Computer Science · Research topic

Open research questions in Information and Cyber Security

107 unresolved questions extracted from the limitations and future-work sections of 1,710 Information and Cyber Security papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • Based on the findings of this study, several recommendations are proposed to improve information systems security in higher learning institutions. 75 CBEL Journal of Multidisciplinary Research Vol. 1 No. 1 (2026): ISSN (Online): 3108-8848 DOI: https://doi.org/10.66313/m7r6z835 Socio-Technical Analysis of the Awareness–Behaviour Gap in Higher Education Cybersecurity: Evidence from Tanzania i. ii. iii. iv. v. vi. First, institutions should implement continuous and practical cybersecurity training programs. Training should focus not only on awareness but also on real-life application, enabling users to develop the skills needed to respond to security threats effectively. Second, there is a need to strengthen policy communication and enforcement. ICT security policies should be clearly communicated, regularly updated, and actively enforced. Users should be made aware of their responsibilities and the consequences of non-compliance. Third, institutions should adopt a holistic cybersecurity approach that integrates human and technical measures. This includes combining user education with strong system controls such as access management, monitoring, and regular updates. Fourth, regular vulnerability assessments should be conducted to identify and address system weaknesses. Tools such as OWASP ZAP can be used periodically to ensure that systems remain secure against emerging threats. Fifth, institutions should promote a security-aware culture, where information security is viewed as a shared responsibility. This can be achieved through awareness campaigns, leadership support, and encouraging responsible user behaviour. Finally, future research should expand the scope of this study by including multiple institutions and applying advanced statistical techniques to further explore the relationships between awareness, behaviour, and security outcomes.

    Bridging the Awareness–Behavior Gap in Information Systems Security: Evidence from a Tanzanian Higher Learning Institution · 2026 · DOI
  • 5.6 There could be several extensions to the study in the future. For instance, future research could involve the use of individual-level anonymized data to develop predictive models of phishing susceptibility. The ability to predict which employees fall victim to phishing attacks repeatedly will give us the opportunity to study learning curves and risk stratification. Additionally, future research could involve adaptive phishing simulations driven by artificial intelligence. AI algorithms will aid in identifying employees’ risk levels, recommending relevant training material, and adapting the difficulty level in the simulation. Another possible extension to this study is an investigation of industry differences. Organizations in manufacturing, finance, healthcare, education, and government agencies could have differing risk profiles depending on their workflow processes, regulatory environments, and cybersecurity cultures. Moreover, psychological variables such as self-efficacy, severity of threat perceptions, usefulness of training programs, trust in the security team, and security fatigue could provide us with explanations for rapid improvements among employees. Fifth, future research could be done on reporting behavior. While avoiding clicks is an important factor, reporting is even more advanced in terms of security maturity. Future researchers can thus investigate factors such as the rate and speed of reporting as significant determinants of organizational resilience against phishing attacks. Lastly, future studies can focus on exploring the effects of simulation outcomes in reducing real-life phishing incidents. This will reveal the degree to which simulation success impacts phishing attack incidences.

    Adaptive Phishing Simulation and Longitudinal Employee Security Behavior: Evidence from a Global Enterprise · 2026 · DOI
  • Contrary to traditional assumptions of Protection Motivation Theory, internal perceptions of threat severity and vulnerability alone were insufficient to stimulate innovative action, regulatory frameworks emerged act as catalytic mechanisms that transform compliance requirements into innovation-driven resilience strategies.

    Aligning data privacy regulations with cybersecurity resilience in South Africa · 2026 · DOI
  • Based on this, we suggest that future research should explore the possibility of ‘cue engineering’—making changes to the UI with the aim of facilitating habit formation by designing better cues.

