Abstract
End-users in a decision-oriented Internet of Things (IoT) healthcare system are often left in the dark regarding critical security information necessary for making informed decisions about potential risks. This is partly due to the lack of transparency and system security awareness end-users have in such systems. To empower end-users and enhance their cybersecurity situational awareness, it is imperative to thoroughly document and report the runtime security controls in place, as well as the security-relevant aspects of the devices they rely on, while the need for better transparency is obvious, it remains uncertain whether current systems offer adequate security metadata for end-users and how future designs can be improved to ensure better visibility into the security measures implemented. To address this gap, we conducted table-top exercises with ten security and ICT experts to evaluate a typical IoT-Health scenario. These exercises revealed the critical role of security metadata, identified the available ones to be presented to users, and suggested potential enhancements that could be integrated into system design. We present our observations from the exercises, highlighting experts’ valuable suggestions, concerns, and views, backed by our in-depth analysis. Moreover, as a proof-of-concept of our study, we simulated three relevant use cases to detect cyber risks. This comprehensive analysis underscores critical considerations that can significantly improve future system protocols, ensuring end-users are better equipped to navigate and mitigate security risks effectively.
| Original language | English |
|---|---|
| Article number | 49 |
| Number of pages | 18 |
| Journal | Journal of Cybersecurity and Privacy |
| Volume | 5 |
| Issue number | 3 |
| DOIs | |
| Publication status | Published - 25 Jul 2025 |
Keywords
- awareness Internet of Things-Health
- cybersecurity
- security metadata
- situational
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver