Purpose

Operator 5.0 represents a paradigm shift in how humans and machines interact and work together in industrial contexts. It leverages advanced digital technologies and automation to optimise processes, enhance productivity and create new possibilities. However, these advanced possibilities also introduce significant cybersecurity challenges. This paper explores the cybersecurity challenges and threats faced by Operator 5.0, emphasising the vulnerabilities inherent in human-machine collaboration, industrial IoT and supply chain integration.

Design/methodology/approach

The paper uses a qualitative approach, using a literature review, to analyse the cybersecurity risks associated with Operator 5.0 and proposes a comprehensive cybersecurity framework to address these challenges.

Findings

The paper identifies key vulnerabilities arising from human–machine collaboration, IIoT and supply chain integration within the Operator 5.0 context. It argues that these vulnerabilities pose significant risks to industrial operations and sensitive data. The proposed framework offers a multi-layered approach to mitigating these risks.

Originality/value

This paper offers a novel perspective on the cybersecurity implications of Operator 5.0. It proposes a holistic framework integrating hardware, software and liveware (human element) to establish human-centric security measures, advanced threat detection and response mechanisms and resilient infrastructure for Operator 5.0 deployments.

The Industry 5.0 paradigm is the next evolutionary phase of industrialisation built on the Industry 4.0 foundation. Industry 5.0 focuses on human-centric innovation, with Operator 5.0 as a key enabler of this collaboration. According to the literature, Operator 5.0 is defined as “an intelligent and skilled worker with creativity, ingenuity and innovation, who, in the face of difficult and/or unexpected scenarios, can properly utilise various information and technologies, overcome various obstacles, and develop a solution to maintain long-term sustainability and workforce well-being” (Kong et al., 2023). Thus, Operator 5.0 is a term used to describe the human workforce in this new industrial era, where workers and intelligent systems operate together. On the one hand, this collaboration can augment operation and maintenance processes with respect to sustainability, availability, reliability, maintainability, capacity, safety and security (Kour and Karim, 2021). On the other hand, it can also introduce cybersecurity risks, including AI-based attacks, Industrial Internet-of-Things (IIoT) vulnerabilities, Supply chain risks, and other ransomware and targeted cyberattacks. These cybersecurity risks must be carefully managed to protect human and machine assets' integrity, confidentiality and availability (CIA) in a fully connected industrial environment. Thus, this can be accomplished by introducing a holistic framework that can integrate hardware, software and liveware. The term liveware was introduced in 1966, referring to computer users and further used as a slang term for people, distinguishing them from software, firmware and hardware (Horak, 2008). In the proposed framework, we use this term for humans as Operator 5.0.

Figure 1 shows the evolution of industrial revolutions and the corresponding roles of operators in cybersecurity. Starting from Industry 1.0 with manual labour, operators gradually transitioned to assembly line workers (Industry 2.0), machine operators (Industry 3.0), smart operators (Industry 4.0) and collaborative operators (Industry 5.0). As technology advanced, so did the complexity of cybersecurity threats. Initially, cybersecurity was a minor concern, focusing primarily on physical security. However, with the rise of digital systems and networks, cybersecurity plays a critical role. In Industry 4.0, cybersecurity became essential due to the digital integration of systems, IoT devices and automation. Threats like data breaches, ransomware, IoT vulnerabilities and industrial espionage are key concerns. However, Industry 5.0 focuses on human–machine collaboration, Artificial Intelligence (AI) ethics and protecting sensitive data in personalised and intelligent systems. This evolution highlights the increasing importance of cybersecurity as industries become more interconnected, human-centric and dependent on technology.

Figure 1
A conceptual timeline diagram showing Industry 1.0 to 5.0 and Operator 1.0 to 5.0 with rising cybersecurity roles.The conceptual timeline diagram illustrates the evolution from Industry 1.0 to Industry 5.0, aligned with Operator 1.0 to Operator 5.0, and the increasing role of cybersecurity. On the far left, a vertical double-headed arrow represents workload transition, labeled “Physical Load” at the bottom and “Cognitive Load” at the middle, with the word “Cybersecurity” written vertically alongside the arrow at the top. A green dashed horizontal line labeled “Easy work” runs across the middle of the diagram. Along the bottom, five horizontal rectangles are arranged from left to right and connected by rightward arrows. They read “Industry 1.0 (Mechanisation)” labeled “1760s to 1850s”; “Industry 2.0 (Mass Production)” labeled “1850s to 1900s”; “Industry 3.0 (Automation)” labeled “1940s to early 2000s”; “Industry 4.0 (Cyber-Physical Systems)” labeled “Early 2000s to today”; and “Industry 5.0 (Human-Centric Manufacturing)” followed by three rightward arrows pointing toward the word “Future”. Above these, corresponding operator stages are shown from left to right: “Operator 1.0 (Manual Laborer)”, “Operator 2.0 (Assembly Line Worker)”, “Operator 3.0 (Machine Operator)”, “Operator 4.0 (Smart Operator)”, and “Operator 5.0 (Collaborative Operator)”. Curved arrows connect each operator stage to the next in left-to-right progression. Above selected operator stages, vertical upward arrows point to cybersecurity description boxes. Above Operator 1.0 and Operator 2.0, a box states, “Cybersecurity: No role, focus was on physical security”. Above Operator 3.0, a box states, “Cybersecurity: Emerging role, focused on securing computers and networks”. Above Operator 4.0, a box states, “Cybersecurity: Critical role, protecting I o T, data, and connected digital systems”. Above Operator 5.0, a box states, “Cybersecurity: Essential role, focusing on human-machine collaboration, A I ethics, and protect sensitive data in personalised and intelligent systems”. Beneath the operator sequence, green labels divide production types: “Labor-intensive Production” on the left and “Information-intensive Production” on the right, separated by a vertical green line.

