Computer Science · Research topic

Open research questions in Information and Cyber Security

321 unresolved questions extracted from the limitations and future-work sections of 2,094 Information and Cyber Security papers in our library. Each links back to the study that raised it.

What the literature leaves open

  • Current quantum hardware is noisy, error-prone, and limited in qubit count, - Unsupervised approaches often suffer from high false positive rates, - ML approaches face limitations in handling complex, high-dimensional data, - The 'black box' nature of deep neural networks poses challenges for security analysts

    Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends · 2026 · DOI
  • Investigating the potential of QML for cryptanalysis, optimization of security configurations, and detection of sophisticated attacks, - Addressing the challenges of explainability and interpretation in AI-driven cybersecurity, - Exploring the applications of federated learning in cybersecurity

    Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends · 2026 · DOI
  • the high theoretic complexity of the search tree algorithm - the need to balance the trade-off between security and usability - the limited support for code virtualization

    Automatic selection of protections to mitigate risks against software applications · 2026 · DOI
  • The approach has a high theoretic complexity, - The ACTC provides limited support for code virtualization, - The validation is based on a proof-of-concept implementation and expert evaluations

    Automatic selection of protections to mitigate risks against software applications · 2026 · DOI
  • The fuzzy nature of Software Protections (SPs), which tries to delay attacks rather than completely prevent them. The diversity of attack techniques and attacker goals. The lack of standardised methodologies for evaluating MATE software protection strength.

    Statistical effort modelling of game resource localisation attacks · 2026 · DOI
  • The study only considers game resource localisation attacks, - The experiments are limited to two games, - The study does not evaluate the method for other types of attacks

    Statistical effort modelling of game resource localisation attacks · 2026 · DOI
  • Across this set, vulnerability management and remediation systems are studied as centralized or orchestrated workflows; none evaluates event-driven architectures for decoupled vulnerability detection, prioritization, and remediation execution. The paper on intelligent vulnerability management does not explore how asynchronous event-driven patterns could improve remediation latency or enable autonomous, distributed patch deployment across heterogeneous infrastructure.

    An Intelligent AI-Driven Vulnerability Management System for Automated Risk Assessment and Remediation · 2026 · DOI
  • None of these studies address how event-driven architectures support the knowledge drift and concept drift challenges identified in LLM-based cybersecurity automation. While one paper identifies that models trained on historical data become less reliable as network behavior evolves, no work proposes event-driven mechanisms for continuous model retraining, feedback propagation, or dynamic rule updates across distributed security agents.

    From static tasks to dynamic reasoning: a characterization framework and study of large language models in next-generation cybersecurity automation · 2026 · DOI
  • Across this set, dynamic threat response and remediation orchestration are evaluated only on centralized or mesh-based architectures; none applies event-driven patterns to the multi-agent AI-driven security systems studied in papers on LLM-powered agents and multi-agent threat assessment. The architectural decoupling and asynchronous coordination that event-driven systems provide remain untested for coordinating autonomous agents in cybersecurity workflows.

    From static tasks to dynamic reasoning: a characterization framework and study of large language models in next-generation cybersecurity automation · 2026 · DOI
  • Future research should focus on developing more effective security paradigms, technologies, and integration schemes to reduce risks and maximize DT technology’s potential.

    A Comprehensive Review on Cybersecurity of Digital Twins Issues, Challenges, and Future Research Directions · 2025 · DOI
  • Although various studies have explored SE attacks and their defense mechanisms, there remains a gap in the literature concerning the holistic and layered classification of these threats and countermeasures.

    A Comprehensive Taxonomy of Social Engineering Attacks and Defense Mechanisms: Toward Effective Mitigation Strategies · 2024 · DOI
  • The increasing complexity and frequency of cyber threats. The lack of flexibility and usability of traditional traffic generators. The need for advanced training tools to prepare cybersecurity professionals effectively.

    A Low-Cost Traffic Generation System Using Open-Source Software for Accessible Cyber Ranges · 2026 · DOI
  • Traditional traffic generators often lack the flexibility and usability required for educational and research applications. There is a significant gap between the capabilities of traditional tools and the requirements of modern cybersecurity education.

    A Low-Cost Traffic Generation System Using Open-Source Software for Accessible Cyber Ranges · 2026 · DOI
  • Investigating the long-term effects of using the CipherQuest platform. Comparing the effectiveness of the CipherQuest platform to other CTF platforms. Evaluating the impact of the CipherQuest platform on cybersecurity professionals and industry practitioners.

