Open research questions in Information and Cyber Security
321 unresolved questions extracted from the limitations and future-work sections of 2,094 Information and Cyber Security papers in our library. Each links back to the study that raised it.
What the literature leaves open
Current quantum hardware is noisy, error-prone, and limited in qubit count, - Unsupervised approaches often suffer from high false positive rates, - ML approaches face limitations in handling complex, high-dimensional data, - The 'black box' nature of deep neural networks poses challenges for security analysts
Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends · 2026 · DOIInvestigating the potential of QML for cryptanalysis, optimization of security configurations, and detection of sophisticated attacks, - Addressing the challenges of explainability and interpretation in AI-driven cybersecurity, - Exploring the applications of federated learning in cybersecurity
Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends · 2026 · DOIthe high theoretic complexity of the search tree algorithm - the need to balance the trade-off between security and usability - the limited support for code virtualization
The approach has a high theoretic complexity, - The ACTC provides limited support for code virtualization, - The validation is based on a proof-of-concept implementation and expert evaluations
The fuzzy nature of Software Protections (SPs), which tries to delay attacks rather than completely prevent them. The diversity of attack techniques and attacker goals. The lack of standardised methodologies for evaluating MATE software protection strength.
The study only considers game resource localisation attacks, - The experiments are limited to two games, - The study does not evaluate the method for other types of attacks
Across this set, vulnerability management and remediation systems are studied as centralized or orchestrated workflows; none evaluates event-driven architectures for decoupled vulnerability detection, prioritization, and remediation execution. The paper on intelligent vulnerability management does not explore how asynchronous event-driven patterns could improve remediation latency or enable autonomous, distributed patch deployment across heterogeneous infrastructure.
An Intelligent AI-Driven Vulnerability Management System for Automated Risk Assessment and Remediation · 2026 · DOINone of these studies address how event-driven architectures support the knowledge drift and concept drift challenges identified in LLM-based cybersecurity automation. While one paper identifies that models trained on historical data become less reliable as network behavior evolves, no work proposes event-driven mechanisms for continuous model retraining, feedback propagation, or dynamic rule updates across distributed security agents.
From static tasks to dynamic reasoning: a characterization framework and study of large language models in next-generation cybersecurity automation · 2026 · DOIAcross this set, dynamic threat response and remediation orchestration are evaluated only on centralized or mesh-based architectures; none applies event-driven patterns to the multi-agent AI-driven security systems studied in papers on LLM-powered agents and multi-agent threat assessment. The architectural decoupling and asynchronous coordination that event-driven systems provide remain untested for coordinating autonomous agents in cybersecurity workflows.
From static tasks to dynamic reasoning: a characterization framework and study of large language models in next-generation cybersecurity automation · 2026 · DOIFuture research should focus on developing more effective security paradigms, technologies, and integration schemes to reduce risks and maximize DT technology’s potential.
A Comprehensive Review on Cybersecurity of Digital Twins Issues, Challenges, and Future Research Directions · 2025 · DOIAlthough various studies have explored SE attacks and their defense mechanisms, there remains a gap in the literature concerning the holistic and layered classification of these threats and countermeasures.
A Comprehensive Taxonomy of Social Engineering Attacks and Defense Mechanisms: Toward Effective Mitigation Strategies · 2024 · DOIThe increasing complexity and frequency of cyber threats. The lack of flexibility and usability of traditional traffic generators. The need for advanced training tools to prepare cybersecurity professionals effectively.
A Low-Cost Traffic Generation System Using Open-Source Software for Accessible Cyber Ranges · 2026 · DOITraditional traffic generators often lack the flexibility and usability required for educational and research applications. There is a significant gap between the capabilities of traditional tools and the requirements of modern cybersecurity education.
