold></italic></p>
        <p>A key contribution of this study is the development of a Conceptual Framework to help practitioners and policymakers understand how cybersecurity workforce capabilities dynamically support critical infrastructure resilience. At its core, this framework positions cybersecurity workforce capability as the foundation of resilience.</p>
        <p>The frameworks (<xref ref-type="fig" rid="fig1">Figure 1</xref> and <xref ref-type="fig" rid="fig2">Figure 2</xref>) are informed by gaps identified in the Systematic Literature Review, and challenges surfaced in five in-depth empirical case studies across the energy, transportation, financial, and telecommunications sectors. The conceptual framework in <xref ref-type="fig" rid="fig1">Figure 1</xref> offers a systems-oriented view of how cybersecurity workforce capability interacts with sectoral demands, operational contexts, and emerging technologies to reinforce resilience in a critical digital infrastructure.</p>
        <p>At the core of the framework is Cybersecurity Workforce Capability, which represents the skills, competencies, and institutional knowledge needed to defend mission-critical systems. Based on multi-sector case studies and a Systematic Literature Review, this study shows that the workforce capability is not static. Continual development and investment are required to adapt to evolving threats, particularly in high-risk sectors such as energy, finance, and transportation.</p>
        <p>Surrounding this central capability are three interdependent drivers:</p>
        <p><italic><bold>Sector</bold></italic><bold>-</bold><italic><bold>Specific</bold></italic><italic><bold>Needs</bold></italic></p>
        <p>Each sector had distinct operational realities. For example, the energy sector must secure legacy Operational Technology (OT) that converges with modern IT, while finance grapples with high-volume transactional risks and strict compliance regimes. The framework underscores that cybersecurity strategies must be tailored, and sector-specific knowledge, regulatory fluency, and mission alignment are essential.</p>
        <p><italic><bold>Operationalisation</bold></italic><italic><bold>Challenges</bold></italic></p>
        <p>These barriers prevent cybersecurity knowledge and frameworks from being translated into sustainable practice. Legacy systems, fragmented governance, complex supply chains, and cultural divides between IT, OT, and business units hinder their execution. Cyber professionals must not only possess technical skills but also integrate security into daily operations and workflows.</p>
        <p><italic><bold>Emerging</bold></italic><italic><bold>Technologies</bold></italic></p>
        <p>The rapid integration of artificial intelligence, blockchain, and the industrial IoT presents new opportunities and risks. As technology evolves, so do threat vectors. Without proactive upskilling, advanced tools fail to deliver resilience. The workforce must remain current, with both innovation and associated vulnerabilities.</p>
        <p><xref ref-type="fig" rid="fig1">Figure 1</xref> visualizes these three elements as overlapping circles feeding into a Resilient Critical Digital Infrastructure, symbolizing how workforce dynamics collectively sustain resilience. This framework helps practitioners identify where targeted investments in skills, contextual knowledge, and technological readiness are urgently needed.</p>
        <p>Importantly, feedback arrows from “Resilient Infrastructure” back to workforce capability represent an adaptive loop. A resilient environment supports continuous learning, reduces burnout, and promotes confidence, thereby allowing cybersecurity professionals to move from reactive firefighting to strategic initiatives. Strong infrastructure also reinforces the security culture and enables long-term professional development.</p>
        <p>Thus, the framework positions the cybersecurity workforce as a linchpin connecting people, processes, and technologies. This affirms that resilience cannot be achieved through tools alone; skilled, adaptable, and sector-aware professionals are essential to designing and evolving effective cybersecurity programs for critical infrastructure.</p>
        <p><bold>A</bold><bold>Conceptual</bold><bold>Framework</bold><bold>Mapping</bold><bold>the</bold><bold>Impact</bold><bold>of</bold><bold>Cybersecurity</bold><bold>Skills</bold><bold>Gaps</bold><bold>on</bold><bold>Infrastructure</bold><bold>Resilience</bold></p>
        <p>The second framework, <italic>the</italic><italic>Cybersecurity</italic><italic>Skills</italic><italic>Gap</italic><italic>Impact</italic><italic>Pathway</italic> (<xref ref-type="fig" rid="fig2">Figure 2</xref>), illustrates how cybersecurity workforce shortages degrade the resilience of critical digital infrastructure. Drawing from the five case studies in the energy, transport/logistics, and financial sectors, it maps a causal pathway to show how workforce gaps translate into systemic risk. The model is intended to help practitioners view workforce issues as operational and security-critical threats, rather than isolated HR challenges.</p>
        <p>The pathway includes five sequential stages:</p>
        <p><italic><bold>Workforce</bold></italic><italic><bold>Shortages</bold></italic></p>
        <p>All sectors examined face acute shortages of skilled cybersecurity professionals capable of managing increasingly complex cyber-physical systems. These shortcomings stem from a limited supply of qualified candidates, skill mismatches, and rapid technological changes outpacing education and training systems.</p>
        <p><italic><bold>Operational</bold></italic><italic><bold>Gaps</bold></italic></p>
        <p>Insufficient staffing leads to delays in core functions such as patching, monitoring, incident response, and compliance. These gaps weaken cybersecurity hygiene and hinder the integration of security practices into organizational processes, particularly in sectors with converging legacy operational technology (OT) and modern Information Technology (IT).</p>
        <p><italic><bold>Increased</bold></italic><italic><bold>Vulnerabilities</bold></italic></p>
        <p>Latent vulnerabilities persist as operational gaps persist. Systems remain unpatched, misconfigurations go unnoticed, and supply chain risks are assessed inadequately. These issues have accumulated and exposed critical systems to exploitation.</p>
        <p><italic><bold>Higher</bold></italic><italic><bold>Attack</bold></italic><italic><bold>Risks</bold></italic></p>
        <p>Unaddressed vulnerabilities increase the risk of a successful attack. Sophisticated threat actors, including ransomware groups and state-sponsored adversaries, scan for such weaknesses and target under-defended infrastructures using known tactics and procedures.</p>
        <p><italic><bold>Reduced</bold></italic><italic><bold>Infrastructure</bold></italic><italic><bold>Resilience</bold></italic></p>
