Strengthening Telecommunications Resilience through Cybersecurity Governance, Preventive Maintenance, and Coordinated Incident Response

Authors

  • Josephat Deogratius Katundabwile School of Engineering, The Catholic University of America, Washington, DC, United States of America Author
  • David Mbui Kamau The Catholic University of America, Washington, DC, United States of America Author

DOI:

https://doi.org/10.15662/IJEETR.2026.0804009

Keywords:

telecommunications resilience, cybersecurity governance, preventive maintenance, incident response, critical digital infrastructure, service continuity

Abstract

Telecommunications networks now underpin the delivery of financial, healthcare, government, and emergency services, which makes service continuity in this sector a matter of public as well as commercial consequence. Operators face disruption from two directions that they typically govern separately: physical and technical failure addressed through engineering maintenance, and adversarial activity addressed through information security. This article examines whether that separation is defensible and what an integrated alternative would involve. Using a structured narrative literature review of thirty peer reviewed sources, six core standards and guidance documents, and selected primary United States legal and regulatory materials, it synthesises four literatures that have developed largely in parallel, covering critical infrastructure resilience, maintenance optimisation, incident response, and cybersecurity governance. The review finds that resilience measurement weights heavily toward outcome indicators, that maintenance optimisation remains largely cyber agnostic, that incident response research centres on enterprise security operations rather than multi vendor field restoration, and that governance research is normative rather than operational. Drawing on management system logic, the governance function of the NIST Cybersecurity Framework 2.0, cyber resiliency engineering objectives, and organisational learning theory, the article proposes a thirteen stage integrated governance framework organised into phases of direction, prevention, response, and learning, together with nine performance indicators combining leading and outcome measures. Its central proposition is that preventive maintenance and security monitoring should share a governance cycle because both depend on asset inventory and behavioural baselining. The framework is proposed rather than empirically validated.

References

1. Aghazadeh Ardebili, A., Lezzi, M., & Pourmadadkar, M. (2024). Risk assessment for cyber resilience of critical infrastructures: Methods, governance, and standards. Applied Sciences, 14(24), 11807. https://doi.org/10.3390/app142411807

2. Ahmad, A., Desouza, K. C., Maynard, S. B., Naseer, H., & Baskerville, R. L. (2020). How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, 71(8), 939–953. https://doi.org/10.1002/asi.24311

3. Ahmad, A., Maynard, S. B., Desouza, K. C., Kotsias, J., Whitty, M. T., & Baskerville, R. L. (2021). How can organizations develop situation awareness for incident response: A case study of management practice. Computers & Security, 101, 102122. https://doi.org/10.1016/j.cose.2020.102122

4. Bi, S., Yuan, X., Hu, S., Li, K., Ni, W., Hossain, E., & Wang, X. (2026). Resilience and failure analysis in next-generation communication networks: A contemporary survey. IEEE Transactions on Network Science and Engineering, 13, 2793–2821. https://doi.org/10.1109/tnse.2025.3620950

5. Busetti, S., & Scanni, F. M. (2025). Evaluating incident reporting in cybersecurity: From threat detection to policy learning. Government Information Quarterly, 42(1), 102000. https://doi.org/10.1016/j.giq.2024.102000

6. Büyüközkan, G., & Güler, M. (2025). Cybersecurity maturity model: Systematic literature review and a proposed model. Technological Forecasting and Social Change, 213, 123996. https://doi.org/10.1016/j.techfore.2025.123996

7. Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/tqm-09-2020-0202

8. Cyber Incident Reporting for Critical Infrastructure Act of 2022, Pub. L. No. 117-103, div. Y, 136 Stat. 49, 1038 (2022) (codified at 6 U.S.C. §§ 681–681g).