Industrial revolutions and operators' role in cybersecurity. Source: Adapted from Kong et al. (2023) 

Figure 1
A conceptual timeline diagram showing Industry 1.0 to 5.0 and Operator 1.0 to 5.0 with rising cybersecurity roles.The conceptual timeline diagram illustrates the evolution from Industry 1.0 to Industry 5.0, aligned with Operator 1.0 to Operator 5.0, and the increasing role of cybersecurity. On the far left, a vertical double-headed arrow represents workload transition, labeled “Physical Load” at the bottom and “Cognitive Load” at the middle, with the word “Cybersecurity” written vertically alongside the arrow at the top. A green dashed horizontal line labeled “Easy work” runs across the middle of the diagram. Along the bottom, five horizontal rectangles are arranged from left to right and connected by rightward arrows. They read “Industry 1.0 (Mechanisation)” labeled “1760s to 1850s”; “Industry 2.0 (Mass Production)” labeled “1850s to 1900s”; “Industry 3.0 (Automation)” labeled “1940s to early 2000s”; “Industry 4.0 (Cyber-Physical Systems)” labeled “Early 2000s to today”; and “Industry 5.0 (Human-Centric Manufacturing)” followed by three rightward arrows pointing toward the word “Future”. Above these, corresponding operator stages are shown from left to right: “Operator 1.0 (Manual Laborer)”, “Operator 2.0 (Assembly Line Worker)”, “Operator 3.0 (Machine Operator)”, “Operator 4.0 (Smart Operator)”, and “Operator 5.0 (Collaborative Operator)”. Curved arrows connect each operator stage to the next in left-to-right progression. Above selected operator stages, vertical upward arrows point to cybersecurity description boxes. Above Operator 1.0 and Operator 2.0, a box states, “Cybersecurity: No role, focus was on physical security”. Above Operator 3.0, a box states, “Cybersecurity: Emerging role, focused on securing computers and networks”. Above Operator 4.0, a box states, “Cybersecurity: Critical role, protecting I o T, data, and connected digital systems”. Above Operator 5.0, a box states, “Cybersecurity: Essential role, focusing on human-machine collaboration, A I ethics, and protect sensitive data in personalised and intelligent systems”. Beneath the operator sequence, green labels divide production types: “Labor-intensive Production” on the left and “Information-intensive Production” on the right, separated by a vertical green line.

Industrial revolutions and operators' role in cybersecurity. Source: Adapted from Kong et al. (2023) 

Close modal

According to the literature, cybersecurity is more than just a technical issue, which involves People, Processes and Technologies (PPTs) (Handri et al., 2023; Parent and Cusack, 2016). The history of the PPT Framework began in the 1960s with Leavitt's diamond model, having four elements – people, structure, tasks and technology, without any interaction between them (Leavitt, 1964) (see, Figure 2).

Figure 2
A conceptual diagram linking task, structure, technology (tools), and people (actors).The conceptual network diagram shows four labeled elements connected by straight lines. On the left side is “Task”. At the top center is “Structure”. On the right side is “Technology (Tools)”. At the bottom center is “People (Actors)”. A straight line connects “Task” upward to “Structure”. Another straight line connects “Structure” downward to “Technology (Tools)”. A horizontal straight line connects “Task” directly to “Technology (Tools)”. A diagonal line connects “Task” downward to “People (Actors)”. Another diagonal line connects “People (Actors)” upward to “Technology (Tools)”.

Harold Leavitt's diamond model

Figure 2
A conceptual diagram linking task, structure, technology (tools), and people (actors).The conceptual network diagram shows four labeled elements connected by straight lines. On the left side is “Task”. At the top center is “Structure”. On the right side is “Technology (Tools)”. At the bottom center is “People (Actors)”. A straight line connects “Task” upward to “Structure”. Another straight line connects “Structure” downward to “Technology (Tools)”. A horizontal straight line connects “Task” directly to “Technology (Tools)”. A diagonal line connects “Task” downward to “People (Actors)”. Another diagonal line connects “People (Actors)” upward to “Technology (Tools)”.

Harold Leavitt's diamond model

Close modal

Later, Bruce Schneier highlighted an interconnected PPT framework in the context of a rapidly evolving IT security ecosystem (Schneier, 2015) (see, Figure 3). Technologies serve as the foundational elements, providing security controls and measures to protect digital assets. These include access control, firewalls, encryption, secure coding practices, intrusion detection systems and adversarial training, among other security measures. However, technology alone is insufficient and requires hand-in-hand with people and processes. Processes include a set of steps to be followed to achieve the required outcome. These processes can be incident response plans, risk assessments, continuous monitoring and so on to provide effective cybersecurity management.

Figure 3
A Venn diagram showing people, process, and technology with overlapping intersections.The Venn diagram consists of three overlapping circles arranged in a triangular layout. The top circle is labeled “People”. Above the label, an icon shows four simplified human figures standing side by side with their arms raised upward. The bottom-left circle is labeled “Process”. Below the label, an icon shows a three-dimensional box centered within three curved arrows forming a circular rotation around it. The bottom-right circle is labeled “Technology”. Below the label, an icon shows a robotic arm with a base, jointed segments, and a claw-like gripper extended outward. All three circles overlap at the center, creating a shared intersection area among “People”, “Process”, and “Technology”.

People, process and technology framework

Figure 3
A Venn diagram showing people, process, and technology with overlapping intersections.The Venn diagram consists of three overlapping circles arranged in a triangular layout. The top circle is labeled “People”. Above the label, an icon shows four simplified human figures standing side by side with their arms raised upward. The bottom-left circle is labeled “Process”. Below the label, an icon shows a three-dimensional box centered within three curved arrows forming a circular rotation around it. The bottom-right circle is labeled “Technology”. Below the label, an icon shows a robotic arm with a base, jointed segments, and a claw-like gripper extended outward. All three circles overlap at the center, creating a shared intersection area among “People”, “Process”, and “Technology”.

People, process and technology framework

Close modal

Unlike technologies and processes, people are complex and the weakest link. Both technology and processes need help from people or operators to program or run them. Additionally (Paul and Dykstra, 2017), have discussed the impacts of high stress and fatigue on its operators within a high-risk environment of cybersecurity operations. So, if people become the weakest link, then it can have a significant impact on both technology and processes, since these three aspects are interrelated and play an essential role in providing effective cybersecurity (Handri et al., 2023). These people can be system administrators, security analysts, managers, end-users and the public in general. They play a critical role in implementing and maintaining cybersecurity measures. Proper cybersecurity awareness and training are essential to shift people from the weakest link to the strongest, which can prevent cybersecurity issues now and in future.

Furthermore, researchers have discussed how visualisations can impact human operators' performance within cybersecurity research. They employed a qualitative study, reporting that 3D visualisations potentially enhanced the understanding of the network topology for cybersecurity operators (Kullman et al., 2019). Additionally, researchers have provided essential security recommendations for electric operators to defend against evolving cyber risks proactively (Aitel, 2013). However, there is still a significant gap in the research community's engagement with cybersecurity for Operator 5.0.