        <p>Ultimately, resilience—the ability to anticipate, withstand, recover from, and adapt to cyber incidents—declines. The cumulative impact of staffing shortages and security gaps renders systems fragile and less responsive to crises.</p>
        <p>A key feature of the framework is the feedback loop from “Reduced Infrastructure Resilience” back to “Workforce Shortages”. Repeated security failures, stress, and dysfunctional response environments drive burnout, attrition, and reduced attractiveness of cybersecurity roles, compounding the skill gap. Practitioners must recognize and disrupt this cycle by prioritizing workforce well-being, training, and retention.</p>
        <p><xref ref-type="fig" rid="fig2">Figure 2</xref> demonstrates that skill gaps are not isolated HR concerns; they propagate through operational systems, escalating into organization-wide vulnerabilities. A well-supported, cross-functionally trained cybersecurity workforce is essential for maintaining resilience in mission-critical infrastructure.</p>
        <p>For policymakers, this framework highlights the need for sector-specific training initiatives, interdisciplinary funding strategies, and integrated workforce development programs. Resilience policies must account for not only technical standards, but also the human capacity needed to implement and adapt them.</p>
        <p>Together, <xref ref-type="fig" rid="fig1">Figure 1</xref> and <xref ref-type="fig" rid="fig2">Figure 2</xref> offer a comprehensive, evidence-informed roadmap that positions cybersecurity workforce capability as the link pin of critical infrastructure resilience. Skill shortages must be treated as a foundational risk that requires coordinated strategic actions.</p>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Theoretical Implications, Suggestions for Future Research and Limitations of This Study</title>
        <p><italic><bold>Avenues</bold></italic><italic><bold>for</bold></italic><italic><bold>Further</bold></italic><italic><bold>Research</bold></italic></p>
        <p>There are several directions that merit further exploration. Thus, sector-specific workforce challenges should be examined in greater detail. While this study focused on energy, transportation, finance, and telecommunications, future research should investigate additional high-stakes domains, such as healthcare and water utilities. As Katsuya and Liu [<xref ref-type="bibr" rid="B17">17</xref>] and Al-Hawamleh [<xref ref-type="bibr" rid="B28">28</xref>] argued, each sector operates under distinct regulatory, cultural, and technical conditions that shape workforce needs.</p>
        <p>Comparative international studies could also add value, particularly given the global disparities in cyber maturity and the workforce development infrastructure. Additionally, the role of automation and Artificial Intelligence (AI) in alleviating workforce strain deserves further study. Future research should assess how AI-based tools impact human workload, decision-making, and cognitive stress and how the governance of such tools affects training and job design.</p>
        <p>Organizational culture and leadership practices warrant further analysis. Qualitative studies, such as ethnographies or participatory action research, could uncover how leadership attitudes toward workforce readiness influence capacity-building and response effectiveness.</p>
        <p><italic><bold>Limitations</bold></italic><italic><bold>of</bold></italic><italic><bold>This</bold></italic><italic><bold>Study</bold></italic></p>
        <p>This study has several limitations. The most notable aspect is the scope of the case study sample. While diverse in sectors, the five-case dataset is not intended to be statistically representative. Broader studies with larger and more varied samples would help to validate the observed patterns.</p>
        <p>Second, the qualitative nature of the data, based on interviews and document reviews, limits the ability to establish causality or measure the impact. While rich in context, this approach does not quantify relationships, such as between staffing levels and incident frequency.</p>
        <p>Finally, the cybersecurity landscape has rapidly evolved. New threats, technologies, and regulations have emerged faster than many organizations can adapt. The findings offer a current snapshot, but ongoing reassessment will be essential to keep workforce strategies aligned with future risks.</p>
      </sec>
    </sec>
    <sec id="sec7">
      <title>Role Declaration and Funding Statement</title>
      <p>The first author (Samuel-Noah Osarenkhoe) wrote this article in its entirety as part of his critical reflection and documentation of his experiences in his role as an IT Business Analyst and through his participation in the Executive Master of Science (MSc) in IT &amp; Cybersecurity program at New England College in Massachusetts, USA. This study was conducted parallel to his full-time employment at Global Partner PLC, based in Waltham, Massachusetts, USA. The second author (Aihie Osarenkhoe) is an academic and therefore served solely in an advisory and corresponding author capacity during the primary author’s development of the article.</p>
    </sec>
    <sec id="sec8">
      <title>NOTES</title>
      <p>*Main/first author.</p>
      <p><sup>#</sup>Corresponding author.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Allen, B., Bapst, B. and Hicks, T.A. (2023) Building a Cyber Risk Management Pro-gram: Evolving Security for the Digital Age. O’Reilly Media.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Allen, B.</string-name>
              <string-name>Bapst, B.</string-name>
              <string-name>Hicks, T.A.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Building a Cyber Risk Management Pro-gram: Evolving Security for the Digital Age</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Duska, K. (2025) Critical Infrastructure-Enhancing Security for Critical Infrastructure 2025.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Duska, K.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Critical Infrastructure-Enhancing Security for Critical Infrastructure 2025</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Malatji, M., Marnewick, A.L. and Von Solms, S. (2022) Cybersecurity Capabilities for Critical Infrastructure Resilience. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 30, 255-279. https://doi.org/10.1108/ics-06-2021-0091 <pub-id pub-id-type="doi">10.1108/ics-06-2021-0091</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-06-2021-0091">https://doi.org/10.1108/ics-06-2021-0091</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Malatji, M.</string-name>
              <string-name>Marnewick, A.L.</string-name>
              <string-name>Solms, S.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Cybersecurity Capabilities for Critical Infrastructure Resilience</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>30</volume>
