<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "http://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="other" dtd-version="1.2" xml:lang="en">
    <front>
        <journal-meta>
            <journal-id journal-id-type="pmc">F1000Research</journal-id>
            <journal-title-group>
                <journal-title>F1000Research</journal-title>
            </journal-title-group>
            <issn pub-type="epub">2046-1402</issn>
            <publisher>
                <publisher-name>F1000 Research Limited</publisher-name>
                <publisher-loc>London, UK</publisher-loc>
            </publisher>
        </journal-meta>
        <article-meta>
            <article-id pub-id-type="doi">10.12688/f1000research.180098.1</article-id>
            <article-categories>
                <subj-group subj-group-type="heading">
                    <subject>Case Study</subject>
                </subj-group>
                <subj-group>
                    <subject>Articles</subject>
                </subj-group>
            </article-categories>
            <title-group>
                <article-title>Developing Cybersecurity Awareness in 9
                    <sup>th</sup> &#x2013;12
                    <sup>th</sup> Grades Students through Scenario&#x2011;Based Learning</article-title>
                <fn-group content-type="pub-status">
                    <fn>
                        <p>[version 1; peer review: awaiting peer review]</p>
                    </fn>
                </fn-group>
            </title-group>
            <contrib-group>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>Vajpayee</surname>
                        <given-names>Prashant</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Project Administration</role>
                    <role content-type="http://credit.niso.org/">Resources</role>
                    <role content-type="http://credit.niso.org/">Supervision</role>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Visualization</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <uri content-type="orcid">https://orcid.org/0009-0006-1285-6676</uri>
                    <xref ref-type="corresp" rid="c1">a</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Eze</surname>
                        <given-names>Esther</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Raheem</surname>
                        <given-names>Tayiba</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Meka Sri Durg</surname>
                        <given-names>Nivedith</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Conceptualization</role>
                    <role content-type="http://credit.niso.org/">Data Curation</role>
                    <role content-type="http://credit.niso.org/">Formal Analysis</role>
                    <role content-type="http://credit.niso.org/">Investigation</role>
                    <role content-type="http://credit.niso.org/">Methodology</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="no">
                    <name>
                        <surname>Khan</surname>
                        <given-names>Fayezuddin Mohammed</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Visualization</role>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <contrib contrib-type="author" corresp="yes">
                    <name>
                        <surname>Hossain</surname>
                        <given-names>Gahangir</given-names>
                    </name>
                    <role content-type="http://credit.niso.org/">Funding Acquisition</role>
                    <role content-type="http://credit.niso.org/">Project Administration</role>
                    <role content-type="http://credit.niso.org/">Validation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Original Draft Preparation</role>
                    <role content-type="http://credit.niso.org/">Writing &#x2013; Review &amp; Editing</role>
                    <xref ref-type="corresp" rid="c2">b</xref>
                    <xref ref-type="aff" rid="a1">1</xref>
                </contrib>
                <aff id="a1">
                    <label>1</label>College of Information, University of North Texas, Denton, Texas, USA</aff>
            </contrib-group>
            <author-notes>
                <corresp id="c1">
                    <label>a</label>
                    <email xlink:href="mailto:prashantvajpayee@my.unt.edu">prashantvajpayee@my.unt.edu</email>
                </corresp>
                <corresp id="c2">
                    <label>b</label>
                    <email xlink:href="mailto:Gahangir.Hossain@unt.edu">Gahangir.Hossain@unt.edu</email>
                </corresp>
                <fn fn-type="conflict">
                    <p>No competing interests were disclosed.</p>
                </fn>
            </author-notes>
            <pub-date pub-type="epub">
                <day>1</day>
                <month>6</month>
                <year>2026</year>
            </pub-date>
            <pub-date pub-type="collection">
                <year>2026</year>
            </pub-date>
            <volume>15</volume>
            <elocation-id>852</elocation-id>
            <history>
                <date date-type="accepted">
                    <day>4</day>
                    <month>5</month>
                    <year>2026</year>
                </date>
            </history>
            <permissions>
                <copyright-statement>Copyright: &#x00a9; 2026 Vajpayee P et al.</copyright-statement>
                <copyright-year>2026</copyright-year>
                <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
                    <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
                </license>
            </permissions>
            <self-uri content-type="pdf" xlink:href="https://f1000research.com/articles/15-852/pdf"/>
            <abstract>
                <sec>
                    <title>Background</title>
                    <p>In the era of accelerating Agentic AI, critical infrastructure sectors have become increasingly vulnerable as they are interconnected with multiple internal and external systems. Furthermore, the growing use of the internet for digital education and activities such as gaming and social media has made students a soft target for attackers. Due to the lack of cybersecurity and cyber-risk education, there is a nationwide scarcity of cyber talent. The motivation for this research is threefold: to protect student identities given their significant online activity, to enable cyber literacy among teachers and students in Grades 9&#x2013;12 to help develop a cyber-aware future workforce, and to build awareness of cyber risks through real-time case studies so students can understand critical infrastructure and the safety considerations associated with it.</p>
                </sec>
                <sec>
                    <title>Methods</title>
                    <p>We developed nine case studies across various domains&#x2014;transportation, supply chains, healthcare, agriculture, manufacturing, AI data centers, energy infrastructure, water utilities, and banking and finance. Each case study follows a standard structure that includes a scenario overview, key assets at risk, a threat event, and impact analysis across multiple dimensions, a simplified risk-analysis model suitable for high-school learners, and diagrammatic representations for summarization.</p>
                </sec>
                <sec>
                    <title>Results</title>
                    <p>These realistic use cases across diverse domains provide comprehensive insights into real-world scenarios and recommended best practices. Teachers can use them to demonstrate layered defense, cyber-risk reduction, and cyber-resilience strategies. The case studies can be easily integrated into STEM, technology, and cyber-career-readiness curricula.</p>
                </sec>
                <sec>
                    <title>Conclusion</title>
                    <p>This research provides a scalable, reusable, and pedagogically sound approach to building cyber literacy among high-school students. The case studies across critical-infrastructure domains help students understand the importance of cyber resilience and the interdisciplinary nature of digital risk. The framework can be extended to hands-on labs, simulations, and learning modules, contributing to national efforts to strengthen cybersecurity awareness and workforce readiness.</p>
                </sec>
            </abstract>
            <kwd-group kwd-group-type="author">
                <kwd>Cyber Literacy</kwd>
                <kwd>K-12 Cybersecurity for High School Students</kwd>
                <kwd>Risk Analysis</kwd>
                <kwd>Critical Infrastructure Security</kwd>
                <kwd>Cyber Resilience</kwd>
                <kwd>Cyber Awareness</kwd>
                <kwd>STEM Cyber Curriculum</kwd>
                <kwd>Threat Modeling</kwd>
            </kwd-group>
            <funding-group>
                <award-group id="fund-1" xlink:href="https://doi.org/10.13039/100000006">
                    <funding-source>ONR</funding-source>
                    <award-id>OfficeofNavalResearch(ONR)</award-id>
                    <award-id>USA</award-id>
                    <award-id>AwardNumberN00014-23-1-245</award-id>
                </award-group>
                <funding-statement>This work has been partially supported by the Office of Naval Research (ONR), USA, Award Number N00014-23-1-245&#13;
</funding-statement>
                <funding-statement>
                    <italic>The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.</italic>
                </funding-statement>
            </funding-group>
        </article-meta>
    </front>
    <body>
        <sec id="sec5">
            <title>Case Studies</title>
        </sec>
        <sec id="sec6">
            <title>Cybersecurity case study: Road and highway cybersecurity
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>During early 2018, the Colorado Department of Transportation (DoT) was impacted by a large-scale cyberattack, which included distributed denial of service (DDoS) style to network flooding followed by service disruption. The attack forced Colorado DoT to turn off 2000+ computers, including systems connected to highway operation, traffic management servers, roadway monitoring systems, and maintenance scheduling. Though no attack occurred on the traffic lights, the supporting IT infrastructure was hacked to manage road and highway operations. This is a great example of how DDoS attacks can hamper transportation operations without interacting a single traffic light directly.</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <p>The attack affected the road and highway operations significantly by impacting the following assets.</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>
Offline Traffic Management System: The entire traffic management system went offline, which paused real time traffic monitoring, incident response reporting system, roadway camera feeds, and congestion prediction tools.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Paused Roadside Communication: The attack disrupted the communication between roadside units, highway sensors, and variable message signs.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Paused updates to Digital Signs: CDoT wasn&#x2019;t able to update warning signs, speed advisories, construction alerts, and weather hazard messages.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Delayed Emergency Response and Maintenance: Along with emergency response routing, the road repair schedule messages and snow-plow operations were delayed.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>A large botnet starts flooding the state&#x2019;s highway traffic-management servers of Colorado DoT with millions of fake requests every second. Due to these messages, the servers become overloaded and stop responding. Due to this service disruption in the centralized traffic management system, the traffic cameras go dark, digital signs freeze, and toll gates malfunction. Furthermore, drivers no longer receive warnings about accidents, speed advisories, construction warnings, and weather hazards. Apart from this, the Emergency responders cannot access real-time road conditions too. Highways and roads become congested and unsafe because the digital systems that normally manage traffic went offline. As an outcome, the transportation agency had to shut down parts of its network and switch to manual operations while cybersecurity teams worked to resolve the attack impact.</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>

                <bold>Operational</bold>
            </p>
            <p>Due to the shutdown of 2000+ computers, the entire traffic management system was heavily impacted along with monitoring and maintenance service. It created a huge backlog for manual processes, delaying all transpiration workflows.</p>
            <p>

                <bold>Safety</bold>
            </p>
            <p>The shutdown of traffic management services, roadway monitoring, and stale operational dashboards reduced situational awareness for transportation staff. It increases safety risk with emergencies such as traffic jams, weather hazards etc. Due to lack of visibility, the operator cannot send the crews timely.</p>
            <p>

                <bold>Financial</bold>
            </p>
            <p>Flight Colorado State paid around $1.5 million recovery cost for system restoration and external support. Furthermore, Colorado&#x2019;s financial systems, which process around ~$100 million payments every month were heavily disrupted, enforcing manual workflow for business continuity.</p>
            <p>

                <bold>Reputational</bold>
            </p>
            <p>This attack event became a case study at a national level in the category of critical infrastructure vulnerability. Public reports highlighted how the vulnerabilities and weak control could cause significant harm to critical infrastructure. This incident generated concerns about CDOT&#x2019;s cybersecurity ecosystem and increased queries from government, media, and public.
                <list list-type="order">
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>For the ease of explanation, the traffic light metaphor is used for cyber risk quantification. The three signal approach has been used to assign risk scores.</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Green light indicates system is working business as usual (score 0&#x2013;2)</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Yellow light reflects warning sign (score 0&#x2013;3)</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Red light indicates complete suspension (score 0&#x2013;5)</p>
                            </list-item>
                        </list>
                        <p>For CDOT&#x2019;s case study, we can map the traffic light colors to provide risk evaluation.</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Green: 0 (Systems were not functioning perfectly)</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Yellow: 3(Warning signs ignored: misconfigured server)</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Red: 5 (Shutdown of 2000+ computers)</p>
                            </list-item>
                        </list>
                        <p>Total Risk Score&#x00a0;=&#x00a0;8/10 (Critical risk).</p>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>

                                    <bold>Network segmentation:</bold> Network segmentation strategy will be helpful to decouple the network zone, which is impacted by malware. It will reduce the expansion of the attack.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>

                                    <bold>Deploy endpoint detection and response (EDR):</bold> By deploying EDR, the unusual behaviour, anomalies, and ransomware activity can be tracked real time.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>

                                    <bold>Connected backup:</bold> Regular backup can help to recover data post compromise and reduce data loss. Also, the backup should be disconnected from the main network to avoid attack impact.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>

                                    <bold>Continuous vulnerability scanning and patching:</bold> Regular vulnerability scanning and resolution will help make systems cyber safe. Furthermore, the patching of software applications to its latest version will strengthen the cyber assets&#x2019; security.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>

                                    <bold>Practice cyber incident response exercise:</bold> To maintain business continuity, it is recommended to simulate cyber incident scenarios and execute recovery steps to determine gaps. It will help to improve the system recovery process consistently.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>This above Figure 1depicts the series of events in a DDoS attack targeting transportation infrastructure, illustrating the effect of network flooding to traffic management systems, roadside communications, and digital signage that lead to inefficiency and increase risk factors
                            <italic toggle="yes">.</italic>
                        </p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following terms available in 
                            <xref ref-type="table" rid="T1">
Table 1</xref> have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f1" orientation="portrait" position="float">
                <label>
Figure 1. </label>
                <caption>
                    <title>Road and highway cyberattack flow (DDoS Scenario)- This diagram depicts the series of events in a DDoS attack targeting transportation infrastructure, illustrating the effect of network flooding to traffic management systems, roadside communications, and digital signage that lead to inefficiency and increase risk factors.</title>
                </caption>
                <graphic id="gr1" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure1.gif"/>
            </fig>
            <table-wrap id="T1" orientation="portrait" position="float">
                <label>
Table 1. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study road and highway cybersecurity&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>DDoS (Distributed denial of service)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A cyberattack that floods a system with fake traffic so it can&#x2019;t respond to real users.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Botnet</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A network of infected computers controlled by attackers to launch large-scale attacks.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Service disruption</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">When a system stops working because it is overloaded or damaged.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Malware</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Harmful software designed to damage or disable systems.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Attack vector</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Any data that can be used to identify a particular person - a name, address, date of birth, Social Security number, etc.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Vulnerability</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A weakness in a system that attackers can exploit.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Misconfigured server</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A server set up incorrectly, making it easy for attackers to access.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Network segmentation</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Splitting a network into smaller zones to stop attacks from spreading.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Endpoint detection &amp; response (EDR)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tools that detect suspicious activity on computers.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Offline backup</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A backup stored away from the main network for attack protection</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Vulnerability scanning</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Checking systems for weaknesses that need fixing.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Patch management</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Updating software to fix security flaws.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Incident response plan</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A step-by-step plan for handling cyber emergencies.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec7">
            <title>Cybersecurity case study: Transportation and supply chain
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>GPS spoofing is the act of sending false GPS signals to mislead a GPS receiver about its actual location. This paper refers to a case study that shows how GPS spoofing has become a major problem for air traffic. It has become a prominent global issue. Since September 2023, civil aviation has been significantly impacted because of this. In a single month, from July 15 to August 15, 2024, a total of 41,000 flights experienced spoofing incidents across the globe. A report reflects a clear rise in spoofing incidents starting from April 2024, based on algorithms applied to ADS-B data. However, not all spoofing incidents can be detected this way, so the true number could be significantly higher.</p>
                        <p>GPS spoofing is a technique that manipulates a GPS receiver by sending fake signals, causing the device to display an incorrect location. The impact is broader and not limited to air travel. It can affect navigation systems, drones, vehicles, and smartphone navigation apps, which can lead to misdirection, theft, and increased security risks.</p>
                        <p>Unlike jamming, which blocks GPS signals, spoofing actively deceives the receiver by providing stronger, fake signals that override legitimate satellite data.</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <p>While GPS spoofing is primarily associated with navigation and positioning systems, its impact is also seen on time-dependent assets and on operational and economic assets. The following 
                            <xref ref-type="table" rid="T2">
Table 2</xref> reflects the list of assets and their corresponding mapping.</p>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The case studies explain how threat events occur step by step. The steps are as follows:</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Attack transmits fake GPS signals towards an aircraft during flight.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The aircraft&#x2019;s GPS receiver considers the fake signal as a stronger spoofed signal and sends false position, altitude, and time data.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>This corrupted information is automatically propagated with different sub systems Flight management systems (FMS), IRS (Inertial Reference System), and Enhanced Ground Proximity Warning System (EGWPS) through ARINC 429 data bus.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The FMS evaluated the aircraft&#x2019;s position based on incorrect GPS Data, causing the aircraft to shift from its intended route while still reflecting authentic navigation.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The IRS system consumes the false GPS updates, reinforcing the erroneous position.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Enhanced GPWS, depending on GPS-derived false altitude, produce false terrain warnings or fail to warn on realistic obstacles.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The flight staff remains unaware of the spoofing event because all the systems fastly show normal functions.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The aircraft continues to travel on an unsafe or unintended path, with downgraded situational awareness and compromised terrain-avoidance protection system.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>Due to malfunction of FMS, IRS, and EGPWS the unintended route shift, loss of reliable backup navigation, and degraded terrain-avoidance capability are the significant operational overhead. Furthermore, the system instability could increase the manual workload when aircraft enter restricted or controlled zones.</p>
                        <p>