According to the Verizon (2024) report, 73% of breaches involved external and 27% involved internal actors within the manufacturing industry (Verizon, 2024). These breaches include people being involved via system intrusion, social engineering and miscellaneous errors (Verizon, 2024). In addition, financial gain remains the primary motive for most attacks (97%), while espionage accounts for a smaller 3% (Verizon, 2024). Data compromised in these breaches include personal information (58%), other sensitive data (40%), credentials (28%) and internal data (25%) (Verizon, 2024). Notably, two of the top patterns from the previous year persist, and financial motivation continues to be the driving force behind most cyberattacks (Verizon, 2024). The “Threat Actors” who cause or contribute to these cyberattacks include external, internal and partners (Verisframework, 2024). Figure 4 shows “Threat Actors” involved in breaches in 2024, adapted from the Verizon (2024) report.

Figure 4
A horizontal bar chart showing percentages for external, internal, and partner categories.The horizontal bar chart shows three categories arranged from top to bottom: “External”, “Internal”, and “Partner”. The horizontal axis ranges from 0 percent to 80 percent in increments of 10 percent. The bar for “External” extends to 73 percent. The bar for “Internal” extends to 27 percent. The bar for “Partner” extends to 15 percent. Note: All numerical data values are approximated.

“Threat actors” involved in breaches in the year 2024

Figure 4
A horizontal bar chart showing percentages for external, internal, and partner categories.The horizontal bar chart shows three categories arranged from top to bottom: “External”, “Internal”, and “Partner”. The horizontal axis ranges from 0 percent to 80 percent in increments of 10 percent. The bar for “External” extends to 73 percent. The bar for “Internal” extends to 27 percent. The bar for “Partner” extends to 15 percent. Note: All numerical data values are approximated.

“Threat actors” involved in breaches in the year 2024

Close modal

External threats originate from sources outside the organisation and its network of partners, while internal threats originate from within the organisation. The insider threat is now one of the greatest and most dangerous threats, since they are trusted and have more privileges than external threats. Partners are third parties with business relationships and have some level of trust and privilege. Partners can include direct or indirect suppliers, vendors or outsourced IT support and third-party software (Verizon, 2024).

The paper employs a qualitative approach, utilising a literature review to analyse the cybersecurity risks associated with Operator 5.0, and proposes a comprehensive cybersecurity framework to address these challenges. Databases such as Scopus and Google Scholar were searched to explore the research landscape. The initial search query used in the literature title was “operator 5.0” AND “cybersecurity”. The absence of literature discussing the role of Operator 5.0 in cybersecurity indicates a significant gap in this area. The literature selection criteria consist of:

  1. Study published in the last decade.

  2. Study includes availability of the full text in Scopus and Google Scholar.

  3. Study type includes e.g. peer-reviewed journal articles, conference papers, theses and systematic reviews.

  4. Studies published in English.

We also explored the literature on “operator” AND “cybersecurity” in the titles of the papers and found 11 articles. Based on the criterion mentioned above and reading the full literature, we identified four relevant literatures presented in this paper.

This section presents the identified cybersecurity challenges and proposes a cybersecurity framework for Operator 5.0.

Operator 5.0 can encounter several new cybersecurity challenges due to the integration of human operators, smart devices, autonomous systems and AI-driven tools. Key challenges include:

  1. Cyber-Physical Systems (CPS) Vulnerabilities: The interconnected nature of CPS in Industry 5.0 makes it vulnerable to cyberattacks, where a cyber layer breach can immediately impact the physical world. This can create risks for the data and models' security and the safety and well-being of human operators working on those physical systems. For example, Colonial Pipeline ransomware attack in 2021 led to fuel delivery disruption and panic across the United States, leading to the shutdown of a critical fuel network (CNN, 2021).

  2. Cybersecurity risks to AI Systems: Industry 5.0's collaborative human–machine interactions can introduce new cybersecurity risks as AI systems become vulnerable to data poisoning, evasion attacks, adversarial attacks, model denial of service, model theft, etc. Figure 5 illustrates various cybersecurity threats targeting AI systems adapted from Steve Moore (2024). Prompt injection attacks manipulate input data to trigger unintended actions, while evasion attacks exploit model vulnerabilities to cause incorrect decisions. Training data poisoning involves appending corrupt data into training datasets, compromising model behaviour. Model denial-of-service attacks aim to overwhelm AI systems with excessive requests, thereby disrupting their availability. Model theft involves unauthorised access and extraction of AI models, posing both financial and security risks. These cybersecurity threats underscore the necessity for robust cybersecurity measures to safeguard AI systems against malicious exploitation in the era of Industry 5.0.

  3. Rise of AI-based cyberattacks: The rise of AI-based cyberattacks presents significant challenges for operators 5.0, as these attacks can use AI's capabilities to escape traditional security controls and launch more sophisticated and targeted attacks. For example, in February 2024, a finance worker at a multinational firm fell victim to a sophisticated deepfake scam. In a video conference call, the attacker posed as the company's CEO, tricking the employee into transferring $25 million (CNN, 2024). Attackers used advanced AI technology to create highly realistic digital replicas of the CEO and other company officials. This incident highlights the growing concern for Operator 5.0 over the potential misuse of deepfake technology for malicious purposes.

  4. Insider threats: Given the central role of the human operator in Industry 5.0, the risk of insider threats (intentional and unintentional) becomes even more critical. For example, a disgruntled employee hacked 142 sewage stations in 2000, causing a million-litre sewage spill (Slay and Miller, 2007)The incident highlighted the dangers of reusing former employees' credentials and emphasised the need for Operator 5.0 to implement stronger security measures.

  5. Third party or supplier chain attacks: As industries become more interconnected, the supply chain becomes a prime target for cybercriminals. A breach in the supply chain could compromise the entire network. For example, IT supplier Tietoevry's Swedish data centre was hit by ransomware in January 2024, which affected several retail stores and customers across Sweden (Tietoevry, 2024).

  6. Cybersecurity-trained workforce: The increasing demand for a specialised cybersecurity-trained workforce will create a significant shortage of qualified professionals. This skills gap poses a significant threat to the security of Operator 5.0 environments. Without highly skilled personnel to manage sophisticated security incidents, monitor systems and respond to cyber threats, these environments will be vulnerable to attack. For example, the Swedish Transport Agency's mishandled IBM outsourcing deal led to a massive data breach, exposing the private data of all vehicles in Sweden in 2017 (BBC, 2017).

