Cybersecurity research on digital twins lacks ‘real-world’ organisational insight, study warns
‘Security fatigue,’ governance challenges and clashing organisational priorities are among the underexplored cybersecurity risks that could threaten digital twin networks, researchers have found.
Digital twins are digital replicas of the physical world that are increasingly being used to improve the efficiency and performance of real-world systems in sectors including transport, construction, manufacturing and healthcare.
But researchers for transport decarbonisation hub TransiT have identified a gap in cybersecurity research, where an overwhelming focus on the technical aspects of digital twinning has meant that cybersecurity challenges around organisations and their teams have been overlooked.

TransiT researcher Dr Stefanos Evripidou.
Research lead author Dr Stefanos Evripidou, a TransiT cybersecurity researcher at University of Glasgow, explained: “Cybersecurity is both a social and a technical challenge, because it involves people and organisational processes, as well as technology. These dimensions are inherently interdependent, so we need to understand the technical and the organisational challenges together rather than in isolation. But our research has found that very little is known about the kind of real-world cybersecurity issues that organisations face around the implementation of digital twins. It’s critical that we bridge this gap in knowledge – because digital twins are being scaled and connected to address increasingly complex challenges that span whole sectors or societies. And this means we’re also hugely expanding the attack surface, increasing exposure to cybersecurity threats.”
Writing in the journal, Computers & Security, Dr Evripidou and his team detail this gap in research and also propose a framework to help identify what further research is needed.
“Where cybersecurity has been the primary focus, works have been overwhelmingly technical, overlooking organisational complexities that affect cybersecurity in practice,” the researchers say.
The work involved searching through more than 1,800 pieces of academic research on cybersecurity, digital twins and organisational challenges to their adoption, and focusing on 41 of these which included social or organisational perspectives, including participant research.

How cybersecurity governance links organisations, people and technology. Graphic by Stefanos Evripidou.
Alongside technical challenges, like how to identify and repel cyber attacks or get diverse systems to interoperate and share data, the research identifies a series of non-technical challenges and organisational barriers. These include how to get cyber security practitioners to collaborate when they have competing priorities, and how to avoid employees ignoring security policies because they conflict with their main job. These challenges may be amplified in digital twin contexts, where multiple stakeholders are involved in the development and operation of digital twins, creating additional governance and coordination challenges.
“Security often conflicts with other business practices, particularly when it adds additional workload, creating friction between security and productivity,” the researchers say. “This can result in security fatigue, where employees may adopt less demanding workarounds and more broadly, lead to security’s exclusion from the decision-making process.”
Other business-related challenges include financial constraints, lack of organisational commitment and ‘cultural inertia’ to digitalisation. Employees can also resist the adoption of digital twins because of fears about potential job losses. And shortages in digital and data-related skills is another major challenge.
While these and other topics are discussed separately in research related to digital twinning or cybersecurity, very few papers explore the two topics together.
“A key gap identified in our analysis is the limited research into how digital twin stakeholders understand cybersecurity and its associated risks in digital twins,” the researchers say.
To address this, the paper sets out an agenda for future research, including high-level research questions that can be adapted to different settings and sectors.

Dr Stefanos Evripidou presenting his work at a cybersecurity event.
Key recommendations include:
- Study cybersecurity in real-world digital twin projects
The paper calls for interviews, case studies and ethnographic research – which captures the lived experiences of community members – to understand how organisations actually manage digital twin cybersecurity in practice, and how cybersecurity risks vary across different digital twin use cases and operational contexts.
- Map stakeholder responsibilities
TransiT’s researchers argue that future work must examine how cybersecurity responsibilities are shared across IT, operational technology, data teams and external suppliers – and how these evolve as digital twins scale.
- Develop governance and regulatory frameworks
The study notes that existing standards do not adequately address digital twin-specific risks. It highlights the need for new governance structures, especially as the UK moves toward interconnected digital twin ecosystems in transport and energy.
- Create tools to help organisations prioritise risks
The authors propose a new “sensemaking framework” that helps organisations assess cybersecurity needs based on a twin’s purpose, level of physical integration and criticality.
“We therefore call for further research to address these gaps and support the development of secure and resilient digital twin systems,” the researchers conclude.
The paper is entitled Organisational cybersecurity challenges in digital twin development: A critical analysis and research directions. Its co-authors are all TransiT academics based at the University of Glasgow and are Xicheng Li, Dr Mohammad Al-Quraan, Dr Runze Cheng, Dr Ahmad Taha, Professor Muhammad Imran, Professor David Flynn and Professor Dimitrios Pezaros.
TransiT is a UK research hub using digital twins to identify the least-risky, lowest-cost routes to zero emission transport in the UK.
It is a collaboration of eight universities and almost 70 industry partners, jointly led by Heriot-Watt University in Edinburgh and the University of Glasgow, and supported by the UKRI Engineering and Physical Sciences Research Council (EPSRC), the main funding body for engineering and physical sciences research in the UK, and by the UK government’s Department for Transport.