                            <bold>Safety</bold>
                        </p>
                        <p>A spoofed aircraft may unknowingly enter unsafe airspace, terrain, or traffic, creating severe accident potential. The safety issues increase due to occurrence of false alarm, missed real hazards, midair collisions, unsafe proximity to obstacles, and corrupted EGPWS geometric altitude information.</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>Flight diversions, delay or cancellations, aircraft damage, increase in insurance premium, cost of investigations, enablement of extended security controls for anti-spoofing defenses, and operational delays are a few of the primary outcomes related to direct financial impacts due to aircraft GPS Spoofing.</p>
                        <p>

                            <bold>Reputational</bold>
                        </p>
                        <p>The reputational impacts are not limited to aircraft companies; they also extend to navigation system providers. Passengers lose confidence in the aircraft service providers, and negative reviews begin to appear, which further generate negative media coverage. The airline&#x2019;s brand becomes diminished, and trust in GPS-based navigation systems is reduced. Furthermore, regulatory investigations increase security concerns.</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following formula could be used to quantify cyber risk.</p>
                        <p>Cyber Risk&#x00a0;=&#x00a0;Chance of GPS Spoofing * Danger if Spoofed.</p>
                        <p>

                            <bold>Chance of GPS spoofing</bold>
                        </p>
                        <p>
The chance of GPS Spoofing could be determined numerically as 1 (Very unlikely), 2 (Unlikely), 3 (Possible), 4 (Likely), 5 (Very likely) on various factors such as exposure, attractiveness to attackers, and control or protection level. The summary is as follows:</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Exposure: The frequency of GPS usage such as never, sometimes or all the time. Users can allocate numbers from 1 to 5 based on usage.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Attractiveness of Attackers: Would an attacker be interested to attack? What negative impact could an attack generate? Users can assign numbers based on anticipated attacker&#x2019;s interest in executing the attack.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Control or Protection Level: What kind of layered protection available such as additional sensors, trust validation, and network monitoring etc. Based on protection level the number can be assigned.</p>
                            </list-item>
                        </list>
                        <p>The following formula can be used to define Spoof scoring.</p>
                    </list-item>
                </list>

                <disp-formula id="e1">

                    <mml:math display="block">
                        <mml:msub>
                            <mml:mi>S</mml:mi>
                            <mml:mtext mathvariant="italic">spoof</mml:mtext>
                        </mml:msub>
                        <mml:mo>=</mml:mo>
                        <mml:mrow>
                            <mml:mo stretchy="true">(</mml:mo>
                            <mml:mtext mathvariant="italic">Exposure Score</mml:mtext>
                            <mml:mo>+</mml:mo>
                            <mml:mtext mathvariant="italic">Attractiveness Score</mml:mtext>
                            <mml:mo>+</mml:mo>
                            <mml:mtext mathvariant="italic">Protection Score</mml:mtext>
                            <mml:mo stretchy="true">)</mml:mo>
                        </mml:mrow>
                    </mml:math>

                    <label>(1)</label>
</disp-formula>
            </p>
            <table-wrap id="T2" orientation="portrait" position="float">
                <label>
Table 2. </label>
                <caption>
                    <title>Key assets at risk for the case study &#x201c;cybersecurity case study transportation and supply chain&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Asset category</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Examples</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Why it&#x2019;s at risk</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Navigation systems</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Aircraft, Ships, Cars, Drones etc.</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Spoofing changes perceived location</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Timing systems</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Energy grids, telecom networks, Financial systems, Industrial control systems</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Spoofing modify times, which cause system failures</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Operational systems</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Emergency response services, Logistics, Weather systems</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Due to misrouting and false alerts negative economic impact occurs</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>Since each score is a number between 1 to 5. Therefore the chance of spoofing can be evaluated as follows:
                <disp-formula id="e2">

                    <mml:math display="block">
                        <mml:mtext mathvariant="italic">Chance of Spoofing</mml:mtext>
                        <mml:mo>=</mml:mo>
                        <mml:mfrac>
                            <mml:msub>
                                <mml:mi>S</mml:mi>
                                <mml:mtext mathvariant="italic">spoof</mml:mtext>
                            </mml:msub>
                            <mml:mn>15</mml:mn>
                        </mml:mfrac>
                    </mml:math>

                    <label>(2)</label>
</disp-formula>
            </p>
            <p>

                <bold>Danger if spoofed</bold>
            </p>
            <p>Now to quantify the danger or impact if the GPS Spoof attack occurs, the following variables can be used.
                <disp-formula id="e3">

                    <mml:math display="block">
                        <mml:msub>
                            <mml:mi>L</mml:mi>
                            <mml:mi>r</mml:mi>
                        </mml:msub>
                        <mml:mo>=</mml:mo>
                        <mml:mtext mathvariant="italic">Length of the route</mml:mtext>
                    </mml:math>
</disp-formula>

                <disp-formula id="e4">

                    <mml:math display="block">
                        <mml:msub>
                            <mml:mi>T</mml:mi>
                            <mml:mi>s</mml:mi>
                        </mml:msub>
                        <mml:mo>=</mml:mo>
                        <mml:mtext mathvariant="italic">Sharpness of turns</mml:mtext>
                    </mml:math>
</disp-formula>

                <disp-formula id="e5">

                    <mml:math display="block">
                        <mml:mspace width="4.2em"/>
                        <mml:msub>
                            <mml:mi>I</mml:mi>
                            <mml:mi>n</mml:mi>
                        </mml:msub>
                        <mml:mo>=</mml:mo>
                        <mml:mtext mathvariant="italic">Number of intersections</mml:mtext>
                    </mml:math>
</disp-formula>
            </p>
            <p>Finally, the cyber risks can be evaluated as follows:
                <disp-formula id="e6">

                    <mml:math display="block">
                        <mml:mtext fontfamily="Roboto" mathvariant="bold">Cyber Risk</mml:mtext>
                        <mml:mo mathvariant="bold">=</mml:mo>
                        <mml:msub>
                            <mml:mi>S</mml:mi>
                            <mml:mtext mathvariant="italic">spoof</mml:mtext>
                        </mml:msub>
                        <mml:mo mathvariant="bold">&#x2217;</mml:mo>
                        <mml:mrow>
                            <mml:mo stretchy="true">(</mml:mo>
                            <mml:msub>
                                <mml:mi>L</mml:mi>
                                <mml:mi>r</mml:mi>
                            </mml:msub>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>T</mml:mi>
                                <mml:mi>s</mml:mi>
                            </mml:msub>
                            <mml:mo>+</mml:mo>
                            <mml:msub>
                                <mml:mi>I</mml:mi>
                                <mml:mi>n</mml:mi>
                            </mml:msub>
                            <mml:mo stretchy="true">)</mml:mo>
                        </mml:mrow>
                    </mml:math>

                    <label>(3)</label>
</disp-formula>

                <list list-type="order">
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The organizations should plan to use multi sensor navigation instead of relying on GPS alone.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Enable Receive autonomous integrity monitoring (RAIM) to detect inconsistencies in satellite geometry and timing.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Robust architecture is needed, which should include a verification step for data received by GPS receivers before it is sent to various sub-systems such as FMS, IRS, and EGPWS.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Incorporate algorithms to detect spoofing by monitoring real time. The algorithms should be capable enough to detect sudden route shifts, identical satellite IDs, abnormal signal strength, and unrealistic satellite geometry.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Spoofed altitude and position frequently conflicts with real terrain data. The terrain database can be used for comparisons of GPS altitude, position, and proximity.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>A strong cryptographic authentication can validate GPS Spoofing signals. It is difficult for Spoofers to bypass that.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The pilot training and refine standard operating procedures can help to identify false positives.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f2">
Figure 2</xref> depicts the propagation of spoofed GPS signals throughout aircraft systems including FMS, IRS, and EGPWS that would cause erroneous navigation data and consequently endanger the safety of the flights.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following terms available in 
                            <xref ref-type="table" rid="T3">
Table 3</xref> have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f2" orientation="portrait" position="float">
                <label>
Figure 2. </label>
                <caption>
                    <title>GPs spoofing attack architecture in aviation systems- This diagram depicts the propagation of spoofed GPS signals throughout aircraft systems including FMS, IRS, and EGPWS that would cause erroneous navigation data and consequently endanger the safety of the flights.</title>
                </caption>
                <graphic id="gr2" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure2.gif"/>
            </fig>
            <fig fig-type="figure" id="f3" orientation="portrait" position="float">
                <label>
Figure 3. </label>
                <caption>
                    <title>Cybersecurity case study for water department- This diagram depicts the possibility of cyberattacks to affect public health and safety by accessing the SCADA system and manipulating its operations involving chemical dosing process.</title>
                </caption>
                <graphic id="gr3" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure3.gif"/>
            </fig>
            <table-wrap id="T3" orientation="portrait" position="float">
                <label>
Table 3. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study transportation and supply chain&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>GPS spoofing</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Sending fake GPS signals to trick a receiver into showing the wrong location, altitude, or time.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>GPS jamming</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Blocking real GPS signals so the receiver cannot get any location information.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>ADS-B (Automatic dependent surveillance&#x2013;broadcast)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A system that broadcasts an aircraft&#x2019;s position, speed, and altitude to air-traffic controllers and nearby aircraft.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Flight management system (FMS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The computer that calculates the aircraft&#x2019;s route and helps pilots navigate.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Inertial reference system (IRS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A navigation system that uses motion sensors to estimate the aircraft&#x2019;s position without GPS.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Enhanced ground proximity warning system (EGPWS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A safety system that warns pilots if the aircraft is too close to the ground or obstacles.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Terrain database</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A digital map of mountains, hills, and ground elevation used for safety warnings.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Signal manipulation attack</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An attack where false signals are sent to mislead a system.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Cyber-Physical attack</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A cyberattack that affects real-world physical systems like aircraft, cars, or power grids.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Attack vector</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The method or path an attacker uses to break into a system.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Threat actor</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A person or group responsible for carrying out a cyberattack.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Silent failure</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">When a system fails without showing any warning signs.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec8">
            <title>Cybersecurity case study: Water department</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>On February 5, 2021, a plant operator in the Bruce T. Haddock Water Treatment Plant, a small city of approximately 15,000 people outside of Tampa in Florida, made an alarming discovery. He was sitting at his computer when he saw the cursor on his computer start moving itself. There was somebody seemingly operating his computer remotely (
                            <xref ref-type="bibr" rid="ref11">CISA, 2021a</xref>).</p>
                        <p>
The plant utilized a remote-access software application known as TeamViewer, which enables the authorized personnel to log in to work from home. The same software has, however, formed a possible access point to any person with the appropriate credentials. As the operator observed, the unknown individual navigated to the sodium hydroxide controls, or lye, as it is generally referred to, which is a small portion of the chemical that is used to treat drinking water and control the acidity. The hacker tried to change the level of a safe 100 parts per million to 11,100 parts per million, 111 times the standard level (CISA, 2021). At such concentrations, the water would lead to serious chemical burns to anyone who drank it.</p>
                        <p>The operator responded in time, restoring the controls to safe settings and notifying supervisors. None of the polluted water ever got to people. Officials of the city confirmed that even though the change was not noticed, the built-in safety alarms and the 24-36&#x00a0;hour delay in the distribution of water would have given additional time to notice the issue (
                            <xref ref-type="bibr" rid="ref10">Cervini et al., 2022</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>SCADA system managing water treatment chemical dosing.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Remote desktop access applications (TeamViewer) utilized by operators of the plants.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Sodium hydroxide and other chemical treatment controls</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Windows 7 operating system computers that are outdated (not getting security updates).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Network shared between multiple plant workstations</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Public drinking water supply for 15,000 residents</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The Pinellas County Sheriff&#x2019;s Office states that the SCADA (Supervisory Control and Data Acquisition) system of the plant was accessed by an unauthorized individual remotely twice on February 5th, at about 8:00&#x00a0;AM and 1:30&#x00a0;PM (
                            <xref ref-type="bibr" rid="ref10">Cervini et al., 2022</xref>).</p>
                        <p>During the second intrusion, the operator watched as the attacker opened software controls and switched the sodium hydroxide set point from 100 to 11,100&#x00a0;ppm and disconnected it before leaving. Within seconds, the operator reverted the change. The Secret Service, FBI, and local police started investigations. CISA used a public warning to state that the computers in the plant were operating Windows 7 - an operating system that Microsoft had officially stopped supporting in January 2020, which means it was no longer being patched or updated. The company was also experiencing poor passwording practices, where passwords could be shared among the workers (
                            <xref ref-type="bibr" rid="ref11">CISA, 2021a</xref>).</p>
                        <p>Notably, a subsequent investigation raised questions on whether the event was indeed an external cyberattack or perhaps it was an accident on the part of a worker who altered a value and reported it as a breach. As of 2023, the FBI has not officially confirmed an external attack, and the former manager of the city confirmed privately that investigators had no evidence to suggest that there was external access (
                            <xref ref-type="bibr" rid="ref70">Vasquez, 2023</xref>). This renders Oldsmar a useful case study in both senses: it demonstrates the actual cybersecurity vulnerabilities of the water systems, and it demonstrates that the reporting and investigation of the incident can be complicated (
                            <xref ref-type="bibr" rid="ref66">Tuptuk et al., 2021</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>The water treatment activities were put on hold to investigate them. The authorities of the city made urgent decisions to disconnect remote access tools and check all system logs. The breach initiated cybersecurity assessments in Florida and other water utilities (
                            <xref ref-type="bibr" rid="ref11">CISA, 2021a</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>
The Oldsmar plant itself did not suffer direct significant financial losses as the change was promptly noticed. Nevertheless, the move triggered the implementation of expensive national security infrastructure improvements in hundreds of water utilities in the U.S. CISA estimated that water delivered to more than 80 percent of Americans is provided by about 153,000 publicly-owned water systems, most of which were observed to have similar vulnerabilities (EPA, 2023).</p>
                        <p>

                            <bold>Safety</bold>
                        </p>
                        <p>Had the sodium hydroxide not been detected early, it would have resulted in serious chemical burns on the throats, skin, and digestive system of residents. The most vulnerable groups, like children, the aged, and those whose immunity is weakened, would have been exposed to the highest risk of the health problem. Even at lower concentrations, lye can cause severe damage (
                            <xref ref-type="bibr" rid="ref10">Cervini et al., 2022</xref>).</p>
                        <p>

                            <bold>Reputational</bold>
                        </p>
                        <p>The incident resulted in national publicity and congressional interest. It served as a wake-up call that small-town water utilities, which are usually under-resourced and understaffed, could become targets of cyberattacks. Several states issued cybersecurity advisories for water suppliers after the incident (
                            <xref ref-type="bibr" rid="ref72">You, 2022</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification:</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T4">
Table 4</xref> provide a brief description about evaluation overall risk.</p>
                        <p>

