Skip to main content

A Workforce Readiness Model for Deception Technology in ICS and OT Cybersecurity Programs

Page 1

International Research Journal of Engineering and Technology (IRJET)

e-ISSN: 2395-0056

Volume: 13 Issue: 06 | Jun 2026

p-ISSN: 2395-0072

www.irjet.net

A Workforce Readiness Model for Deception Technology in ICS and OT Cybersecurity Programs Daniel Ward Associate Professor, Department of Computer Science, Southern New Hampshire University, United States ---------------------------------------------------------------------------***-----------------------------------------------------------------------------become difficult to implement in an OT environment if it Abstract - Critical infrastructure organizations introduces unapproved scanning, unstable traffic, increasingly need personnel who can operate deception ambiguous alerts, or response actions that are not technology safely in industrial control systems and coordinated with operations. operational technology environments. Honeypots, honeytokens, decoy services, simulated engineering files, Deception technology offers a useful detection and and false credentials can generate high confidence intelligence capability for this environment. Rather than indicators when adversaries interact with assets that relying only on perimeter controls or signature-based legitimate operators should not use. However, prior alerts, deception technology uses decoy hosts, fake research on deception technology adoption in credentials, monitored files, simulated services, and false manufacturing and critical infrastructure found that operational artifacts that legitimate personnel should not implementation is constrained by compatibility concerns, normally touch. Interaction with a decoy can therefore limited resources, inadequate professional knowledge, produce a high confidence signal of reconnaissance, infrastructure constraints, and limited practical awareness. credential misuse, lateral movement, unauthorized access, This paper updates a prior policy framework into an or attacker staging. Recent deception research emphasizes engineering-oriented workforce readiness model suitable the value of honeypots and deception strategies for threat for practical program adoption. Using design science and detection and adversary observation [6]. In OT, however, qualitative document analysis, the paper synthesizes public the value of a deception signal depends on whether the cybersecurity standards, operational technology guidance, workforce is prepared to govern, interpret, and act on it workforce frameworks, incident response guidance, and safely. deception technology literature. The result is the Deception Workforce Readiness Model, which defines five domains: Prior dissertation research on deception technology governance literacy, OT context awareness, deception integration in manufacturing and critical infrastructure design, cyber intelligence translation, and response found that adoption was constrained by compatibility integration. The model provides a staged implementation concerns, limited resources, inadequate professional sequence and evidence artifacts that organizations can use knowledge, infrastructure constraints, and concerns about to convert deception technology from a tool concept into a system performance impacts [1]. The same research found governed workforce capability. The paper contributes a that awareness and practical skill were important to non-human subjects framework for improving readiness adoption and effective utilization [1]. These findings before deception technology is piloted in safety-sensitive suggest that deception technology is not only a tool environments. selection issue. It is also a workforce readiness issue. Organizations need personnel who can translate deception Key Words: critical infrastructure, cyber deception, concepts into authorized designs, safe deployment rules, honeypots, industrial control systems, operational monitoring procedures, incident response workflows, and technology, workforce readiness evidence artifacts.

1. INTRODUCTION

The purpose of this paper is to convert that adoption problem into an applied workforce readiness model. The paper does not collect new human participant data and does not use private operational logs. It synthesizes public standards and guidance to define a practical model that critical infrastructure organizations can use before piloting deception technology in safety-sensitive ICS and OT environments.

Industrial control systems (ICS) and operational technology (OT) environments support physical processes in manufacturing, water and wastewater, energy, transportation, building automation, and other critical infrastructure sectors. Cybersecurity decisions in these environments differ from ordinary enterprise information technology decisions because they must account for uptime, deterministic communications, safety, equipment lifecycle constraints, change control, and the division of responsibility between engineering and information security teams. For that reason, a security capability that appears straightforward in enterprise networks can

© 2026, IRJET

|

Impact Factor value: 8.315

1.1 Problem statement The central problem is that deception technology is often introduced as a technical experiment rather than as a

|

ISO 9001:2008 Certified Journal

|

Page 610


Turn static files into dynamic content formats.

Create a flipbook
A Workforce Readiness Model for Deception Technology in ICS and OT Cybersecurity Programs by IRJET Journal - Issuu