{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T15:54:00Z","timestamp":1784390040333,"version":"3.55.0"},"reference-count":40,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:00:00Z","timestamp":1753401600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>End-users in a decision-oriented Internet of Things (IoT) healthcare system are often left in the dark regarding critical security information necessary for making informed decisions about potential risks. This is partly due to the lack of transparency and system security awareness end-users have in such systems. To empower end-users and enhance their cybersecurity situational awareness, it is imperative to thoroughly document and report the runtime security controls in place, as well as the security-relevant aspects of the devices they rely on, while the need for better transparency is obvious, it remains uncertain whether current systems offer adequate security metadata for end-users and how future designs can be improved to ensure better visibility into the security measures implemented. To address this gap, we conducted table-top exercises with ten security and ICT experts to evaluate a typical IoT-Health scenario. These exercises revealed the critical role of security metadata, identified the available ones to be presented to users, and suggested potential enhancements that could be integrated into system design. We present our observations from the exercises, highlighting experts\u2019 valuable suggestions, concerns, and views, backed by our in-depth analysis. Moreover, as a proof-of-concept of our study, we simulated three relevant use cases to detect cyber risks. This comprehensive analysis underscores critical considerations that can significantly improve future system protocols, ensuring end-users are better equipped to navigate and mitigate security risks effectively.<\/jats:p>","DOI":"10.3390\/jcp5030049","type":"journal-article","created":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T08:13:31Z","timestamp":1753431211000},"page":"49","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Empowering End-Users with Cybersecurity Situational Awareness: Findings from IoT-Health Table-Top Exercises"],"prefix":"10.3390","volume":"5","author":[{"given":"Fariha Tasmin","family":"Jaigirdar","sequence":"first","affiliation":[{"name":"School of Information Technology, Deakin University, Burwood, Melbourne VIC 3125, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carsten","family":"Rudolph","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Monash University, Clayton, Melbourne VIC 3800, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Misita","family":"Anwar","sequence":"additional","affiliation":[{"name":"School of Business, Law and Entrepreneurship, Swinburne University, Hawthorn, Melbourne VIC 3122, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6345-0058","authenticated-orcid":false,"given":"Boyu","family":"Tan","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, Monash University, Clayton, Melbourne VIC 3800, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,7,25]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1109\/JIOT.2015.2417684","article-title":"An IoT-Aware Architecture for Smart Healthcare Systems","volume":"2","author":"Catarinucci","year":"2015","journal-title":"IEEE Internet Things J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"10474","DOI":"10.1109\/JIOT.2021.3062630","article-title":"Internet of things (IoT): A review of its enabling technologies in healthcare applications, standards protocols, security, and market opportunities","volume":"8","author":"Bhuiyan","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Jaigirdar, F.T., Rudolph, C., and Bain, C. (2019, January 29\u201331). Can I Trust the Data I See? A Physician\u2019s Concern on Medical Data in IoT Health Architectures. Proceedings of the Australasian Computer Science Week Multiconference, Sydney, Australia.","DOI":"10.1145\/3290688.3290731"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"5503","DOI":"10.1007\/s11276-020-02340-0","article-title":"Review of security challenges in healthcare internet of things","volume":"27","author":"Somasundaram","year":"2021","journal-title":"Wirel. Netw."