                            <bold>Simple cost example</bold>
                        </p>
                        <p>Imagine a confirmed water contamination event required emergency bottled water distribution to 15,000 residents for 3&#x00a0;days, plus medical response and cleanup. The estimated emergency response cost would be over the roof. This usually does not include long-term health costs, lawsuits, or federal fines for regulatory violations.</p>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Discontinue or deactivate remote access software (such as TeamViewer) unless it is necessary (CISA, 2021).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Upgrade outdated operating systems: Windows 7 had not been updated on its security within more than one year before the incident (
                                    <xref ref-type="bibr" rid="ref11">CISA, 2021a</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Use a different password that is strong and unique to every employee - do not share passwords among employees (NIST, 2018).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Any remote login to plant control systems should be done using multi-factor authentication (MFA).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Set hard limits on the level of chemicals to ensure that no remote command can exceed the safe limits of the levels, which is a basic engineering safeguard (
                                    <xref ref-type="bibr" rid="ref10">Cervini et al., 2022</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Educate all employees in the plants to identify and report suspicious computer activity to the management (
                                    <xref ref-type="bibr" rid="ref72">You, 2022</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Regularly perform cybersecurity assessments with support from CISA&#x2019;s free Water Sector resources (EPA, 2023).</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above Figure 3depicts the possibility of cyberattacks to affect public health and safety by accessing the SCADA system and manipulating its operations involving chemical dosing process.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T5">
Table 5</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <table-wrap id="T4" orientation="portrait" position="float">
                <label>
Table 4. </label>
                <caption>
                    <title>Overall risk evaluation for the case study &#x201c;cybersecurity case study for water department&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Medium-high
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Water systems are normally underfunded and are exposed to outdated technology, which makes them much easier to attack.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Thousands of individuals, particularly children and elderly people, can be affected by contaminated water.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Overall risk</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The risk of mass public harm makes water systems among the highest-priority targets to secure.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <table-wrap id="T5" orientation="portrait" position="float">
                <label>
Table 5. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study for water department&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>SCADA system</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Supervisory Control and Data Acquisition (SCADA): A mechanism or computer system that is used to observe and manage machines or processes remotely or centrally.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Remote desktop access</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Software that allows one to remotely operate and control a computer from a different location.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>credential</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A username and a password to gain access to a system.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Dormant account</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A user account that is no longer actively used but has not been deleted or disabled and is still accessible.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Sodium hydroxide (Lye)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A substance used in small amounts to treat water, and is also hazardous at high concentrations.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Chemical dosing System</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An automated machine that measures and injects the correct amounts of treatment chemicals (like chlorine, fluoride, and lye) into water at a treatment plant.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Insider threat</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A security threat originating with an individual, with or without authorized access to a system, including an employee, contractor/business partner, or former employee. The threat actor involved in this case study was an ex-contractor, whose credentials were not revoked, and it is an insider threat scenario.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Forensic investigation</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A detailed technical examination to determine the post-cyberattack outcome.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Operational technology (OT)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Hardware and software that monitor or control physical devices, processes, and events within water, energy, and manufacturing industries. In contrast to traditional IT (which manipulates information and communications), OT is actually used to operate physical devices directly. OT needs to be secured since physical damage can be caused by an attack.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec9">
            <title>Cybersecurity case study: AI data center
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>The case study focuses on the 2019 Capital one cyberattack, which is one of the most massive data breaches of cloud-based analytics infrastructure. To store and process high amounts of customer information, the company relied on a modern architecture of a data center hosted on Amazon Web Services. These systems facilitated the processes of automated decision-making, analytics, and machine learning. Nevertheless, due to improperly set up web application firewalls, there was a vulnerability through which an attacker accessed sensitive information. This event showed that AI-based and cloud-based data centers are vulnerable to configuration mistakes and lack of monitoring (
                            <xref ref-type="bibr" rid="ref67">U.S. Department of Justice, 2019</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The attack revealed several assets vital to the AI and analytics functions:</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Personal information of customers (address, credit scores, names).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Buckets in cloud storage of structured datasets.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Training datasets of machine learning.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Credential identities and authentication keys.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Monitoring and logging systems within the company</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Analytics data processing pipelines.</p>
                            </list-item>
                        </list>
                        <p>Such assets are critical in the decision-making process using AI, and their security is a necessity.</p>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The attacker took advantage of the improper firewall configuration in the cloud infrastructure. Due to this, the attacker was able to carry out a Server-Side Request Forgery (SSRF) attack and obtain credentials. After obtaining the credentials, the attacker was able to access the storage containers and obtain the information stored in them. The breach led to the compromise of 100 million citizens in the United States and 6 million citizens in Canada. The attacker was also able to obtain the internal logs, hence allowing them to maintain unauthorized access (
                            <xref ref-type="bibr" rid="ref24">FBI, 2019</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>: The systems were to be restricted as a means to estimate the level of damage.</p>
                        <p>

                            <bold>Financial</bold>: To resolve the problem, Capital One was forced to pay an 80 million dollar fine to regulators. Other expenses incurred by the company were associated with taking measures to deal with the problem (
                            <xref ref-type="bibr" rid="ref39">Office of the Comptroller of the Currency, 2020</xref>).</p>
                        <p>

                            <bold>Security</bold>: Customer data was compromised because the systems were infiltrated, which resulted in credit card application information disclosure.</p>
                        <p>

                            <bold>Reputation</bold>: The hack was covered by the media, which affected the organization.</p>
                        <p>

                            <bold>Legal impact</bold>: There were various lawsuits and compliance reviews carries out.</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>

                            <bold>Plausibility:</bold> Medium.</p>
                        <p>

                            <bold>Aftermath:</bold>
 High.</p>
                        <p>

                            <bold>Cumulative-risk:</bold>
 High.</p>
                        <p>

                            <bold>Simple quantification example:</bold>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>1. System downtime cost
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Downtime duration: 
                            <bold>48&#x00a0;hours</bold>
                        </p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Estimated business loss per hour: 

                            <bold>$150,000</bold>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>

                <inline-formula id="e7">

                    <mml:math display="block">
                        <mml:mn>48</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>150,000</mml:mn>
                        <mml:mo>=</mml:mo>
                        <mml:mn>7,200,000</mml:mn>
                    </mml:math>
</inline-formula>
            </p>
            <p>

                <bold>Downtime Cost&#x00a0;=&#x00a0;$7.2 million</bold>
            </p>
            <p>2. System recovery &amp; reconfiguration cost
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>IT engineers: 
                            <bold>30 engineers</bold>
                        </p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Cost per hour: 
                            <bold>$100/hour</bold>
                        </p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Duration: 
                            <bold>120&#x00a0;hours (approx. 2&#x00a0;weeks work)</bold>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>

                <inline-formula id="e8">

                    <mml:math display="block">
                        <mml:mn>30</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>100</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>120</mml:mn>
                        <mml:mo>=</mml:mo>
                        <mml:mn>360,000</mml:mn>
                    </mml:math>
</inline-formula>
            </p>
            <p>

                <bold>Recovery Cost&#x00a0;=&#x00a0;$360,000</bold>
            </p>
            <p>3. Security tools &amp; infrastructure upgrade
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Firewall upgrades</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Monitoring tools</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Cloud security improvements</p>
                    </list-item>
                </list>
            </p>
            <p>Estimated: 
                <bold>$8 million.</bold>
            </p>
            <p>4. Continuous monitoring cost (post-breach)
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Security monitoring team: 
                            <bold>10 members</bold>
                        </p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Monthly cost per person: 

                            <bold>$8,000</bold>
                        </p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Duration: 
                            <bold>6&#x00a0;months</bold>
                        </p>
                    </list-item>
                </list>
            </p>
            <p>

                <inline-formula id="e9">

                    <mml:math display="block">
                        <mml:mn>10</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>8,000</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>6</mml:mn>
                        <mml:mo>=</mml:mo>
                        <mml:mn>480,000</mml:mn>
                    </mml:math>
</inline-formula>
            </p>
            <p>

                <bold>Monitoring Cost&#x00a0;=&#x00a0;$480,000</bold>
            </p>
            <p>Total system impact cost</p>
            <p>

                <inline-formula id="e10">

                    <mml:math display="block">
                        <mml:mn>7.2</mml:mn>
                        <mml:mi mathvariant="normal">M</mml:mi>
                        <mml:mo>+</mml:mo>
                        <mml:mn>0.36</mml:mn>
                        <mml:mi mathvariant="normal">M</mml:mi>
                        <mml:mo>+</mml:mo>
                        <mml:mn>8</mml:mn>
                        <mml:mi mathvariant="normal">M</mml:mi>
                        <mml:mo>+</mml:mo>
                        <mml:mn>0.48</mml:mn>
                        <mml:mi mathvariant="normal">M</mml:mi>
                        <mml:mo>=</mml:mo>
                        <mml:mn>16.04</mml:mn>
                        <mml:mi mathvariant="normal">M</mml:mi>
                    </mml:math>
</inline-formula>
            </p>
            <p>

                <bold>Total &#x2248; $16 million (System-related direct cost)</bold>
            </p>
            <p>The actual figure might be even higher due to the presence of various hidden costs such as:
                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Legal costs and class-action suits</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Regulatory fines and penalties</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Incident response and forensic analysis</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Employee overtime and business disruption</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Loss of customer trust and brand damage (
                            <xref ref-type="bibr" rid="ref42">IBM Security, 2023</xref>).
</p>
                    </list-item>
                </list>

                <list list-type="order">
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <p>The various steps that can be taken to prevent such breaches include:
</p>
                    </list-item>
                </list>

                <list list-type="bullet">
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Implementing zero-trust security</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Implementing multi-factor authentication for cloud account access</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Monitoring cloud configurations</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Implementing least privilege access</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Encrypting sensitive AI and analytics data</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Conducting regular vulnerability tests</p>
                    </list-item>
                    <list-item>
                        <label>&#x2022;</label>
                        <p>Implementing real-time threat detection
</p>
                    </list-item>
                </list>

                <list list-type="order">
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f4">
Figure 4</xref> depicts the consequences of misconfigured cloud computing infrastructures by exploiting SSRF, causing an unwanted exposure and exfiltration of stored data.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T6">
Table 6</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f4" orientation="portrait" position="float">
                <label>
Figure 4. </label>
                <caption>
                    <title>Cybersecurity case study AI data center- This diagram depicts the consequences of misconfigured cloud computing infrastructures by exploiting SSRF, causing an unwanted exposure and exfiltration of stored data.</title>
                </caption>
                <graphic id="gr4" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure4.gif"/>
            </fig>
            <table-wrap id="T6" orientation="portrait" position="float">
                <label>
Table 6. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study ai data center&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Zero trust architecture (ZTA)</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A security model that requires verification of every user and device before access is granted (&#x201c;never trust, always verify&#x201d;).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Cloud infrastructure</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Systems where data and applications are stored on remote servers instead of local machines (e.g., AWS).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Web application firewall (WAF)</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A security tool that monitors and filters web traffic to protect applications from attacks.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Server-Side request forgery (SSRF)</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An attack where a hacker tricks a server into making unauthorized requests to access sensitive data.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Multi-factor authentication (MFA)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A login method that requires multiple verification steps, such as a password and a one-time code.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Least privilege access</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Giving users only the minimum access needed to perform their tasks.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Machine learning dataset</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Data used to train AI systems for decision-making or predictions.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Incident response</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The process of handling and recovering from a cybersecurity attack.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Monitoring and logging</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Tracking system activity to detect unusual or suspicious behavior.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec10">
            <title>Cybersecurity case study: energy infrastructure
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>On May 7, 2021, Colonial Pipeline, the largest refined fuel pipeline in the United States, was hit with a ransomware attack that made national headlines. The pipeline stretches 5,500&#x00a0;miles long, running between Houston, Texas, and New York City, with gasoline, diesel, and jet fuel flowing through it that serve approximately 45% of the fuel demand on the East Coast (
                            <xref ref-type="bibr" rid="ref12">CISA, 2021b</xref>).</p>
                        <p>Colonial Pipeline was hacked into its computer systems by a hacker group Darkside using a single stolen employee password of a VPN account that has not been disabled. Their account was not subjected to multi-factor authentication (additional security measures such as a text message code), and this is why the attackers found it easy to access the account (
                            <xref ref-type="bibr" rid="ref54">Mittal, 2024</xref>).</p>
                        <p>
The hackers stole 100 gigabytes of company data within hours and then put a ransomware (software that scrambles computer files and then requires a payment to unlock them) lock on the billing systems of Colonial Pipeline. The company closed down the fuel delivery operations because they feared that the attackers might cause further havoc by destroying the physical pipeline controls. The closure took six days and caused fuel shortages, panic purchases, and gas station queues throughout the southeastern United States (
                            <xref ref-type="bibr" rid="ref19">DOE, 2021</xref>). On May 9, 2021, President Biden issued a state of emergency.</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key Assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Computer system for billing and accounting.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Remote access accounts on VPN (Virtual Private Network)</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Industrial control systems managing 5,500&#x00a0;miles of pipeline</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Scheduling and operations software for fuel delivery.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Employee and company data are stored on corporate servers</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Customer communications and systems of payment.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The attack began with one compromised password. The password was later discovered by security investigators in a store of stolen credentials sold on the dark web (the hidden part of the internet where stolen data is bought and sold). The password was for a VPN account that was not actively used but not deactivated (
                            <xref ref-type="bibr" rid="ref7">Beerman et al., 2023</xref>).</p>
                        <p>
Darkside attackers remotely accessed the network of Colonial Pipeline using the password. They had no further barrier since no multi-factor authentication was implemented on the account. While inside, they took their time to move through the network, designating systems and determining the most important files using a method referred to as lateral movement. They stole approximately 100 gigabytes of data within a span of two hours. Then they installed ransomware, encrypted billing systems, and demanded 75 bitcoin (which was at that time valued at about 4.4 million dollars) as a ransom (
                            <xref ref-type="bibr" rid="ref12">CISA, 2021b</xref>).</p>
                        <p>The leadership of Colonial Pipeline was uncertain of the level of intrusion that had occurred and therefore decided to close down the entire pipeline as a precautionary measure. The ransom was paid on the same day by the company. The FBI provided a decryption tool, but it was too slow to be of any use, and the company was forced to restore its systems using backups. On May 12, 2021, a few days after the attack, the pipeline operations returned to normal (
                            <xref ref-type="bibr" rid="ref19">DOE, 2021</xref>). The U.S. Department of Justice subsequently reclaimed some 63.7 Bitcoin (about $2.3 million) of the ransom.</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>The six-day shutdown of the pipeline impacted gas supply in 17 states and Washington, D.C. Gas stations were forced to run out of fuel, airlines were concerned with the supply, and the Federal Motor Carrier Safety Administration declared emergency measures to compensate by allowing fuel trucks to work extra hours (
                            <xref ref-type="bibr" rid="ref19">DOE, 2021</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>Colonial Pipeline had to pay a ransom of $4.4 million. The company also received nearly 1 million proposed fines by the Department of Transportation due to safety breaches that are related to the incident. Millions were added with recovery expenses, legal fees, and cybersecurity upgrades. According to 
                            <xref ref-type="bibr" rid="ref54">Mittal (2024)</xref>, the breaches in the energy sector are the costliest, with the average price of a breach being more than 4.7 million.</p>
                        <p>

                            <bold>Safety</bold>
                        </p>
                        <p>There was a disruption of fuel supply in hospitals, emergency services, and airports on the East Coast. Panic buying also caused unsafe behaviors, including storing fuel in unsafe containers by the people. The incident showed that a cyberattack on the energy infrastructure can pose real physical risks to citizens (
                            <xref ref-type="bibr" rid="ref12">CISA, 2021b</xref>).</p>
                        <p>

                            <bold>Reputational</bold>
                        </p>
                        <p>Colonial Pipeline experienced heavy scrutiny by the public and Congress. Senate hearings were carried out to analyze how one leaked password could shut down the biggest fuel pipeline in the country. The incident was one of the most cited cases of cybersecurity failure to protect critical infrastructure in the history of the US (
                            <xref ref-type="bibr" rid="ref65">Tsvetanov &amp; Slaria, 2021</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T7">
Table 7</xref> provide a brief description about evaluation overall risk.</p>
                        <p>Simple cost example.</p>
                        <p>Colonial Pipeline had to pay a ransom of $4.4 million. The pipeline supply is more than 100 million gallons of fuel per day. A conservative estimate of the lost economic activity during the 6-day shutdown:
</p>
                    </list-item>
                </list>