Figure 5
A classification diagram listing five A I attack types with bracketed bullet descriptions.The classification diagram presents five attack categories arranged vertically on the left side, each connected by a right curly bracket to a rectangular box containing bullet-point descriptions on the right. From top to bottom, the first category label is “Prompt Injection”, connected to a box containing two bullet points: “attack specific to A I models based on Natural Language Processing” and “triggering an unintended response by manipulating input to the A I system”. The second category label is “Evasion Attacks”, connected to a box containing four bullet points: “manipulating input data to A I systems; mostly image classifiers”, “causes incorrect decisions or classifications”, “exploit the model’s vulnerabilities without altering the model itself or the underlying algorithm”, and “for example, adding a sticker to the stop sign to confuse a self-driving car”. The third category label is “Training Data Poisoning”, connected to a box containing three bullet points: “injecting inaccurate data into the dataset that is used to train an A I model”, “poisoned data may not be quickly identifiable within the vast amount of training data”, and “compromised models that behave unpredictably, such as by misclassifying malicious activities as benign”. The fourth category label is “Model Denial of Service”, connected to a box containing three bullet points: “aims to overwhelm the A I systems capacity”, “slower them with a flood of requests or complex data inputs”, and “disrupt A I system's services, affecting legitimate users from their use”. The fifth category label is “Model Theft”, connected to a box containing four bullet points: “unauthorised access and stealing of A I models”, “attackers intent to reproduce or copy or reverse-engineer proprietary technologies without authorisation”, “financial loss to organisations that invest in A I development”, “stolen or misused models can be exploited to identify vulnerabilities, leading to further cyberattacks or data breaches”.

Cybersecurity risks to AI systems. Source: Adapted from Steve Moore (2024) 

Figure 5
A classification diagram listing five A I attack types with bracketed bullet descriptions.The classification diagram presents five attack categories arranged vertically on the left side, each connected by a right curly bracket to a rectangular box containing bullet-point descriptions on the right. From top to bottom, the first category label is “Prompt Injection”, connected to a box containing two bullet points: “attack specific to A I models based on Natural Language Processing” and “triggering an unintended response by manipulating input to the A I system”. The second category label is “Evasion Attacks”, connected to a box containing four bullet points: “manipulating input data to A I systems; mostly image classifiers”, “causes incorrect decisions or classifications”, “exploit the model’s vulnerabilities without altering the model itself or the underlying algorithm”, and “for example, adding a sticker to the stop sign to confuse a self-driving car”. The third category label is “Training Data Poisoning”, connected to a box containing three bullet points: “injecting inaccurate data into the dataset that is used to train an A I model”, “poisoned data may not be quickly identifiable within the vast amount of training data”, and “compromised models that behave unpredictably, such as by misclassifying malicious activities as benign”. The fourth category label is “Model Denial of Service”, connected to a box containing three bullet points: “aims to overwhelm the A I systems capacity”, “slower them with a flood of requests or complex data inputs”, and “disrupt A I system's services, affecting legitimate users from their use”. The fifth category label is “Model Theft”, connected to a box containing four bullet points: “unauthorised access and stealing of A I models”, “attackers intent to reproduce or copy or reverse-engineer proprietary technologies without authorisation”, “financial loss to organisations that invest in A I development”, “stolen or misused models can be exploited to identify vulnerabilities, leading to further cyberattacks or data breaches”.

Cybersecurity risks to AI systems. Source: Adapted from Steve Moore (2024) 

Close modal

Operator 5.0 plays a crucial role in cybersecurity by actively monitoring systems for threats, collaborating with intelligent and autonomous systems to ensure safe responses and promoting cyber hygiene and awareness training. As both user and controller of these intelligent systems, operator 5.0 must possess technical skills and a deep understanding of potential security risks to manage cybersecurity in Industry 5.0 environments effectively.

Therefore, for operator 5.0, it is very important to always be proactive and vigilant because she/he play a vital role in ensuring the system's security. Some examples from the past show how some operators have saved organisations from huge damage. In one case, Marcus Hutchins, a cybersecurity hacker, played a crucial role in stopping the WannaCry ransomware attack (NBC NEWS, 2017). His discovery of a vulnerability within the malware itself allowed him to create a “sinkhole”, effectively halting the spread of the infection and preventing further damage. In another case, an attacker exploited a remote access program to raise sodium hydroxide levels in a Florida water plant, but this was quickly noticed and reversed by a vigilant operator (The Telegraph, 2021). These instances lay the groundwork for the importance of humans or operators as a bridge between using new and advanced technologies.

Thus, this paper has proposed a Cybersecurity Framework (Figure 6) using the People, Process and Technology (PPT) model in the context of Operator 5.0 in the inner shell. The framework also includes cybersecurity countermeasures for Operator 5.0 in the outer shell. Details of these cybersecurity countermeasures are provided in section 3.3. The Framework has aligned its key components, PPTs, with Operator 5.0's goal within Industry 5.0. This Framework consists of hardware, software and liveware (operator 5.0). At the heart of this framework is Operator 5.0, emphasising the importance of balancing Process and Technology. This balance is crucial for creating an efficient operational environment, which combines structured workflows with advanced technology, particularly in AI and automation. This integration enables organisations to detect and respond to cybersecurity threats more effectively and efficiently. The role of Operator 5.0 centres on strategy, creativity and complex decision-making, while routine tasks and data processing are delegated to AI-driven systems. By integrating AI and machine learning (ML), Operator 5.0 enhances human capabilities, empowering decision-making and driving greater operational efficiency. Additionally, other technologies like biometric sensors, eye-tracking, facial analysis, Electroencephalogram (EEG), smart wearables, VR/AR can measure Operator 5.0 state. In the literature, authors have mentioned measuring operators' physiological and mental states to evaluate their performance (Golan et al., 2020). Authors have discussed that motivation, learning, fatigue, emotions, attentiveness and propensity for error are key dimensions of operator's performance that can be measured by leveraging various technologies like smart watches, smart rings, or even brain computer interfaces like, EEG (electroencephalogram) devices.