            <pub-id pub-id-type="doi">10.1108/ics-06-2021-0091</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Thomas, G. and Sule, M. (2023) A Service Lens on Cybersecurity Continuity and Management for Organizations’ Subsistence and Growth. <italic>Organizational</italic><italic>Cybersecurity</italic><italic>Journal</italic>: <italic>Practice</italic>, <italic>Process</italic><italic>and</italic><italic>People</italic>, 3, 18-40. https://doi.org/10.1108/ocj-09-2021-0025 <pub-id pub-id-type="doi">10.1108/ocj-09-2021-0025</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ocj-09-2021-0025">https://doi.org/10.1108/ocj-09-2021-0025</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Thomas, G.</string-name>
              <string-name>Sule, M.</string-name>
              <string-name>Practice, P</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Service Lens on Cybersecurity Continuity and Management for Organizations’ Subsistence and Growth</article-title>
            <source>Organizational Cybersecurity Journal: Practice</source>
            <volume>3</volume>
            <pub-id pub-id-type="doi">10.1108/ocj-09-2021-0025</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kandpal, V., Ozili, P.K., Jeyanthi, P.M., Ranjan, D. and Chandra, D. (2025) Cybersecurity and Ensuring Privacy in Digital Finance. In: Kandpal, V., Ozili, P.K., Jeyanthi, P.M., Ranjan, D. and Chandra, D., Eds., <italic>Digital</italic><italic>Finance</italic><italic>and</italic><italic>Metaverse</italic><italic>in</italic><italic>Banking</italic>, Emerald Publishing Limited, 157-170. https://doi.org/10.1108/978-1-83662-088-420251007 <pub-id pub-id-type="doi">10.1108/978-1-83662-088-420251007</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/978-1-83662-088-420251007">https://doi.org/10.1108/978-1-83662-088-420251007</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kandpal, V.</string-name>
              <string-name>Ozili, P.K.</string-name>
              <string-name>Jeyanthi, P.M.</string-name>
              <string-name>Ranjan, D.</string-name>
              <string-name>Chandra, D.</string-name>
              <string-name>Kandpal, V.</string-name>
              <string-name>Ozili, P.K.</string-name>
              <string-name>Jeyanthi, P.M.</string-name>
              <string-name>Ranjan, D.</string-name>
              <string-name>Chandra, D.</string-name>
              <string-name>Banking, E</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Cybersecurity and Ensuring Privacy in Digital Finance</article-title>
            <source>In: Kandpal</source>
            <volume>157</volume>
            <pub-id pub-id-type="doi">10.1108/978-1-83662-088-420251007</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Kour, R. and Karim, R. (2021) Cybersecurity Workforce in Railway: Its Maturity and Awareness. <italic>Journal</italic><italic>of</italic><italic>Quality</italic><italic>in</italic><italic>Maintenance</italic><italic>Engineering</italic>, 27, 453-464. https://doi.org/10.1108/jqme-07-2020-0059 <pub-id pub-id-type="doi">10.1108/jqme-07-2020-0059</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jqme-07-2020-0059">https://doi.org/10.1108/jqme-07-2020-0059</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Kour, R.</string-name>
              <string-name>Karim, R.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Cybersecurity Workforce in Railway: Its Maturity and Awareness</article-title>
            <source>Journal of Quality in Maintenance Engineering</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1108/jqme-07-2020-0059</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Baxter, G. and Sommerville, I. (2011) Socio-Technical Systems: From Design Methods to Systems Engineering. <italic>Interacting</italic><italic>with</italic><italic>Computers</italic>, 23, 4-17. https://doi.org/10.1016/j.intcom.2010.07.003 <pub-id pub-id-type="doi">10.1016/j.intcom.2010.07.003</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.intcom.2010.07.003">https://doi.org/10.1016/j.intcom.2010.07.003</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Baxter, G.</string-name>
              <string-name>Sommerville, I.</string-name>
            </person-group>
            <year>2011</year>
            <article-title>Socio-Technical Systems: From Design Methods to Systems Engineering</article-title>
            <source>Interacting with Computers</source>
            <volume>23</volume>
            <pub-id pub-id-type="doi">10.1016/j.intcom.2010.07.003</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Whitworth, B. (2009) A Brief Introduction to Sociotechnical Systems. In: Khosrow-Pour, M., Ed., <italic>Encyclopedia</italic><italic>of</italic><italic>Information</italic><italic>Science</italic><italic>and</italic><italic>Technology</italic>, <italic>Second</italic><italic>Edition</italic>, IGI Global, 394-400. https://doi.org/10.4018/978-1-60566-026-4.ch066 <pub-id pub-id-type="doi">10.4018/978-1-60566-026-4.ch066</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4018/978-1-60566-026-4.ch066">https://doi.org/10.4018/978-1-60566-026-4.ch066</ext-link></mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Whitworth, B.</string-name>
              <string-name>Khosrow-Pour, M.</string-name>
              <string-name>Technology, S</string-name>
              <string-name>Edition, I</string-name>
            </person-group>
            <year>2009</year>
            <article-title>A Brief Introduction to Sociotechnical Systems</article-title>
            <source>In: Khosrow-Pour</source>
            <volume>394</volume>
            <pub-id pub-id-type="doi">10.4018/978-1-60566-026-4.ch066</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Graham, C.M. (2025) AI Skills in Cybersecurity: Global Job Trends Analysis. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 33, 673-689. https://doi.org/10.1108/ics-09-2024-0235 <pub-id pub-id-type="doi">10.1108/ics-09-2024-0235</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-09-2024-0235">https://doi.org/10.1108/ics-09-2024-0235</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Graham, C.M.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>AI Skills in Cybersecurity: Global Job Trends Analysis</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>33</volume>
            <pub-id pub-id-type="doi">10.1108/ics-09-2024-0235</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Stavrou, E. and Piki, A. (2024) Cultivating Self-Efficacy to Empower Professionals’ Re-Up Skilling in Cybersecurity. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 32, 523-541. https://doi.org/10.1108/ics-02-2024-0038 <pub-id pub-id-type="doi">10.1108/ics-02-2024-0038</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-02-2024-0038">https://doi.org/10.1108/ics-02-2024-0038</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Stavrou, E.</string-name>
              <string-name>Piki, A.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Cultivating Self-Efficacy to Empower Professionals’ Re-Up Skilling in Cybersecurity</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>32</volume>
            <pub-id pub-id-type="doi">10.1108/ics-02-2024-0038</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">U.S. Bureau of Labor Statistics (2023) Information Security Analysts. Occupational Outlook Handbook. U.S. Department of Labor.</mixed-citation>