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"150","DOI":"10.3390\/iot4020009","article-title":"IoT health devices: Exploring security risks in the connected landscape","volume":"4","author":"Affia","year":"2023","journal-title":"IoT"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Butt, S.A., Diaz-Martinez, J.L., Jamal, T., Ali, A., De-La-Hoz-Franco, E., and Shoaib, M. (2019, January 1\u20134). IoT smart health security threats. Proceedings of the 2019 19th International Conference on Computational Science and Its Applications (ICCSA), St. Petersburg, Russia.","DOI":"10.1109\/ICCSA.2019.000-8"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1186\/s42400-024-00219-7","article-title":"Classification of DDoS attack traffic on SDN network environment using deep learning","volume":"7","author":"Clinton","year":"2024","journal-title":"Cybersecurity"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"222","DOI":"10.63180\/jcsra.thestap.2025.4.3","article-title":"A Novel Permissioned Blockchain Approach for Scalable and Privacy-Preserving IoT Authentication","volume":"2025","author":"Addula","year":"2025","journal-title":"J. Cyber Secur. Risk Audit."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Jaigirdar, F.T., Rudolph, C., and Bain, C. (2021, January 5\u201310). Risk and Compliance in IoT- Health Data Propagation: A Security-Aware Provenance based Approach. Proceedings of the 2021 IEEE International Conference on Digital Health (ICDH), Chicago, IL, USA.","DOI":"10.1109\/ICDH52753.2021.00015"},{"key":"ref_10","unstructured":"Jaigirdar, F.T. (2021). Provenance for Secure Propagation of IoT Data. [Ph.D. Thesis, Monash University]."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.63180\/jcsra.thestap.2025.1.1","article-title":"Cybersecurity threats, countermeasures and mitigation techniques on the IoT: Future research directions","volume":"1","author":"Almuqren","year":"2025","journal-title":"J. Cyber Secur. Risk Audit."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Jaigirdar, F.T., Rudolph, C., Oliver, G., Watts, D., and Bain, C. (2020, January 1\u20133). What information is required for explainable AI?: A provenance-based research agenda and future challenges. Proceedings of the 2020 IEEE 6th International Conference on Collaboration and Internet Computing (CIC), Atlanta, GA, USA.","DOI":"10.1109\/CIC50333.2020.00030"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1186\/s42400-024-00259-z","article-title":"Research on distribution automation security situational awareness technology based on risk transmission path and multi-source information fusion","volume":"7","author":"Liu","year":"2024","journal-title":"Cybersecurity"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1080\/19393555.2020.1855374","article-title":"A four-part typology to assess organizational and individual security awareness","volume":"31","author":"Reveraert","year":"2022","journal-title":"Inf. Secur. J. A Glob. Perspect."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Jaigirdar, F.T., Rudolph, C., and Bain, C. (2020\u20131, January 29). Prov-IoT: A security-aware IoT provenance model. Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guangzhou, China.","DOI":"10.1109\/TrustCom50675.2020.00183"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"55677","DOI":"10.1109\/ACCESS.2023.3280928","article-title":"Security-Aware Provenance for Transparency in IoT Data Propagation","volume":"11","author":"Jaigirdar","year":"2023","journal-title":"IEEE Access"},{"key":"ref_17","first-page":"120","article-title":"Training as a Tool of Fostering CIP Concept Implementation: Results of a Table Top Exercise on Critical Energy Infrastructure Resilience","volume":"40","author":"Sukhodolia","year":"2018","journal-title":"Inf. Secur. Int. J."},{"key":"ref_18","unstructured":"Shaikh, A. (2025, July 20). Smartphones Usage at Workplace: Assessing Information Security Risks from Accessibility Perspective. Available online: http:\/\/hdl.handle.net\/2142\/106547."},{"key":"ref_19","unstructured":"Fietkiewicz, K.J., and Ilhan, A. (2025, July 20). How Do Users of Activity Tracking Technologies Perceive the Data Privacy Environment in the EU?. Available online: http:\/\/hdl.handle.net\/2142\/106603."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Wilbanks, L.R. (2021). CyberSecurity Privacy Risks. Advances in Human Factors in Robots, Unmanned Systems and Cybersecurity, Proceedings of the AHFE 2021 Virtual Conferences on Human Factors in Robots, Drones and Unmanned Systems, and Human Factors in Cybersecurity, Online, July 25\u201329 2021, Springer.","DOI":"10.1007\/978-3-030-79997-7_24"},{"key":"ref_21","first-page":"150","article-title":"Wearable devices in healthcare: Privacy and information security issues","volume":"49","author":"Cilliers","year":"2020","journal-title":"Health Inf. Manag. J."},{"key":"ref_22","unstructured":"Bada, M., Sasse, A.M., and Nurse, J.R. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour?. arXiv."