A Conceptual Framework to Illustrate Cybersecurity Workforce Gaps and the Resilience of Critical Digital Infrastructure—A Multi-Sector Case Study — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
A Conceptual Framework to Illustrate Cybersecurity Workforce Gaps and the Resilience of Critical Digital Infrastructure—A Multi-Sector Case Study
Global Partners LP, Waltham, MA, USA
,
Department of Business & Economic Studies, University of Gävle, Gävle, Sweden
1 Global Partners LP, Waltham, MA, USA
2 Department of Business & Economic Studies, University of Gävle, Gävle, Sweden
This study examines how cybersecurity workforce shortages undermine the resilience of critical digital infrastructure, with emphasis on the energy sector and comparisons to finance, transportation, and telecommunications. It reframes the skills gap as a systemic risk that weakens organizations’ capacity to prevent, manage, and recover from cyber incidents. Using a two‑phase qualitative approach—a PRISMA-guided literature review (n = 70) and multi‑sector case studies (n = 5) based on 22 interviews—the analysis draws on socio‑technical systems theory. Findings show that resilience is limited less by missing technical controls than by a lack of hybrid professionals who can bridge Information Technology (IT), Operational Technology (OT) and Artificial Intelligence domains. Shortages slow incident response, impede risk communication, and reduce coordination. The study concludes that workforce capability is central to infrastructure resilience, requiring sector-aligned training, interdisciplinary collaboration, and continuous upskilling. Policy measures should support cross‑sector training and educational reform. Limitations include the small qualitative sample, suggesting future global and AI‑human studies.
KeywordsCybersecurity Workforce ShortageCritical Infrastructure ResilienceSocio-Technical SystemsOperational TechnologyHybrid-Skilled ProfessionalsPRISMA Systematic Literature ReviewMulti-Sector Case Study
Allen, B., Bapst, B. and Hicks, T.A. (2023) Building a Cyber Risk Management Pro-gram: Evolving Security for the Digital Age. O’Reilly Media.
Duska, K. (2025) Critical Infrastructure-Enhancing Security for Critical Infrastructure 2025.
Malatji, M., Marnewick, A.L. and Von Solms, S. (2022) Cybersecurity Capabilities for Critical Infrastructure Resilience. Information & Computer Security , 30, 255-279. https://doi.org/10.1108/ics-06-2021-0091
Thomas, G. and Sule, M. (2023) A Service Lens on Cybersecurity Continuity and Management for Organizations’ Subsistence and Growth. Organizational Cybersecurity Journal : Practice , Process and People , 3, 18-40. https://doi.org/10.1108/ocj-09-2021-0025
Kandpal, V., Ozili, P.K., Jeyanthi, P.M., Ranjan, D. and Chandra, D. (2025) Cybersecurity and Ensuring Privacy in Digital Finance. In: Kandpal, V., Ozili, P.K., Jeyanthi, P.M., Ranjan, D. and Chandra, D., Eds., Digital Finance and Metaverse in Banking , Emerald Publishing Limited, 157-170. https://doi.org/10.1108/978-1-83662-088-420251007
Kour, R. and Karim, R. (2021) Cybersecurity Workforce in Railway: Its Maturity and Awareness. Journal of Quality in Maintenance Engineering , 27, 453-464. https://doi.org/10.1108/jqme-07-2020-0059
Baxter, G. and Sommerville, I. (2011) Socio-Technical Systems: From Design Methods to Systems Engineering. Interacting with Computers , 23, 4-17. https://doi.org/10.1016/j.intcom.2010.07.003
Whitworth, B. (2009) A Brief Introduction to Sociotechnical Systems. In: Khosrow-Pour, M., Ed., Encyclopedia of Information Science and Technology , Second Edition , IGI Global, 394-400. https://doi.org/10.4018/978-1-60566-026-4.ch066
Graham, C.M. (2025) AI Skills in Cybersecurity: Global Job Trends Analysis. Information & Computer Security , 33, 673-689. https://doi.org/10.1108/ics-09-2024-0235
Stavrou, E. and Piki, A. (2024) Cultivating Self-Efficacy to Empower Professionals’ Re-Up Skilling in Cybersecurity. Information & Computer Security , 32, 523-541. https://doi.org/10.1108/ics-02-2024-0038
U.S. Bureau of Labor Statistics (2023) Information Security Analysts. Occupational Outlook Handbook. U.S. Department of Labor.
