{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T23:35:52Z","timestamp":1776900952517,"version":"3.51.2"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032195395","type":"print"},{"value":"9783032195401","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-19540-1_15","type":"book-chapter","created":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T22:41:39Z","timestamp":1776897699000},"page":"284-302","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Phase-Driven Transitions in\u00a0Cyber-Physical Incident Command Systems: Communication Dynamics from\u00a0Tabletop Exercises"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-0118-925X","authenticated-orcid":false,"given":"Kenta","family":"Nakayama","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kenji","family":"Watanabe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ichiro","family":"Koshijima","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,4,1]]},"reference":[{"issue":"1","key":"15_CR1","first-page":"14","volume":"4","author":"AR Hadri","year":"2025","unstructured":"Hadri, A.R.: Hybrid warfare in the 21st century: a threat beyond the battlefield. Magna Carta Contemp. Soc. Sci. 4(1), 14\u201325 (2025)","journal-title":"Magna Carta Contemp. Soc. Sci."},{"key":"15_CR2","doi-asserted-by":"publisher","unstructured":"Stodolnik, M.: Cyber threats as hybrid activity against the European Union in light of the current geopolitical situation. Terroryzm - studia, analizy, prewencja, pp. 225\u2013248 (2025). https:\/\/doi.org\/10.4467\/27204383TER.25.021.21524","DOI":"10.4467\/27204383TER.25.021.21524"},{"key":"15_CR3","unstructured":"World Economic Forum: Global Cybersecurity Outlook 2025. World Economic Forum, Geneva (2025). https:\/\/reports.weforum.org\/docs\/WEF_Global_Cybersecurity_Outlook_2025.pdf"},{"key":"15_CR4","unstructured":"NEC: Cyberattacks on industrial control systems and security countermeasures (in Japanese). NEC Technical J. 17(2) (2017). https:\/\/jpn.nec.com\/techrep\/journal\/g17\/n02\/170204.html"},{"key":"15_CR5","unstructured":"CISA: Cyber-Attack Against Ukrainian Critical Infrastructure. https:\/\/www.cisa.gov\/news-events\/ics-alerts\/ir-alert-h-16-056-01"},{"key":"15_CR6","unstructured":"Hydro: Cyber-attack on Hydro. https:\/\/www.hydro.com\/en\/global\/media\/on-the-agenda\/cyber-attack\/"},{"key":"15_CR7","unstructured":"Handa Hospital: Expert Panel Report on the Computer Virus Incident at Handa Hospital. https:\/\/www.handa-hospital.jp\/topics\/2022\/0616\/index.html"},{"key":"15_CR8","unstructured":"Japan Construction Information Center: Report on the NUTS System Failure Incident. https:\/\/meikoukyo.com\/wp-content\/uploads\/2023\/07\/0bb9d9907568e832da8f400e529efc99.pdf"},{"key":"15_CR9","unstructured":"NISC (National center of Incident readiness and Strategy for Cybersecurity): Cybersecurity 2024: Annual Report FY2023 and Annual Plan FY2024. Cabinet Secretariat, Japan (2024). https:\/\/www.nisc.go.jp\/pdf\/policy\/kihon"},{"key":"15_CR10","unstructured":"World Economic Forum: Cyber Resilience Index 2022. World Economic Forum, Geneva (2022). https:\/\/www3.weforum.org\/docs\/WEF_Cyber_Resilience_Index_2022.pdf"},{"key":"15_CR11","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/s10207-025-01032-0","volume":"24","author":"K Khadka","year":"2025","unstructured":"Khadka, K., Ullah, A.B.: Human factors in cybersecurity: an interdisciplinary review and framework proposal. Int. J. Inf. Secur. 24, 119 (2025). https:\/\/doi.org\/10.1007\/s10207-025-01032-0","journal-title":"Int. J. Inf. Secur."},{"issue":"2","key":"15_CR12","doi-asserted-by":"publisher","first-page":"51","DOI":"10.37458\/ssj.2.2.3","volume":"2","author":"E Kadena","year":"2021","unstructured":"Kadena, E., Gupi, M.: Human factors in cybersecurity: risks and impacts. Secur. Sci. J. 2(2), 51\u201364 (2021)","journal-title":"Secur. Sci. J."},{"issue":"3","key":"15_CR13","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1080\/08874417.2020.1845583","volume":"62","author":"A Georgiadou","year":"2022","unstructured":"Georgiadou, A., Mouzakitis, S., Bounas, K., Askounis, D.: A cyber-security culture framework for assessing organization readiness. J. Comput. Inf. Syst. 62(3), 452\u2013462 (2022). https:\/\/doi.org\/10.1080\/08874417.2020.1845583","journal-title":"J. Comput. Inf. Syst."},{"issue":"1","key":"15_CR14","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1080\/07366981.2021.1977026","volume":"66","author":"SA Chamkar","year":"2022","unstructured":"Chamkar, S.A., Maleh, Y., Gherabi, N.: The human factor capabilities in security operation center (SOC). Edpacs 66(1), 1\u201314 (2022). https:\/\/doi.org\/10.1080\/07366981.2021.1977026","journal-title":"Edpacs"},{"issue":"2","key":"15_CR15","doi-asserted-by":"publisher","first-page":"162","DOI":"10.2478\/bsaft-2023-0016","volume":"28","author":"SL Burton","year":"2023","unstructured":"Burton, S.L., Burrell, D.N., Nobles, C., Jones, L.A.: Exploring the nexus of cybersecurity leadership, human factors, emotional intelligence, innovative work behavior, and critical leadership traits. Sci. Bull. 28(2), 162\u2013175 (2023). https:\/\/doi.org\/10.2478\/bsaft-2023-0016","journal-title":"Sci. Bull."},{"key":"15_CR16","unstructured":"Security Magazine: 5 Key Elements of Cyber Simulation Exercises to Boost Cyber Resilience. https:\/\/www.securitymagazine.com\/articles\/100762-5-key-elements-of-cyber-simulation-exercises-to-boost-cyber-resilience"},{"issue":"5","key":"15_CR17","doi-asserted-by":"publisher","first-page":"1081","DOI":"10.20965\/jdr.2017.p1081","volume":"12","author":"T Aoyama","year":"2017","unstructured":"Aoyama, T., Nakano, T., Koshijima, I., Hashimoto, Y., Watanabe, K.: On the complexity of cybersecurity exercises proportional to preparedness. J. Disaster Res. 12(5), 1081\u20131090 (2017). https:\/\/doi.org\/10.20965\/jdr.2017.p1081","journal-title":"J. Disaster Res."},{"key":"15_CR18","unstructured":"U.S. Department of Energy, CESER: Exercises and Training. https:\/\/www.energy.gov\/ceser\/exercises-and-training"},{"key":"15_CR19","doi-asserted-by":"publisher","unstructured":"Vykopal, J., Celeda, P., Svabensky, V., Hofbauer, M., Horak, M.: Research and practice of delivering tabletop exercises. In: Proceedings of the 29th Annual ACM Conference on Innovation and Technology in Computer Science Education (ITiCSE\u201924), pp. 220\u2013226 (2024). https:\/\/doi.org\/10.1145\/3649217.3653642","DOI":"10.1145\/3649217.3653642"},{"issue":"6","key":"15_CR20","doi-asserted-by":"publisher","DOI":"10.1002\/spy2.126","volume":"3","author":"GN Angafor","year":"2020","unstructured":"Angafor, G.N., Yevseyeva, I., He, Y.: Game-based learning: A review of tabletop exercises for cybersecurity incident response training. Security Privacy 3(6), e126 (2020). https:\/\/doi.org\/10.1002\/spy2.126","journal-title":"Security Privacy"},{"key":"15_CR21","unstructured":"Haddouch, R., Clouse, S.F., Wright, R.T., Floyd, T., Perry, P.: Strengthening incident response: lessons from cybersecurity tabletop exercises for rural critical infrastructure. In: Proceedings of the ISCAP Conference, vol. 10, no. 6201 (2024)"},{"key":"15_CR22","doi-asserted-by":"publisher","unstructured":"Abbott, G.R., Mcclain, J., Anderson, B., Nauer, K., Silva, A., Forsythe, C.: Log analysis of cyber security training exercises. Procedia Manuf. 3 (2015). https:\/\/doi.org\/10.1016\/j.promfg.2015.07.523","DOI":"10.1016\/j.promfg.2015.07.523"},{"key":"15_CR23","doi-asserted-by":"publisher","unstructured":"Veksler, V.D., Buchler, N., LaFleur, C.G., Yu, M.S., Lebiere, C., Gonzalez, C.: Cognitive models in cybersecurity: learning from expert analysts and predicting attacker behavior. Front. Psychol. 11 (2020). https:\/\/doi.org\/10.3389\/fpsyg.2020.01049","DOI":"10.3389\/fpsyg.2020.01049"},{"key":"15_CR24","doi-asserted-by":"publisher","unstructured":"Ur Rehman, M., Bahsi, H., Bukauskas, L., Knox, B.: Exploring trainees\u2019 behaviour in hands-on cybersecurity exercises through data mining. In: Proceedings of the 23rd European Conference on Cyber Warfare and Security (ECCWS), pp. 585\u2013593 (2024). https:\/\/doi.org\/10.34190\/eccws.23.1.2141","DOI":"10.34190\/eccws.23.1.2141"},{"key":"15_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1007\/978-3-030-01168-0_26","volume-title":"Internet of Things, Smart Spaces, and Next Generation Networks and Systems","author":"T Kokkonen","year":"2018","unstructured":"Kokkonen, T., Puuska, S.: Blue team communication and reporting for enhancing situational awareness from white team perspective in cyber security exercises. In: Galinina, O., Andreev, S., Balandin, S., Koucheryavy, Y. (eds.) NEW2AN\/ruSMART -2018. LNCS, vol. 11118, pp. 277\u2013288. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-01168-0_26"},{"key":"15_CR26","doi-asserted-by":"publisher","first-page":"591","DOI":"10.1111\/joop.12349","volume":"94","author":"O Brown","year":"2021","unstructured":"Brown, O., Power, N., Conchie, S.M.: Communication and coordination across event phases: a multi-team system emergency response. J. Occupat. Organiz. Psychol. 94, 591\u2013615 (2021). https:\/\/doi.org\/10.1111\/joop.12349","journal-title":"J. Occupat. Organiz. Psychol."},{"issue":"1","key":"15_CR27","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1007\/s10796-009-9174-z","volume":"12","author":"N Bharosa","year":"2010","unstructured":"Bharosa, N., Lee, J., Janssen, M.: Challenges and obstacles in sharing and coordinating information during multi-agency disaster response: Propositions from field exercises. Inf. Syst. Front. 12(1), 49\u201365 (2010)","journal-title":"Inf. Syst. Front."},{"key":"15_CR28","doi-asserted-by":"publisher","unstructured":"Buck, D., Aguirre, B.: A critical evaluation of the Incident Command System and NIMS. J. Homel. Secur. Emerg. Manag. 3 (2006). https:\/\/doi.org\/10.2202\/1547-7355.1252","DOI":"10.2202\/1547-7355.1252"},{"issue":"1","key":"15_CR29","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1080\/12294659.2013.10805240","volume":"18","author":"LK Comfort","year":"2013","unstructured":"Comfort, L.K., Okada, A.: Emergent leadership in extreme events: a knowledge commons for sustainable communities. Int. Rev. Public Adm. 18(1), 61\u201377 (2013). https:\/\/doi.org\/10.1080\/12294659.2013.10805240","journal-title":"Int. Rev. Public Adm."},{"key":"15_CR30","doi-asserted-by":"publisher","first-page":"192","DOI":"10.1007\/s13753-014-0025-2","volume":"5","author":"JM Berlin","year":"2014","unstructured":"Berlin, J.M., Carlstrom, E.D.: Collaboration exercises-the lack of collaborative benefits. Int. J. Disaster Risk Sci. 5, 192\u2013205 (2014)","journal-title":"Int. J. Disaster Risk Sci."},{"key":"15_CR31","doi-asserted-by":"publisher","unstructured":"Cichonski, P., Millar, T., Grance, T., Scarfone, K.: Computer security incident handling guide. NIST Special Publication 800\u201361 Revision 2 (2012). https:\/\/doi.org\/10.6028\/NIST.SP.800-61r2","DOI":"10.6028\/NIST.SP.800-61r2"},{"key":"15_CR32","unstructured":"Information-technology Promotion Agency, Japan.: Industrial Cyber Security Center of Excellence (ICSCoE). https:\/\/www.ipa.go.jp\/en\/about\/org\/icscoe\/index.html"},{"key":"15_CR33","doi-asserted-by":"publisher","unstructured":"Nakayama, K., Koshijima, I., Watanabe, K.: Analyzing important factors in cybersecurity incidents using table-top exercise. In: Moallem, A. (ed.) Human Factors in Cybersecurity. AHFE (2024) International Conference. AHFE Open Access, vol. 127. AHFE International, USA (2024). https:\/\/doi.org\/10.54941\/ahfe1004770","DOI":"10.54941\/ahfe1004770"},{"issue":"4","key":"15_CR34","doi-asserted-by":"publisher","first-page":"475","DOI":"10.1016\/j.jarmac.2020.09.003","volume":"9","author":"RA Bjork","year":"2020","unstructured":"Bjork, R.A., Bjork, E.L.: Desirable difficulties in theory and practice. J. Appl. Res. Mem. Cogn. 9(4), 475\u2013479 (2020)","journal-title":"J. Appl. Res. Mem. Cogn."},{"issue":"2","key":"15_CR35","doi-asserted-by":"publisher","first-page":"311","DOI":"10.1037\/0021-9010.91.2.311","volume":"91","author":"LA DeChurch","year":"2006","unstructured":"DeChurch, L.A., Marks, M.A.: Leadership in multi-team systems. J. Appl. Psychol. 91(2), 311\u2013329 (2006). https:\/\/doi.org\/10.1037\/0021-9010.91.2.311","journal-title":"J. Appl. Psychol."},{"key":"15_CR36","unstructured":"CISA: Cybersecurity Incident & Vulnerability Response Playbooks (2021). https:\/\/www.cisa.gov\/sites\/default\/files\/2024-08\/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf"},{"key":"15_CR37","unstructured":"FEMA.: Homeland Security Exercise and Evaluation Program (HSEEP). FEMA\/National Preparedness (2020). https:\/\/www.fema.gov\/emergency-managers\/national-preparedness\/exercises\/hseep"},{"key":"15_CR38","unstructured":"International Organization for Standardization (ISO): ISO 22398:2013 - Societal security - Guidelines for exercises. ISO (2013)"}],"container-title":["Lecture Notes in Computer Science","Critical Information Infrastructures Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-19540-1_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T22:41:41Z","timestamp":1776897701000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-19540-1_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032195395","9783032195401"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-19540-1_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRITIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Critical Information Infrastructures Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"J\u00f6nk\u00f6ping","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sweden","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"critis2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/jth-critis.hj.se\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}