    Can secure habits counter phishing? An exploration using a novel in-tray simulation · 2026 · DOI
  • The study recommends that management should formally adopt the proposed IT end-user training framework as an organisational policy instrument, embedding mandatory quarterly participation within HR policy, IT Acceptable Use Policy, and employment contracts, with non-completion escalated to dep- IJFMR260483880 Volume 8, Issue 4, July-August 2026 12 International Journal for Multidisciplinary Research (IJFMR) E-ISSN: 2582-2160 ● Website: www.ijfmr.com ● Email: [email protected] artment heads as a recorded compliance gap. The study also recommends that the IT department implement the five-tier, role-differentiated training curriculum and a structured quarterly phishing simulation programme using scenarios reflective of organizational actual operational communications, while the Human Resources department formally integrates cybersecurity training performance into the Annual Performance Appraisal and issues digital Certificates of Completion to create an auditable, career-linked compliance record. Finally, the study recommends a longitudinal evaluation of the designed framework's effectiveness following implementation, measuring changes in phishing click-rates, incident frequency, and reporting behaviour over a 12 to 24 month period, and recommends extending this research methodology to other similar operations and comparable East African agri-commodity trading organizations.

    It End-user Training Framework for Mitigating Human-related Internal Cybersecurity Risks: a Case Study of Uganda Coffee Ltd · 2026 · DOI
  • At last, it detect research gaps, present open challenges, and deduce the trending and most effective and emerging methodologies used across the AI-CPSY landscape.

    AI in Cyberpsychology: A systematic literature review of Cybersecurity enhancement by using AI for analyzing psychology of Victims, Attackers, and Defenders · 2026
  • Successful incident stabilization is not characterized by rigid adherence to static, step-by-step checklists. Responders operating in modern threat landscapes are forced to manage an overwhelming velocity of ambiguous and contradictory data. This study addresses a critical gap in literature by moving beyond traditional, static models of cybersecurity management to provide a socio-technical lens on cyber crisis navigation.

    A Chaos Theory Perspective on Expert Decision-Making in Cyber Incident Response · 2026 · DOI
  • Implement continuous, mandatory cybersecurity awareness training covering password hygiene and phishing recognition. 2. Integrate cybersecurity into core strategic planning rather than treating it as an isolated IT function. 3. Promote active executive and board-level involvement in cybersecurity decision-making. 4. Invest in advanced security tools such as intrusion detection systems, SIEM, and EDR technologies. 5. Strengthen incident response and disaster recovery planning through regular testing. 6. Enforce strong password policies and multi-factor authentication to address human vulnerabilities. 7. Increase the frequency and rigor of cybersecurity audits and risk assessments. 8. Ensure ongoing compliance with cybersecurity standards such as ISO 27001, NIST, and GDPR. 9. Allocate a dedicated cybersecurity budget covering infrastructure, training, and compliance. 8. SCOPE FOR FUTURE RESEARCH Future research could explore longitudinal changes in cybersecurity maturity, industry-specific comparisons across healthcare, finance, and manufacturing sectors, the impact of board-level cybersecurity committees on governance outcomes, and cost-benefit or ROI analysis of cybersecurity investment. Qualitative studies examining organizational culture and behavioural factors, along with cross-geographic comparisons of regulatory and governance environments, would further deepen understanding of this evolving field. 9. CONCLUSION This study confirms that cybersecurity has evolved from a purely technical concern into a strategic, organization-wide priority. While awareness and foundational protective measures are reasonably established, meaningful integration of cybersecurity into corporate governance and strategic decision-making remains inconsistent, particularly at the board and senior leadership level. The human factor reflected in weak passwords and insufficient training stands out as the most pressing vulnerability, while moderate confidence in recovery capability highlights the need for stronger incident response frameworks. Going forward, organizations must treat cybersecurity as a core governance imperative, supported by leadership commitment, continuous risk assessment, and sustained investment in both technology and people. 10. REFERENCES Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M. J., Levi, M.,... & Savage, S. (2019). Security economics and the internal market. European Network and Information Security Agency (ENISA). Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. International Journal of Electronic Commerce, 9(1), 69–104. ENISA. (2023). Threat Landscape Report 2023. European Union Agency for Cybersecurity. Kaspersky Lab. (2022).

    The Role of Cybersecurity in Organizational Strategy and Corporate Governance · 2026 · DOI
  • Future research could explore the relationships between OCAS dimensions and related constructs such as security self-efficacy, organizational security climate, management support for security, and actual security behaviors. Future research should examine whether the four-factor structure is invariant across organizational types, or whether certain dimensions (e.

    Development of Organizational Cybersecurity Awareness Scale (OCAS) · 2026 · DOI
  • Future research should consider longitudinal designs, include objective cybersecurity incident records where available, and examine additional organizational and behavioural factors, such as leadership support, employee trust, remote work arrangements, and emerging artificial intelligence- enabled insider threats, to further advance understanding of insider cybersecurity risks.

