JOURNAL

Organisational cybersecurity challenges in digital twin development: A critical analysis and research directions

November 2026

Digital twin cybersecurity

Authors:

Stefanos Evripidou
Xicheng Li a
Mohammad Al-Quraan
Runze Cheng
Ahmad Taha
Muhammad Imran
David Flynn
Dimitrios Pezaros

Universities

University of Glasgow

Demonstrator / Work Package

Work Package 3

In the past decade, Digital Twins (DTs) have emerged as a key enabler of industry digitalisation. As digital representations of physical objects and processes, DTs integrate a range of technologies to support applications from process monitoring to policymaking. However, increased system integration expands their attack surface, heightening cybersecurity risks. Efforts to integrate DTs into larger ecosystems have further intensified these concerns.

Cybersecurity is inherently a socio-technical challenge influenced by various organisational and governance considerations. However, cybersecurity research on DTs has remained predominantly technical. As such, the current understanding of how organisational cybersecurity challenges emerge in DT contexts is limited. This work addresses this gap through a critical analysis of literature, examining how cybersecurity is conceptualised in DT implementation and the extent to which organisational cybersecurity challenges are addressed.

Our analysis demonstrates that cybersecurity is widely acknowledged as a challenge in DT implementation. Nevertheless, most research offers limited in-depth analysis of specific cybersecurity challenges in real-world contexts. When addressed, cybersecurity was primarily framed around confidentiality and privacy, while other elements including data integrity and system availability are overlooked. Where cybersecurity has been the primary focus, works have been overwhelmingly technical, overlooking organisational complexities that affect cybersecurity in practice. This highlights a clear gap in understanding of how organisational cybersecurity challenges emerge in DTs. We conclude by outlining an agenda for future research to support more effective and secure approaches to DT implementation.