          <element-citation publication-type="other">
            <year>2023</year>
            <article-title>Information Security Analysts</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Spruit, M. (2022) Information Security Education Based on Job Profiles and the E-CF. <italic>Higher</italic><italic>Education</italic>, <italic>Skills</italic><italic>and</italic><italic>Work</italic>- <italic>Based</italic><italic>Learning</italic>, 12, 294-308. https://doi.org/10.1108/heswbl-09-2020-0208 <pub-id pub-id-type="doi">10.1108/heswbl-09-2020-0208</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/heswbl-09-2020-0208">https://doi.org/10.1108/heswbl-09-2020-0208</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Spruit, M.</string-name>
              <string-name>Education, S</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Information Security Education Based on Job Profiles and the E-CF</article-title>
            <source>Higher Education</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.1108/heswbl-09-2020-0208</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Haney, J.M. and Lutters, W.G. (2021) Cybersecurity Advocates: Discovering the Characteristics and Skills of an Emergent Role. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 29, 485-499. https://doi.org/10.1108/ics-08-2020-0131 <pub-id pub-id-type="doi">10.1108/ics-08-2020-0131</pub-id><pub-id pub-id-type="pmid">34853700</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-08-2020-0131">https://doi.org/10.1108/ics-08-2020-0131</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Haney, J.M.</string-name>
              <string-name>Lutters, W.G.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Cybersecurity Advocates: Discovering the Characteristics and Skills of an Emergent Role</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>29</volume>
            <pub-id pub-id-type="doi">10.1108/ics-08-2020-0131</pub-id>
            <pub-id pub-id-type="pmid">34853700</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Khaw, T.Y., Amran, A. and Teoh, A.P. (2024) Building a Thematic Framework of Cybersecurity: A Systematic Literature Review Approach. <italic>Journal</italic><italic>of</italic><italic>Systems</italic><italic>and</italic><italic>Information</italic><italic>Technology</italic>, 26, 234-256. https://doi.org/10.1108/jsit-07-2023-0132 <pub-id pub-id-type="doi">10.1108/jsit-07-2023-0132</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jsit-07-2023-0132">https://doi.org/10.1108/jsit-07-2023-0132</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Khaw, T.Y.</string-name>
              <string-name>Amran, A.</string-name>
              <string-name>Teoh, A.P.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Building a Thematic Framework of Cybersecurity: A Systematic Literature Review Approach</article-title>
            <source>Journal of Systems and Information Technology</source>
            <volume>26</volume>
            <pub-id pub-id-type="doi">10.1108/jsit-07-2023-0132</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Bechara, F.R. and Schuch, S.B. (2021) Cybersecurity and Global Regulatory Challenges. <italic>Journal</italic><italic>of</italic><italic>Financial</italic><italic>Crime</italic>, 28, 359-374. https://doi.org/10.1108/jfc-07-2020-0149 <pub-id pub-id-type="doi">10.1108/jfc-07-2020-0149</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jfc-07-2020-0149">https://doi.org/10.1108/jfc-07-2020-0149</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Bechara, F.R.</string-name>
              <string-name>Schuch, S.B.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Cybersecurity and Global Regulatory Challenges</article-title>
            <source>Journal of Financial Crime</source>
            <volume>28</volume>
            <pub-id pub-id-type="doi">10.1108/jfc-07-2020-0149</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Haleem, A., Javaid, M., Singh, R.P., Rab, S. and Suman, R. (2022) Perspectives of Cybersecurity for Ameliorative Industry 4.0 Era: A Review-Based Framework. <italic>Industrial</italic><italic>Robot</italic>: <italic>the</italic><italic>international</italic><italic>journal</italic><italic>of</italic><italic>robotics</italic><italic>research</italic><italic>and</italic><italic>application</italic>, 49, 582-597. https://doi.org/10.1108/ir-10-2021-0243 <pub-id pub-id-type="doi">10.1108/ir-10-2021-0243</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ir-10-2021-0243">https://doi.org/10.1108/ir-10-2021-0243</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Haleem, A.</string-name>
              <string-name>Javaid, M.</string-name>
              <string-name>Singh, R.P.</string-name>
              <string-name>Rab, S.</string-name>
              <string-name>Suman, R.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Perspectives of Cybersecurity for Ameliorative Industry 4</article-title>
            <source>0 Era: A Review-Based Framework. Industrial Robot: the international journal of robotics research and application</source>
            <volume>49</volume>
            <pub-id pub-id-type="doi">10.1108/ir-10-2021-0243</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Katsuya, R. and Liu, X. (2025) Policy and Management Implications of Firmware Vulnerabilities in Medical IoT Devices: A Multi-Case Analysis. <italic>Journal</italic><italic>of</italic><italic>Science</italic><italic>and</italic><italic>Technology</italic><italic>Policy</italic><italic>Management</italic>, Ahead-of-Print. https://doi.org/10.1108/jstpm-09-2024-0346 <pub-id pub-id-type="doi">10.1108/jstpm-09-2024-0346</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jstpm-09-2024-0346">https://doi.org/10.1108/jstpm-09-2024-0346</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Katsuya, R.</string-name>
              <string-name>Liu, X.</string-name>
              <string-name>Management, A</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Policy and Management Implications of Firmware Vulnerabilities in Medical IoT Devices: A Multi-Case Analysis</article-title>
            <source>Journal of Science and Technology Policy Management</source>
            <pub-id pub-id-type="doi">10.1108/jstpm-09-2024-0346</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Friday, D., Melnyk, S.A., Altman, M., Harrison, N. and Ryan, S. (2024) An Inductive Analysis of Collaborative Cybersecurity Management Capabilities, Relational Antecedents and Supply Chain Cybersecurity Parameters. <italic>International</italic><italic>Journal</italic><italic>of</italic><italic>Physical</italic><italic>Distribution</italic><italic>&amp;</italic><italic>Logistics</italic><italic>Management</italic>, 54, 476-500. https://doi.org/10.1108/ijpdlm-01-2023-0034 <pub-id pub-id-type="doi">10.1108/ijpdlm-01-2023-0034</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ijpdlm-01-2023-0034">https://doi.org/10.1108/ijpdlm-01-2023-0034</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Friday, D.</string-name>