                <disp-formula id="e11">

                    <mml:math display="block">
                        <mml:mn>100</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext>million</mml:mtext>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>6</mml:mn>
                        <mml:mo>=</mml:mo>
                        <mml:mn>600</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext>million gallons of fuel were disrupted</mml:mtext>
                        <mml:mo>.</mml:mo>
                    </mml:math>
</disp-formula>
            </p>
            <table-wrap id="T7" orientation="portrait" position="float">
                <label>
Table 7. </label>
                <caption>
                    <title>overall risk evaluation for the case study &#x201c;cybersecurity Case Study Energy Infrastructure&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Energy companies are often targeted since the attackers are aware that outages impact millions of people.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Shutting down fuel supply to half the East Coast is a life, safety, and economic impact (
                                <xref ref-type="bibr" rid="ref33">Goodell &amp; Corbet, 2023</xref>).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Overall Risk</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">This type of attack is possible to have recurrence, and in this case, they did so with just a single stolen password.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>Total impact&#x00a0;=&#x00a0;$4.4 million +600 million gallons of fuel disruption + additional recovery and economic costs.
                <list list-type="order">
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Always deactivate unused accounts immediately (
                                    <xref ref-type="bibr" rid="ref12">CISA, 2021b</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Multi-factor authentication (MFA) should be used on any remote access - a single additional step would have prevented this whole attack (NIST, 2018).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Separate IT networks (billing, email) from OT networks (pipeline controls) to restrict damage in case attackers gain access (
                                    <xref ref-type="bibr" rid="ref12">CISA, 2021b</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Encourage employees to reset their passwords frequently.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Conduct frequent incident response exercises to ensure that employees are aware of the precise steps to take in case an attack is experienced (
                                    <xref ref-type="bibr" rid="ref19">DOE, 2021</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Adhere to the NIST Cybersecurity Framework, a free governmental tool for securing critical systems (NIST, 2018).</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f5">
Figure 5</xref> depicts how compromised credentials would lead to access and lateral movements in a system and ransomware implementation that can cause disturbance in the functioning of critical energy infrastructures.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T8">
Table 8</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f5" orientation="portrait" position="float">
                <label>
Figure 5. </label>
                <caption>
                    <title>Cybersecurity case study energy infrastructure- This diagram depicts how compromised credentials would lead to access and lateral movements in a system and ransomware implementation that can cause disturbance in the functioning of critical energy infrastructures.</title>
                </caption>
                <graphic id="gr5" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure5.gif"/>
            </fig>
            <table-wrap id="T8" orientation="portrait" position="float">
                <label>
Table 8. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study energy infrastructure&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Ransomware</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Malicious software that encrypts files and requires a ransom to decrypt them.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>VPN (virtual private network)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An encrypted and secure means by which employees can access the computer network of a company, even though they are not within the company.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Multi-factor authentication (MFA)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A security system in which more than one step is required to log in to gain access.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Lateral movement</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A technique that allows attackers, once inside a network, to quietly move from one computer or system to another to explore and gather information.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Dark web</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A hidden part of the internet that cannot be accessed through normal browsers, and where crime is frequently committed.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Encryption</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Coding (Scrambling) information so that it is only decipherable by the authorized user.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Decryption</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The process of unscrambling encrypted data back to its original, readable form using a special key.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Industrial control system (ICS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Computer systems that monitor and control physical equipment.
                                <break/>They are machines and physical processes controller systems.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Critical infrastructure</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Systems and assets are so essential to a country&#x2019;s safety, economy, and public health that their disruption would have a severe national impact.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Bitcoin</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A digital currency, which is solely virtual and can be sent between users without passing through a bank.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec11">
            <title>Cybersecurity case study: banking and financial security</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>Flagstar Bank is a large U.S. financial institution headquartered in New York, boasting total assets of more than $31 billion and annual revenue of more than $ 1.9 billion. It belongs to the New York Community Bank and offers its customers such services as retail banking, mortgages, and commercial lending that are offered in the United States (
                            <xref ref-type="bibr" rid="ref51">Mascellino, 2023</xref>).</p>
                        <p>Like most modern banks, Flagstar uses external technology vendors, also known as third-party vendors, to support certain areas of its business. One of such vendors is Fiserv, a large payment processing and mobile banking technology company. Fiserv, in turn, used the MOVEit Transfer file transfer program to move large volumes of sensitive financial information across organizations (
                            <xref ref-type="bibr" rid="ref32">Ghanbari et al., 2024</xref>).</p>
                        <p>In May 2023, a ransomware gang known as Clop discovered and exploited a previously unknown security vulnerability, or zero-day, in the MOVEit software. By the time the bug was publicly disclosed and fixed, Clop had gained unauthorized access to the data of thousands of organizations worldwide, including Fiserv&#x2019;s. Consequently, personal data of 837,390 customers of Flagstar Bank were stolen - names and Social Security numbers (
                            <xref ref-type="bibr" rid="ref51">Mascellino, 2023</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Personal identifying information (PII) and Customer Social Security numbers.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Third-party file transfer systems (MOVEit) are used to process banking data</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Mobile banking and payment processing platforms managed by vendor Fiserv</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Customer account records and transaction data</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The bank&#x2019;s reputation and compliance standing with regulators</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Trust relationships between the bank and its third-party service providers</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The attack did not originate at Flagstar Bank itself, but at one of its technology vendors. The ransomware group Clop used a zero-day vulnerability in MOVEit Transfer software between May 27 and 31, 2023. A zero-day vulnerability is a security flaw that is unknown to the software developer and the community at large, meaning there is no patch or fix yet. This provides attackers with a significant advantage (
                            <xref ref-type="bibr" rid="ref32">Ghanbari et al., 2024</xref>).</p>
                        <p>Clop exploited the weakness to silently gain access to the information being transferred using the Fiserv MOVEit systems, including files belonging to Flagstar Bank clients. Fiserv was unable to detect or prevent the attack in time because it occurred before the flaw was publicly known. On May 31, 2023, the vulnerability was publicly disclosed by Progress Software (the creator of MOVEit), more than two months after the breach itself happened, making Fiserv aware of it on the same day, at which point Flagstar Bank was notified about it (approximately August 8, 2023). On October 6, 2023, Flagstar Bank began notifying affected customers through notification letters (
                            <xref ref-type="bibr" rid="ref51">Mascellino, 2023</xref>).</p>
                        <p>By October 2023, it had compromised more than 2,500 organizations worldwide, including banks, government bodies, universities, and corporations, exposing the personal data of more than 64 million people (
                            <xref ref-type="bibr" rid="ref51">Mascellino, 2023</xref>). Clop took ownership of the attack and posted the names of victim organizations on its own site as a way of pressurizing them to pay the ransom to prevent further data exposure.</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>Flagstar Bank had to investigate the breach, track down all affected customers, report to regulators, and implement identity monitoring for more than 837,000 customers. It was achieved over several months and required significant resources and staff beyond regular banking operations (
                            <xref ref-type="bibr" rid="ref51">Mascellino, 2023</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>All customers who were impacted by this began receiving free identity monitoring services from Kroll for 2&#x00a0;years, organized by Flagstar Bank. The direct expenses included legal charges, regulatory notification expenses, credit surveillance, and exposure to a class-action lawsuit. According to 
                            <xref ref-type="bibr" rid="ref49">Lee et al. (2022)</xref>, financial sector data breaches cost an average of $5.9 million per incident, one of the highest among industries. Research on U.S. commercial banks indicates that breached institutions record considerably lower returns on equity and assets in the quarters following an attack (
                            <xref ref-type="bibr" rid="ref22">Erkan-Barlow et al., 2023</xref>).</p>
                        <p>

                            <bold>Safety</bold>
                        </p>
                        <p>
If a Social Security number is stolen, the thief can commit identity theft by creating a counterfeit credit card, filing a false tax return, and taking out loans in the victim&#x2019;s name. This may cost people years of money. Victims who do not monitor their credit carefully may not realize they are victims of identity theft until serious harm has already occurred (
                            <xref ref-type="bibr" rid="ref46">Kamiya et al., 2021</xref>).</p>
                        <p>

                            <bold>Reputational</bold>
                        </p>
                        <p>It is the third large data breach at Flagstar Bank in three years (2021, 2022, and 2023), which has been devastating to customer trust (
                            <xref ref-type="bibr" rid="ref46">Kamiya et al., 2021</xref>). The bank&#x2019;s security experts and vendors publicly criticized the lack of proper supply chain risk management. The case illustrated how a bank may fall victim to a significant breach even when its own systems are not directly attacked through a trusted vendor&#x2019;s vulnerability.</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T9">
Table 9</xref> provide a brief description about evaluation overall risk.</p>
                        <p>

                            <bold>Simple cost example</bold>
                        </p>
                        <p>837,390 customers each received 2&#x00a0;years of identity monitoring at approximately $20/month per person:
</p>
                    </list-item>
                </list>

                <disp-formula id="e12">

                    <mml:math display="block">
                        <mml:mn mathvariant="bold">837,390</mml:mn>
                        <mml:mo mathvariant="bold">&#x00d7;</mml:mo>
                        <mml:mtext mathvariant="bold">$</mml:mtext>
                        <mml:mn mathvariant="bold">20</mml:mn>
                        <mml:mo>/</mml:mo>
                        <mml:mtext mathvariant="bold">month</mml:mtext>
                        <mml:mo mathvariant="bold">&#x00d7;</mml:mo>
                        <mml:mn mathvariant="bold">24</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext mathvariant="bold">months</mml:mtext>
                        <mml:mo mathvariant="bold">=</mml:mo>
                        <mml:mo mathvariant="bold">~</mml:mo>
                        <mml:mtext mathvariant="bold">$</mml:mtext>
                        <mml:mn mathvariant="bold">402</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext mathvariant="bold">million in monitoring costs alone</mml:mtext>
                    </mml:math>
</disp-formula>
            </p>
            <table-wrap id="T9" orientation="portrait" position="float">
                <label>
Table 9. </label>
                <caption>
                    <title>Overall risk evaluation for the case study &#x201c;cybersecurity case study banking and financial security&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>High</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Banks are the most targeted industry because attackers can steal money or personal data used for identity theft.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>High</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Over 837,000 individuals were victims of having their Social Security numbers stolen, a form of damage that can have a long-term effect.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Overall risk</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>High</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Even secure banks can be compromised through their vendors, a risk that is difficult to see and control (
                                <xref ref-type="bibr" rid="ref50">Liu &amp; Babar, 2026</xref>).</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>This figure does not include legal fees, regulatory fines, staff time, or reputational losses.
                <list list-type="order">
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Carry out thorough cybersecurity assessments on all third-party vendors before sharing sensitive customer data with them (
                                    <xref ref-type="bibr" rid="ref14">Cremer et al., 2022</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Require vendors to notify the bank immediately, not months later, if a breach or vulnerability is discovered.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Encrypt all transfers of data to ensure that if files are accessed, they cannot be read without a key (NIST, 2018).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Apply zero-trust principles: Authenticate all users and all systems, including trusted vendor networks (
                                    <xref ref-type="bibr" rid="ref32">Ghanbari et al., 2024</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Develop a vendor risk management program that rates and continuously monitors the security posture of every technology partner.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f6">
Figure 6</xref> shows the possible attack on financial information through vulnerability in third-party software applications used for other purposes.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T10">
Table 10</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.
</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f6" orientation="portrait" position="float">
                <label>
Figure 6. </label>
                <caption>
                    <title>Cybersecurity Case Study Banking and Financial Security- This diagram shows the possible attack on financial information through vulnerability in third-party software applications used for other purposes.</title>
                </caption>
                <graphic id="gr6" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure6.gif"/>
            </fig>
            <table-wrap id="T10" orientation="portrait" position="float">
                <label>
Table 10. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study banking and financial security&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Zero-day vulnerability</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A vulnerability in software that the software developer and the public are unaware of, meaning there is no patch (fix) available. Since one knows about it, defenders have no protection against it.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>SQL injection</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A cyberattack where the attacker executes malicious code in a website query or database query to trick the system into issuing unauthorized access to its data.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Supply chain attack</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An attack whereby a company does not attack directly, but via a trusted third-party vendor or software supplier that the company uses.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Third-party vendor</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A company that is outside and is contracted by a business to offer service or technology.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Personally identifiable information (PII)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Any data that can be used to identify a particular person - a name, address, date of birth, Social Security number, etc.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Patch</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A computer software update that a developer publishes to correct a security vulnerability or bug.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Data exfiltration</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The unauthorized transfer of data from a computer or network by an attacker to a third-party location.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Ransomware-as-a-service (RaaS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">A type of criminal business where a ransomware organization (such as Clop) creates and sells its hacking infrastructure to other criminals to execute their own attacks and share the profits.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">
                                <bold>Identity theft</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">When an individual steals the personal information of another person and uses it to commit a fraud, such as a credit card, a loan, or a forged tax filing in the name of another person.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec12">
            <title>Cybersecurity Case Study: Ransomware attack on jaguar land rover
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>Jaguar Land Rover (JLR) is a British multinational automotive manufacturer and a subsidiary of India&#x2019;s Tata Motors. The company produces luxury and off-road vehicles under the Jaguar and Land Rover brands, operating major manufacturing plants in Solihull, Halewood, and Wolverhampton in the United Kingdom. JLR is one of the UK&#x2019;s largest manufacturers, supporting an extensive supply chain of over 5,000 organizations and more than 104,000 supply chain jobs across the country (
                            <xref ref-type="bibr" rid="ref9">Burgess, 2025</xref>).</p>
                        <p>The manufacturing sector is one of the most targeted industries for cyberattacks worldwide. According to the 
                            <xref ref-type="bibr" rid="ref4">Arctic Wolf 2026</xref> Threat and Predictions Report, from 2024 to 2025, the number of victimized manufacturers nearly doubled, making manufacturing the sector with the highest victim count globally. IBM&#x2019;s X-Force 2025 Threat Intelligence Index also lists manufacturing as the top-targeted industry, a position it has held for four consecutive years. The median cost of a manufacturing ransomware attack is now $600,000 USD (
                            <xref ref-type="bibr" rid="ref4">Arctic Wolf, 2026</xref>).</p>
                        <p>On August 31, 2025, a cybercriminal collective known as Scattered Lapsus Hunters launched a devastating ransomware attack on JLR&#x2019;s IT systems. The attack forced the automaker to shut down all production across its UK plants for over five weeks, making it the most damaging cyberattack in British history, with an estimated total cost to the UK economy of &#x00a3;1.9 billion (
                            <xref ref-type="bibr" rid="ref6">BBC News, 2025b</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>
Production line control systems and operational technology (OT) across three major UK manufacturing plants</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>
Enterprise IT infrastructure, including SAP systems, internal communications, and automated ordering platforms</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Proprietary vehicle designs, engineering blueprints, and manufacturing process intellectual property</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Employee personal data, payroll records, and human resources information</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Global supply chain coordination systems linking over 5,000 supplier organizations</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Brand reputation and consumer trust in Jaguar and Land Rover as premium automotive brands</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The attack began on August 31, 2025, when threat actors exploited a zero-day vulnerability in a third-party remote-access tool to gain an initial foothold in JLR&#x2019;s critical systems. Once inside the network, the attackers moved laterally across the infrastructure before deploying ransomware on the company&#x2019;s systems, including its SAP enterprise resource planning platform. JLR paused production on September 1, 2025, and by September 22, all production lines at the Solihull, Halewood, and Wolverhampton plants had ceased operations entirely, with staff instructed to stay at home (
                            <xref ref-type="bibr" rid="ref69">Vallance &amp; Leggett, 2025</xref>).</p>
                        <p>A group calling itself Scattered Lapsus$ Hunters claimed responsibility for the attack on Telegram, suggesting a collaboration between three English-speaking cybercrime groups: Scattered Spider, Lapsus$, and ShinyHunters. Members of the group shared screenshots reportedly taken from inside JLR&#x2019;s IT networks, including images of internal SAP systems, and claimed to have deployed ransomware and exfiltrated sensitive data (
                            <xref ref-type="bibr" rid="ref31">Gatlan, 2025</xref>). The same collective was linked to a wave of cyberattacks on major UK retailers, including Marks &amp; Spencer, earlier in 2025 (
                            <xref ref-type="bibr" rid="ref53">Milmo, 2025</xref>).</p>
                        <p>Initially, JLR planned to restart production on September 24, but announced on September 23 that the shutdown would continue until October 1. Production finally began restarting on October 8, 2025, following a gradual, controlled approach, but the company did not return to normal production levels until mid-November 2025. A forensic investigation was launched, and a criminal investigation was opened by law enforcement (
                            <xref ref-type="bibr" rid="ref73">Young, 2025</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>The ransomware attack forced a complete production shutdown across all three of JLR&#x2019;s major UK manufacturing plants for over five weeks. Assembly lines stood idle, employees were sent home, and workarounds were introduced to partially restore some functions, but significant disruption continued for months. Internal systems, including automated production lines, ordering platforms, and communication tools, were taken offline to contain the breach. September 2025 car production in the UK fell to its lowest level since 1952 as a direct result of the shutdown (
                            <xref ref-type="bibr" rid="ref9">Burgess, 2025</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>In its financial results published in November 2025, JLR revealed that the attack cost &#x00a3;196 million in direct costs during the second quarter of its fiscal year. The company posted a pre-tax loss of &#x00a3;485 million for the July&#x2013;September 2025 quarter, compared with a profit of &#x00a3;398 million for the same period the previous year. The cyberattack was estimated to cost JLR over &#x00a3;50 million per week of downtime. The broader impact on the UK economy was estimated at &#x00a3;1.9 billion, accounting for supply chain disruptions, lost output, and reduced exports (
                            <xref ref-type="bibr" rid="ref59">Pearson, 2025</xref>).</p>
                        <p>