Figure 6
A concentric circular framework diagram linking “Human-centric”, “Sustainable”, and “Resilience” with security layers.The concentric circular framework diagram contains three structural layers arranged from center to outer boundary. At the center is a small circle labeled “Operator 5.0”, positioned above two overlapping smaller circles labeled “Process” and “Technology”, each containing a small icon. The “Operator 5.0” circle contains a group of humans with their arms raised upward, the “Process” circle contains a gear icon, and the “Technology” circle contains a robotic arm icon. Around these three inner circles are colored curved arrows connecting them in a triangular flow. Adjacent to these arrows are short bullet lists. To the left of the inner cluster appear “Real-time threat intelligence”, “Adaptive defense mechanisms”, “A I-powered incident response”, “Automation of repetitive and routine tasks” connecting them to Process circle. Below the inner cluster appear: “A I for real-time threat detection”, “Autonomous defense systems”, “Cloud-based security tools” connecting them to Technology circle. To the right of the inner cluster appear “Skills in A I-driven threat detection”, “Continuous training on emerging threats and tools”, “Human-A I trust-building”, “Balanced workload (less stress, fatigue, and frustration)” connecting them to Operator 5.0 circle. Surrounding this inner structure is a larger circle containing three grey circular nodes positioned triangularly. At the top is “Human-centric” with a small icon of three connected people. At the bottom left is “Sustainable” with a recycling-style icon. At the bottom right is “Resilience” with a curved line icon resembling mirrored arcs. Beneath “Sustainable” are bullet points: “Energy efficiency”, “Reduced cost”, “Global collaboration”. To the right of “Resilience” are bullet points: “A I, M L, D L”, “Big data”, “Cloud or Edge or Fog computing”, “I I o T”, “E E G”, “Smart wearables”, “Blockchain”, “Threat Intelligence”, “Advanced security controls”, “Cryptography”, “Cyber Resilience Act”, “Governance, policies, regulations, guidelines, and standards”, “Backups”. To the left of “Human-centric” are bullet points: “User-friendly Security”, “Security Culture; holistic security awareness”, “Effective Training”, “Evaluating the security of partners and suppliers”, “Privacy preserving; federated learning”, “Cobot”. Enclosing all elements is a large outer boundary circle. Along the top arc is the label “Implement Security Standards, Directives, and Regulations”. Along the right arc is the label “Data and Model Security”. Along the bottom right arc is the label “Operational Security and standards”. Along the bottom left arc is the label “Control Access to Data and Models”. Along the left arc is the label “Consult with External Security Experts”.

Cybersecurity framework for Operator 5.0 based on People, Processes and Technologies (PPTs). Source: adapted from Kour et al. (2024) in the context of Industry 5.0

Figure 6
A concentric circular framework diagram linking “Human-centric”, “Sustainable”, and “Resilience” with security layers.The concentric circular framework diagram contains three structural layers arranged from center to outer boundary. At the center is a small circle labeled “Operator 5.0”, positioned above two overlapping smaller circles labeled “Process” and “Technology”, each containing a small icon. The “Operator 5.0” circle contains a group of humans with their arms raised upward, the “Process” circle contains a gear icon, and the “Technology” circle contains a robotic arm icon. Around these three inner circles are colored curved arrows connecting them in a triangular flow. Adjacent to these arrows are short bullet lists. To the left of the inner cluster appear “Real-time threat intelligence”, “Adaptive defense mechanisms”, “A I-powered incident response”, “Automation of repetitive and routine tasks” connecting them to Process circle. Below the inner cluster appear: “A I for real-time threat detection”, “Autonomous defense systems”, “Cloud-based security tools” connecting them to Technology circle. To the right of the inner cluster appear “Skills in A I-driven threat detection”, “Continuous training on emerging threats and tools”, “Human-A I trust-building”, “Balanced workload (less stress, fatigue, and frustration)” connecting them to Operator 5.0 circle. Surrounding this inner structure is a larger circle containing three grey circular nodes positioned triangularly. At the top is “Human-centric” with a small icon of three connected people. At the bottom left is “Sustainable” with a recycling-style icon. At the bottom right is “Resilience” with a curved line icon resembling mirrored arcs. Beneath “Sustainable” are bullet points: “Energy efficiency”, “Reduced cost”, “Global collaboration”. To the right of “Resilience” are bullet points: “A I, M L, D L”, “Big data”, “Cloud or Edge or Fog computing”, “I I o T”, “E E G”, “Smart wearables”, “Blockchain”, “Threat Intelligence”, “Advanced security controls”, “Cryptography”, “Cyber Resilience Act”, “Governance, policies, regulations, guidelines, and standards”, “Backups”. To the left of “Human-centric” are bullet points: “User-friendly Security”, “Security Culture; holistic security awareness”, “Effective Training”, “Evaluating the security of partners and suppliers”, “Privacy preserving; federated learning”, “Cobot”. Enclosing all elements is a large outer boundary circle. Along the top arc is the label “Implement Security Standards, Directives, and Regulations”. Along the right arc is the label “Data and Model Security”. Along the bottom right arc is the label “Operational Security and standards”. Along the bottom left arc is the label “Control Access to Data and Models”. Along the left arc is the label “Consult with External Security Experts”.

Cybersecurity framework for Operator 5.0 based on People, Processes and Technologies (PPTs). Source: adapted from Kour et al. (2024) in the context of Industry 5.0

Close modal

Additionally, the framework centres around improving cybersecurity operations by integrating three main pillars of Industry 5.0, i.e. Human-centricity, Sustainability and Resilience. Each of these principles acts as a pillar for all three components of the PPT model. We know that Industry 5.0 is a human-centric industry that puts people/liveware/operator at its heart. It focuses on human–machine collaboration, driving customised products, enhancing customer satisfaction and advancing economic growth in modern businesses. Operator 5.0 plays an important role in ensuring the cybersecurity of Industry 5.0 environments both as a user and controller of intelligent systems. Human operators are no longer passive recipients of automated processes but active participants in decision-making and problem-solving with intelligent systems. To manage cybersecurity in this environment, Operator 5.0 must have technical skills and awareness of potential security risks. Thus, the human-centric pillar ensures that people remain at the core of cybersecurity operations, even as technology evolves. Key components include building expertise in AI-driven threat detection, providing continuous training to keep teams updated on emerging threats and tools and encouraging cross-team collaboration. Human operators are often the weakest link in cybersecurity. Ensuring that Operator 5.0 is continuously trained on emerging threats, social engineering tactics and safe cyber practices is essential in maintaining system integrity and resilience. Researchers are discussing the role of human-centric cyber defence that prioritises user-friendly, adaptive security systems, behavioural analytics and gamified training to reduce human error. Thus, training operators through awareness, responsibility and a strong security culture enhances overall cyber resilience (Ayodele et al., 2025). Further, an interdisciplinary Human-Centric Cybersecurity Framework has been proposed that integrates psychological resilience, adaptive training, socio-technical approach and ethical AI principles to build a resilient and inclusive cybersecurity ecosystem (Khadka and Ullah, 2025). Additionally, an important aspect of this pillar is the emphasis on Human-AI trust-building, which is critical for ensuring that operators are comfortable and confident in working alongside AI-powered systems and tools. This trust is crucial for successful human-machine collaboration. Researchers have proposed a Symbiotic Integration Framework (SIF) that promotes continuous interaction and ethical oversight between AI systems and human operators to foster adaptive learning and ethical alignment in real-time cybersecurity threat scenarios (Saadallah et al., 2025).