              <string-name>Melnyk, S.A.</string-name>
              <string-name>Altman, M.</string-name>
              <string-name>Harrison, N.</string-name>
              <string-name>Ryan, S.</string-name>
              <string-name>Capabilities, R</string-name>
            </person-group>
            <year>2024</year>
            <article-title>An Inductive Analysis of Collaborative Cybersecurity Management Capabilities, Relational Antecedents and Supply Chain Cybersecurity Parameters</article-title>
            <source>International Journal of Physical Distribution &amp; Logistics Management</source>
            <volume>54</volume>
            <pub-id pub-id-type="doi">10.1108/ijpdlm-01-2023-0034</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Mumford, E. (2006) The Story of Socio‐Technical Design: Reflections on Its Successes, Failures and Potential. <italic>Information</italic><italic>Systems</italic><italic>Journal</italic>, 16, 317-342. https://doi.org/10.1111/j.1365-2575.2006.00221.x <pub-id pub-id-type="doi">10.1111/j.1365-2575.2006.00221.x</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1111/j.1365-2575.2006.00221.x">https://doi.org/10.1111/j.1365-2575.2006.00221.x</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Mumford, E.</string-name>
              <string-name>Successes, F</string-name>
            </person-group>
            <year>2006</year>
            <article-title>The Story of Socio‐Technical Design: Reflections on Its Successes, Failures and Potential</article-title>
            <source>Information Systems Journal</source>
            <volume>16</volume>
            <pub-id pub-id-type="doi">10.1111/j.1365-2575.2006.00221.x</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B20">
        <label>20.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Xenakis, A., Vlachos, V., Roig, P.J. and Alcaraz, S. (2025) Addressing the Necessity of Cybersecurity Literacy: The Case of ETTCS Cyberteach Project. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 33, 427-451. https://doi.org/10.1108/ics-04-2024-0095 <pub-id pub-id-type="doi">10.1108/ics-04-2024-0095</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-04-2024-0095">https://doi.org/10.1108/ics-04-2024-0095</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Xenakis, A.</string-name>
              <string-name>Vlachos, V.</string-name>
              <string-name>Roig, P.J.</string-name>
              <string-name>Alcaraz, S.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Addressing the Necessity of Cybersecurity Literacy: The Case of ETTCS Cyberteach Project</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>33</volume>
            <pub-id pub-id-type="doi">10.1108/ics-04-2024-0095</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B21">
        <label>21.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Moher, D., Liberati, A., Tetzlaff, J. and Altman, D.G. (2009) Preferred Reporting Items for Systematic Reviews and Meta-Analyses: The PRISMA Statement. <italic>PLOS</italic><italic>Medicine</italic>, 6, e1000097. https://doi.org/10.1371/journal.pmed.1000097 <pub-id pub-id-type="doi">10.1371/journal.pmed.1000097</pub-id><pub-id pub-id-type="pmid">19621072</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1371/journal.pmed.1000097">https://doi.org/10.1371/journal.pmed.1000097</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Moher, D.</string-name>
              <string-name>Liberati, A.</string-name>
              <string-name>Tetzlaff, J.</string-name>
              <string-name>Altman, D.G.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>Preferred Reporting Items for Systematic Reviews and Meta-Analyses: The PRISMA Statement</article-title>
            <source>PLOS Medicine</source>
            <volume>6</volume>
            <pub-id pub-id-type="doi">10.1371/journal.pmed.1000097</pub-id>
            <pub-id pub-id-type="pmid">19621072</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B22">
        <label>22.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Singh, T., Johnston, A.C., D’Arcy, J. and Harms, P.D. (2023) Stress in the Cybersecurity Profession: A Systematic Review of Related Literature and Opportunities for Future Research. <italic>Organizational</italic><italic>Cybersecurity</italic><italic>Journal</italic>: <italic>Practice</italic>, <italic>Process</italic><italic>and</italic><italic>People</italic>, 3, 100-126. https://doi.org/10.1108/ocj-06-2022-0012 <pub-id pub-id-type="doi">10.1108/ocj-06-2022-0012</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ocj-06-2022-0012">https://doi.org/10.1108/ocj-06-2022-0012</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Singh, T.</string-name>
              <string-name>Johnston, A.C.</string-name>
              <string-name>Arcy, J.</string-name>
              <string-name>Harms, P.D.</string-name>
              <string-name>Practice, P</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Stress in the Cybersecurity Profession: A Systematic Review of Related Literature and Opportunities for Future Research</article-title>
            <source>Organizational Cybersecurity Journal: Practice</source>
            <volume>3</volume>
            <pub-id pub-id-type="doi">10.1108/ocj-06-2022-0012</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B23">
        <label>23.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Bowen, P., Hash, J. and Wilson, M. (2006) Information Security Handbook: A Guide for Managers. National Institute of Standards and Technology (NIST Special Publication 800-100).</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Bowen, P.</string-name>
              <string-name>Hash, J.</string-name>
              <string-name>Wilson, M.</string-name>
            </person-group>
            <year>2006</year>
            <article-title>Information Security Handbook: A Guide for Managers</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B24">
        <label>24.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Orji, I.J. and U-Dominic, C.M. (2024) Modelling the Conundrums to Cyber-Risks Management in Logistics Firms for Supply Chain Social Sustainability. <italic>Journal</italic><italic>of</italic><italic>Enterprise</italic><italic>Information</italic><italic>Management</italic>, 37, 1885-1925. https://doi.org/10.1108/jeim-12-2023-0635 <pub-id pub-id-type="doi">10.1108/jeim-12-2023-0635</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jeim-12-2023-0635">https://doi.org/10.1108/jeim-12-2023-0635</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Orji, I.J.</string-name>
              <string-name>U-Dominic, C.M.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Modelling the Conundrums to Cyber-Risks Management in Logistics Firms for Supply Chain Social Sustainability</article-title>
            <source>Journal of Enterprise Information Management</source>
            <volume>37</volume>
            <pub-id pub-id-type="doi">10.1108/jeim-12-2023-0635</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B25">