                            <bold>Supply chain</bold>
                        </p>
                        <p>
The shutdown devastated JLR&#x2019;s supply chain. According to the Cyber Monitoring Centre, over 5,000 UK organizations were impacted, including first-, second-, and third-tier automotive parts suppliers, logistics companies, service providers, and dealerships. One smaller JLR supplier confirmed that it had laid off 40 people, nearly half of its workforce. The trade union Unite reported that supply chain staff were advised to apply for Universal Credit, the UK&#x2019;s social welfare benefit. MP Liam Byrne described the situation as a &#x201c;digital siege&#x201d; and warned that thousands of jobs were at risk across the supply chain.</p>
                        <p>

                            <bold>Reputational and national impact</bold>
                        </p>
                        <p>The JLR cyberattack attracted national and international media coverage and became a matter of parliamentary debate. The Bank of England cited the attack as one of the key factors contributing to lower-than-expected UK GDP growth in the third quarter of 2025, noting that the production stoppage directly contributed to a 0.17 percentage point contraction in GDP in September (
                            <xref ref-type="bibr" rid="ref45">Jones, 2025</xref>). The UK government intervened with a &#x00a3;1.5 billion loan guarantee to stabilize the automotive supply chain. The Department for Business and Trade and the Society of Motor Manufacturers and Traders issued a joint statement acknowledging the significant impact on JLR and the broader manufacturing sector (
                            <xref ref-type="bibr" rid="ref68">UK Government, 2025</xref>). Jamie MacColl of the Royal United Services Institute described the incident as &#x201c;unprecedented in the UK&#x201d; in terms of the level of disruption caused by a cyberattack (
                            <xref ref-type="bibr" rid="ref9">Burgess, 2025</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T11">
Table 11</xref> provide a brief description about evaluation overall risk.</p>
                        <p>

                            <bold>Simple cost example</bold>
                        </p>
                        <p>JLR&#x2019;s estimated weekly cost of the production shutdown was &#x00a3;50 million. With a shutdown lasting approximately 5&#x00a0;weeks: &#x00a3;50,000,000&#x00a0;&#x00d7;&#x00a0;5&#x00a0;weeks&#x00a0;=&#x00a0;&#x00a3;250 million in lost production revenue.</p>
                        <p>This figure accounts only for direct production losses. The total direct cost reported by JLR was &#x00a3;196 million for the quarter, while the broader economic impact, including supply chain losses, reduced exports, and government intervention costs, was estimated at &#x00a3;1.9 billion ($2.5 billion USD) (
                            <xref ref-type="bibr" rid="ref59">Pearson, 2025</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Implement zero-trust architecture to verify all users, devices, and systems before granting access, particularly for remote-access tools and third-party integrations that served as the initial attack vector in the JLR breach (NIST, 2018).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Segment IT and OT networks to prevent lateral movement from corporate systems to production control systems, ensuring that a breach in one domain does not cascade to manufacturing operations (
                                    <xref ref-type="bibr" rid="ref4">Arctic Wolf, 2026</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Conduct regular vulnerability assessments and patch management for all third-party remote-access tools and software, prioritizing zero-day vulnerability monitoring.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Develop and regularly test a multi-site incident response plan that includes procedures for coordinating with suppliers, government agencies, and law enforcement during extended production shutdowns (
                                    <xref ref-type="bibr" rid="ref68">UK Government, 2025</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Maintain offline, immutable backups of critical production data, SAP configurations, and enterprise systems to enable rapid recovery without reliance on ransomware decryption (NIST, 2018) [54].</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Establish supply chain cybersecurity requirements and communication protocols so that dependent organizations receive timely notification and can activate their own contingency plans during an incident (
                                    <xref ref-type="bibr" rid="ref9">Burgess, 2025</xref>).</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f7">
Figure 7</xref> demonstrates the way ransomware propagates between the IT systems and OT systems, causing disruption of manufacturing operations through the supply chain.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T12">
Table 12</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <table-wrap id="T11" orientation="portrait" position="float">
                <label>
Table 11. </label>
                <caption>
                    <title>Overall risk evaluation for the case study &#x201c;cybersecurity case study ransomware attack on Jaguar Land Rover&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Manufacturing has been the most targeted industry for cyberattacks for four consecutive years. The raw count of victimized manufacturers nearly doubled between 2024 and 2025 (
                                <xref ref-type="bibr" rid="ref4">Arctic Wolf, 2026</xref>).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Five weeks of total production shutdown, &#x00a3;196 million in direct costs, &#x00a3;1.9 billion in economic damage to the UK, over 5,000 organizations impacted in the supply chain, and GDP contraction cited by the Bank of England.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Overall risk</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Large manufacturers with interconnected IT/OT systems and extensive supply chains face cascading risks where a single breach can paralyze thousands of dependent organizations and impact national economies (
                                <xref ref-type="bibr" rid="ref9">Burgess, 2025</xref>).</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <fig fig-type="figure" id="f7" orientation="portrait" position="float">
                <label>
Figure 7. </label>
                <caption>
                    <title>Cybersecurity case study ransomware attack on Jaguar Land Rover- The figure demonstrates the way ransomware propagates between the IT systems and OT systems, causing disruption of manufacturing operations through the supply chain.</title>
                </caption>
                <graphic id="gr7" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure7.gif"/>
            </fig>
            <table-wrap id="T12" orientation="portrait" position="float">
                <label>
Table 12. </label>
                <caption>
                    <title>
Key terms used in the case study &#x201c;cybersecurity case study ransomware attack on jaguar land rover&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Ransomware</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A type of malicious software that encrypts a victim&#x2019;s files or systems and demands a payment (ransom) to restore access. If the ransom is not paid, the attacker may the data or publish it online.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Zero-day vulnerability</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A security flaw in software that the software developer and the public are unaware of, meaning there is no patch (fix) available. Since no one knows about it, defenders have no protection against it.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Lateral movement</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A security flaw in software that the software developer and the public are unaware of, meaning there is no patch (fix) available. Since no one knows about it, defenders have no protection against it.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Supply chain attack</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A cyberattack in which a company is not targeted directly, but through a trusted third-party vendor, software supplier, or service provider that the company depends on.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Operational technology (OT)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Hardware and software systems that monitor and control physical processes, such as robotic assembly lines, production equipment, and industrial control systems in a factory.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Zero-trust architecture</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A cybersecurity approach that assumes no user, device, or system should be trusted by default, even if they are inside the organization&#x2019;s network. Every access request must be verified before being granted.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Network segmentation</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">The practice of dividing a computer network into smaller, isolated sections so that if an attacker gains access to one section, they cannot easily move to other parts of the network.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Personally identifiable information (PII)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Any data that can be used to identify a specific person, such as a name, address, date of birth, Social Security number, or email address.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Intellectual property (IP)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Creations of the mind that have commercial value and are legally protected, such as vehicle designs, engineering blueprints, proprietary manufacturing processes, and trade secrets.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec13">
            <title>Agriculture Cybersecurity Case study: Ransomware attack on duvel moortgat brewery
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario overview</bold>
                        </p>
                        <p>Duvel Moortgat is a major Belgian brewery founded in 1871, headquartered in Puurs-Sint-Amands, Belgium. The company is known for producing iconic beer brands including Duvel, Maredsous, and La Chouffe. Duvel Moortgat operates four brewing facilities in Belgium and one in Kansas City, Missouri, in the United States through its subsidiary Boulevard Brewing Company. The brewery relies on interconnected IT systems for production management, inventory tracking, supply chain coordination, and enterprise resource planning across all its international sites (
                            <xref ref-type="bibr" rid="ref34">Greig, 2024</xref>) [63].</p>
                        <p>The food and agriculture sector, which includes beverage production, is classified as one of 16 critical infrastructure sectors by the U.S. Department of Homeland Security. This sector is increasingly targeted by cybercriminals due to its reliance on operational technology (OT) and information technology (IT) systems that are vulnerable to cyberattacks (
                            <xref ref-type="bibr" rid="ref13">CISA, 2024</xref>). In 2021, the FBI issued warnings about ransomware groups specifically targeting the food and agriculture sector, noting that disruptions could have cascading effects on food supply chains (
                            <xref ref-type="bibr" rid="ref25">FBI, 2022</xref>).</p>
                        <p>On the night of March 5, 2024, the Stormous ransomware gang launched a ransomware attack on Duvel Moortgat Brewery, causing all production to halt at the company&#x2019;s Belgian and U.S. facilities. The attackers claimed to have stolen 88 gigabytes of data from the brewery&#x2019;s systems and demanded a ransom payment by March 25, 2024 (
                            <xref ref-type="bibr" rid="ref30">Gatlan, 2024</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Production control systems managing brewing, bottling, and packaging operations across five facilities.</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Enterprise IT infrastructure including servers, databases, and internal communication systems</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Proprietary brewing data, recipes, and operational trade secrets</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Employee and human resources records, including accounting and payroll information</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Supply chain management systems coordinating ingredient procurement and distribution logistics</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Brand reputation and consumer trust in Duvel Moortgat&#x2019;s portfolio of premium beer brands</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>
At approximately 1:30&#x00a0;AM on March 6, 2024, automated threat detection systems in Duvel Moortgat&#x2019;s IT department flagged the presence of ransomware on the company&#x2019;s network. Spokesperson Ellen Aerts confirmed that the IT team immediately initiated incident response procedures, shutting down servers across all sites to contain the spread of the malware. This decision brought production to a standstill at all four Belgian facilities and the Kansas City brewery in the United States (
                            <xref ref-type="bibr" rid="ref30">Gatlan, 2024</xref>).</p>
                        <p>The Stormous ransomware group, a pro-Russian cybercriminal organization, claimed responsibility for the attack. Stormous added Duvel Moortgat to its leak site on March 7, 2024, claiming to have exfiltrated 88 gigabytes of data and setting a ransom deadline of March 25, 2024. According to Cisco Talos research, Stormous had been collaborating with another hacking group called GhostSec since July 2023, jointly conducting double extortion ransomware attacks using the GhostLocker and StormousX ransomware programs against victims across more than 15 countries (
                            <xref ref-type="bibr" rid="ref60">Raghuprasad, 2024</xref>). The groups operated a ransomware-as-a-service (RaaS) platform called STMX_GhostLocker, which allowed affiliates to deploy ransomware or sell stolen data through their infrastructure (
                            <xref ref-type="bibr" rid="ref60">Raghuprasad, 2024</xref>).</p>
                        <p>The situation was further complicated when, on March 13, 2024, a second ransomware group called Black Basta also claimed to have stolen more than one terabyte of data from Duvel Moortgat and its U.S. subsidiary Boulevard Brewing, including accounting and human resources information. Duvel Moortgat refused to pay the ransom, and the stolen data was subsequently published on the attackers&#x2019; leak sites (
                            <xref ref-type="bibr" rid="ref17">Cyber-Plan, 2024</xref>). The Antwerp public prosecutor&#x2019;s office opened an investigation into the cyberattack.</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>
The ransomware attack caused a complete production shutdown across all five of Duvel Moortgat&#x2019;s brewing and bottling facilities in Belgium and the United States. Production at the main Puurs-Sint-Amands brewery was not restored until March 8, approximately three days after the attack was detected. During this period, no beer was brewed, bottled, or shipped from any facility. The company was forced to rely on existing inventory to fulfill orders. IT teams worked around the clock to restore systems, investigate the breach, and implement additional security measures before resuming operations (
                            <xref ref-type="bibr" rid="ref30">Gatlan, 2024</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>The financial impact included direct costs from lost production revenue during the multi-day shutdown, IT incident response and forensic investigation expenses, system restoration costs, and potential legal liabilities related to the exfiltration of employee data. According to 
                            <xref ref-type="bibr" rid="ref48">Kulkarni et al. (2025)</xref>, ransomware attacks on the food and agriculture sector have resulted in ransom demands ranging from tens of thousands to millions of dollars, with the JBS Foods attack in 2021 resulting in an $11 million ransom payment. While Duvel Moortgat refused to pay the ransom, the indirect costs of operational downtime, data breach remediation, and reputational damage are significant.</p>
                        <p>

                            <bold>Safety/Food supply</bold>
                        </p>
                        <p>Although the Duvel Moortgat attack did not directly compromise food safety, it demonstrated how cyberattacks on the food and agriculture sector can disrupt supply chains. The FBI has warned that ransomware attacks on this sector risk causing shortages in food availability, particularly when attacks coincide with critical production periods (
                            <xref ref-type="bibr" rid="ref25">FBI, 2022</xref>). In a more extreme case in the same sector, a ransomware attack on a Swiss farm in November 2023 disabled livestock monitoring systems, leading to the death of a calf and the euthanasia of the mother cow, showing that cyberattacks on agriculture can directly endanger animal welfare and food production (
                            <xref ref-type="bibr" rid="ref44">James, 2024</xref>).</p>
                        <p>

                            <bold>Reputational</bold>
                        </p>
                        <p>The public disclosure of the attack, combined with the publication of stolen data on dark web leak sites by both Stormous and Black Basta, caused reputational harm to Duvel Moortgat. Extensive media coverage of the attack drew global attention to the brewery&#x2019;s cybersecurity vulnerabilities. The fact that two separate ransomware groups claimed to have breached the company&#x2019;s systems raised questions about the adequacy of its cybersecurity posture. For a premium brand built on heritage and trust, such exposure can erode consumer and business partner confidence (
                            <xref ref-type="bibr" rid="ref48">Kulkarni et al., 2025</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T13">
Table 13</xref> provide a brief description about evaluation overall risk.</p>
                        <p>

                            <bold>Simple Cost Example</bold>
                        </p>
                        <p>Assuming Duvel Moortgat&#x2019;s five facilities generate combined daily revenue of approximately $1.5 million and production was halted for 3&#x00a0;days:
</p>
                    </list-item>
                </list>

