Argues that the Digital Twin concept is the missing link for addressing scarce cybersecurity resources in operational technology domains.
Digital Twins and the Future of their Use Enabling Shift Left and Shift Right Cybersecurity Operations is a vision paper by Ahmad Mohsin, Helge Janicke, Surya Nepal, and David Holmes (Security Research Institute/CSIRO Data61) that proposes Security Digital Twins (SDTs) to enhance cybersecurity in Smart Critical Systems (SCS). The authors argue that SDTs serve as a critical architectural paradigm to bridge the gap between Information Technology (IT) and Operational Technology (OT), addressing vulnerabilities in interconnected infrastructure like smart grids and water treatment plants.
The framework utilizes a Shift Left, Shift Right (SLSR) strategy to ensure resilience throughout a system's lifecycle: Shift Left (Design-Time): SDTs allow for rigorous threat modeling, simulation of cyberattacks, and verification of security controls in a virtual environment before physical systems are built, ensuring security is "baked in" from the start. Shift Right (Runtime Resilience): During operations, SDTs act as real-time mirrors of physical plants, enabling security teams to test potential fixes or response strategies in the virtual twin first to prevent unintended physical consequences like equipment damage.
Key technical components include Virtual Components (VCs) that provide a reliable "Virtual Source of Truth" by hosting control logic in software replicas, and Hybrid Intelligence combining data-driven Machine Learning, Semantic Modeling/Knowledge Graphs, and Generative AI (including LLMs and GANs) for anomaly detection and attack simulation. The paper highlights that while SDTs shift cybersecurity from reactive to proactive, challenges remain in securing the twin itself, achieving interoperability with diverse hardware, and ensuring Explainable AI (XAI) for operator trust.
The material argues that digital twins can serve as a missing operational layer for cybersecurity in operational technology (OT) environments, where specialized security resources are often scarce and systems are long-lived, safety-critical, and difficult to modify. Rather than treating the digital twin only as an engineering visualization or asset model, the piece frames it as a shared substrate for security reasoning: a continuously updated virtual representation of OT assets, network topology, process states, and control behavior that can be used to analyze risk, validate configurations, and support operational decisions without directly disturbing production systems.
Its key insight is that this capability enables both “shift-left” and “shift-right” cybersecurity operations. Shift-left means moving security work earlier into design, commissioning, and change-management workflows, where the twin can be used to test segmentation, access controls, configuration baselines, and potential failure or attack scenarios before changes are deployed. Shift-right extends the same model-driven approach into live operations and incident response, where the twin can help correlate observed telemetry with expected behavior, prioritize anomalies, and support response planning when security expertise is limited.
This matters because OT cybersecurity is constrained by a combination of scarce specialized staff, regulatory and safety obligations, and the high cost of disruption in critical infrastructure. By providing a reusable decision-support layer between engineering and security, digital twins can reduce reliance on ad hoc expert judgment, improve consistency of controls, and shorten the time needed to detect, assess, and remediate anomalies. The material’s broader contribution is to position the digital twin not as a perfect replica of physical systems, but as a practical mechanism for extending cybersecurity capability across the full asset lifecycle.