    Building Cyber Defense Skills: The CipherQuest Educational CTF Framework · 2026 · DOI
  • The development of CipherQuest followed a structured, iterative methodology encompassing design, implementation, and testing phases to create an effective cybersecurity education platform. During the design phase, careful consideration was given to system architecture, ensuring alignment with pedagogical objectives while prioritizing scalability, security, and usability. The implementation phase successfully transformed theoretical designs into a functional system, marked by key achievements such as the development of an automated scoring mechanism and the integration of a unique writeup feature, which facilitates reflective learning and distinguishes CipherQuest from existing CTF platforms. System testing confirmed the platform’s reliability, usability, and performance, with evaluations demonstrating high user satisfaction in navigation, responsiveness, and educational value. The successful deployment of CipherQuest underscores its potential as a tool for cybersecurity education, effectively bridging theoretical knowledge and practical application through structured challenges and real-time feedback. Future work will focus on expanding CipherQuest’s capabilities to enhance both educational impact and user engagement. First, the platform’s pedagogical framework will be strengthened through the introduction of structured learning paths, integrating guided tutorials with progressive challenges to benefit learners. Second, the challenge repository will be diversified to encompass additional cybersecurity domains, including network security, reverse engineering, and digital forensics, ensuring comprehensive skill development. Third, gamification elements— such as achievement badges, leaderboard tiers, and time-limited competitions—will be incorporated to sustain user motivation and encourage long-term participation. To improve 82 Journal of Engineering Research and Education Volume 18, (Special Issue) 2026 [73-83] accessibility, a cross-platform mobile application will be developed, enabling users to engage with challenges beyond desktop environments. Furthermore, interactive tutorials will be introduced to lower the entry barrier for beginners, providing step-by-step guidance on fundamental concepts. Finally, the database infrastructure will be upgraded to a more robust system (e.g., PostgreSQL) to enhance scalability, optimize query performance, and ensure stability during peak usage. These enhancements will not only address current limitations but also position CipherQuest as a continually evolving platform capable of adapting to emerging trends in cybersecurity education. REFERENCES S. J. Leudo, P. Braun, R. G. Sanfelice, and I.

    Building Cyber Defense Skills: The CipherQuest Educational CTF Framework · 2026 · DOI
  • Future research can focus on improving the accuracy of the model. Future research can explore the use of other machine learning models. Future research can investigate the application of the system in real-world scenarios.

    Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process · 2026 · DOI
  • The lack of effective characterization of MITRE ATT&CK tactics and techniques. The limitation of traditional approaches to incident detection.

    Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process · 2026 · DOI
  • The sources and platforms of OSINT data are very fragmented. There is a need for a system that consolidates passive data collection, intelligent risk analysis, and real-time visualization in a single portable and ethical platform running on embedded hardware.

    An AI Powered Passive Reconnaissance Kit To Identifies Potential Vulnerabilities By Correlating Open Source Intelligence (OSINT) · 2026 · DOI
  • Risk score calculation accuracy is reported at 91-93% but the paper does not provide a confusion matrix, false positive/false negative rates, or precision/recall metrics stratified by risk severity level (Low vs Critical). Comparative evaluation against established OSINT tools or baseline passive reconnaissance frameworks is absent.

    An AI Powered Passive Reconnaissance Kit To Identifies Potential Vulnerabilities By Correlating Open Source Intelligence (OSINT) · 2026 · DOI
  • The globalisation of mandatory cybersecurity audit regimes, the complexity of cyber threats, the need for high audit quality and rigorous gap analysis

    Audit to Assurance: Evaluating the Impact of Regulatory Cybersecurity Audits on Organisational Cyber Resilience and Strategic Decision-Making · 2026 · DOI
  • Despite widespread regulatory adoption, evidence on whether compliance translates into genuine cyber resilience remains contested. Prior literature has examined direct paths and mediated paths in isolation, but not in a comprehensive framework.

    Audit to Assurance: Evaluating the Impact of Regulatory Cybersecurity Audits on Organisational Cyber Resilience and Strategic Decision-Making · 2026 · DOI
  • The generalization of results remains tentative and calls for longitudinal replication across multiple organizations. The study's sample size is limited to a single SME. The evaluation period is limited to six months.

    Enhancing Information Security in Technology Small and Medium-Sized Enterprises: A Metrics-Driven Model Based on ISO/IEC 27001:2022 · 2026 · DOI
  • Longitudinal replication of the study across multiple organizations. Evaluation of the model's effectiveness in other industries and organizations. Development of new metrics and approaches to information security management.

    Enhancing Information Security in Technology Small and Medium-Sized Enterprises: A Metrics-Driven Model Based on ISO/IEC 27001:2022 · 2026 · DOI
  • Cyber security threats are growing more advanced and frequent. Traditional security methods are not enough to tackle these threats. There is a need to identify weak points in a network and develop better defense systems.

    Mathematical Modeling of Cyber Security Threats for Network Risk Assessment and Prevention · 2026 · DOI
  • Traditional cybersecurity approaches are not enough to capture the deeper structural and dynamic aspects of how threats evolve and spread. There is a need for a strong analytical foundation to tackle cyber security threats.

    Mathematical Modeling of Cyber Security Threats for Network Risk Assessment and Prevention · 2026 · DOI

Most-cited papers in Information and Cyber Security

Most recent work

Find a gap in your own Information and Cyber Security sub-topic

This page shows what the Information and Cyber Security literature already flags as unresolved. To narrow it to your specific question, search the Research Gap Finder: the search is free with a free account and lists the papers closest to your topic first. Unlocking that topic (50 credits, charged once) fills the comparison table from our 4.5M-paper local library and writes the gaps from its rows.

Open the Research Gap Finder →

Related topics in Computer Science

321 open questions have been extracted from the limitations and future-work passages of 2,094 Information and Cyber Security papers in our 4.5M-paper local library. Each one below links back to the study that raised it, so you can read the original claim in context.

Tools for your next paper

Compare the category — Honest roundups of the AI research tools, ours listed alongside the alternatives.

Command palette

Jump anywhere, run any action.