Business & Technology
Glasgow study flags digital twin cyber risks in firms
University of Glasgow researchers have warned that cybersecurity research on digital twins is overlooking organisational risks. The study was carried out within the TransiT transport decarbonisation research hub.
Academic work has focused heavily on technical questions such as detecting attacks, securing data sharing and making systems interoperable, while paying much less attention to how organisations and staff manage cyber risk in practice.
Digital twins are digital replicas of physical assets or systems. They are used in sectors including transport, construction, manufacturing and healthcare. In transport, they are increasingly seen as tools for testing changes to complex networks without relying solely on real-world trials.
The Glasgow team reviewed more than 1,800 academic papers on cybersecurity, digital twins and organisational barriers to adoption, then narrowed the pool to 41 studies that included social or organisational perspectives, including participant-based research.
The analysis identified a series of underexplored issues beyond software and infrastructure. These included competing priorities between cybersecurity teams and operational staff, employee resistance to security policies when they interfere with core work, financial pressures, limited organisational commitment, skills shortages and worker concern about possible job losses linked to digitalisation.
It also highlighted governance problems that can grow when digital twin systems involve multiple organisations. Shared responsibility across IT teams, operational technology specialists, data teams and external suppliers can make accountability harder to define, particularly as systems expand and become more interconnected.
Dr Stefanos Evripidou, a cybersecurity researcher at the University of Glasgow and lead author of the study, said the gap matters because digital twins are moving beyond isolated deployments.
“Cybersecurity is both a social and a technical challenge, because it involves people and organisational processes, as well as technology. These dimensions are inherently interdependent, so we need to understand the technical and the organisational challenges together rather than in isolation. But our research has found that very little is known about the kind of real-world cybersecurity issues that organisations face around the implementation of digital twins. It’s critical that we bridge this gap in knowledge, because digital twins are being scaled and connected to address increasingly complex challenges that span whole sectors or societies. This means we’re also hugely expanding the attack surface and increasing exposure to cybersecurity threats,” Dr Evripidou said.
The study, published in the journal Computers & Security, argues that most research focused on cybersecurity remains strongly technical, even though day-to-day security outcomes inside organisations often depend on management structures, workplace culture and staff behaviour.
Workplace friction
Among the specific concerns identified is what the researchers describe as security fatigue. This can emerge when staff see cyber rules as adding to their workload or slowing their main responsibilities, making them more likely to adopt informal workarounds or leave security concerns out of operational decisions.
The paper states: “Security often conflicts with other business practices, particularly when it adds additional workload, creating friction between security and productivity. This can result in security fatigue, where employees may adopt less demanding workarounds and more broadly, lead to security’s exclusion from the decision-making process.”
The findings are likely to draw attention in transport and energy, where policymakers and industry have shown growing interest in linked digital twin environments spanning assets, companies and public infrastructure. The authors argue that current standards do not properly address the risks specific to those arrangements.
To address the gap, the paper sets out several research priorities. These include more interviews, case studies and ethnographic work on live digital twin projects, closer examination of how responsibilities are divided among stakeholders, and the development of governance and regulatory frameworks suited to connected digital twin systems.
The researchers also propose what they call a sensemaking framework to help organisations assess cyber needs according to a twin’s purpose, how closely it is integrated with the physical world and how critical the underlying system is.
TransiT, the research hub behind the work, focuses on using digital twins to identify lower-risk, lower-cost routes to cutting emissions in UK transport across road, rail, air and maritime networks for passengers and freight. The collaboration brings together eight universities and almost 70 industry partners, and is jointly led by Heriot-Watt University and the University of Glasgow.
The study involved co-authors Xicheng Li, Dr Mohammad Al-Quraan, Dr Runze Cheng, Dr Ahmad Taha, Professor Muhammad Imran, Professor David Flynn and Professor Dimitrios Pezaros, all based at the University of Glasgow through TransiT.
One of the clearest weaknesses in the current literature, the authors argue, is the limited understanding of how digital twin stakeholders themselves view cyber risk.
“A key gap identified in our analysis is the limited research into how digital twin stakeholders understand cybersecurity and its associated risks in digital twins,” the researchers wrote.
Business & Technology
Shirtless intruder wakes couple in Travelodge hotel room
Kim Hutchison, 60, and Harry Grieve, 57, were staying in a Travelodge in Dundee when the early morning incident happened last month.
Ms Hutchison said she was “petrified” before the man – wearing just shorts – left after about a minute of arguing over who was actually in the wrong room.
READ MORE: MP meets Travelodge bosses following room key assault case
Travelodge, which has headquarters in Thame, apologised to the couple and said room access security policies were not correctly followed.
Earlier this year, a man was jailed for sexually assaulting a woman in her hotel bed after Travelodge staff gave him a key card and her room number.
