Hybrid Tabletop Exercise (TTX) based on a Mathematical Simulation-based Model for the Maritime Sector

📅 2026-02-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the critical gap in effective cybersecurity training for C-suite executives in the maritime sector, who often struggle to respond to complex cyber incidents. To bridge this gap, the authors propose SERDUX-MARCIM, a novel hybrid training framework that integrates mathematical contagion models with tabletop exercises (TTX). This approach uniquely combines dynamic multi-node attack simulation with scenario-based decision-making drills, significantly enhancing executives’ cyber situational awareness, anticipatory judgment, and governance capabilities. Empirical evaluations conducted in Argentina and the United States demonstrate that the framework effectively improves participants’ understanding of cyber threats, their ability to forecast attack trajectories, and their organizations’ overall cybersecurity governance maturity.

Technology Category

Application Category

📝 Abstract
As cyber threats grow in complexity and scale, many security incidents remain poorly managed due to the lack of proper training among C-level executives. Thus, there is a need for targeted cybersecurity education to enhance executive decision-making and crisis response. Traditional training methods, such as cyber wargames and Tabletop Exercises (TTX), aim to develop abilities to face critical incidents, however, they often lack the interactive and dynamic elements required to prepare individuals for real-world cyber incidents. This paper presents a novel approach to cybersecurity and cyberdefense education through the design of a specialized hybrid TTX for the maritime domain, which uses a framework to model mathematically how a cyberattack spreads along multiple nodes and impacts infrastructure. Our proposal was validated through exercises in Argentina and the United States, demonstrating a positive impact in developing the comprehension and projection levels of Cyber Situational Awareness (CSA), and reinforcing governance. Documentation about the Hybrid TTX, scenario, datasets and implementation of the SERDUX-MARCIM model, is available at the project repository at https://github.com/diegocabuya/SERDUX-MARCIM
Problem

Research questions and friction points this paper is trying to address.

cybersecurity training
executive decision-making
Tabletop Exercise (TTX)
maritime sector
Cyber Situational Awareness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hybrid Tabletop Exercise
Mathematical Simulation Model
Cyber Situational Awareness
Maritime Cybersecurity
SERDUX-MARCIM
🔎 Similar Papers
No similar papers found.
D
Diego Cabuya-Padilla
"Cyberspace, Technology and Innovation" research group, Escuela Superior de Guerra "General Rafael Reyes Prieto", Cra. 11 # 102-50, Bogotá, Colombia
Daniel Díaz-López
Daniel Díaz-López
Assistant Professor, Universidad del Rosario
CybersecurityThreat intelligencePentestingAIBlockchain
C
Carlos Castaneda-Marroquín
"Cyberspace, Technology and Innovation" research group, Escuela Superior de Guerra "General Rafael Reyes Prieto", Cra. 11 # 102-50, Bogotá, Colombia