Glasgow study flags digital twin cyber risks in firms
Wed, 29th Jul 2026 (Today)
University of Glasgow researchers have warned that cybersecurity research on digital twins is overlooking organisational risks. The study was carried out within the TransiT transport decarbonisation research hub.
Academic work has focused heavily on technical questions such as detecting attacks, securing data sharing and making systems interoperable, while paying much less attention to how organisations and staff manage cyber risk in practice.
Digital twins are digital replicas of physical assets or systems. They are used in sectors including transport, construction, manufacturing and healthcare. In transport, they are increasingly seen as tools for testing changes to complex networks without relying solely on real-world trials.
The Glasgow team reviewed more than 1,800 academic papers on cybersecurity, digital twins and organisational barriers to adoption, then narrowed the pool to 41 studies that included social or organisational perspectives, including participant-based research.
The analysis identified a series of underexplored issues beyond software and infrastructure. These included competing priorities between cybersecurity teams and operational staff, employee resistance to security policies when they interfere with core work, financial pressures, limited organisational commitment, skills shortages and worker concern about possible job losses linked to digitalisation.
It also highlighted governance problems that can grow when digital twin systems involve multiple organisations. Shared responsibility across IT teams, operational technology specialists, data teams and external suppliers can make accountability harder to define, particularly as systems expand and become more interconnected.
Dr Stefanos Evripidou, a cybersecurity researcher at the University of Glasgow and lead author of the study, said the gap matters because digital twins are moving beyond isolated deployments.
"Cybersecurity is both a social and a technical challenge, because it involves people and organisational processes, as well as technology. These dimensions are inherently interdependent, so we need to understand the technical and the organisational challenges together rather than in isolation. But our research has found that very little is known about the kind of real-world cybersecurity issues that organisations face around the implementation of digital twins. It's critical that we bridge this gap in knowledge, because digital twins are being scaled and connected to address increasingly complex challenges that span whole sectors or societies. This means we're also hugely expanding the attack surface and increasing exposure to cybersecurity threats," Dr Evripidou said.
The study, published in the journal Computers & Security, argues that most research focused on cybersecurity remains strongly technical, even though day-to-day security outcomes inside organisations often depend on management structures, workplace culture and staff behaviour.
Workplace friction
Among the specific concerns identified is what the researchers describe as security fatigue. This can emerge when staff see cyber rules as adding to their workload or slowing their main responsibilities, making them more likely to adopt informal workarounds or leave security concerns out of operational decisions.
The paper states: "Security often conflicts with other business practices, particularly when it adds additional workload, creating friction between security and productivity. This can result in security fatigue, where employees may adopt less demanding workarounds and more broadly, lead to security's exclusion from the decision-making process."
The findings are likely to draw attention in transport and energy, where policymakers and industry have shown growing interest in linked digital twin environments spanning assets, companies and public infrastructure. The authors argue that current standards do not properly address the risks specific to those arrangements.
To address the gap, the paper sets out several research priorities. These include more interviews, case studies and ethnographic work on live digital twin projects, closer examination of how responsibilities are divided among stakeholders, and the development of governance and regulatory frameworks suited to connected digital twin systems.
The researchers also propose what they call a sensemaking framework to help organisations assess cyber needs according to a twin's purpose, how closely it is integrated with the physical world and how critical the underlying system is.
TransiT, the research hub behind the work, focuses on using digital twins to identify lower-risk, lower-cost routes to cutting emissions in UK transport across road, rail, air and maritime networks for passengers and freight. The collaboration brings together eight universities and almost 70 industry partners, and is jointly led by Heriot-Watt University and the University of Glasgow.
The study involved co-authors Xicheng Li, Dr Mohammad Al-Quraan, Dr Runze Cheng, Dr Ahmad Taha, Professor Muhammad Imran, Professor David Flynn and Professor Dimitrios Pezaros, all based at the University of Glasgow through TransiT.
One of the clearest weaknesses in the current literature, the authors argue, is the limited understanding of how digital twin stakeholders themselves view cyber risk.
"A key gap identified in our analysis is the limited research into how digital twin stakeholders understand cybersecurity and its associated risks in digital twins," the researchers wrote.