Kyran Smith had gone to the reception of the Maidenhead branch of the hotel chain in the early hours in December 2022 and said he was the woman’s boyfriend.
He was jailed for seven-and-a-half years following the assault.
The chain’s chief executive Jo Boydell apologised to the victim and said changes would ensure additional or replacement keys were only issued with permission from the person staying in the room.
In the latest incident, Ms Hutchison and Mr Grieve had been visiting relatives in Dundee and had gone to bed at the Strathmore Avenue branch of Travelodge, before they were disturbed at 2am on July 11.
“I just woke up, I had heard the door click, and sat up in bed,” Hutchison told the BBC.
“Here was a guy at the bottom of the bed, just standing with shorts on. He had something in his hand which I took to be the key card for the room.”
It is understood that the man had made a mistake regarding the room number, believing he was in room 316 not 313.
Mr Grieve, who works in Aberdeenshire, got dressed and went down to reception to try to find out what had happened and “get some answers” about why a stranger had been able to get into their room.
Following their complaint, the couple were given a room refund, as well as a £100 Travelodge voucher – which Mr Grieve said he doubted they would use.
The couple decided to publicise their case after becoming aware of the Maidenhead assault.
In April, Freddie van Mierlo, Liberal Democrat MP for Henley and Thame, met the senior leadership team at Travelodge’s headquarters in Thame to discuss guest and employee safety following serious concerns about hotel room security.
Henley and Thame MP Frieddie van Mierlo (Image: Contributed)
Travelodge said it was “very sorry” for what had happened, and that customer safety and security was a priority.
“Any case of an unauthorised person entering a guest’s room is a significant cause for concern and we want to be clear that this should not have happened,” a statement said.
“Our updated room access security policies were not correctly followed in this instance, which is not acceptable.
“We have retrained the team at our Dundee Strathmore Avenue hotel on our updated room security and check-in procedures, and would like to apologise again to Mr Grieve and Ms Hutchison for their experience with us.”
The previously-announced Travelodge safety review remains ongoing.
Business & Technology
Orbital Industries signs BASF deal to speed research
JOSEPH GABRIEL LAGONSIN
News Editor
Orbital Industries has signed an agreement with BASF Environmental Catalyst and Metal Solutions to license its CurieOS materials discovery platform, bringing the software into catalyst research for automotive emissions applications.
BASF’s Environmental Catalyst and Metal Solutions unit, known as ECMS, supplies aftertreatment systems and catalytic products to the automotive market. Under the agreement, the division will use CurieOS in its catalyst research and development work.
The deal expands Orbital Industries beyond its existing work in data centres, where it has used the same platform to develop a PFAS-free cooling material for its Orbital IT brand. CurieOS is designed to help researchers identify promising materials before producing laboratory samples.
Materials discovery in industrial settings often involves long testing cycles, as candidate substances must be synthesised, characterised and assessed under operating conditions. CurieOS is intended to shorten that process by combining literature review, data analysis and simulation in a single scientist-directed workflow.
At the centre of CurieOS is Orb, the company’s atomistic simulation model. Orbital Industries says the model can predict the properties of new materials and give researchers what it describes as a virtual laboratory for evaluating candidates computationally before committing to physical testing.
Orb can simulate 100,000 atoms on a single graphics processing unit, according to Orbital Industries, which also says the model runs faster than competing systems from large technology groups and academic teams. It cited independent benchmark results in support of those claims.
Automotive pressure
The BASF unit is entering the agreement as carmakers and suppliers face continued pressure to adapt emissions technologies to tighter regulation, changing powertrain designs, alternative fuels and cost constraints. Those factors have kept catalyst development a priority across the automotive supply chain.
Saeed Alerasool, Senior Vice President and Chief Technology Officer for ECMS at BASF, said this backdrop had made faster development more important.
“The agreement comes at a critical time for the automotive sector. The development of mobile emissions catalyst technologies continues to be driven by tightening emissions regulations, evolving powertrain technologies and alternative fuels, as well as growing cost pressure. At BASF ECMS, we continuously explore new approaches to accelerate development and further improve R&D and application efficiency. Through this agreement, we look forward to leveraging emerging AI technologies to enhance our ability to deliver leading solutions and help address evolving customer and market needs,” Alerasool said.
Research tool
Orbital Industries describes CurieOS as an AI research system that can follow goal-based instructions from scientists across several steps, including reviewing published work, analysing experimental results and running simulations to generate new hypotheses. It says this approach can reduce the number of physical experiments needed in the earliest stages of a programme.
That matters in catalysis because the field involves interactions at material surfaces that can be difficult to model accurately with lower-cost methods. Larger, more detailed simulations can help researchers narrow which candidates should move to laboratory testing.
James Gin-Pollock, Chief Technology Officer at Orbital Industries, said the technical demands of catalyst work made it a useful proving ground for the software.
