International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722430

1722430 Vol 10 · Issue 2 Download Paper

Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives

Ken Mudzingwa Stewart Munyaradzi Nyamutswa Admore Tafadzwa Mugwadzi Panashe Yolanda Dhegwa Munashe Naphtali Mupa

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

Abstract

Critical infrastructure now depends on cloud platforms, 5G-enabled connectivity, operational technology, Internet of Things devices and data-intensive service delivery. This convergence has widened the attack surface for essential sectors such as energy, water, telecommunications, healthcare, banking, government and transportation. Building on critical-infrastructure cybersecurity scholarship and using a structured public incident dataset of 3,000 records covering 2015-2024, this paper develops an empirical picture of cyber risk across attack types, industries, countries, vulnerability classes and defensive mechanisms. The analysis shows that the sample records an aggregate estimated financial exposure of USD 151.48 billion, an average incident loss of USD 50.49 million, approximately 1.51 billion affected-user records and a mean resolution time of 36.48 hours. DDoS and phishing appear as the most frequent attack categories, while the IT, banking and healthcare sectors carry the largest incident counts. Heat-map analysis identifies Government-DDoS, Telecommunications-Man-in-the-Middle and IT-Man-in-the-Middle combinations as notable high-risk cells under a composite impact measure combining financial loss, affected users and incident resolution time. Statistical tests show weak direct association between categorical attack labels and loss severity, implying that omitted variables such as asset criticality, control maturity, identity exposure, network segmentation, patch latency, vendor concentration and incident-response capability may be more decisive than sector labels alone. The paper therefore proposes a risk-based Critical Infrastructure Cyber Resilience Framework built around governance, asset visibility, zero-trust identity, vulnerability prioritisation, AI-assisted detection, supply-chain assurance, incident reporting and recovery engineering. The contribution is both empirical and practical: it provides an applied analytics model for prioritising critical-infrastructure cyber risk and a governance architecture aligned with NIST CSF 2.0 and contemporary critical-infrastructure protection requirements.

Keywords

critical infrastructure; cybersecurity; 5G security; cloud security; cyber resilience; ransomware; DDoS; vulnerability management; NIST CSF; cyber risk analytics.

How to cite this paper

Ken Mudzingwa, Stewart Munyaradzi Nyamutswa, Admore Tafadzwa Mugwadzi, Panashe Yolanda Dhegwa, Munashe Naphtali Mupa "Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives" Iconic Research And Engineering Journals Volume 10 Issue 2 2026 Page 2482-2496
Ken Mudzingwa, Stewart Munyaradzi Nyamutswa, Admore Tafadzwa Mugwadzi, Panashe Yolanda Dhegwa, Munashe Naphtali Mupa "Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026
Ken Mudzingwa, Stewart Munyaradzi Nyamutswa, Admore Tafadzwa Mugwadzi, Panashe Yolanda Dhegwa, Munashe Naphtali Mupa (2026). Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives. Iconic Research And Engineering Journals, 10(2).
Ken Mudzingwa, Stewart Munyaradzi Nyamutswa, Admore Tafadzwa Mugwadzi, Panashe Yolanda Dhegwa, Munashe Naphtali Mupa "Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026.
@article{1722430,
      author = {Ken Mudzingwa, Stewart Munyaradzi Nyamutswa, Admore Tafadzwa Mugwadzi, Panashe Yolanda Dhegwa, Munashe Naphtali Mupa},
      title = {Cybersecurity of Critical Infrastructures: Challenges, Empirical Threat Analytics and Future Resilience Perspectives},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {2},
      pages = {2482-2496},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722430.pdf},
      abstract = {Critical infrastructure now depends on cloud platforms, 5G-enabled connectivity, operational technology, Internet of Things devices and data-intensive service delivery. This convergence has widened the attack surface for essential sectors such as energy, water, telecommunications, healthcare, banking, government and transportation. Building on critical-infrastructure cybersecurity scholarship and using a structured public incident dataset of 3,000 records covering 2015-2024, this paper develops an empirical picture of cyber risk across attack types, industries, countries, vulnerability classes and defensive mechanisms. The analysis shows that the sample records an aggregate estimated financial exposure of USD 151.48 billion, an average incident loss of USD 50.49 million, approximately 1.51 billion affected-user records and a mean resolution time of 36.48 hours. DDoS and phishing appear as the most frequent attack categories, while the IT, banking and healthcare sectors carry the largest incident counts. Heat-map analysis identifies Government-DDoS, Telecommunications-Man-in-the-Middle and IT-Man-in-the-Middle combinations as notable high-risk cells under a composite impact measure combining financial loss, affected users and incident resolution time. Statistical tests show weak direct association between categorical attack labels and loss severity, implying that omitted variables such as asset criticality, control maturity, identity exposure, network segmentation, patch latency, vendor concentration and incident-response capability may be more decisive than sector labels alone. The paper therefore proposes a risk-based Critical Infrastructure Cyber Resilience Framework built around governance, asset visibility, zero-trust identity, vulnerability prioritisation, AI-assisted detection, supply-chain assurance, incident reporting and recovery engineering. The contribution is both empirical and practical: it provides an applied analytics model for prioritising critical-infrastructure cyber risk and a governance architecture aligned with NIST CSF 2.0 and contemporary critical-infrastructure protection requirements.},
      keywords = {critical infrastructure; cybersecurity; 5G security; cloud security; cyber resilience; ransomware; DDoS; vulnerability management; NIST CSF; cyber risk analytics.},
      month = {August},
  }