Identifying root causes and propagation paths of systemic cybersecurity risks in digital twins: a mixed-method approach
| dc.contributor.author | Erol, İsmail | |
| dc.contributor.author | Öztel, Ahmet | |
| dc.contributor.author | Medeni, Ihsan Tolga | |
| dc.contributor.author | Ar, İlker Murat | |
| dc.date.accessioned | 2026-08-16T09:26:29Z | |
| dc.date.issued | 2026 | |
| dc.department | Bartın Üniversitesi | |
| dc.description.abstract | Purpose This study addresses the research gap in understanding systemic interdependencies among cybersecurity challenges in digital twins (DTs) by proposing a novel framework to model these relationships under uncertainty, supporting anticipatory governance in critical sectors such as healthcare.Design/methodology/approach A mixed methods approach combines a systematic literature review with a Picture Fuzzy Interpretive Structural Modeling and MICMAC (PF-ISM MICMAC) framework. Picture fuzzy sets capture indeterminacy and refusal in expert judgments from a multidisciplinary panel of experts. Robustness is validated through 10,000 Monte Carlo simulations and a leave-one-out sensitivity analysis, complemented by semi-structured interviews.Findings Ten key cybersecurity challenges are identified. Lack of standardization and regulation, infrastructure vulnerabilities and inadequate resilience metrics emerge as foundational drivers. Data poisoning, secure communication and lack of interoperability are linkage factors with high driving and dependence power, forming a dynamic risk core. Insider threats and lack of system resilience are dependent outcomes. Validation confirms high structural stability and practical relevance.Practical implications Policy: Urges global regulatory harmonization and standardized security frameworks for DTs. Managerial: Provides a risk-based prioritization heuristic that invests in high driving factors, integrates responses for linkage factors and monitors dependent outcomes.Originality/value This study does not claim to invent a wholly new methodology. Rather, its originality lies in: (1) the novel application of the PF-ISM MICMAC framework to model systemic interdependencies among DT cybersecurity challenges, a domain where prior research has treated challenges as independent and (2) the empirically grounded and validated six-level hierarchical framework, which enables proactive systemic risk analysis. | |
| dc.identifier.doi | 10.1108/JEIM-03-2026-0497 | |
| dc.identifier.issn | 1741-0398 | |
| dc.identifier.issn | 1758-7409 | |
| dc.identifier.uri | http://doi.org/10.1108/JEIM-03-2026-0497 | |
| dc.identifier.uri | https://hdl.handle.net/11772/27876 | |
| dc.identifier.wos | WOS:001804250600001 | |
| dc.identifier.wosquality | Q1 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.language.iso | en | |
| dc.publisher | Emerald Group Publishing Ltd | |
| dc.relation.ispartof | Journal of Enterprise Information Management | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/closedAccess | |
| dc.snmz | KA_WoS_20260815 | |
| dc.subject | Digital Twin Security | |
| dc.subject | Cybersecurity Risk Propagation | |
| dc.subject | Interpretive Structural Modeling | |
| dc.subject | Micmac Analysis | |
| dc.subject | Qualitative And Quantitative Validation | |
| dc.title | Identifying root causes and propagation paths of systemic cybersecurity risks in digital twins: a mixed-method approach | |
| dc.type | Article | |
| dc.wosindex | Social Science Citation Index (SSCI) | |
| dspace.entity.type | Publication |