        <label>25.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Schreiber, A. and Schreiber, I. (2024) Bridging Knowledge Gap: The Contribution of Employees’ Awareness of AI Cyber Risks Comprehensive Program to Reducing Emerging AI Digital Threats. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 32, 613-635. https://doi.org/10.1108/ics-10-2023-0199 <pub-id pub-id-type="doi">10.1108/ics-10-2023-0199</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-10-2023-0199">https://doi.org/10.1108/ics-10-2023-0199</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Schreiber, A.</string-name>
              <string-name>Schreiber, I.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Bridging Knowledge Gap: The Contribution of Employees’ Awareness of AI Cyber Risks Comprehensive Program to Reducing Emerging AI Digital Threats</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>32</volume>
            <pub-id pub-id-type="doi">10.1108/ics-10-2023-0199</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B26">
        <label>26.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Lawelai, H., Purnomo, E.P., Nurmandi, A., Jovita, H. and Baulete, E.M. (2025) Cybersecurity Policy on Smart City Infrastructure: A Mapping of New Threats and Protections. <italic>Journal</italic><italic>of</italic><italic>Science</italic><italic>and</italic><italic>Technology</italic><italic>Policy</italic><italic>Management</italic>, Ahead-of-Print. https://doi.org/10.1108/jstpm-09-2024-0359 <pub-id pub-id-type="doi">10.1108/jstpm-09-2024-0359</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jstpm-09-2024-0359">https://doi.org/10.1108/jstpm-09-2024-0359</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Lawelai, H.</string-name>
              <string-name>Purnomo, E.P.</string-name>
              <string-name>Nurmandi, A.</string-name>
              <string-name>Jovita, H.</string-name>
              <string-name>Baulete, E.M.</string-name>
              <string-name>Management, A</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Cybersecurity Policy on Smart City Infrastructure: A Mapping of New Threats and Protections</article-title>
            <source>Journal of Science and Technology Policy Management</source>
            <pub-id pub-id-type="doi">10.1108/jstpm-09-2024-0359</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B27">
        <label>27.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">NIST (2017) National Institute of Standards and Technology Special Publication 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations, Initial Public Draft.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Organizations, I</string-name>
            </person-group>
            <year>2017</year>
            <article-title>National Institute of Standards and Technology Special Publication 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations, Initial Public Draft</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B28">
        <label>28.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Al-Hawamleh, A.M. (2024) Investigating the Multifaceted Dynamics of Cybersecurity Practices and Their Impact on the Quality of E-Government Services: Evidence from the KSA. <italic>Digital</italic><italic>Policy</italic>, <italic>Regulation</italic><italic>and</italic><italic>Governance</italic>, 26, 317-336. https://doi.org/10.1108/dprg-11-2023-0168 <pub-id pub-id-type="doi">10.1108/dprg-11-2023-0168</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/dprg-11-2023-0168">https://doi.org/10.1108/dprg-11-2023-0168</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Al-Hawamleh, A.M.</string-name>
              <string-name>Policy, R</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Investigating the Multifaceted Dynamics of Cybersecurity Practices and Their Impact on the Quality of E-Government Services: Evidence from the KSA</article-title>
            <source>Digital Policy</source>
            <volume>26</volume>
            <pub-id pub-id-type="doi">10.1108/dprg-11-2023-0168</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B29">
        <label>29.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">NIST (2017) Framework for Improving Critical Infrastructure Cybersecurity, Draft Version 1.1.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cybersecurity, D</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Framework for Improving Critical Infrastructure Cybersecurity, Draft Version 1</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B30">
        <label>30.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Otoom, A.A., Atoum, I., Al-Harahsheh, H., Aljawarneh, M., Al Refai, M.N. and Baklizi, M. (2024) A Collaborative Cybersecurity Framework for Higher Education. <italic>Information</italic><italic>&amp;</italic><italic>Computer</italic><italic>Security</italic>, 33, 362-389. https://doi.org/10.1108/ics-02-2024-0048 <pub-id pub-id-type="doi">10.1108/ics-02-2024-0048</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/ics-02-2024-0048">https://doi.org/10.1108/ics-02-2024-0048</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Otoom, A.A.</string-name>
              <string-name>Atoum, I.</string-name>
              <string-name>Al-Harahsheh, H.</string-name>
              <string-name>Aljawarneh, M.</string-name>
              <string-name>Refai, M.N.</string-name>
              <string-name>Baklizi, M.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Collaborative Cybersecurity Framework for Higher Education</article-title>
            <source>Information &amp; Computer Security</source>
            <volume>33</volume>
            <pub-id pub-id-type="doi">10.1108/ics-02-2024-0048</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B31">
        <label>31.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kritzinger, E. and von Solms, S.H. (2010) Cyber Security for Home Users: A New Way of Protection through Awareness Enforcement. <italic>Computers</italic><italic>&amp;</italic><italic>Security</italic>, 29, 840-847. https://doi.org/10.1016/j.cose.2010.08.001 <pub-id pub-id-type="doi">10.1016/j.cose.2010.08.001</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2010.08.001">https://doi.org/10.1016/j.cose.2010.08.001</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kritzinger, E.</string-name>
              <string-name>Solms, S.H.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>Cyber Security for Home Users: A New Way of Protection through Awareness Enforcement</article-title>
            <source>Computers &amp; Security</source>
            <volume>29</volume>
            <pub-id pub-id-type="doi">10.1016/j.cose.2010.08.001</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B32">
        <label>32.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Asbaş, A.T. and Tuzlukaya, Ş. (2022) Analysis of Critical Infrastructure Resilience for Cyber-Physical Systems. <italic>Journal of Information Security and Cybercrimes Research</italic>, 5, 102-114.</mixed-citation>
          <element-citation publication-type="journal">
            <year>2022</year>