A Low-Cost Traffic Generation System Using Open-Source Software for Accessible Cyber Ranges · 2026 · DOIInvestigating the long-term effects of using the CipherQuest platform. Comparing the effectiveness of the CipherQuest platform to other CTF platforms. Evaluating the impact of the CipherQuest platform on cybersecurity professionals and industry practitioners.
The development of CipherQuest followed a structured, iterative methodology encompassing design, implementation, and testing phases to create an effective cybersecurity education platform. During the design phase, careful consideration was given to system architecture, ensuring alignment with pedagogical objectives while prioritizing scalability, security, and usability. The implementation phase successfully transformed theoretical designs into a functional system, marked by key achievements such as the development of an automated scoring mechanism and the integration of a unique writeup feature, which facilitates reflective learning and distinguishes CipherQuest from existing CTF platforms. System testing confirmed the platform’s reliability, usability, and performance, with evaluations demonstrating high user satisfaction in navigation, responsiveness, and educational value. The successful deployment of CipherQuest underscores its potential as a tool for cybersecurity education, effectively bridging theoretical knowledge and practical application through structured challenges and real-time feedback. Future work will focus on expanding CipherQuest’s capabilities to enhance both educational impact and user engagement. First, the platform’s pedagogical framework will be strengthened through the introduction of structured learning paths, integrating guided tutorials with progressive challenges to benefit learners. Second, the challenge repository will be diversified to encompass additional cybersecurity domains, including network security, reverse engineering, and digital forensics, ensuring comprehensive skill development. Third, gamification elements— such as achievement badges, leaderboard tiers, and time-limited competitions—will be incorporated to sustain user motivation and encourage long-term participation. To improve 82 Journal of Engineering Research and Education Volume 18, (Special Issue) 2026 [73-83] accessibility, a cross-platform mobile application will be developed, enabling users to engage with challenges beyond desktop environments. Furthermore, interactive tutorials will be introduced to lower the entry barrier for beginners, providing step-by-step guidance on fundamental concepts. Finally, the database infrastructure will be upgraded to a more robust system (e.g., PostgreSQL) to enhance scalability, optimize query performance, and ensure stability during peak usage. These enhancements will not only address current limitations but also position CipherQuest as a continually evolving platform capable of adapting to emerging trends in cybersecurity education. REFERENCES S. J. Leudo, P. Braun, R. G. Sanfelice, and I.
Future research can focus on improving the accuracy of the model. Future research can explore the use of other machine learning models. Future research can investigate the application of the system in real-world scenarios.
Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process · 2026 · DOIThe lack of effective characterization of MITRE ATT&CK tactics and techniques. The limitation of traditional approaches to incident detection.
Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process · 2026 · DOIThe sources and platforms of OSINT data are very fragmented. There is a need for a system that consolidates passive data collection, intelligent risk analysis, and real-time visualization in a single portable and ethical platform running on embedded hardware.
An AI Powered Passive Reconnaissance Kit To Identifies Potential Vulnerabilities By Correlating Open Source Intelligence (OSINT) · 2026 · DOIRisk score calculation accuracy is reported at 91-93% but the paper does not provide a confusion matrix, false positive/false negative rates, or precision/recall metrics stratified by risk severity level (Low vs Critical). Comparative evaluation against established OSINT tools or baseline passive reconnaissance frameworks is absent.
An AI Powered Passive Reconnaissance Kit To Identifies Potential Vulnerabilities By Correlating Open Source Intelligence (OSINT) · 2026 · DOIThe globalisation of mandatory cybersecurity audit regimes, the complexity of cyber threats, the need for high audit quality and rigorous gap analysis
Audit to Assurance: Evaluating the Impact of Regulatory Cybersecurity Audits on Organisational Cyber Resilience and Strategic Decision-Making · 2026 · DOIDespite widespread regulatory adoption, evidence on whether compliance translates into genuine cyber resilience remains contested. Prior literature has examined direct paths and mediated paths in isolation, but not in a comprehensive framework.