On the other hand, the Sustainable pillar highlights the need for energy-efficient, resource-optimised, adaptive and automated solutions that can support cybersecurity efforts in real-time. This can include processes like real-time threat intelligence, adaptive defence mechanisms, AI-powered incident response and automating repetitive tasks and routine operations. By automating repetitive tasks, this pillar can ensure that human resources are used efficiently, allowing organisations to focus their attention on other high-priority areas. This can further lead to streamlined workflows, better resource use and less operational waste. Sustainability can also highlight the need for cloud-based security tools and AI-driven systems to optimise energy consumption and lower the environmental footprint of cybersecurity infrastructures. Thus, sustainability in this context is about creating a system that can continuously operate and adapt without exhausting human or technological resources.

Finally, the Resilience pillar underlines the importance of having robust, autonomous and well-trained operators in place to detect and respond to threats. According to Romero and Stahre (2021), Resilient Operator 5.0 is defined as “a smart and skilled operator that uses human creativity, ingenuity, and innovation empowered by information and technology as a way of overcoming obstacles in the path to create new, frugal solutions for guaranteeing manufacturing operations sustainable continuity and workforce wellbeing in light of difficult and/or unexpected conditions”. Thus, Operator 5.0 plays a critical role in maintaining resilience by continuously enhancing their skills in AI-driven threat detection and working collaboratively across teams to respond to emerging cybersecurity challenges and unexpected conditions (Mouhib et al., 2023). To overcome these unexpected conditions, the resilience pillar can include processes like the use of adaptive defence mechanisms, AI-powered incidence response and real-time threat detection, ensuring that the organization can quickly respond to and recover from these conditions. On the technology front, the implementation of AI, along with autonomous defence systems and cloud-based security tools, reinforces the security infrastructure's capacity to withstand these unexpected conditions.

Together, these three interconnected pillars create a comprehensive cybersecurity approach for Operator 5.0. Integrating advanced technology with well-structured processes, along with the ongoing development of human skills and collaboration, creates an efficient but also human-centric, resilient and sustainable system in the face of evolving cyber threats. This framework reflects the increasing role of AI and automation in cybersecurity, while still recognising the irreplaceable value of human expertise and oversight. Additionally, the epicentre where the three elements of the PPT framework meet with all the aspects of Industry 5.0 is the optimal point where Operator 5.0 plays a critical role in achieving cybersecurity within Industry 5.0. In future, we will also look into the depth of this epicentre and how operators can achieve this and broaden this intersecting area for better cybersecurity within the context of Industry 5.0.

In addition, implementing this proposed framework within any industrial setting follows a structured approach across the following phases defined by Khadka and Ullah (2025).

  • Assessment Phase:

    • Examine the industry's current maturity and operational capabilities with respect to Industry 5.0.

    • Access its current state of technological infrastructure.

    • Evaluate the existing operator's skills.

  • Design Phase:

    • Based on results from the assessment phase, develop the roadmap for operator and technology integration.

    • Augment the operator's role through process redesign for human–machine collaboration.

    • Develop a comprehensive training curriculum to address identified skill gaps.

    • Plan a change management strategy for workforce support.

  • Implementation Phase:

    • Provide life to designs through pilot programs in specific areas to test how new technologies integrate with the operator and collect feedback.

    • Execute tailored training programs and actively cultivate a collaborative organisational culture through workshops, seminars, hands-on practices and leadership support.

  • Evaluation Phase:

    • Ensure continuous improvements by establishing Key Performance Indicators (KPIs) to monitor the organisation's and operators' overall performance.

    • Collect regular feedback from operators about their experiences and challenges.

    • Iteratively refining the framework to adapt to evolving technological landscapes and business needs, ensuring long-term success and sustainability.

Operator 5.0 refers to the concept of the next generation of industrial operations, driven by Industry 5.0 and enabled by advanced technologies like AI, ML, IIoT, Robotics, Virtual Reality/Augmented Reality, Metaverse, 6G, Human–Machine Collaboration (COBOT), etc. Cybersecurity measures for Operator 5.0 are essential to safeguard these interconnected and highly automated systems from unique cybersecurity challenges, as discussed in Section 3.1. To address these cybersecurity challenges, industries must implement a comprehensive cybersecurity strategy that includes Zero Trust Architecture (ZTA), network segmentation, strong identity and access management, data protection measures, operational security practices and protection of emerging technologies. Further, collaboration with suppliers, compliance with regulations and participation in industry forums are essential for maintaining a robust cybersecurity posture in the era of Industry 5.0.

Figure 7 provides a comprehensive overview of cybersecurity measures to be considered by Operator 5.0 as a user and controller of AI systems (Steve Moore, 2024). It outlines key standards, directives and regulations that organisations must adhere to, such as GDPR, ISO/IEC 27001 (ISO, 2022) and the National Institute of Standards and Technology Cybersecurity Framework (NIST, 2024). To control access to data and models, Figure 7 recommends implementing c (RBAC) (Computer Security Division, 2016; Ferraiolo et al., 1999; Sandhu, 1998), multi-factor authentication (MFA) and biometric or behavioural authentication. Additionally, adopting a ZTA can enhance security by enforcing strict verification and authorisation policies (Stafford, 2020).

Figure 7
A grouped list diagram of A I security measures with five bracketed categories.The grouped list diagram presents five category labels arranged vertically on the left side, each connected by a right curly bracket to a rectangular section containing bullet-point text on the right. From top to bottom, the first category label reads “Implement Security Standards, Directives, and Regulations”, connected to a box listing “G D P R (General Data Protection Regulation)”, “I S O or I E C 27001 (Information Security Management Systems)”, “N I S T Cybersecurity Framework”, “I S O or I E C 27032: 2023; Cybersecurity — Guidelines for Internet security”, “European Union A I Act”, “European Commission Guidelines for Trustworthy A I”, “Cyber Resilient Act”, and “N I S 2 Directive”. The second category label reads “Control Access to Data and Models”, connected to a box listing “Role-based access control (R B A C)”, “Multi-factor authentication (M F A)”, “Biometric and behavioral authentication”, and “Zero Trust Architecture (Z T A)”. The third category label reads “Data and Model Security”, connected to a box listing: “By securing the code, industries can protect A I applications from exploits and reduce the risk of cybersecurity threats”, “Regular code reviews”, “Using strong encryption and secure key management protects sensitive data from interception and unauthorized access”, “Vulnerability assessments”, and “Safeguard the integrity and confidentiality of data handled by A I systems”. The fourth category label reads “Operational Security and standards”, connected to a box listing “Training and eduation programmes of workforce”, “Development of comprehensive incident response plan to effectively handle cybersecurity threats”, “Regularly monitor networks and systems for signs of compromise”, “Perform regular risk assessments to detect and mitigate potential vulnerabilities”, “N I S T S P 800-82 r 3- Guide to Operational Technology Security”, and “I S A or I E C 62443 Series of Standards”. The fifth category label reads “Consult with External Security Experts”, connected to a box listing “Provide new insights on vulnerabilities and suggest best practices and innovative risk mitigations” and “Carry out comprehensive security assessments and penetration tests to uncover and fix security gaps”.

