PHYSICAL VULNERABILITY OF CYBER SYSTEMS: ANALYSIS OF INCIDENTS, RISK FACTORS AND SECURITY STRATEGIES
DOI:
https://doi.org/10.68302/std2026.vol1.58Keywords:
Critical Infrastructure Protection, Cyber-Physical Systems, Physical Vulnerability, Risk AssessmentAbstract
Physical security is an essential component of cybersecurity risk management because many cyber and operational technology systems depend on protected facilities, equipment, power supply, communication links and environmental conditions. This paper revises the analysis of physical vulnerability in cyber systems by distinguishing direct physical compromise from cyber incidents that produce physical consequences. A qualitative incident-based methodology is applied to selected cases from 2020 to 2024 and to recent cyber-physical security literature. The method includes source screening, inclusion and exclusion criteria, incident coding by physical vector, affected asset, impact and dependency, and a reproducible ordinal risk score. The results systematize incidents into five categories: direct physical attacks on infrastructure, environmental disruption, compromise of physical-security platforms, compromise of operational technology with physical consequences, and hybrid cyber-physical scenarios. The paper proposes a methodological framework for assessing such incidents and maps the main risk factors to practical security strategies. The findings show that physical vulnerability should not be reduced to facility protection alone; it should be treated as a combined governance, engineering and incident-response problem linking physical access, operational technology, cyber monitoring and business continuity.
Downloads
References
[1] Allied Universal, "World Security Report 2023," 2023. [Online]. Available: https://www.worldsecurityreport.com/media/v1ahrj2v/a4_world-security-report_vf_en.pdf. [Accessed: May 4, 2026].
[2] K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, A. Hahn, and S. H. Le, "Guide to Operational Technology (OT) Security," NIST Special Publication 800-82 Rev. 3, 2023. [Online]. Available: https://doi.org/10.6028/NIST.SP.800-82r3. [Accessed: May 4, 2026].
[3] H. Harkat, L. M. Camarinha-Matos, J. Goes, and H. F. T. Ahmed, "Cyber-physical systems security: A systematic review," Computers & Industrial Engineering, vol. 188, 109891, Feb. 2024, https://doi.org/10.1016/j.cie.2024.109891.
[4] A. Akbarzadeh and S. K. Katsikas, "Dependency-based security risk assessment for cyber-physical systems," International Journal of Information Security, vol. 22, no. 3, pp. 563-578, 2023, https://doi.org/10.1007/s10207-022-00608-4.
[5] X. Lyu, Y. Ding, and S.-H. Yang, "Safety and security risk assessment in cyber-physical systems," IET Cyber-Physical Systems: Theory & Applications, vol. 4, no. 3, pp. 221-232, 2019, https://doi.org/10.1049/iet-cps.2018.5068.
[6] N. Agrawal and R. Kumar, "Security perspective analysis of industrial cyber physical systems (I-CPS): A decade-wide survey," ISA Transactions, vol. 130, pp. 10-24, 2022, https://doi.org/10.1016/j.isatra.2022.03.018.
[7] National Institute of Standards and Technology, "The NIST Cybersecurity Framework (CSF) 2.0," NIST Cybersecurity White Paper 29, Feb. 2024. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf. [Accessed: May 4, 2026].
[8] Cybersecurity and Infrastructure Security Agency, "Cross-Sector Cybersecurity Performance Goals," 2023. [Online]. Available: https://www.cisa.gov/cybersecurity-performance-goals-cpgs. [Accessed: May 4, 2026].
[9] National Conference of State Legislatures, "Human-Driven Physical Threats to Energy Infrastructure," May 22, 2023. [Online]. Available: https://www.ncsl.org/energy/human-driven-physical-threats-to-energy-infrastructure. [Accessed: May 4, 2026].
[10] NASA Jet Propulsion Laboratory, "Glass Fire, September 27, 2020," Oct. 7, 2021. [Online]. Available: https://www.jpl.nasa.gov/images/pia24209-glass-fire-september-27-2020/. [Accessed: May 4, 2026].
[11] Verkada, "Verkada Security Update - Incident Report," 2021. [Online]. Available: https://www.verkada.com/security-update/report/. [Accessed: May 4, 2026].
[12] Dark Reading, "Lights Out: Cyberattacks Shut Down Building Automation Systems," 2021. [Online]. Available: https://www.darkreading.com/cyberattacks-data-breaches/lights-out-cyberattacks-shut-down-building-automation-systems. [Accessed: May 4, 2026].
[13] BBC News, "Hacker tries to poison water supply of Florida city," Feb. 8, 2021. [Online]. Available: https://www.bbc.com/news/world-us-canada-55989843. [Accessed: May 4, 2026].
[14] Cyber Threat Intelligence Integration Center, "Recent Cyber Attacks on US Infrastructure Underscore Vulnerability of Critical US Systems, November 2023-April 2024," Office of the Director of National Intelligence, June 2024. [Online]. Available: https://www.dni.gov/files/CTIIC/documents/products/Recent_Cyber_Attacks_on_US_Infrastructure_Underscore_Vulnerability_of_Critical_US_Systems-June2024.pdf. [Accessed: May 4, 2026].
[15] European Commission, CORDIS, "Safety and Security Standards of Space Systems, Ground Segments and Satellite Data Assets, via Prevention, Detection, Response and Mitigation of Physical and Cyber Threats (7SHIELD)," Project Fact Sheet, 2023. [Online]. Available: https://cordis.europa.eu/project/id/883284. [Accessed: May 4, 2026].
[16] ENISA, "Good Practices for Security of Internet of Things in the Context of Smart Manufacturing," 2018. [Online]. Available: https://www.enisa.europa.eu/publications/good-practices-for-security-of-iot. [Accessed: May 4, 2026].
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Nikolay Penev, Daniela Pavlova, Jasen Tanev, Nikolay Koev, Andrian Stoilov, Kiril Nikolov

This work is licensed under a Creative Commons Attribution 4.0 International License.