Audit to Assurance: Evaluating the Impact of Regulatory Cybersecurity Audits on Organisational Cyber Resilience and Strategic Decision-Making · 2026 · DOIThe generalization of results remains tentative and calls for longitudinal replication across multiple organizations. The study's sample size is limited to a single SME. The evaluation period is limited to six months.
Enhancing Information Security in Technology Small and Medium-Sized Enterprises: A Metrics-Driven Model Based on ISO/IEC 27001:2022 · 2026 · DOILongitudinal replication of the study across multiple organizations. Evaluation of the model's effectiveness in other industries and organizations. Development of new metrics and approaches to information security management.
Enhancing Information Security in Technology Small and Medium-Sized Enterprises: A Metrics-Driven Model Based on ISO/IEC 27001:2022 · 2026 · DOICyber security threats are growing more advanced and frequent. Traditional security methods are not enough to tackle these threats. There is a need to identify weak points in a network and develop better defense systems.
Mathematical Modeling of Cyber Security Threats for Network Risk Assessment and Prevention · 2026 · DOITraditional cybersecurity approaches are not enough to capture the deeper structural and dynamic aspects of how threats evolve and spread. There is a need for a strong analytical foundation to tackle cyber security threats.
Mathematical Modeling of Cyber Security Threats for Network Risk Assessment and Prevention · 2026 · DOI
Most-cited papers in Information and Cyber Security
- Current methods of the U.S. Preventive Services Task Force · American Journal of Preventive Medicine · 2001 · 1,303 citations
- Users are not the enemy · Communications of the ACM · 1999 · 982 citations
- From information security to cyber security · Computers & Security · 2013 · 800 citations
- Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory · Computers & Security · 2011 · 682 citations
- Encouraging information security behaviors in organizations: Role of penalties, pressures and perceived effectiveness · Decision Support Systems · 2009 · 595 citations
- Artificial intelligence for cybersecurity: Literature review and future research directions · Information Fusion · 2023 · 516 citations
- A review of cyber security risk assessment methods for SCADA systems · Computers & Security · 2015 · 491 citations
- Future directions for behavioral information security research · Computers & Security · 2012 · 464 citations
- Studying users' computer security behavior: A health belief perspective · Decision Support Systems · 2008 · 433 citations
- Analysis of end user security behaviors · Computers & Security · 2004 · 432 citations
Most recent work
- AEKG4APT: An AI-Enhanced Knowledge Graph for Advanced Persistent Threats with Large Language Model Analysis · ACM Transactions on Intelligent Systems and Technology · 2026
- Co-evolutionary dynamics of attack and defence in cybersecurity · Knowledge-Based Systems · 2026
- A Unified Framework for Human–AI Collaboration in Security Operations Centers with Trusted Autonomy · ACM Transactions on Internet Technology · 2026
- Hybrid threats require hybrid solutions: A roadmap for healthcare security · Health Policy · 2026
- Cybersecurity in Higher Education Institutions Digitalisation: Addressing Threats and Vulnerabilities · SAGE Open · 2026
- Security and privacy in LLMs: A comprehensive survey of threats and mitigation strategies · Information Fusion · 2026
- Beyond self-reporting: Uncovering the operational realities of SME cybersecurity through expert assessment · Computers & Security · 2026
- Cyberattacks, perception, and market impact: Financial and social media dynamics of breach disclosure · Computers & Security · 2026
- Development and cross-cultural validation of the cybersecurity resilience scale (CSRS) · Computers & Security · 2026
- Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process · Future Generation Computer Systems · 2026
Find a gap in your own Information and Cyber Security sub-topic
This page shows what the Information and Cyber Security literature already flags as unresolved. To narrow it to your specific question, search the Research Gap Finder: the search is free with a free account and lists the papers closest to your topic first. Unlocking that topic (50 credits, charged once) fills the comparison table from our 4.5M-paper local library and writes the gaps from its rows.
Open the Research Gap Finder →