Spruit, M. (2022) Information Security Education Based on Job Profiles and the E-CF. Higher Education , Skills and Work - Based Learning , 12, 294-308. https://doi.org/10.1108/heswbl-09-2020-0208
Haney, J.M. and Lutters, W.G. (2021) Cybersecurity Advocates: Discovering the Characteristics and Skills of an Emergent Role. Information & Computer Security , 29, 485-499. https://doi.org/10.1108/ics-08-2020-0131
Khaw, T.Y., Amran, A. and Teoh, A.P. (2024) Building a Thematic Framework of Cybersecurity: A Systematic Literature Review Approach. Journal of Systems and Information Technology , 26, 234-256. https://doi.org/10.1108/jsit-07-2023-0132
Bechara, F.R. and Schuch, S.B. (2021) Cybersecurity and Global Regulatory Challenges. Journal of Financial Crime , 28, 359-374. https://doi.org/10.1108/jfc-07-2020-0149
Haleem, A., Javaid, M., Singh, R.P., Rab, S. and Suman, R. (2022) Perspectives of Cybersecurity for Ameliorative Industry 4.0 Era: A Review-Based Framework. Industrial Robot : the international journal of robotics research and application , 49, 582-597. https://doi.org/10.1108/ir-10-2021-0243
Katsuya, R. and Liu, X. (2025) Policy and Management Implications of Firmware Vulnerabilities in Medical IoT Devices: A Multi-Case Analysis. Journal of Science and Technology Policy Management , Ahead-of-Print. https://doi.org/10.1108/jstpm-09-2024-0346
Friday, D., Melnyk, S.A., Altman, M., Harrison, N. and Ryan, S. (2024) An Inductive Analysis of Collaborative Cybersecurity Management Capabilities, Relational Antecedents and Supply Chain Cybersecurity Parameters. International Journal of Physical Distribution & Logistics Management , 54, 476-500. https://doi.org/10.1108/ijpdlm-01-2023-0034
Mumford, E. (2006) The Story of Socio‐Technical Design: Reflections on Its Successes, Failures and Potential. Information Systems Journal , 16, 317-342. https://doi.org/10.1111/j.1365-2575.2006.00221.x
Xenakis, A., Vlachos, V., Roig, P.J. and Alcaraz, S. (2025) Addressing the Necessity of Cybersecurity Literacy: The Case of ETTCS Cyberteach Project. Information & Computer Security , 33, 427-451. https://doi.org/10.1108/ics-04-2024-0095
Moher, D., Liberati, A., Tetzlaff, J. and Altman, D.G. (2009) Preferred Reporting Items for Systematic Reviews and Meta-Analyses: The PRISMA Statement. PLOS Medicine , 6, e1000097. https://doi.org/10.1371/journal.pmed.1000097
Singh, T., Johnston, A.C., D’Arcy, J. and Harms, P.D. (2023) Stress in the Cybersecurity Profession: A Systematic Review of Related Literature and Opportunities for Future Research. Organizational Cybersecurity Journal : Practice , Process and People , 3, 100-126. https://doi.org/10.1108/ocj-06-2022-0012
Bowen, P., Hash, J. and Wilson, M. (2006) Information Security Handbook: A Guide for Managers. National Institute of Standards and Technology (NIST Special Publication 800-100).
Orji, I.J. and U-Dominic, C.M. (2024) Modelling the Conundrums to Cyber-Risks Management in Logistics Firms for Supply Chain Social Sustainability. Journal of Enterprise Information Management , 37, 1885-1925. https://doi.org/10.1108/jeim-12-2023-0635
Schreiber, A. and Schreiber, I. (2024) Bridging Knowledge Gap: The Contribution of Employees’ Awareness of AI Cyber Risks Comprehensive Program to Reducing Emerging AI Digital Threats. Information & Computer Security , 32, 613-635. https://doi.org/10.1108/ics-10-2023-0199
Lawelai, H., Purnomo, E.P., Nurmandi, A., Jovita, H. and Baulete, E.M. (2025) Cybersecurity Policy on Smart City Infrastructure: A Mapping of New Threats and Protections. Journal of Science and Technology Policy Management , Ahead-of-Print. https://doi.org/10.1108/jstpm-09-2024-0359
NIST (2017) National Institute of Standards and Technology Special Publication 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations, Initial Public Draft.
Al-Hawamleh, A.M. (2024) Investigating the Multifaceted Dynamics of Cybersecurity Practices and Their Impact on the Quality of E-Government Services: Evidence from the KSA. Digital Policy , Regulation and Governance , 26, 317-336. https://doi.org/10.1108/dprg-11-2023-0168
NIST (2017) Framework for Improving Critical Infrastructure Cybersecurity, Draft Version 1.1.
