Published July 30, 2026 | Version CC-BY-NC-ND 4.0

Operationalizing Deception Technology in ICS/OT: A Control Mapping Framework for Critical Infrastructure Cybersecurity

  • 1. Assistant Professor, Department of Computer Science, Southern New Hampshire University, United States.

Description

Abstract: Deception technologies, including honeypots, decoy devices, honeytokens, and simulated industrial assets, are increasingly relevant to industrial control systems and operational technology (ICS/OT) security because they can generate high-confidence alerts when adversaries interact with assets that legitimate operators should not use. Prior dissertation research on deception technology adoption in U.S. manufacturing and critical infrastructure identified persistent barriers, including compatibility concerns, limited resources, inadequate professional knowledge, infrastructure constraints, and the absence of policy structures that enable practitioners to make deception technology actionable. This paper extends that work without collecting new human-subject data. Using design science and qualitative document analysis, the study maps ICS/OT deception technology use cases to recognized cybersecurity frameworks and control objectives, including the NIST Cybersecurity Framework 2.0, NIST SP 800-82 Revision 3, NIST SP 800-53 Revision 5, IEC 62443-2-1:2024 security program requirements, CISA Cross-Sector Cybersecurity Performance Goals, and MITRE ATT&CK for ICS. The result is the Deception Technology Integration Control Framework (DTICF). This practitioner-oriented artefact translates deception technology from a novel security tool into an auditable set of governance, architecture, monitoring, response, and continuous improvement practices. The framework provides a control crosswalk, an implementation model, a maturity model, and a set of metrics that organisations can use to evaluate deception readiness and plan low-risk deployment in safety-sensitive OT environments.

Files

C372316030726.pdf

Files (522.2 kB)

Name Size Download all
md5:1270b7494eca3b8a143b0fb921c56671
522.2 kB Preview Download

Additional details

Identifiers

Dates

Accepted
2026-07-15
Manuscript received on 08 June 2026 | First Revised Manuscript received on 12 June 2026 | Second Revised Manuscript received on 20 June 2026 | Manuscript Accepted on 15 July 2026 | Manuscript published on 30 July 2026.

References

  • D. Ward, "Enhancing security: A comprehensive study on deception technology integration in manufacturing and critical infrastructure," Doctoral dissertation, University of the Cumberlands, 2025. [Online]. Available: https://www.proquest.com/openview/ebf38e1aa599115548a9f7486917 e669/1. Accessed: Jun. 8, 2026.
  • K. Stouffer, M. Pease, C. Y. Tang, T. Zimmerman, V. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, "Guide to operational technology (OT) security," NIST Special Publication 800-82, Rev. 3, National Institute of Standards and Technology, 2023. [Online]. Available: DOI: https://doi.org/10.6028/NIST.SP.800-82r3.
  • National Institute of Standards and Technology, "The NIST Cybersecurity Framework (CSF) 2.0," NIST Cybersecurity White Paper 29, 2024. [Online]. Available: DOI: https://doi.org/10.6028/NIST.CSWP.29.
  • Joint Task Force, "Security and privacy controls for information systems and organizations," NIST Special Publication 800-53, Rev. 5, National Institute of Standards and Technology, 2020. [Online]. Available: DOI: https://doi.org/10.6028/NIST.SP.800-53r5.
  • International Electrotechnical Commission, "IEC 62443-2-1:2024: Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners," IEC Webstore, 2024. [Online]. Available: Accessed: Jun. 8, 2026. https://webstore.iec.ch/en/publication/62883.
  • The MITRE Corporation, "ATT&CK for ICS matrix," MITRE ATT&CK v19.1, 2026. [Online]. Version history: Accessed: Jun. 8, 2026. Available: https://attack.mitre.org/matrices/ics/. https://attack.mitre.org/resources/versions/.
  • Cybersecurity and Infrastructure Security Agency, "Cross-Sector Cybersecurity Performance Goals, Version 2.0," U.S. Department of Homeland Security, 2025. [Online]. Accessed: Jun. 8, 2026. Available: https://www.cisa.gov/sites/default/files/2025 12/CPG_Report_2.0_508c.pdf.