            <article-title>Analysis of Critical Infrastructure Resilience for Cyber-Physical Systems</article-title>
            <source>Journal of Information Security and Cybercrimes Research</source>
            <volume>5</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B33">
        <label>33.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Pipyros, K. and Liasidou, S. (2025) A New Cybersecurity Risk Assessment Framework for the Hospitality Industry: Techniques and Methods for Enhanced Data Protection and Threat Mitigation. <italic>Worldwide</italic><italic>Hospitality</italic><italic>and</italic><italic>Tourism</italic><italic>Themes</italic>, 17, 48-61. https://doi.org/10.1108/whatt-12-2024-0296 <pub-id pub-id-type="doi">10.1108/whatt-12-2024-0296</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/whatt-12-2024-0296">https://doi.org/10.1108/whatt-12-2024-0296</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Pipyros, K.</string-name>
              <string-name>Liasidou, S.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>A New Cybersecurity Risk Assessment Framework for the Hospitality Industry: Techniques and Methods for Enhanced Data Protection and Threat Mitigation</article-title>
            <source>Worldwide Hospitality and Tourism Themes</source>
            <volume>17</volume>
            <pub-id pub-id-type="doi">10.1108/whatt-12-2024-0296</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B34">
        <label>34.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Yeboah-Ofori, A. and Opoku-Boateng, F.A. (2023) Mitigating Cybercrimes in an Evolving Organizational Landscape. <italic>Continuity</italic><italic>&amp;</italic><italic>Resilience</italic><italic>Review</italic>, 5, 53-78. https://doi.org/10.1108/crr-09-2022-0017 <pub-id pub-id-type="doi">10.1108/crr-09-2022-0017</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/crr-09-2022-0017">https://doi.org/10.1108/crr-09-2022-0017</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Yeboah-Ofori, A.</string-name>
              <string-name>Opoku-Boateng, F.A.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Mitigating Cybercrimes in an Evolving Organizational Landscape</article-title>
            <source>Continuity &amp; Resilience Review</source>
            <volume>5</volume>
            <pub-id pub-id-type="doi">10.1108/crr-09-2022-0017</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B35">
        <label>35.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Mwogosi, A. and Simba, R. (2025) Digital Policy and Governance Frameworks for EHR Systems in Tanzania: A Scoping Review. <italic>Digital</italic><italic>Policy</italic>, <italic>Regulation</italic><italic>and</italic><italic>Governance</italic>, 28, 52-74. https://doi.org/10.1108/dprg-11-2024-0289 <pub-id pub-id-type="doi">10.1108/dprg-11-2024-0289</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/dprg-11-2024-0289">https://doi.org/10.1108/dprg-11-2024-0289</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Mwogosi, A.</string-name>
              <string-name>Simba, R.</string-name>
              <string-name>Policy, R</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Digital Policy and Governance Frameworks for EHR Systems in Tanzania: A Scoping Review</article-title>
            <source>Digital Policy</source>
            <volume>28</volume>
            <pub-id pub-id-type="doi">10.1108/dprg-11-2024-0289</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B36">
        <label>36.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Chen, S.P. and Redar, J.M. (2014) Ageing Workforce Knowledge Management and Transactional and Transformational Leadership: A Socio-Technical Systems Framework and a Norwegian Case Study. <italic>International Journal of Business and Social Science</italic>, 5, 11-21.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Chen, S.P.</string-name>
              <string-name>Redar, J.M.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Ageing Workforce Knowledge Management and Transactional and Transformational Leadership: A Socio-Technical Systems Framework and a Norwegian Case Study</article-title>
            <source>International Journal of Business and Social Science</source>
            <volume>5</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B37">
        <label>37.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Lnenicka, M., Kysela, T. and Horák, O. (2025) Building Security and Resilience: A Guide to Implementing Effective Cybersecurity and Data Protection Measures in Smart Cities. <italic>Smart</italic><italic>and</italic><italic>Sustainable</italic><italic>Built</italic><italic>Environment</italic>, 15, 908-937. https://doi.org/10.1108/sasbe-09-2024-0363 <pub-id pub-id-type="doi">10.1108/sasbe-09-2024-0363</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/sasbe-09-2024-0363">https://doi.org/10.1108/sasbe-09-2024-0363</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Lnenicka, M.</string-name>
              <string-name>Kysela, T.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Building Security and Resilience: A Guide to Implementing Effective Cybersecurity and Data Protection Measures in Smart Cities</article-title>
            <source>Smart and Sustainable Built Environment</source>
            <volume>15</volume>
            <pub-id pub-id-type="doi">10.1108/sasbe-09-2024-0363</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B38">
        <label>38.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Krishna, B., Krishnan, S. and Sebastian, M.P. (2023) Understanding the Process of Building Institutional Trust among Digital Payment Users through National Cybersecurity Commitment Trustworthiness Cues: A Critical Realist Perspective. <italic>Information</italic><italic>Technology</italic><italic>&amp;</italic><italic>People</italic>, 38, 714-756. https://doi.org/10.1108/itp-05-2023-0434 <pub-id pub-id-type="doi">10.1108/itp-05-2023-0434</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/itp-05-2023-0434">https://doi.org/10.1108/itp-05-2023-0434</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Krishna, B.</string-name>
              <string-name>Krishnan, S.</string-name>
              <string-name>Sebastian, M.P.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Understanding the Process of Building Institutional Trust among Digital Payment Users through National Cybersecurity Commitment Trustworthiness Cues: A Critical Realist Perspective</article-title>
            <source>Information Technology &amp; People</source>
            <volume>38</volume>
            <pub-id pub-id-type="doi">10.1108/itp-05-2023-0434</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B39">
        <label>39.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Anderson, R. and Moore, T. (2006) The Economics of Information Security. <italic>Science</italic>, 314, 610-613. https://doi.org/10.1126/science.1130992 <pub-id pub-id-type="doi">10.1126/science.1130992</pub-id><pub-id pub-id-type="pmid">17068253</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1126/science.1130992">https://doi.org/10.1126/science.1130992</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Anderson, R.</string-name>