Otoom, A.A., Atoum, I., Al-Harahsheh, H., Aljawarneh, M., Al Refai, M.N. and Baklizi, M. (2024) A Collaborative Cybersecurity Framework for Higher Education. Information & Computer Security , 33, 362-389. https://doi.org/10.1108/ics-02-2024-0048
Kritzinger, E. and von Solms, S.H. (2010) Cyber Security for Home Users: A New Way of Protection through Awareness Enforcement. Computers & Security , 29, 840-847. https://doi.org/10.1016/j.cose.2010.08.001
Asbaş, A.T. and Tuzlukaya, Ş. (2022) Analysis of Critical Infrastructure Resilience for Cyber-Physical Systems. Journal of Information Security and Cybercrimes Research , 5, 102-114.
Pipyros, K. and Liasidou, S. (2025) A New Cybersecurity Risk Assessment Framework for the Hospitality Industry: Techniques and Methods for Enhanced Data Protection and Threat Mitigation. Worldwide Hospitality and Tourism Themes , 17, 48-61. https://doi.org/10.1108/whatt-12-2024-0296
Yeboah-Ofori, A. and Opoku-Boateng, F.A. (2023) Mitigating Cybercrimes in an Evolving Organizational Landscape. Continuity & Resilience Review , 5, 53-78. https://doi.org/10.1108/crr-09-2022-0017
Mwogosi, A. and Simba, R. (2025) Digital Policy and Governance Frameworks for EHR Systems in Tanzania: A Scoping Review. Digital Policy , Regulation and Governance , 28, 52-74. https://doi.org/10.1108/dprg-11-2024-0289
Chen, S.P. and Redar, J.M. (2014) Ageing Workforce Knowledge Management and Transactional and Transformational Leadership: A Socio-Technical Systems Framework and a Norwegian Case Study. International Journal of Business and Social Science , 5, 11-21.
Lnenicka, M., Kysela, T. and Horák, O. (2025) Building Security and Resilience: A Guide to Implementing Effective Cybersecurity and Data Protection Measures in Smart Cities. Smart and Sustainable Built Environment , 15, 908-937. https://doi.org/10.1108/sasbe-09-2024-0363
Krishna, B., Krishnan, S. and Sebastian, M.P. (2023) Understanding the Process of Building Institutional Trust among Digital Payment Users through National Cybersecurity Commitment Trustworthiness Cues: A Critical Realist Perspective. Information Technology & People , 38, 714-756. https://doi.org/10.1108/itp-05-2023-0434
Anderson, R. and Moore, T. (2006) The Economics of Information Security. Science , 314, 610-613. https://doi.org/10.1126/science.1130992
Younies, H. and Al-Tawil, T.N. (2020) Effect of Cybercrime Laws on Protecting Citizens and Businesses in the United Arab Emirates (UAE). Journal of Financial Crime , 27, 1089-1105. https://doi.org/10.1108/jfc-04-2020-0055
Radanliev, P., De Roure, D., Van Kleek, M., Santos, O. and Ani, U. (2020) Artificial Intelligence in Cyber Physical Systems. AI & SOCIETY , 36, 783-796. https://doi.org/10.1007/s00146-020-01049-0
Rangarajan, A., Nobles, C., Dykstra, J., Cunningham, M., Robinson, N., Hollis, T., et al. (2025) A Roadmap to Address Burnout in the Cybersecurity Profession: Outcomes from a Multifaceted Workshop. In: Moallem, A., Ed., Lecture Notes in Computer Science , Springer Nature Switzerland, 125-140. https://doi.org/10.1007/978-3-031-92833-8_8
Tallam, K. (2025) The Cyber Immune System: Harnessing Adversarial Forces for Security Resilience. arXiv:2502.17698. https://arxiv.org/abs/2502.17698
Walendy, P., Koch, D. and Paar, C. (2024) A Curriculum Initiative for Hardware Reverse Engineering (HRE). In: Proceedings of the 2024 Workshop on Cybersecurity Education ( CSE ‘24). Association for Computing Machinery.
Alevizos, L. (2025) A Complexity-Informed Approach to Optimise Cyber Defences. Volvo Group. https://arxiv.org/pdf/2501.15578
Ncube, T.R., Sishi, K.K. and Skinner, J.P. (2025) The Impact of Artificial Intelligence on Human Resource Management Practices: An Investigation. SA Journal of Human Resource Management , 23, a2960. https://doi.org/10.4102/sajhrm.v23i0.2960