Skip to main navigation Skip to search Skip to main content

Empowering End-Users with Cybersecurity Situational Awareness: Findings from IoT-Health Table-Top Exercises

Research output: Contribution to journalArticleResearchpeer-review

Abstract

End-users in a decision-oriented Internet of Things (IoT) healthcare system are often left in the dark regarding critical security information necessary for making informed decisions about potential risks. This is partly due to the lack of transparency and system security awareness end-users have in such systems. To empower end-users and enhance their cybersecurity situational awareness, it is imperative to thoroughly document and report the runtime security controls in place, as well as the security-relevant aspects of the devices they rely on, while the need for better transparency is obvious, it remains uncertain whether current systems offer adequate security metadata for end-users and how future designs can be improved to ensure better visibility into the security measures implemented. To address this gap, we conducted table-top exercises with ten security and ICT experts to evaluate a typical IoT-Health scenario. These exercises revealed the critical role of security metadata, identified the available ones to be presented to users, and suggested potential enhancements that could be integrated into system design. We present our observations from the exercises, highlighting experts’ valuable suggestions, concerns, and views, backed by our in-depth analysis. Moreover, as a proof-of-concept of our study, we simulated three relevant use cases to detect cyber risks. This comprehensive analysis underscores critical considerations that can significantly improve future system protocols, ensuring end-users are better equipped to navigate and mitigate security risks effectively.

Original languageEnglish
Article number49
Number of pages18
JournalJournal of Cybersecurity and Privacy
Volume5
Issue number3
DOIs
Publication statusPublished - 25 Jul 2025

Keywords

  • awareness Internet of Things-Health
  • cybersecurity
  • security metadata
  • situational

Cite this