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1080\/0144929X.2012.708787","article-title":"User preference of cyber security awareness delivery methods","volume":"33","author":"Abawajy","year":"2014","journal-title":"Behav. Inf. Technol."},{"key":"ref_24","first-page":"1","article-title":"Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks","volume":"12","author":"Thomas","year":"2018","journal-title":"Int. J. Bus. Manag."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Lamprinakos, G., Kosmatos, E., Kaklamani, D., and Venieris, I. (2010, January 10\u201312). An integrated architecture for remote healthcare monitoring. Proceedings of the 2010 14th Panhellenic Conference on Informatics, Tripoli, Greece.","DOI":"10.1109\/PCI.2010.20"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3384471","article-title":"Gaps and opportunities in situational awareness for cybersecurity","volume":"1","author":"Gutzwiller","year":"2020","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_27","unstructured":"Braun, U., Shinnar, A., and Seltzer, M. (2008, January 29). Securing provenance. Proceedings of the 3rd Conference on Hot Topics in Security (HOTSEC\u201908), San Jose, CA, USA."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"14757","DOI":"10.1109\/ACCESS.2017.2730843","article-title":"MeDShare: Trust-less medical data sharing among cloud service providers via blockchain","volume":"5","author":"Xia","year":"2017","journal-title":"IEEE Access"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"743","DOI":"10.1016\/j.future.2010.07.005","article-title":"The open provenance model core specification (v1.1)","volume":"27","author":"Moreau","year":"2011","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Sultana, S., and Bertino, E. (2012). A comprehensive model for provenance. Provenance and Annotation of Data and Processes, Springer.","DOI":"10.1007\/978-3-642-34222-6_27"},{"key":"ref_31","unstructured":"Forero, C.A.M. (2016). Tabletop Exercise For Cybersecurity Educational Training; Theoretical Grounding Furthermore, Development. [Master\u2019s Thesis, University of Tartu]."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Conklin, A., and White, G.B. (2006, January 4\u20137). E-government and cyber security: The role of cyber security exercises. Proceedings of the 39th Annual Hawaii International Conference on System Sciences (HICSS\u201906), Kauai, HI, USA.","DOI":"10.1109\/HICSS.2006.133"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1081","DOI":"10.20965\/jdr.2017.p1081","article-title":"On the complexity of cybersecurity exercises proportional to preparedness","volume":"12","author":"Aoyama","year":"2017","journal-title":"J. Disaster Res."},{"key":"ref_34","unstructured":"(2025, June 03). Miro Whiteboard. Available online: https:\/\/miro.com\/."},{"key":"ref_35","unstructured":"Richards, L. (2025, June 03). Using NVivo in Qualitative Research. Available online: https:\/\/help-nv11.qsrinternational.com\/desktop\/concepts\/using_nvivo_for_qualitative_research.htm."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"23","DOI":"10.63180\/jcsra.thestap.2024.1.4","article-title":"Enhancing DDoS attack detection and mitigation in SDN using advanced machine learning techniques","volume":"2024","author":"Frederick","year":"2024","journal-title":"J. Cyber Secur. Risk Audit."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Hyla, T., and Fabisiak, L. (2020, January 7\u201310). Measuring cyber security awareness within groups of medical professionals in Poland. Proceedings of the 53rd Hawaii International Conference on System Sciences, Maui, HI, USA.","DOI":"10.24251\/HICSS.2020.473"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1016\/j.istr.2010.05.002","article-title":"The positive outcomes of information security awareness training in companies\u2014A case study","volume":"14","author":"Eren","year":"2009","journal-title":"Inf. Secur. Tech. Rep."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Moustafa, A.A., Bello, A., and Maurushat, A. (2021). The role of user behaviour in improving cyber security management. Front. Psychol., 12.","DOI":"10.3389\/fpsyg.2021.561011"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Mitchell, C. (Trusted Computing, 2005). Trusted Computing.","DOI":"10.1049\/PBPC006E"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/49\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:15:45Z","timestamp":1760033745000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/49"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,25]]},"references-count":40,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030049"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030049","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,25]]}}}