Cybersecurity countermeasures for the operator of AI Systems. Source: Adapted from Steve Moore (2024) 

Figure 7
A grouped list diagram of A I security measures with five bracketed categories.The grouped list diagram presents five category labels arranged vertically on the left side, each connected by a right curly bracket to a rectangular section containing bullet-point text on the right. From top to bottom, the first category label reads “Implement Security Standards, Directives, and Regulations”, connected to a box listing “G D P R (General Data Protection Regulation)”, “I S O or I E C 27001 (Information Security Management Systems)”, “N I S T Cybersecurity Framework”, “I S O or I E C 27032: 2023; Cybersecurity — Guidelines for Internet security”, “European Union A I Act”, “European Commission Guidelines for Trustworthy A I”, “Cyber Resilient Act”, and “N I S 2 Directive”. The second category label reads “Control Access to Data and Models”, connected to a box listing “Role-based access control (R B A C)”, “Multi-factor authentication (M F A)”, “Biometric and behavioral authentication”, and “Zero Trust Architecture (Z T A)”. The third category label reads “Data and Model Security”, connected to a box listing: “By securing the code, industries can protect A I applications from exploits and reduce the risk of cybersecurity threats”, “Regular code reviews”, “Using strong encryption and secure key management protects sensitive data from interception and unauthorized access”, “Vulnerability assessments”, and “Safeguard the integrity and confidentiality of data handled by A I systems”. The fourth category label reads “Operational Security and standards”, connected to a box listing “Training and eduation programmes of workforce”, “Development of comprehensive incident response plan to effectively handle cybersecurity threats”, “Regularly monitor networks and systems for signs of compromise”, “Perform regular risk assessments to detect and mitigate potential vulnerabilities”, “N I S T S P 800-82 r 3- Guide to Operational Technology Security”, and “I S A or I E C 62443 Series of Standards”. The fifth category label reads “Consult with External Security Experts”, connected to a box listing “Provide new insights on vulnerabilities and suggest best practices and innovative risk mitigations” and “Carry out comprehensive security assessments and penetration tests to uncover and fix security gaps”.

Cybersecurity countermeasures for the operator of AI Systems. Source: Adapted from Steve Moore (2024) 

Close modal

Securing the code is another critical aspect of AI security by Operator 5.0. Regular code reviews and vulnerability assessments can help detect and resolve weaknesses in the codebase. By securing the code, organisations can protect AI applications from exploits and minimise the risks of security breaches. Encrypting model data is essential to protect sensitive information from unauthorised access. Strong encryption algorithms and secure management of encryption keys can safeguard data from interception and unauthorised disclosure. Next, operational security includes cybersecurity training and education of the workforce, developing comprehensive incident response plans to effectively handle security breaches, regularly monitoring networks and systems for signs of compromise, and conducting regular risk assessments to identify and address potential vulnerabilities using a series of Standards like IEC 62443. Further, consultation with external cybersecurity experts can provide new insights on vulnerabilities and suggest best practices and innovative risk mitigations. Conducting thorough security assessments and penetration testing can help uncover and fix security gaps in AI systems.

In the age of Industry 5.0, where humans and machines collaborate and complement each other, cybersecurity must be reimagined to protect both physical and digital assets. Operator 5.0 plays a critical role in this landscape, requiring a new and advanced set of skills and tools to safeguard these assets. To accomplish this, a cybersecurity framework for Operator 5.0, integrating three components: PPTs, has been proposed for advanced threat detection and response mechanisms using AI, ML, automated threat intelligence, blockchain, human-centric design, etc., to ensure the resilience and security of Industry 5.0 environments. By addressing these critical areas, industries can mitigate risks, protect sensitive data, and ensure the continued success of their Operator 5.0 initiatives. The proposed framework's limitation is that it is theoretically derived from a synthesis of existing literature and has not yet been empirically tested in real-world scenarios. In the future, the framework will be implemented in an industrial setting to explore the epicentre where the PPT framework's three elements converge with Industry 5.0 aspects. Thus, we will delve deeper into the epicenter's characteristics and investigate how operators can expand this intersecting area to improve cybersecurity within Industry 5.0. As Industry 5.0 continues to evolve, cybersecurity strategies must also be advanced, ensuring that human creativity and technological innovation can grow to streamline workflows in this new industrial environment.

A photograph of Ravdeep Kour smiling while looking at the camera.
Ravdeep Kour is Senior Lecturer in the Division of Operation and Maintenance Engineering at the Luleå University of Technology with 20 years of academic and research experience. Her focus lies in developing cybersecurity frameworks, tools, methods, and technologies for industries. With a good publication record, she has contributed significantly to the field, addressing topics such as cyber-attack simulation, cyber kill chain models, cybersecurity risk assessment, cybersecurity maturity models, and more. Ravdeep has a diverse academic background, holding a PhD in Operation & Maintenance Engineering and a Master in Computer Science Engineering.

A photograph of Ramin Karim looking at the camera with a neutral expression.
Ramin Karim is PhD in Operation and Maintenance Engineering with specialisation in eMaintenance. Currently, he is a Subject Head and Professor in the Division of Operation and Maintenance Engineering at Luleå University of Technology and Director of the Centre of Intelligent Asset Maintenance (CIAM). He has worked for more than 15 years in the IT industry after obtaining his degree in computer science. He is responsible for the eMaintenance LAB, an applied laboratory for research and innovation in Industrial AI and eMaintenance. His research interest includes data analytics and predictive technology closely connected to operation and maintenance of industrial assets. Prof. Karim has initiated and developed the concept and platform called “AI Factory”, which is a universal concept for cross-industrial data and model sharing based on digital and AI technologies.

The authors would like to acknowledge Luleå Railway Research Center (JVTC), Centre of Intelligent Asset Management (CIAM), Energimyndigheten, Vinnova, & AI Factory for financial support and eMaintenance lab for carrying out this work.