              <string-name>Moore, T.</string-name>
            </person-group>
            <year>2006</year>
            <article-title>The Economics of Information Security</article-title>
            <source>Science</source>
            <volume>314</volume>
            <pub-id pub-id-type="doi">10.1126/science.1130992</pub-id>
            <pub-id pub-id-type="pmid">17068253</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B40">
        <label>40.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Younies, H. and Al-Tawil, T.N. (2020) Effect of Cybercrime Laws on Protecting Citizens and Businesses in the United Arab Emirates (UAE). <italic>Journal</italic><italic>of</italic><italic>Financial</italic><italic>Crime</italic>, 27, 1089-1105. https://doi.org/10.1108/jfc-04-2020-0055 <pub-id pub-id-type="doi">10.1108/jfc-04-2020-0055</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1108/jfc-04-2020-0055">https://doi.org/10.1108/jfc-04-2020-0055</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Younies, H.</string-name>
              <string-name>Al-Tawil, T.N.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Effect of Cybercrime Laws on Protecting Citizens and Businesses in the United Arab Emirates (UAE)</article-title>
            <source>Journal of Financial Crime</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1108/jfc-04-2020-0055</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B41">
        <label>41.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Radanliev, P., De Roure, D., Van Kleek, M., Santos, O. and Ani, U. (2020) Artificial Intelligence in Cyber Physical Systems. <italic>AI</italic><italic>&amp;</italic><italic>SOCIETY</italic>, 36, 783-796. https://doi.org/10.1007/s00146-020-01049-0 <pub-id pub-id-type="doi">10.1007/s00146-020-01049-0</pub-id><pub-id pub-id-type="pmid">32874020</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s00146-020-01049-0">https://doi.org/10.1007/s00146-020-01049-0</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Radanliev, P.</string-name>
              <string-name>Roure, D.</string-name>
              <string-name>Kleek, M.</string-name>
              <string-name>Santos, O.</string-name>
              <string-name>Ani, U.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Artificial Intelligence in Cyber Physical Systems</article-title>
            <source>AI &amp; SOCIETY</source>
            <volume>36</volume>
            <pub-id pub-id-type="doi">10.1007/s00146-020-01049-0</pub-id>
            <pub-id pub-id-type="pmid">32874020</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B42">
        <label>42.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Rangarajan, A., Nobles, C., Dykstra, J., Cunningham, M., Robinson, N., Hollis, T., et al. (2025) A Roadmap to Address Burnout in the Cybersecurity Profession: Outcomes from a Multifaceted Workshop. In: Moallem, A., Ed., <italic>Lecture</italic><italic>Notes</italic><italic>in</italic><italic>Computer</italic><italic>Science</italic>, Springer Nature Switzerland, 125-140. https://doi.org/10.1007/978-3-031-92833-8_8 <pub-id pub-id-type="doi">10.1007/978-3-031-92833-8_8</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-031-92833-8_8">https://doi.org/10.1007/978-3-031-92833-8_8</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Rangarajan, A.</string-name>
              <string-name>Nobles, C.</string-name>
              <string-name>Dykstra, J.</string-name>
              <string-name>Cunningham, M.</string-name>
              <string-name>Robinson, N.</string-name>
              <string-name>Hollis, T.</string-name>
              <string-name>Moallem, A.</string-name>
              <string-name>Science, S</string-name>
            </person-group>
            <year>2025</year>
            <article-title>A Roadmap to Address Burnout in the Cybersecurity Profession: Outcomes from a Multifaceted Workshop</article-title>
            <source>In: Moallem</source>
            <volume>125</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-031-92833-8_8</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B43">
        <label>43.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Tallam, K. (2025) The Cyber Immune System: Harnessing Adversarial Forces for Security Resilience. arXiv:2502.17698. https://arxiv.org/abs/2502.17698</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Tallam, K.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>The Cyber Immune System: Harnessing Adversarial Forces for Security Resilience</article-title>
            <fpage>2502</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B44">
        <label>44.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Walendy, P., Koch, D. and Paar, C. (2024) A Curriculum Initiative for Hardware Reverse Engineering (HRE). In: <italic>Proceedings of the</italic>2024 <italic>Workshop on Cybersecurity Education</italic> ( <italic>CSE</italic> ‘24). Association for Computing Machinery.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Walendy, P.</string-name>
              <string-name>Koch, D.</string-name>
              <string-name>Paar, C.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Curriculum Initiative for Hardware Reverse Engineering (HRE)</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B45">
        <label>45.</label>
        <citation-alternatives>
          <mixed-citation publication-type="web">Alevizos, L. (2025) A Complexity-Informed Approach to Optimise Cyber Defences. Volvo Group. https://arxiv.org/pdf/2501.15578</mixed-citation>
          <element-citation publication-type="web">
            <person-group person-group-type="author">
              <string-name>Alevizos, L.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>A Complexity-Informed Approach to Optimise Cyber Defences</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B46">
        <label>46.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ncube, T.R., Sishi, K.K. and Skinner, J.P. (2025) The Impact of Artificial Intelligence on Human Resource Management Practices: An Investigation. <italic>SA</italic><italic>Journal</italic><italic>of</italic><italic>Human</italic><italic>Resource</italic><italic>Management</italic>, 23, a2960. https://doi.org/10.4102/sajhrm.v23i0.2960 <pub-id pub-id-type="doi">10.4102/sajhrm.v23i0.2960</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajhrm.v23i0.2960">https://doi.org/10.4102/sajhrm.v23i0.2960</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ncube, T.R.</string-name>
              <string-name>Sishi, K.K.</string-name>
              <string-name>Skinner, J.P.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>The Impact of Artificial Intelligence on Human Resource Management Practices: An Investigation</article-title>
            <source>SA Journal of Human Resource Management</source>
            <volume>23</volume>
            <pub-id pub-id-type="doi">10.4102/sajhrm.v23i0.2960</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>