“Catalysis is a brutal test for any simulation model – you’re dealing with complex surfaces, large systems, and subtle interactions that cheaper methods miss. Orb was built for exactly this: it can simulate systems of a scale and complexity that were previously out of reach, fast enough that scientists can actually iterate. That’s what makes it valuable for real industrial workflows rather than just a research demo,” Gin-Pollock said.
Jonathan Godwin, Chief Executive Officer of Orbital Industries, said the BASF agreement was a practical application of the company’s work in industrial materials development.
“The hardest part of materials discovery is knowing where to look. CurieOS gives scientists a way to explore and test ideas computationally before committing time in the lab, which means more of their effort goes into the candidates that matter. ECMS hosts exactly the kind of demanding, real-world materials development we built this for,” Godwin said.
The agreement places Orbital Industries in a segment of the industrial software market where chemical and materials companies are increasingly testing artificial intelligence tools against established laboratory processes. For BASF ECMS, the immediate use case is catalyst development for emissions systems, an area where small gains in material performance can carry commercial and regulatory significance.
Business & Technology
Why some tax transformation projects succeed while others struggle
RUSSELL GAMMON
Chief Innovation Officer
Alphatax
As professionals across the industry will be all too aware, the tax function is experiencing one of the most significant periods of change seen for many years. Whether the priority is to address broader reporting and compliance obligations or respond to more demanding business expectations, teams are under significant pressure.
To deal with these challenges, many organisations have turned to digital transformation, with an increasing number accelerating their move to cloud-based technology to modernise legacy systems and automate manual processes. Progress, however, is far from consistent, with some tax teams moving extremely quickly while others continue to rely on desktop software, manual methods and spreadsheet-based workflows. Indeed, organisations operating in similar markets often achieve very different outcomes.
So what’s happening, and why are some making rapid progress while others continue to struggle? At the heart of the matter is digital maturity, or in other words, how well an organisation uses digital capabilities to achieve its strategic goals.
Organisations that can be categorised as having higher digital maturity already have the foundations needed to modernise successfully. They typically have connected systems, robust data governance, standardised processes and infrastructure that can support modern applications, whether deployed in the cloud or on-premise. In these environments, introducing new tax technology becomes an extension of existing capabilities rather than a wholesale overhaul. By contrast, organisations with lower digital maturity often find that new platforms expose existing weaknesses rather than resolving them, limiting the value they ultimately deliver.
This explains why organisations investing in similar technologies can experience very different outcomes. One may accelerate transformation, while another struggles to realise the benefits it is hoping for.
Getting the foundations right
The challenge rarely lies just with the software itself. The bigger obstacle is the environment in which it has to operate. For example, moving tax applications into the cloud does not automatically solve fragmented data. If tax information originates from multiple business systems and is inconsistent or difficult to access, cloud implementations simply expose those issues more quickly.
Then there are the challenges associated with data quality, which should be addressed before implementation begins rather than treated as something that can be corrected after the fact. The objective should be that changes made in one area flow consistently across the overall tax function, minimising the need for manual intervention and improving confidence in the information used. This also means that tax teams spend less time resolving data issues and more time focusing on higher-value activities.
Many transformation projects fail because organisations concentrate on selecting technology before understanding the processes it needs to support. The approach taken to data, for example, is key and strongly indicative of whether a transformation strategy is set up to succeed. In practical terms, organisations with higher digital maturity can work from a shared data foundation rather than maintaining multiple versions of the same information across different processes.
Existing processes also play a major role. If workflows are inefficient or poorly defined (even if they have been considered fit for purpose for many years), digital transformation rarely produces the desired improvements. Success also depends on the wider organisation being ready to support new ways of working, rather than viewing implementation as simply replacing one software platform or legacy process with something new.
Reaping the benefits
Building digital maturity allows organisations to move away from the tendency many have to adopt disconnected point solutions towards a more integrated tax operating model.
Consistency also makes it easier to identify issues or errors earlier in the process, when they are generally quicker and less costly to resolve. The cumulative effect is greater control, rather than simply a faster way of completing existing tasks.
The underlying point is that digital maturity should not be viewed as a destination that organisations eventually reach. It is an ongoing capability that becomes increasingly valuable as processes need to change or there are new opportunities for improvement.
This is crucial because future tax obligations, from reporting to compliance and everything in between, are becoming even more demanding, making it more important than ever to build an operating model that can adapt without requiring fundamental redesign every time priorities change. Organisations that continue investing in those underlying capabilities will be better placed to take advantage of future technologies because the conditions needed to support them already exist.
Ultimately, successful modernisation is about more than adopting cloud technology. Organisations that invest in the right digital foundations will be far better positioned to realise the full value of cloud and take advantage of future innovations, including AI, as the demands on the tax function continue to evolve.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