                <disp-formula id="e13">

                    <mml:math display="block">
                        <mml:mtext>$</mml:mtext>
                        <mml:mn>1,500,000</mml:mn>
                        <mml:mo>&#x00d7;</mml:mo>
                        <mml:mn>3</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext>days</mml:mtext>
                        <mml:mo>=</mml:mo>
                        <mml:mo>~</mml:mo>
                        <mml:mtext>$</mml:mtext>
                        <mml:mn>4.5</mml:mn>
                        <mml:mspace width="0.25em"/>
                        <mml:mtext>million in lost production revenue</mml:mtext>
                    </mml:math>
</disp-formula>
            </p>
            <table-wrap id="T13" orientation="portrait" position="float">
                <label>
Table 13. </label>
                <caption>
                    <title>Overall risk evaluation for the case study &#x201c;cybersecurity case study ransomware attack on Duvel Moortgat Brewery&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">The food and agriculture sector has experienced a significant increase in ransomware attacks, with the FBI documenting ransomware targeting six grain cooperatives during the 2021 harvest season alone (
                                <xref ref-type="bibr" rid="ref25">FBI, 2022</xref>).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Production was halted for three days across all facilities, 88&#x00a0;GB of data was exfiltrated, and a second ransomware group (Black Basta) also claimed to have stolen over 1&#x00a0;TB of data.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Overall risk</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Beverage producers and food manufacturers are high-value targets due to their time-sensitive production schedules and the cascading effects of supply chain disruptions (
                                <xref ref-type="bibr" rid="ref48">Kulkarni et al., 2025</xref>).</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <p>This figure does not include IT forensic investigation costs, system restoration expenses, legal fees, employee data breach notification costs, or long-term reputational losses.
                <list list-type="order">
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <p>Deploy endpoint detection and response (EDR) systems across all production and IT environments to detect ransomware activity early, as Duvel&#x2019;s automated threat detection enabled rapid response (
                            <xref ref-type="bibr" rid="ref13">CISA, 2024</xref>).</p>
                        <p>Implement network segmentation to isolate production OT systems from corporate IT networks, preventing lateral movement of ransomware across facilities.</p>
                        <p>Maintain regular offline backups of critical production data and enterprise systems to enable rapid recovery without paying ransom demands (
                            <xref ref-type="bibr" rid="ref13">CISA, 2024</xref>).</p>
                        <p>Enforce multi-factor authentication (MFA) on all remote access points, VPNs, and privileged accounts to reduce the risk of unauthorized access (
                            <xref ref-type="bibr" rid="ref13">CISA, 2024</xref>).</p>
                        <p>Develop and regularly test an incident response plan that includes procedures for multi-site shutdowns, communication protocols, and coordination with law enforcement agencies.</p>
                        <p>Conduct regular cybersecurity awareness training for all employees, focusing on recognizing phishing attempts and social engineering tactics commonly used by ransomware groups (
                            <xref ref-type="bibr" rid="ref48">Kulkarni et al., 2025</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f8">
Figure 8</xref> represents the propagation of ransomware among the IT systems and OT systems of food production operations, which cause supply chain disruptions.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T14">
Table 14</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <fig fig-type="figure" id="f8" orientation="portrait" position="float">
                <label>
Figure 8. </label>
                <caption>
                    <title>Cybersecurity case study ransomware attack on Duvel Moortgat Brewer- The figure represents the propagation of ransomware among the IT systems and OT systems of food production operations, which cause supply chain disruptions.</title>
                </caption>
                <graphic id="gr8" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure8.gif"/>
            </fig>
            <table-wrap id="T14" orientation="portrait" position="float">
                <label>
Table 14. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study ransomware attack on Duvel Moortgat Brewery&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Ransomware</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A type of malicious software that encrypts a victim&#x2019;s files or systems and demands a payment (ransom) to restore access. If the ransom is not paid, the attacker may delete the data or publish it online.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Ransomware-as-a-Service (RaaS)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A criminal business model where a ransomware group develops hacking tools and rents or sells them to other criminals (affiliates) who carry out attacks and share the profits with the developers.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Double extortion</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A ransomware tactic where attackers not only encrypt the victim&#x2019;s data but also steal a copy of it. They then threaten to publish the stolen data online if the ransom is not paid, putting pressure on the victim from two directions.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Data exfiltration</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">The unauthorized transfer of data from a computer or network by an attacker to an external location under the attacker&#x2019;s control.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Operational technology (OT)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Hardware and software systems that monitor and control physical processes, such as manufacturing equipment, brewing systems, and production lines in a factory or plant.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Information technology (IT)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Computer systems, networks, and software used for storing, processing, and communicating data, such as email servers, databases, and enterprise applications.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Critical Infrastructure</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Essential systems and assets that a country relies on for national security, economic stability, and public health. Examples include energy grids, water systems, healthcare, and food and agriculture.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Endpoint detection and response (EDR)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A cybersecurity tool installed on computers and servers that continuously monitors for suspicious activity, detects threats, and helps security teams respond to attacks quickly.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Network segmentation</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">The practice of dividing a computer network into smaller, isolated sections so that if an attacker gains access to one section, they cannot easily move to other parts of the network.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Multi-factor authentication (MFA)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A security method that requires users to verify their identity using two or more forms of proof before accessing a system, such as a password plus a code sent to their phone.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Leak Site</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A website, usually on the dark web, where ransomware groups publish stolen data from victims who refuse to pay the ransom, as a way to pressure them or damage their reputation.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Incident response plan</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A documented set of procedures that an organization follows when a cybersecurity incident occurs, including steps for detection, containment, recovery, and communication.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Personally identifiable information (PII)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Any data that can be used to identify a specific person, such as a name, address, date of birth, Social Security number, or email address.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Phishing</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A social engineering attack where an attacker sends a fraudulent message, usually by email, designed to trick the recipient into revealing sensitive information or clicking a malicious link.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
        </sec>
        <sec id="sec14">
            <title>Cybersecurity case study: Ransomware attack on change healthcare
</title>
            <p>

                <list list-type="order">
                    <list-item>
                        <label>1.</label>
                        <p>

                            <bold>Scenario Overview</bold>
                        </p>
                        <p>Change Healthcare is a large healthcare technology and Payments Company and a subsidiary of UnitedHealth Group, one of the largest healthcare companies in the world. Change Healthcare operates as the largest medical claims clearinghouse in the United States, processing approximately 15 billion healthcare transactions annually and touching one in every three patient records. The company handles an estimated $2 trillion in annual medical claims, representing approximately 44% of all funds flowing through the U.S. medical system. About 189,000 medical providers rely on its software and services for eligibility verification, prior authorization, claims processing, and payment facilitation (
                            <xref ref-type="bibr" rid="ref26">Fliegelman &amp; Stemp, 2024</xref>).</p>
                        <p>The American Hospital Association (AHA) has described Change Healthcare as the predominant source for &#x201c;more than 100 critical functions that keep the healthcare system operating&#x201d; (
                            <xref ref-type="bibr" rid="ref1">AHA, 2024a</xref>). Because of this central role, Change Healthcare functions as a single point of failure in the U.S. healthcare system. A court filing made by the Department of Justice quoted Change Healthcare as stating that &#x201c;the healthcare system, and how payers and providers interact and transact, would not work without Change Healthcare&#x201d; (
                            <xref ref-type="bibr" rid="ref26">Fliegelman &amp; Stemp, 2024</xref>).</p>
                        <p>On February 21, 2024, the ALPHV/BlackCat ransomware gang launched a devastating ransomware attack on Change Healthcare, encrypting the company&#x2019;s systems and stealing up to 6 terabytes of sensitive data, including patient Social Security numbers, medical records, and information on active military personnel. The attack disrupted healthcare operations across the entire United States and has been described as &#x201c;the most significant and consequential incident of its kind against the U.S. healthcare system in history&#x201d; (
                            <xref ref-type="bibr" rid="ref1">AHA, 2024a</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>2.</label>
                        <p>

                            <bold>Key Assets at risk</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Protected health information (PHI) of an estimated 190 million individuals, including medical records, diagnoses, and treatment information</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Personally identifiable information (PII), including patient Social Security numbers, dates of birth, and addresses</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Financial and insurance data, including claims records, payment information, and coverage details</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Claims clearinghouse infrastructure processing 15 billion annual healthcare transactions</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Eligibility verification, prior authorization, and electronic payment systems used by 189,000 medical providers</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>The operational continuity of the entire U.S. healthcare payment ecosystem, including hospitals, pharmacies, and physician practices</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>3.</label>
                        <p>

                            <bold>Threat event</bold>
                        </p>
                        <p>The attack began on February 12, 2024, when the ALPHV/BlackCat ransomware group gained initial access to Change Healthcare&#x2019;s systems using stolen credentials. According to testimony by UnitedHealth Group CEO Andrew Witty before the U.S. Congress, the attackers used the compromised credentials to remotely access a Change Healthcare Citrix portal that enabled remote desktop access. Critically, this portal did not have multi-factor authentication (MFA) enabled, allowing the attackers to gain access with stolen credentials alone. As Senator Ron Wyden summarized, &#x201c;This hack could have been stopped with cybersecurity 101&#x201d; (
                            <xref ref-type="bibr" rid="ref41">Hyperproof, 2026</xref>).</p>
                        <p>After gaining initial access, the attackers moved laterally within Change Healthcare&#x2019;s network for nine days, exfiltrating approximately 6 terabytes of data before deploying ransomware on February 21, 2024, which encrypted the company&#x2019;s systems. Change Healthcare detected the attack on February 21, disconnected its networks, and took all operations offline. The ALPHV/BlackCat group claimed responsibility for the attack on February 26 and stated it had stolen patient Social Security numbers, medical records, and information on active military personnel. UnitedHealth Group, through its subsidiary Optum, paid a $22 million ransom in Bitcoin on March 3 to secure the deletion of the stolen data. However, the ransomware group performed an exit scam, and the payment did not secure the data (
                            <xref ref-type="bibr" rid="ref3">Alder, 2026</xref>).</p>
                        <p>The situation worsened in April 2024 when a second ransomware group, RansomHub, claimed to have obtained the stolen data from a former ALPHV affiliate and issued an additional extortion demand, threatening to sell the data to the highest bidder. RansomHub leaked screenshots that appeared to include Change Healthcare patient files. The demand was later removed from RansomHub&#x2019;s website, though it remains unclear whether a second ransom was paid (
                            <xref ref-type="bibr" rid="ref41">Hyperproof, 2026</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>4.</label>
                        <p>

                            <bold>Impact analysis</bold>
                        </p>
                        <p>

                            <bold>Operational</bold>
                        </p>
                        <p>The attack caused an immediate and nationwide disruption to the U.S. healthcare system. When Change Healthcare took its systems offline, hospitals could not verify patient insurance eligibility, pharmacies could not process prescriptions, and physicians could not submit claims or receive payments for services rendered. The AHA reported that nearly 94% of hospitals experienced financial repercussions from the attack (
                            <xref ref-type="bibr" rid="ref2">AHA, 2024b</xref>). According to Kodiak Solutions, the value of claims submitted dropped by $6.3 billion across its 1,850 hospitals and 250,000 physician clients in just the first three weeks after the attack. UnitedHealth reported that it took months to restore full functionality, with 99% of pharmacy network services restored by March 18, 2024, while other systems took significantly longer (
                            <xref ref-type="bibr" rid="ref41">Hyperproof, 2026</xref>).</p>
                        <p>

                            <bold>Financial</bold>
                        </p>
                        <p>The financial impact of the Change Healthcare attack has been staggering. UnitedHealth Group reported $872 million in losses in Q1 2024 alone. By the end of Q3 2024, the total cyberattack cost had risen to $2.457 billion, including $1.521 billion in direct response costs. The total anticipated cost for 2024 was revised to $2.87 billion. UnitedHealth Group advanced more than $9 billion to struggling healthcare providers to mitigate the cash flow crisis caused by the disruption. Large health systems reported losing more than $100 million per day during the outage. An American Medical Association survey revealed that 80% of physician practices lost revenue from unpaid claims (Healthcare IT, 2024).</p>
                        <p>

                            <bold>Safety/patient care</bold>
                        </p>
                        <p>The disruption to claims processing and eligibility verification directly endangered patient care. Patients experienced delays in receiving medications as pharmacies could not verify insurance coverage. Hospitals postponed elective procedures due to uncertainty about reimbursement. The financial strain was particularly severe for smaller practices and rural hospitals, with some facing the risk of closure due to prolonged inability to process claims and receive payments. The AHA warned that the attack endangered patients and threatened the solvency of U.S. healthcare providers across the country (
                            <xref ref-type="bibr" rid="ref1">AHA, 2024a</xref>).</p>
                        <p>

                            <bold>Reputational and legal</bold>
                        </p>
                        <p>The breach triggered massive legal and regulatory consequences. The U.S. Department of Health and Human Services Office for Civil Rights (OCR) launched an investigation into potential HIPAA violations. By June 2024, a judicial panel had consolidated over 50 federal lawsuits into a single multidistrict litigation case in Minnesota (MDL No. 3108). Multiple state attorneys general, beginning with Nebraska, filed lawsuits against Change Healthcare. U.S. Senators demanded answers from UnitedHealth Group CEO Andrew Witty, and Senator Mark Warner introduced legislation proposing cybersecurity conditions for Medicare payments during cyberattacks. The revelation that the breach was caused by the absence of basic multi-factor authentication on a critical access portal drew widespread criticism of UnitedHealth Group&#x2019;s cybersecurity posture (
                            <xref ref-type="bibr" rid="ref41">Hyperproof, 2026</xref>).</p>
                    </list-item>
                    <list-item>
                        <label>5.</label>
                        <p>

                            <bold>Cyber risk awareness/quantification</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T15">
Table 15</xref> provide a brief description about evaluation overall risk.</p>
                        <p>

                            <bold>Simple cost example</bold>
                        </p>
                        <p>UnitedHealth Group reported total cyberattack costs of $2.87 billion for 2024, broken down as follows:</p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>$1.521 billion in direct response costs (forensics, system restoration, notifications)&#x00a0;+&#x00a0;$22 million ransom payment + $9 billion in provider advances + legal fees and regulatory costs&#x00a0;=&#x00a0;$2.87 billion in total reported costs for 2024</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>This figure does not account for the broader economic harm to the healthcare system, including the $6.3 billion drop in claims submissions in just the first three weeks, revenue losses suffered by 94% of U.S. hospitals, or the long-term costs of ongoing litigation and regulatory penalties.</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>6.</label>
                        <p>

                            <bold>Best practices/mitigation</bold>
                        </p>
                        <list list-type="bullet">
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Enforce multi-factor authentication (MFA) on all remote access points, VPNs, and Citrix portals without exception. The absence of MFA on a single Citrix portal was the root cause of the Change Healthcare breach (
                                    <xref ref-type="bibr" rid="ref41">Hyperproof, 2026</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Implement network segmentation to prevent lateral movement, ensuring that an attacker who compromises one system cannot move freely across the entire network for days without detection (
                                    <xref ref-type="bibr" rid="ref26">Fliegelman &amp; Stemp, 2024</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Deploy advanced endpoint detection and response (EDR) systems with behavioral analysis capabilities to detect data exfiltration and lateral movement before ransomware is deployed. Furthermore, maintain immutable, offline backups of all critical systems and data, tested regularly for recovery readiness, to enable rapid restoration without reliance on ransom payment (
                                    <xref ref-type="bibr" rid="ref18">Cybersecurity, 2018</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Develop business continuity plans that account for extended outages of critical third-party service providers, including alternative claims processing and payment pathways (
                                    <xref ref-type="bibr" rid="ref1">AHA, 2024a</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>
Conduct regular third-party risk assessments to identify single points of failure in the healthcare supply chain, and establish redundant systems or alternative providers for critical functions (
                                    <xref ref-type="bibr" rid="ref26">Fliegelman &amp; Stemp, 2024</xref>).</p>
                            </list-item>
                            <list-item>
                                <label>&#x2022;</label>
                                <p>Use detect, protect, identify, recover, and respond framework to maintain business continuity (
                                    <xref ref-type="bibr" rid="ref18">Cybersecurity, 2018</xref>).</p>
                            </list-item>
                        </list>
                    </list-item>
                    <list-item>
                        <label>7.</label>
                        <p>

                            <bold>Diagrammatic representation of case study</bold>
                        </p>
                        <p>The above 
                            <xref ref-type="fig" rid="f9">
Figure 9</xref> reflects the diagrammatic representation of how credential compromise leads to data breach and ransomware infection, causing disruptions in the national healthcare systems.</p>
                        <p>

