Skip to content
Review Open access

Threats, Defences, and Governance in Cyber–Physical Systems Security: A Structured Review of the 2020–2026 Literature

Sep 2026 · Journal of Cybersecurity and Privacy · 0 citations · 57 references

TL;DR

A structured narrative review of 82 sources organised through the CPS Defence-Gap Taxonomy—a framework that classifies 14 attack mechanisms by architectural layer and physical impact, evaluates six defensive technology categories against documented failure modes, and maps five governance dimensions to the institutional conditions required for deployment.

Abstract

When a water treatment plant, power grid, or pipeline is compromised, the consequences extend beyond data loss: a manipulated sensor reading can trigger physical damage, and a disabled safety interlock can endanger lives. Cyber–physical systems (CPSs) sit at this intersection of digital control and physical process, yet existing security reviews treat threats and defences in separate silos, leaving practitioners without a clear picture of which defences fail against which attacks, and why. This paper fills that gap with a structured narrative review of 82 sources (70 from the primary window January 2020 to April 2026, plus 12 foundational pre-2020 works), organised through the CPS Defence-Gap Taxonomy (CPS-DGT)—a framework that classifies 14 attack mechanisms by architectural layer and physical impact, evaluates six defensive technology categories against documented failure modes, and maps five governance dimensions to the institutional conditions required for deployment. Across five intrusion detection system (IDS) studies that differ in dataset, attack selection, training regime and evaluation scope, reported F1 scores lie between 0.796 and 0.969 under each study’s own standard conditions; these values are not a controlled comparison and are reported descriptively. For the one architecture evaluated under adversarial evasion, F1 falls by 37.4 percentage points in absolute terms, a relative reduction of 38.6%. The defence-gap matrix identifies seven entries with insufficient coverage. Five of the 14 attack mechanisms are uncovered: A03, A09, A10, A11 and A14. Two further mechanisms, A01 and A12, have only partial defences. Adversarial evasion of learned detectors is reported separately as a transversal failure mode of one defensive category rather than as an attack mechanism. The uncovered mechanisms cluster at the cyber–physical boundary and in supply-chain channels. We conclude with five concrete research challenges, each with a direct path from the identified gap to a tractable research agenda.

Read PDF

Similar papers

Open access Aug 2026

Weaponised interdependence and European energy security: Infrastructure, systemic vulnerability, and the post-2022 transformation

This article extends a concept developed by Farrell and Newman (2019) beyond its original financial and digital domains to physical energy infrastructure, examining how the Russia–Ukraine war has transformed European energy security from a market-based relationship into a condition of systemic vulnerability. The analys...

Elmir Badalov · 0 citations
Review Open access Sep 2026

A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030

This review examines how a threat-driven cyber resilience approach combining integrated security architecture, cyber-threat intelligence (CTI), zero-trust principles, and adaptive security operations can enhance the continuity and protection of Saudi government digital services within the wider objectives of Vision 203...

Ilyas Siddiqui Mohammad · 0 citations
Open access Sep 2026

A UNIFIED CYBER‑PHYSICAL INCIDENT RESPONSE AND BUSINESS CONTINUITY ARCHITECTURE FOR MANAGING HYBRID, SYSTEMIC, AND CASCADING RISKS ACROSS IT, OT, AND PHYSICAL SECURITY DOMAINS

The proposed IRBC architecture will help improve organisational resilience by consolidating incident response and continuity functions, share a common situational awareness based on integrated monitoring, limit lateral movement through the enforcement of Zero Trust and enrich recovery goals across the different domains...

Vladimir Bunic · 0 citations
Review Open access 2026

Emerging Technologies and Cybersecurity in Critical Information Infrastructure and Industrial Control Systems: An Integrated Cyber Risk Pathway Model

The digital transformation of Critical Information Infrastructure (CII) and Industrial Control Systems (ICS) through Industry 4.0 technologies introduces significant cybersecurity challenges. While existing research examines technologies individually, little attention has been given to how their combined adoption resha...

Jennita Rao Appanah Appayya, S. Armoogum, Kaleem Usmani · 0 citations
Open access Sep 2026

A Study on an Attack-Stage-Based Integrated Response Framework for Security Vulnerability Management in Defense Companies

Defense companies possess critical technologies directly linked to national security and remain persistent targets of state-sponsored hacking groups. Recent attacks combine application vulnerabilities, compromised accounts, externally exposed assets, and software supply chains. Consequently, conventional vulnerability...

Seoungsoo Park · 0 citations
Open access Oct 2026

Resilience of Critical Defence Buildings and Building Services Infrastructure to Hybrid and Climate Threats: A Multicriteria Assessment Framework

Defence missions depend on buildings, utilities, operational technologies, and external services that increasingly function as an interdependent cyber-physical system. Conventional asset-condition assessments do not adequately capture mission continuity under simultaneous physical, cyber, energy, and climate disruption...

Mihai Alexandru Veleanu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.