    MODELING INSIDER CYBERSECURITY RISKS ASSOCIATED WITH TEMPORARY AND CONTRACT STAFF IN THE BANKING INDUSTRY · 2026 · DOI
  • Limitations. include the exclusive reliance on publicly available documents, which may omit classifi ed operational details, regarding particularly budgets, procurement decisions, or operational readiness. Consequently, fi ndings refl ect institutional intent than logic and planning rather 454545454545454545 AI-DRIVEN CYBER CAPABILITIES IN DEFENSE RESOURCE PLANNING AI-DRIVEN CYBER CAPABILITIES IN DEFENSE RESOURCE PLANNING AI-DRIVEN CYBER CAPABILITIES IN DEFENSE RESOURCE PLANNING precise implementation outcomes. Additionally, the rapidly evolving nature of AI and cyber technologies means that policy documents may technological lag behind actual capabilities and emerging threats.

    AI-DRIVEN CYBER CAPABILITIES IN DEFENSE RESOURCE PLANNING · 2026 · DOI
  • This study is conceptual in nature and does not include empirical validation. While the proposed framework integrates cybersecurity and organisational resilience theories, its practical appli- cability has not been quantitatively tested. Future research should therefore focus on empirical verification within organisations deploying AI agents in real-world settings, especially in sec- tors where operational continuity and safety are critical, such as healthcare and manufacturing. Another important direction for future work involves extending the conceptual model to large language model (LLM)-based agent architectures, where adaptive learning mecha- nisms and dynamic decision-making introduce new layers of complexity for risk management FOE 1(374) 2026 https://www.czasopisma.uni.lodz.pl/foe/ 81 Krystian Bień, Elwira Pyk, Mariusz Rafało Managing Security Risks of AI Agents in Adversarial Contexts… and governance. Comparative studies across industries and regulatory contexts could further refine the framework and support the development of actionable policies for AI governance and digital resilience.

    Managing Security Risks of AI Agents in Adversarial Contexts: A Conceptual Integration of the CIA Triad and Organisational Resilience for Digital Governance · 2026 · DOI
  • If open sources resources are still insufficient to meet the course needs, using the various Generative AI tools are also a fast and effective way to generate virtual reality simulations tailored to specific courses.

    Immersive Cyber-Verse: The State of Immersive Learning Techniques in Cybersecurity Education in Small Colleges · 2026 · DOI
  • This work is subject to several methodological and conceptual limitations that should be acknowledged. First, the data collection process was structured as an unstructured, qualitative synthesis rather than a systematic review; as such, no formal coding protocol or systematic search criteria were applied to the secondary sources. This exploratory approach may lead to the omission of relevant literature outside the selected databases or timeframe. Second, while the Socio-Technical Systems (STS) framework was employed to guide the analysis, it was used conceptually to map vulnerabilities rather than as a tool for empirical operationalization. Consequently, the study’s focus on high-profile individuals limits the generalizability of the findings to broader, low-visibility populations. Furthermore, the case studies presented in Section 4 are constructed scenarios intended for conceptual illustration rather than real-world empirical demonstrations and thus represent plausible routes rather than verified incident reports. Finally, the analysis primarily treats service sectors in isolation, with restricted engagement in cross-platform interaction analysis.

    Exploring Personalized Personnel Protection within Cybersecurity · 2026 · DOI
  • While prior research has exam- ined trust in AI or explainability effects in isolation, few studies have modeled calibration as a structured, culture- embedded socio-technical process and validated it using both psychometric and behavioral indicators (e.

    Embedding governance in AI security culture: from trust calibration to accountable decisions · 2026 · DOI
  • The relatively moderate impact of digital literacy, compared to the stronger influence of critical thinking and cybersecurity knowledge, indicates that the ability to operate digital tools is insufficient without the capacity to interpret, evaluate, and respond to risks. Furthermore, the relatively lower influence of ethical awareness suggests that ethical principles alone are insufficient unless they are reinforced through real-life practice and contextual learning.