                            <bold>Key terms and definitions</bold>
                        </p>
                        <p>The following 
                            <xref ref-type="table" rid="T16">
Table 16</xref> reflects the key terms, which have been used throughout this case study. Each definition is written in plain language for easy understanding.</p>
                    </list-item>
                </list>
            </p>
            <table-wrap id="T15" orientation="portrait" position="float">
                <label>
Table 15. </label>
                <caption>
                    <title>Overall risk evaluation for the case study &#x201c;Cybersecurity case study ransomware attack on change healthcare&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">Factor</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">Rating</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Explanation</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Likelihood</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">High</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Healthcare has been one of the most targeted sectors for ransomware attacks. Between 2020 and 2024, healthcare data breaches increased year over year, with 2024 seeing breaches affecting over 289 million individuals (
                                <xref ref-type="bibr" rid="ref3">Alder, 2026</xref>).</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Impact</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">An estimated 190 million individuals had their data compromised, 94% of U.S. hospitals experienced financial repercussions, and total costs exceeded $2.87 billion. The attack disrupted the entire U.S. healthcare payment ecosystem.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="top">Overall Risk</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Critical</td>
                            <td align="left" colspan="1" rowspan="1" valign="top">Change Healthcare&#x2019;s role as a single point of failure in the healthcare system means that a single breach can paralyze claims processing, eligibility verification, and payments for the majority of U.S. healthcare providers (
                                <xref ref-type="bibr" rid="ref26">Fliegelman &amp; Stemp, 2024</xref>).</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <fig fig-type="figure" id="f9" orientation="portrait" position="float">
                <label>
Figure 9. </label>
                <caption>
                    <title>Cybersecurity case study ransomware attack on change healthcare- The figure reflects the diagrammatic representation of how credential compromise leads to data breach and ransomware infection, causing disruptions in the national healthcare systems.</title>
                </caption>
                <graphic id="gr9" orientation="portrait" position="float" xlink:href="https://f1000research-files.f1000.com/manuscripts/198681/0b9928f6-acd6-4a3f-9bb6-b8b9ad2aa595_figure9.gif"/>
            </fig>
            <table-wrap id="T16" orientation="portrait" position="float">
                <label>
Table 16. </label>
                <caption>
                    <title>Key terms used in the case study &#x201c;cybersecurity case study ransomware attack on change Healthcare&#x201d;.</title>
                </caption>
                <table content-type="article-table" frame="hsides">
                    <thead>
                        <tr>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Term</th>
                            <th align="left" colspan="1" rowspan="1" valign="top">
Definition</th>
                        </tr>
                    </thead>
                    <tbody>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Ransomware</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A type of malicious software that encrypts a victim&#x2019;s files or systems and demands a payment (ransom) to restore access. If the ransom is not paid, the attacker may delete the data or publish it online.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>ALPHV/blackCat</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A Russian-linked ransomware group that operates a ransomware-as-a-service (RaaS) platform, providing tools to affiliates who carry out attacks. They were responsible for the Change Healthcare breach.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Multi-factor authentication (MFA)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A security method that requires users to verify their identity using two or more forms of proof before accessing a system, such as a password plus a code sent to their phone.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Protected health information (PHI)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Any health-related information that can be linked to a specific individual, including medical records, diagnoses, treatment histories, and insurance details. PHI is protected under HIPAA regulations.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Personally identifiable information (PII)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">Any data that can be used to identify a specific person, such as a name, address, date of birth, Social Security number, or email address.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>HIPAA (health insurance portability and accountability act)</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A U.S. federal law that sets standards for protecting sensitive patient health information. Organizations that handle PHI must implement security safeguards and report data breaches.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Data exfiltration</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">The unauthorized transfer of data from a computer or network by an attacker to an external location under the attacker&#x2019;s control.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Single point of failure</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A component in a system that, if it fails, will cause the entire system to stop working. In this case, Change Healthcare was a single point of failure for U.S. healthcare payments.</td>
                        </tr>
                        <tr>
                            <td align="left" colspan="1" rowspan="1" valign="middle">
                                <bold>Exit scam</bold>
</td>
                            <td align="left" colspan="1" rowspan="1" valign="middle">A fraudulent scheme in which a criminal group collects a ransom payment but does not fulfill its promise (such as deleting stolen data), instead disappearing with the money.</td>
                        </tr>
                    </tbody>
                </table>
            </table-wrap>
            <sec id="sec15">
                <title>Ethical considerations</title>
                <p>This study does not involve human subjects, collect personal data collection, or any form of intervention. All case studies presented in this work are based on publicly available information, open-source reports, and illustrative hypothetical scenarios created for educational purposes. No identifiable student data, teacher data, or institutional records were used. Because the research relies solely on secondary sources and constructed examples designed to build cyber awareness among Grades 9&#x2013;12 students, formal ethics approval and informed consent were not required.</p>
            </sec>
        </sec>
    </body>
    <back>
        <sec id="sec18" sec-type="data-availability">
            <title>Data availability</title>
            <p>No data was generated or analyzed in this study. The work is based on publicly available information and illustrative case-study examples used solely for educational purposes.</p>
        </sec>
        <ref-list>
            <title>References</title>
            <ref id="ref1">
                <mixed-citation publication-type="other">
                    <collab>AHA</collab>:
                    <article-title>Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field.</article-title>
                    <year>2024a</year>
                    <ext-link ext-link-type="uri" xlink:href="https://www.aha.org/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref2">
                <mixed-citation publication-type="other">
                    <collab>AHA</collab>:
                    <article-title>AHA Survey: Change Healthcare Cyberattack Significantly Disrupts Patient Care, Hospitals&#x2019; Finances.</article-title>
                    <year>2024b, March 15</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.aha.org/2024-03-15-aha-survey-change-healthcare-cyberattack-significantly-disrupts-patient-care-hospitals-finances">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref3">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Alder</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Healthcare Data Breach Statistics &#x2013; Updated for 2026.</article-title>
                    <source>

                        <italic toggle="yes">The HIPAA Journal.</italic>
</source>
                    <year>2026, February 26</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.hipaajournal.com/healthcare-data-breach-statistics/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref4">
                <mixed-citation publication-type="other">
                    <collab>Arctic Wolf</collab>:
                    <article-title>The Top 10 Manufacturing Industry Cyber Attacks.</article-title>
                    <year>2026, January 22</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://arcticwolf.com/resources/blog/top-8-manufacturing-industry-cyberattacks/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref5">
                <mixed-citation publication-type="other">
                    <collab>BBC News</collab>:
                    <article-title>JLR hack could see thousands laid off - MP.</article-title>
                    <year>2025a, September 17</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bbc.com/news/articles/cwyrqxj3eqqo">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref6">
                <mixed-citation publication-type="other">
                    <collab>BBC News</collab>:
                    <article-title>JLR hack is costliest cyber attack in UK history, say analysts.</article-title>
                    <year>2025b, October 22</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bbc.com/news/articles/cy9pdld4y81o">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref7">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Beerman</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Berent</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Falter</surname>
                            <given-names>Z</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A review of colonial pipeline ransomware attack.</chapter-title>
                    <source>

                        <italic toggle="yes">2023 IEEE/ACM 23rd international symposium on cluster, cloud and internet computing workshops (CCGridW).</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2023, May</year>; pp.<fpage>8</fpage>&#x2013;<lpage>15</lpage>.</mixed-citation>
            </ref>
            <ref id="ref8">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Bostrom</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Anselin</surname>
                            <given-names>L</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Farris</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>Visualizing seismic risk and uncertainty: A review of related research.</article-title>
                    <source>

                        <italic toggle="yes">Ann. N. Y. Acad. Sci.</italic>
</source>
                    <year>2008</year>;<volume>1128</volume>(<issue>1</issue>):<fpage>29</fpage>&#x2013;<lpage>40</lpage>.</mixed-citation>
            </ref>
            <ref id="ref9">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Burgess</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">22 A Cyberattack on Jaguar Land Rover Is Causing a Supply Chain Disaster.</italic>
</source>
                    <publisher-name>Wired</publisher-name>;<year>2025, September</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.wired.com/story/jlr-jaguar-land-rover-cyberattack-supply-chain-disaster/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref10">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cervini</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Rubin</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Watkins</surname>
                            <given-names>L</given-names>
                        </name>
</person-group>:
                    <article-title>Don&#x2019;t drink the cyber: Extrapolating the possibilities of Oldsmar&#x2019;s water treatment cyberattack.</article-title>
                    <source>

                        <italic toggle="yes">
                            <italic toggle="yes">International Conference on Cyber Warfare and Security.</italic>
                        </italic>
</source>
                    <year>2022</year>;<volume>17</volume>(<issue>1</issue>):<fpage>19</fpage>&#x2013;<lpage>25</lpage>.
                    <pub-id pub-id-type="doi">10.34190/iccws.17.1.29</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref11">
                <mixed-citation publication-type="other">
                    <collab>CISA</collab>:
                    <article-title>Compromise of U.S. water treatment facilities. Cybersecurity and Infrastructure Security Agency CISA.</article-title>
                    <year>2021a</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-042a">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref12">
                <mixed-citation publication-type="book">
                    <collab>CISA</collab>:
                    <source>

                        <italic toggle="yes">DarkSide ransomware: Best practices for preventing business disruption from ransomware attacks.</italic>
</source>
                    <publisher-name>Cybersecurity and Infrastructure Security Agency CISA</publisher-name>;<year>2021b</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref13">
                <mixed-citation publication-type="book">
                    <collab>CISA</collab>:
                    <source>

                        <italic toggle="yes">Food and agriculture cybersecurity checklist and resources.</italic>
</source>
                    <publisher-name>Cybersecurity and Infrastructure Security Agency</publisher-name>;<year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.cisa.gov/resources-tools/resources/food-and-agriculture-cybersecurity-checklist-and-resources">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref14">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cremer</surname>
                            <given-names>F</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Sheehan</surname>
                            <given-names>B</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Fortmann</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Cyber risk and cybersecurity: a systematic review of data availability.</article-title>
                    <source>

                        <italic toggle="yes">The Geneva Papers on Risk and Insurance Issues and Practice.</italic>
</source>
                    <year>2022</year>;<volume>47</volume>(<issue>3</issue>):<fpage>698</fpage>&#x2013;<lpage>736</lpage>.
                    <pub-id pub-id-type="doi">10.1057/s41288-022-00266-6</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref15">
                <mixed-citation publication-type="other">
                    <collab>Cyber Defense Magazine</collab>:<year>2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.cyberdefensemagazine.com/2000-computers-at-colorado-dot-were-infected-with-the-samsam-ransomware/&#x201d;">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref16">
                <mixed-citation publication-type="other">
                    <collab>Cybercraft</collab>:<year>2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://cyberkrafttraining.com/wp-content/uploads/2022/06/Colorado-DOT-Lessons-Learned.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref17">
                <mixed-citation publication-type="other">
                    <collab>Cyber-Plan</collab>:
                    <article-title>The impact of the cyber attack on Duvel Moortgat brewery.</article-title>
                    <year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://cyber-plan.com/en/articles/the-impact-of-the-cyber-attack-on-duvel-moortgat-brewery/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref18">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Cybersecurity</surname>
                            <given-names>CI</given-names>
                        </name>
</person-group>:
                    <article-title>Framework for improving critical infrastructure cybersecurity.</article-title>
                    <year>2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://nvlpubs.nist.gov/nistpubs/cswp/nist.cswp.04162018.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref19">
                <mixed-citation publication-type="book">
                    <collab>DOE</collab>:
                    <source>

                        <italic toggle="yes">Colonial Pipeline cyber incident.</italic>
</source>
                    <publisher-name>U.S. Department Of Energy</publisher-name>;<year>2021</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.energy.gov/ceser/colonial-pipeline-cyber-incident">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref20">
                <mixed-citation publication-type="other">
                    <collab>EASA</collab>:
                    <article-title>Opinion on Management of information security risks.</article-title>
                    <year>2021</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.easa.europa.eu/en/newsroom-and-events/press-releases/easa-publishes-opinion-management-information-security-risks">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref21">
                <mixed-citation publication-type="book">
                    <collab>EPA</collab>:
                    <source>

                        <italic toggle="yes">EPA cybersecurity for the water sector.</italic>
</source>
                    <publisher-name>US Environmental Protection Agency (EPA)</publisher-name>;<year>2020, December 23</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref22">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Erkan-Barlow</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ngo</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Goel</surname>
                            <given-names>R</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>An in-depth analysis of the impact of cyberattacks on the profitability of commercial banks in the United States.</article-title>
                    <source>

                        <italic toggle="yes">Journal of Global Business Insights.</italic>
</source>
                    <year>2023</year>.<volume>8</volume>(<issue>2</issue>):<fpage>120</fpage>&#x2013;<lpage>135</lpage>.
                    <pub-id pub-id-type="doi">10.5038/2640-6489.8.2.1246</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref23">
                <mixed-citation publication-type="other">
                    <collab>European Union Aviation Safety Agency (EASA)</collab>:
                    <article-title>Safety Information Bulletin.</article-title>
                    <year>2023</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.ainonline.com/aviation-news/business-aviation/2023-11-07/easa-updates-gnss-interference-advice">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref24">
                <mixed-citation publication-type="other">
                    <collab>FBI</collab>:
                    <article-title>A Case Study of the Capital One Data Breach.</article-title>
                    <year>2019</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://cams.mit.edu/wp-content/uploads/capitalonedatapaper.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref25">
                <mixed-citation publication-type="book">
                    <collab>FBI</collab>:
                    <source>

                        <italic toggle="yes">Ransomware attacks on agricultural cooperatives (Private Industry Notification PIN-20220420-001).</italic>
</source>
                    <publisher-name>Federal Bureau of Investigation</publisher-name>;<year>2022</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.ic3.gov/CSA/2022/220420-2.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref26">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Fliegelman</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Stemp</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">The Cyberattack on Change Healthcare:Lessons for Financial Stability (OFR Brief Series 24&#x2013;05).</italic>
</source>
                    <publisher-name>Office of Financial Research, U.S. Department of the Treasury</publisher-name>;<year>2024 November 13</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.financialresearch.gov/briefs/files/OFRBrief-24-05-change-healthcare-cyberattack.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref27">
                <mixed-citation publication-type="other">
                    <collab>Framework for Improving Critical Infrastructure</collab>:
                    <ext-link ext-link-type="uri" xlink:href="https://www.nitrd.gov/nitrdgroups/images/6/66/Cybersecurity_Framework_03222018.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref28">
                <mixed-citation publication-type="other">
                    <collab>GAO (Government Accountability Office)</collab>:
                    <article-title>GPS Disruptions.</article-title>
                    <year>2021</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.gao.gov/assets/gao-21-145.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref29">
                <mixed-citation publication-type="other">
                    <collab>GAO (Government Accountability Office)</collab>:
                    <article-title>Critical Infrastructure Protection.</article-title>
                    <year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.gao.gov/assets/d24106221.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref30">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gatlan</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Duvel says it has "more than enough" beer after ransomware attack.</italic>
</source>
                    <publisher-name>BleepingComputer</publisher-name>;<year>2024, March 6</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bleepingcomputer.com/news/security/duvel-says-it-has-more-than-enough-beer-after-ransomware-attack/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref31">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Gatlan</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Jaguar Land Rover confirms data theft after recent cyberattack.</article-title>
                    <year>2025, September 3</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bleepingcomputer.com/news/security/jaguar-land-rover-jlr-confirms-data-theft-after-recent-cyberattack/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref32">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Ghanbari</surname>
                            <given-names>H</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Koskinen</surname>
                            <given-names>K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wei</surname>
                            <given-names>Y</given-names>
                        </name>
</person-group>:
                    <article-title>From SolarWinds to Kaseya: The rise of supply chain attacks in a digital world.</article-title>
                    <source>

                        <italic toggle="yes">J. Inf. Technol. Teach. Cases.</italic>
</source>
                    <year>2024</year>;<fpage>20438869241299823</fpage>.
                    <pub-id pub-id-type="doi">10.1177/20438869241299823</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref33">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Goodell</surname>
                            <given-names>JW</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Corbet</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Commodity market exposure to energy-firm distress: Evidence from the Colonial Pipeline ransomware attack.</article-title>
                    <source>

                        <italic toggle="yes">Financ. Res. Lett.</italic>
</source>
                    <year>2023</year>.<volume>51</volume>(<issue>103329</issue>):<fpage>103329</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.frl.2022.103329</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref34">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Greig</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>A strumous ransomware gang takes credit for the attack on Belgian brewer Duvel.</article-title>
                    <source>