Aitel
,
D.
(
2013
), “
Cybersecurity essentials for electric operators
”,
The Electricity Journal
, Vol. 
26
No. 
1
, pp. 
52
-
58
, doi: .
Ayodele
,
G.T.
,
Abdulrahman
,
I.A.
,
Alebiosu
,
J.
,
Egbedion
,
G.E.
and
Akinbolajo
,
O.E.
(
2025
), “
Human-centric cybersecurity: addressing the human factor in cyber defense strategies
”.
BBC
(
2017
), “
Sweden data leak ‘a disaster’, says PM. NEWS
”,
available at:
 Link to the website
CNN
(
2021
),
What We Know about the Pipeline Ransomware Attack: How it Happened, Who Is Responsible and More
,
NEWS
.
CNN
(
2024
),
Finance Worker Pays Out $25 Million after Video Call with Deepfake Chief Financial Officer
,
NEWS
,
available at:
 Link to the website
Computer Security Division, I. T. L
(
2016
),
Role Based Access Control | CSRC | CSRC
,
NIST
,
available at:
 Link to the website
Ferraiolo
,
D.F.
,
Barkley
,
J.F.
and
Kuhn
,
D.R.
(
1999
), “
A role-based access control model and reference implementation within a corporate intranet
”,
ACM Transactions on Information and System Security (TISSEC)
, Vol. 
2
No. 
1
, pp. 
34
-
64
, doi: .
Golan
,
M.
,
Cohen
,
Y.
and
Singer
,
G.
(
2020
), “
A framework for operator–workstation interaction in Industry 4.0
”,
International Journal of Production Research
, Vol. 
58
No. 
8
, pp. 
2421
-
2432
, doi: .
Handri
,
E.Y.
,
Putro
,
P.A.W.
and
Sensuse
,
D.I.
(
2023
), “
Evaluating the people, process, and technology priorities for NIST cybersecurity framework implementation in E-Government
”,
Proceedings - 2023 IEEE International Conference on Cryptography, Informatics, and Cybersecurity: Cryptography and Cybersecurity: Roles, Prospects, and Challenges, ICoCICs 2023
, pp. 
82
-
87
, doi: .
Horak
,
R.
(
2008
),
Webster’s New World Telecom Dictionary
,
John Wiley & Sons
,
Washington
.
ISO
(
2022
), “
ISO/IEC 27001:2022: information security, cybersecurity and privacy protection — information security management systems — requirements
”,
Standard
,
available at:
 Link to the website
Khadka
,
K.
and
Ullah
,
A.B.
(
2025
), “
Human factors in cybersecurity: an interdisciplinary review and framework proposal
”,
International Journal of Information Security
, Vol. 
24
No. 
3
, pp. 
1
-
13
, doi: .
Kong
,
F.
,
Lu
,
Z.
,
Kong
,
L.
and
Chen
,
T.
(
2023
), “Information field in a manufacturing System: concepts, measurements and applications”,
Advanced Engineering Informatics
, Vol. 
56
, 101946, doi: .
Kour
,
R.
and
Karim
,
R.
(
2021
), “
Cybersecurity workforce in railway: its maturity and awareness
”,
Journal of Quality in Maintenance Engineering
, Vol. 
27
No. 
3
, pp. 
453
-
464
, doi: .
Kour
,
R.
,
Karim
,
R.
,
Dersin
,
P.
and
Venkatesh
,
N.
(
2024
), “
Cybersecurity for Industry 5.0: trends and gaps
”,
Frontiers of Computer Science
, Vol. 
6
, 1434436, doi: .
Kullman
,
K.
,
Asher
,
N.B.
and
Sample
,
C.
(
2019
), “
Operator impressions of 3D visualizations for cybersecurity analysts
”,
Proceedings of the 18th European Conference on Cyber Warfare and Security, ECCWS 2019
,
University of Coimbra, Portugal
, pp. 
257
-
266
.
Leavitt, H.J.
(
1964
), “
Applied organization change in industry: structural, technological and humanistic approaches
”, in
March, J.G. (Ed.)
,
Handbook of Organizations
,
Routledge
.
Mouhib
,
H.
,
Amar
,
S.
,
Elrhanimi
,
S.
and
El Abbadi
,
L.
(
2023
),
An Extended Review of the Manufacturing Transition under the Era of Industry 5.0
,
2023 7th IEEE Congress on Information Science and Technology (CiSt)
, pp. 
709
-
714
.
NBC NEWS
(
2017
),
Marcus Hutchins ‘Saved the U.S.’ from WannaCry Cyberattack on Bedroom Computer
,
NEWS
,
available at:
 Link to the website
NIST
(
2024
), “
The NIST cybersecurity framework (CSF) 2.0
”,
Standard
,
available at:
 Link to the website
Parent
,
M.
and
Cusack
,
B.
(
2016
), “Cybersecurity in 2016: people, technology, and processes”,
Business Horizons
, Vol. 
59
No. 
6
, pp. 
567
-
569
, doi: .
Paul
,
C.L.
and
Dykstra
,
J.
(
2017
), “
Understanding operator fatigue, Frustration, and cognitive workload in tactical cybersecurity operations contents
”,
available at:
 Link to the website
Romero
,
D.
and
Stahre
,
J.
(
2021
), “
Towards the resilient Operator 5.0: the future of work in smart resilient manufacturing systems
”,
Procedia CIRP
, Vol. 
104
, pp. 
1089
-
1094
, doi: .
Saadallah
,
M.
,
Shahim
,
A.
and
Khapova
,
S.
(
2025
), “
Optimizing AI and human expertise integration in cybersecurity: enhancing operational efficiency and collaborative decision-making
”.
Sandhu
,
R.S.
(
1998
), “Role-based access control”, in
Advances in Computers
,
Elsevier
, Vol. 
46
, pp. 
237
-
286
, doi: .
Schneier
,
B.
(
2015
),
Secrets and Lies: Digital Security in a Networked World
,
John Wiley & Sons
,
Washington
.
Slay
,
J.
and
Miller
,
M.
(
2007
), “
Lessons learned from the maroochy water breach
”,
International Conference on Critical Infrastructure Protection
, pp. 
73
-
82
,
available at:
 Link to the website
Stafford
,
V.
(
2020
),
Zero Trust Architecture
, Vol. 
800
,
NIST Special Publication
, p.
207
.
Steve Moore
(
2024
), “
AI cyber security: securing AI systems against cyber threats
”.
The
,
T.
(
2021
),
Hacker Tries to Poison Water Supply in Florida City
,
NEWS
,
available at:
 Link to the website
Tietoevry
(
2024
), “
Ransomware attack in Sweden – restoration work progressing
”,
Tietoevry, available at:
 Link to the website
Verisframework
(
2024
), “
Threat actors
”,
Report, available at:
 Link to the website
Verizon
(
2024
), “
2024 data breach investigations report
”,
Report, available at:
 Link to the website
Published in Organizational Cybersecurity Journal: Practice, Process and People. Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) license. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this license may be seen at Link to the terms of the CC BY 4.0 licence.

or Create an Account

Close Modal
Close Modal