arXiv · 2509.07649
Leveraging Digital Twin-as-a-Service Towards Continuous and Automated Cybersecurity Certification
Abstract
Traditional risk assessments rely on manual audits and system scans, often causing operational disruptions and leaving security gaps. To address these challenges, this work presents Security Digital Twin-as-a-Service (SDT-aaS), a novel approach that leverages Digital Twin (DT) technology for automated, non-intrusive security compliance. SDT-aaS enables real-time security assessments by mirroring real-world assets, collecting compliance artifacts, and creating machine-readable evidence. The proposed work is a scalable and interoperable solution that supports open standards like CycloneDX and Web of Things (WoT), facilitating seamless integration and efficient compliance management. Empirical results from a moderate-scale infrastructure use case demonstrate its feasibility and performance, paving the way for efficient, on-demand cybersecurity governance with minimal operational impact.
Explore related subjects
Keep this discovery
Ioannis Koufos, Abdul Rehman Qureshi, Adrian Asensio, Allen Abishek, Efstathios Zaragkas, Ricard Vilalta, Maria Souvalioti, George Xilouris, Michael-Alexandros Kourtis. 2025-09-09. Leveraging Digital Twin-as-a-Service Towards Continuous and Automated Cybersecurity Certification. https://arxiv.org/abs/2509.07649
Cite the original work for its findings. Save a collection to share your selection of sources.