                        <italic toggle="yes">The Record.</italic>
</source>
                    <year>2024, March 7</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://therecord.media/stormous-claims-duvel-beer-attack">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref35">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Healthcare</surname>
                            <given-names>IT</given-names>
                        </name>
</person-group>:
                    <article-title>The Cost of Change Healthcare Ransomware Attack to Reach $2.87bn in 2024.</article-title>
                    <year>2024</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.healthcareit.tech/the-cost-of-change-healthcare-ransomware-attack-to-reach-2-87bn-in-2024/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref36">
                <mixed-citation publication-type="other">
                    <collab>ICAO Annex 10 &#x2013; Aeronautical Telecommunications</collab>:
                    <ext-link ext-link-type="uri" xlink:href="https://www.icao.int/sites/default/files/postalhistory/annex_10_aeronautical_telecommunications.htm">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref37">
                <mixed-citation publication-type="other">
                    <collab>Colorado DOT offers lessons learned after recovering from two 2018 ransomware attacks</collab>:
                    <ext-link ext-link-type="uri" xlink:href="https://www.itskrs.its.dot.gov/2019-l00856">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref38">
                <mixed-citation publication-type="other">
                    <collab>NTSB Lessons Learned and Lives Saved</collab>:
                    <ext-link ext-link-type="uri" xlink:href="https://www.ntsb.gov/safety/safety-studies/Documents/SR0601.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref39">
                <mixed-citation publication-type="other">
                    <collab>Office of the Comptroller of the Currency</collab>:<year>2020</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref40">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Humphreys</surname>
                            <given-names>TE</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Ledvina</surname>
                            <given-names>BM</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Psiaki</surname>
                            <given-names>ML</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Assessing the spoofing threat: Development of a portable GPS civilian spoofer.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of the 21st International technical meeting of the satellite division of the institute of navigation (ION GNSS 2008).</italic>
</source>
                    <year>2008, September</year>; pp.<fpage>2314</fpage>&#x2013;<lpage>2325</lpage>.</mixed-citation>
            </ref>
            <ref id="ref41">
                <mixed-citation publication-type="book">
                    <collab>Hyperproof Team</collab>:
                    <source>

                        <italic toggle="yes">Understanding the Change Healthcare breach and its impact on security compliance.</italic>
</source>
                    <publisher-name>Hyperproof</publisher-name>;<year>2026, February 24</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://hyperproof.io/resource/understanding-the-change-healthcare-breach/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref42">
                <mixed-citation publication-type="other">
                    <collab>IBM Security</collab>:
                    <article-title>Cost of a Data Breach Report.</article-title>
                    <year>2023</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://d110erj175o600.cloudfront.net/wp-content/uploads/2023/07/25111651/Cost-of-a-Data-Breach-Report-2023.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref43">
                <mixed-citation publication-type="other">
                    <collab>ICAO (International Civil Aviation Organization)</collab>:
                    <article-title>Resolution A41&#x2013;19: Addressing Cybersecurity in Civil Aviation.</article-title>
                    <year>2022</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.icao.int/sites/default/files/sp-files/aviationcybersecurity/Documents/A41-19.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref44">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>James</surname>
                            <given-names>W</given-names>
                        </name>
</person-group>:
                    <article-title>8 recent cyber attacks on food production and agriculture.</article-title>
                    <source>

                        <italic toggle="yes">Wisdiam.</italic>
</source>
                    <year>2024, October 6</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://wisdiam.com/publications/recent-cyber-attacks-food-agriculture-sector/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref45">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Jones</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">The Bank of England says JLR's cyberattack contributed to the UK's unexpectedly slower GDP growth.</italic>
</source>
                    <publisher-name>The Register</publisher-name>;<year>2025, November 7</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.theregister.com/2025/11/07/bank_of_england_says_jlrs/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref46">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kamiya</surname>
                            <given-names>S</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kang</surname>
                            <given-names>J-K</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Kim</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Risk management, firm reputation, and the impact of successful cyberattacks on target firms.</article-title>
                    <source>

                        <italic toggle="yes">J. Financ. Econ.</italic>
</source>
                    <year>2021</year>.<volume>139</volume>(<issue>3</issue>):<fpage>719</fpage>&#x2013;<lpage>749</lpage>.
                    <pub-id pub-id-type="doi">10.1016/j.jfineco.2019.05.019</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref47">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kerns</surname>
                            <given-names>AJ</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shepard</surname>
                            <given-names>DP</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bhatti</surname>
                            <given-names>JA</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Unmanned aircraft capture and control via GPS spoofing.</article-title>
                    <source>

                        <italic toggle="yes">Journal of field robotics.</italic>
</source>
                    <year>2014</year>;<volume>31</volume>(<issue>4</issue>):<fpage>617</fpage>&#x2013;<lpage>636</lpage>.</mixed-citation>
            </ref>
            <ref id="ref48">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Kulkarni</surname>
                            <given-names>A</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Gopinath</surname>
                            <given-names>M</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A review of cybersecurity incidents in the food and agriculture sector.</article-title>
                    <source>

                        <italic toggle="yes">J. Agric. Food Res.</italic>
</source>
                    <year>2025</year>;<fpage>102245</fpage>.</mixed-citation>
            </ref>
            <ref id="ref49">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Lee</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Guzman</surname>
                            <given-names>MC</given-names>
                            <prefix>de</prefix>
                        </name>

                        <name name-style="western">
                            <surname>Wang</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>Investigating perceptions about risk of data breaches in financial institutions: A routine activity-approach.</article-title>
                    <source>

                        <italic toggle="yes">Comput. Secur.</italic>
</source>
                    <year>2022</year>;<volume>121</volume>(<issue>102832</issue>):<fpage>102832</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.cose.2022.102832</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref50">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Babar</surname>
                            <given-names>MA</given-names>
                        </name>
</person-group>:
                    <article-title>Corporate cybersecurity risk and data breaches: A systematic review of empirical research.</article-title>
                    <source>

                        <italic toggle="yes">Aust. J. Manag.</italic>
</source>
                    <year>2026</year>;<volume>51</volume>(<issue>1</issue>):<fpage>62</fpage>&#x2013;<lpage>92</lpage>.
                    <pub-id pub-id-type="doi">10.1177/03128962241293658</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref51">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mascellino</surname>
                            <given-names>A</given-names>
                        </name>
</person-group>:
                    <source>

                        <italic toggle="yes">Flagstar bank MOVEit breach affects 800K customer records.</italic>
</source>
                    <publisher-name>Infosecurity Magazine</publisher-name>;<year>2023</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.infosecurity-magazine.com/news/flagstar-bank-moveit-breach/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref52">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>McCallie</surname>
                            <given-names>D</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Butts</surname>
                            <given-names>J</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Mills</surname>
                            <given-names>R</given-names>
                        </name>
</person-group>:
                    <article-title>Security analysis of the ADS-B implementation in the next generation air transportation system.</article-title>
                    <source>

                        <italic toggle="yes">Int. J. Crit. Infrastruct. Prot.</italic>
</source>
                    <year>2011</year>;<volume>4</volume>(<issue>2</issue>):<fpage>78</fpage>&#x2013;<lpage>87</lpage>.</mixed-citation>
            </ref>
            <ref id="ref53">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Milmo</surname>
                            <given-names>D</given-names>
                        </name>
</person-group>:
                    <article-title>Hackers linked to M&amp;S breach claim responsibility for Jaguar Land Rover cyber-attack.</article-title>
                    <source>

                        <italic toggle="yes">The Guardian.</italic>
</source>
                    <year>2025, September 3</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.theguardian.com/business/2025/sep/03/hacking-group-linked-to-marks-and-spencer-cyber-attack-claim-responsibility-for-jaguar-land-rover-hack">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref54">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Mittal</surname>
                            <given-names>M</given-names>
                        </name>
</person-group>:
                    <article-title>Colonial Pipeline cyberattack drives urgent reforms in cybersecurity and critical infrastructure resilience.</article-title>
                    <source>

                        <italic toggle="yes">International Journal of Oil Gas and Coal Engineering.</italic>
</source>
                    <year>2024</year>;<volume>12</volume>(<issue>5</issue>):<fpage>106</fpage>&#x2013;<lpage>119</lpage>.
                    <pub-id pub-id-type="doi">10.11648/j.ogce.20241205.11</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref55">
                <mixed-citation publication-type="book">
                    <collab>NIST</collab>:
                    <source>

                        <italic toggle="yes">Cybersecurity framework.</italic>
</source>
                    <publisher-name>NIST</publisher-name>;<year>2018a</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.nist.gov/cyberframework">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref56">
                <mixed-citation publication-type="book">
                    <collab>NIST</collab>:
                    <source>

                        <italic toggle="yes">Cybersecurity framework.</italic>
</source>
                    <publisher-name>NIST</publisher-name>;<year>2018b</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.nist.gov/cyberframework">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref57">
                <mixed-citation publication-type="book">
                    <collab>NIST</collab>:
                    <source>

                        <italic toggle="yes">Framework for improving critical infrastructure cybersecurity, version 1.1.</italic>
</source>
                    <publisher-name>National Institute of Standards and Technology</publisher-name>;<year>2018c</year>.
                    <pub-id pub-id-type="doi">10.6028/nist.cswp.04162018</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref58">
                <mixed-citation publication-type="book">
                    <collab>NIST</collab>:
                    <source>

                        <italic toggle="yes">Framework for Improving Critical Infrastructure Cybersecurity, version 1.1.</italic>
</source>
                    <publisher-name>National Institute of Standards and Technology</publisher-name>;<year>2018d</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://nvlpubs.nist.gov/nistpubs/cswp/nist.cswp.04162018.pdf">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref59">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Pearson</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>Jaguar Land Rover hack cost UK economy an estimated $2.5 billion, report says.</article-title>
                    <year>2025, October 22</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.reuters.com/sustainability/boards-policy-regulation/jaguar-land-rover-hack-cost-uk-economy-25-billion-report-says-2025-10-22/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref60">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Raghuprasad</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:
                    <article-title>GhostSec's joint ransomware operation and evolution of their arsenal.</article-title>
                    <source>

                        <italic toggle="yes">Cisco Talos Blog.</italic>
</source>
                    <year>2024, March 5</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://blog.talosintelligence.com/ghostsec-ghostlocker2-ransomware/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref61">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Sch&#x00e4;fer</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Strohmeier</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lenders</surname>
                            <given-names>V</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>Bringing up OpenSky: A large-scale ADS-B sensor network for research.</chapter-title>
                    <source>

                        <italic toggle="yes">IPSN-14 proceedings of the 13th international symposium on information processing in sensor networks.</italic>
</source>
                    <publisher-name>IEEE</publisher-name>;<year>2014, April</year>; pp.<fpage>83</fpage>&#x2013;<lpage>94</lpage>.</mixed-citation>
            </ref>
            <ref id="ref62">
                <mixed-citation publication-type="other">
                    <collab>Shepard, Cybersecurity Incident Databse</collab>:<year>Feb, 2018</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.csidb.net/csidb/incidents/650dee5c-1331-4cc3-b49b-5a55889632d5">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref63">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Shepard</surname>
                            <given-names>DP</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Bhatti</surname>
                            <given-names>JA</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Humphreys</surname>
                            <given-names>TE</given-names>
                        </name>
</person-group>:
                    <article-title>Drone hack. Gps.</article-title>
                    <source>

                        <italic toggle="yes">World.</italic>
</source>
                    <year>2012</year>;<volume>23</volume>(<issue>8</issue>):<fpage>30</fpage>&#x2013;<lpage>33</lpage>.</mixed-citation>
            </ref>
            <ref id="ref64">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Strohmeier</surname>
                            <given-names>M</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Martinovic</surname>
                            <given-names>I</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Lenders</surname>
                            <given-names>V</given-names>
                        </name>
</person-group>:
                    <chapter-title>Securing the air&#x2013;ground link in aviation.</chapter-title>
                    <source>

                        <italic toggle="yes">The Security of Critical Infrastructures: Risk, Resilience and Defense.</italic>
</source>
                    <publisher-loc>Cham</publisher-loc>:
                    <publisher-name>Springer International Publishing</publisher-name>;<year>2020</year>; pp.<fpage>131</fpage>&#x2013;<lpage>154</lpage>.</mixed-citation>
            </ref>
            <ref id="ref65">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tsvetanov</surname>
                            <given-names>T</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Slaria</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>The effect of the Colonial Pipeline shutdown on gasoline prices.</article-title>
                    <source>

                        <italic toggle="yes">Econ. Lett.</italic>
</source>
                    <year>2021</year>;<volume>209</volume>(<issue>110122</issue>):<fpage>110122</fpage>.
                    <pub-id pub-id-type="doi">10.1016/j.econlet.2021.110122</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref66">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Tuptuk</surname>
                            <given-names>N</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Hazell</surname>
                            <given-names>P</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Watson</surname>
                            <given-names>J</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <article-title>A systematic review of the state of cyber-security in water systems.</article-title>
                    <source>

                        <italic toggle="yes">Water.</italic>
</source>
                    <year>2021</year>;<volume>13</volume>(<issue>1</issue>):<fpage>81</fpage>.
                    <pub-id pub-id-type="doi">10.3390/w13010081</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref67">
                <mixed-citation publication-type="other">
                    <collab>U.S. Department of Justice</collab>:
                    <article-title>Capital One hacker charged with data breach affecting over 100 million people.</article-title>
                    <year>2019</year>.</mixed-citation>
            </ref>
            <ref id="ref68">
                <mixed-citation publication-type="book">
                    <collab>UK Government</collab>:
                    <source>

                        <italic toggle="yes">Joint statement on government-industry supplier meeting regarding Jaguar Land Rover cyber incident.</italic>
</source>
                    <publisher-name>GOV.UK</publisher-name>;<year>2025, September 19</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/news/joint-statement-on-government-industry-supplier-meeting-regarding-jaguar-land-rover-cyber-incident">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref69">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vallance</surname>
                            <given-names>C</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Leggett</surname>
                            <given-names>T</given-names>
                        </name>
</person-group>:
                    <article-title>Jaguar Land Rover production severely hit by cyber-attack.</article-title>
                    <source>

                        <italic toggle="yes">BBC News.</italic>
</source>
                    <year>2025, September 2</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.bbc.com/news/articles/c9wywvllq7wo">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref70">
                <mixed-citation publication-type="book">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Vasquez</surname>
                            <given-names>C</given-names>
                        </name>
</person-group>:<year>2023</year>.
                    <source>

                        <italic toggle="yes">Did someone really hack into the Oldsmar, Florida, water treatment plant? New details suggest maybe not.</italic>
</source>
                    <publisher-name>CyberScoop</publisher-name>;
                    <ext-link ext-link-type="uri" xlink:href="https://cyberscoop.com/water-oldsmar-incident-cyberattack/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref71">
                <mixed-citation publication-type="book">
                    <collab>Workgroup, G. S</collab>:
                    <source>

                        <italic toggle="yes">GPS spoofing: Final report of the GPS spoofing workgroup.</italic>
</source>
                    <publisher-loc>London, UK</publisher-loc>:
                    <publisher-name>GPS Spoofing WorkGroup</publisher-name>;<year>2024</year>.</mixed-citation>
            </ref>
            <ref id="ref72">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>You</surname>
                            <given-names>J</given-names>
                        </name>
</person-group>:
                    <article-title>Strengthening cybersecurity of water infrastructure through legislative actions.</article-title>
                    <source>

                        <italic toggle="yes">J. Am. Water Resour. Assoc.</italic>
</source>
                    <year>2022</year>;<volume>58</volume>(<issue>2</issue>):<fpage>282</fpage>&#x2013;<lpage>288</lpage>.
                    <pub-id pub-id-type="doi">10.1111/1752-1688.12995</pub-id>
                </mixed-citation>
            </ref>
            <ref id="ref73">
                <mixed-citation publication-type="journal">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Young</surname>
                            <given-names>S</given-names>
                        </name>
</person-group>:
                    <article-title>Jaguar Land Rover cyberattack shutdown to hit four weeks.</article-title>
                    <source>

                        <italic toggle="yes">The Irish Times.</italic>
</source>
                    <year>2025, September 23</year>.
                    <ext-link ext-link-type="uri" xlink:href="https://www.irishtimes.com/business/2025/09/23/jaguar-land-rover-cyberattack-shutdown-to-hit-four-weeks/">Reference Source</ext-link>
                </mixed-citation>
            </ref>
            <ref id="ref74">
                <mixed-citation publication-type="other">
                    <person-group person-group-type="author">

                        <name name-style="western">
                            <surname>Zeng</surname>
                            <given-names>KC</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Shu</surname>
                            <given-names>Y</given-names>
                        </name>

                        <name name-style="western">
                            <surname>Liu</surname>
                            <given-names>S</given-names>
                        </name>

                        <etal/>
</person-group>:
                    <chapter-title>A practical GPS location spoofing attack in road navigation scenario.</chapter-title>
                    <source>

                        <italic toggle="yes">Proceedings of the 18th international workshop on mobile computing systems and applications.</italic>
</source>
                    <year>2017, February</year>; pp.<fpage>85</fpage>&#x2013;<lpage>90</lpage>.</mixed-citation>
            </ref>
        </ref-list>
    </back>
</article>