    PEDAGOGICAL FRAMEWORK FOR DEVELOPING CYBERSECURITY AWARENESS AMONG STUDENTS: A COMPETENCY-BASED AND DATA-DRIVEN APPROACH · 2026 · DOI
  • The results indicate that dominant failure patterns in Web3 environments are insufficiently addressed by generic security control catalogues, particularly with respect to cryptographic key management, transaction approval governance, signer and validator infrastructure, third-party tooling dependencies, and human-in-the-loop processes.

    Bridging the Cybersecurity Gap Between Web2 and Web3 -- An Incident-Based Analysis of Organizational and Application-Level Security Failures · 2026
  • The mechanisms linking ICT endowment, organizational security investment, and firmlevel outcomes remain underexplored, particularly in developing economies.

    Securing the Digital Edge: How Security Management Mediates the Impact of ICT Infrastructure on Firm Performance in Emerging Markets · 2026 · DOI
  • To identify, present and map peer-reviewed literature on SME cyber incident prevention and response, and to categorise open problems into a People, Process, Technology (PPT) framework.

    Cyber incident prevention and response for small and medium sized enterprises: A scoping review · 2026 · DOI
  • This research demonstrates the viability and efficacy of leveraging language models, particularly LLMs, for mapping CVE descriptions to their corresponding CWEs. First, we fine-tuned various language models specifically for the CVE-to-CWE mapping task and identified the best-performing model. Building on this, we developed a two-step neural network that further enhanced performance by leveraging the hierarchical structure of the CWE taxonomy. This combined methodology delivered a 5% improvement in F1-score over previous supervised state-of-the-art techniques. To the best of our knowledge, no prior work has integrated LLM-based representations with hierarchical CWE family classification in this manner, making our approach both methodologically relevant and domain-specific. Looking ahead, a promising direction to address the persistent data imbalance issue is to generate additional synthetic data for underrepresented CWEs. Future work could explore advanced data augmentation techniques or utilize generative models, such as generative adversarial networks (GANs), to create realistic and diverse CVE descriptions. This approach could enhance both the balance and diversity of data, potentially further improving mapping accuracy. Another valuable extension of this work is the application of our hierarchical classification approach to other CTI taxonomies. Domains such as TTPs and CAPEC share similar hierarchical structures, suggesting that coarse-to-fine prediction strategies could yield comparable performance gains. Exploring these adjacent taxonomies would further validate the generalizability of our methodology. Knowing your weaknesses is your greatest strength ASIA CCS ’26, June 1–5, 2026, Bangalore, India Kethan Kota, A Manjunatha, et al. 2024. CWE prediction using CVE descriptionthe semantic similarity approach. Procedia Computer Science 235 (2024), 1167– 1178. Xin Liu, Yuan Tan, Zhenghang Xiao, Jianwei Zhuge, and Rui Zhou. 2023. Not the end of story: An evaluation of ChatGPT-driven vulnerability description mappings. In Findings of the Association for Computational Linguistics: ACL 2023. 3724–3731. Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019). Alex Mallen, Akari Asai, Victor Zhong, Rajarshi Das, Daniel Khashabi, and Hannaneh Hajishirzi. 2023. When Not to Trust Language Models: Investigating Effectiveness of Parametric and Non-Parametric Memories. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Anna Rogers, Jordan Boyd-Graber, and Naoaki Okazaki (Eds.). Association for Computational Linguistics, Toronto, Canada, 9802–9822. doi:10. 18653/v1/2023.acl-long.546 Microsoft Research Blog. [n. d.].

    Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE Hierarchy and fine-tuned LLMs · 2026 · DOI
  • In our supervised approach, it is essential to define a cut-off threshold, since, among the 130 CWEs, some have few associated samples. For example, CWE-920 (Improper Restriction of Power Consumption) is linked to only 3 CVEs. We determined our threshold by analyzing the KEV database. Specifically, we based the threshold on the number of CVEs associated with the least frequent CWE among the top 30 most exploited base CWEs. This analysis led us to exclude any CWE with fewer than 315 associated CVEs, a threshold that covers 95% of all CVEs linked to a CWE. Consequently, our focus is on the 57 most common CWEs. To assess how this threshold impacts classification performance, we systematically evaluated our two-step neural network approach across various thresholds. Specifically, we explored thresholds slightly below and above our primary choice (resulting in 52 and 62 classes, respectively), thresholds substantially below and above (26 and 91 classes), and finally, a scenario where no threshold was applied, including all available CWEs. This comprehensive evaluation enabled us to rigorously compare the performance of our two-step method against a simpler one-step approach, determining both the consistency of observed improvements across varying class selections and quantifying their magnitude (see Table 16 in the Appendix). Figure 5 compares the F1-scores of the one-step and two-step neural network models across different class counts. The results clearly demonstrate that the two-step neural network consistently outperforms the one-step model, with the performance gap widening as the number of classes increases. This trend suggests that the two-step architecture is more effective at managing the complexity of multi-class scenarios, yielding enhanced performance, particularly when handling larger class sets.

    Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE Hierarchy and fine-tuned LLMs · 2026 · DOI
  • We introduce ATAG, a novel framework that extends MulVAL with specific facts and IRs for the structured assessment of threats in MAASs. Unlike existing frame- works that focus on threat models or manual testing, ATAG provides semi-automated, continuous threat assessment ca- pabilities that are easily integrable with enterprise security infrastructure. The varied topologies and use cases in the two case studies demonstrate the ATAG framework’s versatility and applicability across diverse MAAS domains. ATAG is complemented by the proposed LVD which initiates the process of standardizing LLM vulnerability documentation for MAASs. While ATAG represents a significant step in the process of developing a systematic and effective methodology for understanding emerging security threats in the MAAS do- main, future work will focus on exploring ATAG’s scalabil- ity for larger, more complex MAAS and expanding the LVD knowledge base. Developing automated mitigation strategies informed by the critical attack paths in the AGs is another key research direction.

    ATAG: AI-Agent Application Threat Assessment with Attack Graphs · 2026 · DOI
  • Based on the findings, it is recommended that banks in Edo State implement continuous cybersecurity awareness programs to enhance staff knowledge and vigilance. Management should ensure full deployment and regular updating of technological controls such as firewalls, encryption, and security software. Compliance monitoring should be strengthened, with clear policies and accountability mechanisms to reduce lapses. Finally, banks should integrate regular risk assessments and staff training to proactively address emerging cyber threats, thereby safeguarding financial data and promoting trust in banking operations.

    CYBERSECURITY IN ACCOUNTING INFORMATION SYSTEMS IN THE BANKING SECTOR IN EDO STATE, NIGERIA · 2026 · DOI
  • This study is subject to several limitations. First, like all event studies, it is difficult to perfectly control for confounding information, despite our screening process. Second, our sample relies on publicly announced breaches. Firms may be more likely to conceal smaller or less significant breaches, Page 9 of 12 potentially leading to a sample bias toward more severe incidents. Third, the accuracy of reported information, such as the number of records compromised, can be uncertain in the initial announcement, and our analysis captures only the immediate reaction to this initial information. Finally, our study is confined to publicly traded U.S. companies. The findings may not be generalizable to private companies, which face different stakeholder pressures (Cole et al., 2009), or to firms operating in different legal and cultural contexts, such as Brazil (Masullo, 2015) or other regions. Future research should extend this analysis to other international markets to understand the influence of different regulatory regimes like GDPR. Investigating the long-term impacts on operational metrics like sales growth and profitability, as well as on the cost of debt, would provide a more complete picture of the total costs of a breach. Furthermore, as threat vectors evolve with technologies like generative AI (Alami et al., 2024), continuous research will be needed to track the market's pricing of these new and emerging cyber risks.

    Cybersecurity Breaches and Shareholder Value: An Event Study of Publicly Traded Companies (2020-2025) · 2026 · DOI
  • The framework should be validated in future research, by conducting enterprise case studies, quantitative SOC performance measurements, and longitudinal analyses of MXDR maturity.

    Driving Cybersecurity Transformation Through Managed Extended Detection and Response (MXDR): A Framework for Unified Threat Visibility and Operational Resilience · 2026 · DOI

Most-cited papers in Information and Cyber Security

Most recent work

Find a gap in your own Information and Cyber Security sub-topic

This page shows what the Information and Cyber Security literature already flags as unresolved. To narrow it to your specific question, run the guided finder — it searches the gap library on demand and checks candidates against 250M+ OpenAlex works.

Open the Research Gap Finder →

Related topics in Computer Science

107 open questions have been extracted from the limitations and future-work passages of 1,710 Information and Cyber Security papers in our library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the categoryHonest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.