9. Cybersecurity and Infrastructure Security Agency. (n.d.). Public safety communications and cyber resiliency toolkit (Version 24.2). Retrieved August 6, 2026, from https://www.cisa.gov/resources-tools/resources/communications-and-cyber-resiliency-toolkit

10. Cybersecurity and Infrastructure Security Agency. (2024). Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) reporting requirements: Notice of proposed rulemaking (89 Fed. Reg. 23644, April 4, 2024). https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements

11. Cybersecurity and Infrastructure Security Agency. (2025). Cross-sector cybersecurity performance goals. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals

12. Cybersecurity and Infrastructure Security Agency. (n.d.). Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA): Frequently asked questions. Retrieved August 19, 2026, from https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs

13. Federal Communications Commission. (2024). Resilient networks; disruptions to communications (Second Report and Order, FCC 24-5; 89 Fed. Reg. 25542, April 11, 2024). https://www.federalregister.gov/documents/2024/04/11/2024-07402/resilient-networks-disruptions-to-communications

14. Federal Communications Commission. (2025). Protecting the nation’s communications systems from cybersecurity threats (Order on Reconsideration, PS Docket No. 22-329, FCC 25-81; 90 Fed. Reg. 58006, December 15, 2025). https://www.federalregister.gov/documents/2025/12/15/2025-22830/protecting-the-nations-communications-systems-from-cybersecurity-threats

15. Federal Communications Commission. (n.d.). Network Outage Reporting System (NORS). Retrieved August 19, 2026, from https://www.fcc.gov/general/network-outage-reporting-system-nors

16. Galaitsi, S. E., Pinigina, E., Keisler, J. M., Pescaroli, G., Keenan, J. M., & Linkov, I. (2023). Business continuity management, operational resilience, and organizational resilience: Commonalities, distinctions, and synthesis. International Journal of Disaster Risk Science, 14(5), 713–721. https://doi.org/10.1007/s13753-023-00494-x

17. Gallarno, G., Muniz, J., Parnell, G. S., Pohl, E. A., & Wu, J. (2024). Development and assessment of a resilient telecoms system. The Journal of Defense Modeling and Simulation: Applications, Methodology, Technology, 21(4), 405–420. https://doi.org/10.1177/15485129221143791

18. Ghadge, A., Weiß, M., Caldwell, N. D., & Wilding, R. (2020). Managing cyber risk in supply chains: A review and research agenda. Supply Chain Management: An International Journal, 25(2), 223–240. https://doi.org/10.1108/scm-10-2018-0357

19. International Organization for Standardization. (2019). ISO 22301:2019. Security and resilience: Business continuity management systems, requirements.

20. International Organization for Standardization. (2022). ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection: Information security management systems, requirements.

21. Jiang, P., Rowsell, J., & Schmidt, S. (2025). Crisis-ready telecom: Global approaches to emergency management in telecommunications. Telecommunications Policy, 49(4), 102914. https://doi.org/10.1016/j.telpol.2025.102914

22. Miller, T., Staves, A., Maesschalck, S., Sturdee, M., & Green, B. (2021). Looking back to look forward: Lessons learnt from cyber-attacks on industrial control systems. International Journal of Critical Infrastructure Protection, 35, 100464. https://doi.org/10.1016/j.ijcip.2021.100464

23. Mottahedi, A., Sereshki, F., Ataei, M., Nouri Qarahasanlou, A., & Barabadi, A. (2021). The resilience of critical infrastructure systems: A systematic literature review. Energies, 14(6), 1571. https://doi.org/10.3390/en14061571

24. Naseer, A., Naseer, H., Ahmad, A., Maynard, S. B., & Masood Siddiqui, A. (2021). Real-time analytics, incident response process agility and enterprise cybersecurity performance: A contingent resource-based analysis. International Journal of Information Management, 59, 102334. https://doi.org/10.1016/j.ijinfomgt.2021.102334

25. Naseer, A., Naseer, H., Ahmad, A., Maynard, S. B., & Siddiqui, A. M. (2023). Moving towards agile cybersecurity incident response: A case study exploring the enabling role of big data analytics-embedded dynamic capabilities. Computers & Security, 135, 103525. https://doi.org/10.1016/j.cose.2023.103525

26. Naseer, H., Desouza, K. C., Maynard, S. B., & Ahmad, A. (2024). Enabling cybersecurity incident response agility through dynamic capabilities: The role of real-time analytics. European Journal of Information Systems, 33(2), 200–220. https://doi.org/10.1080/0960085x.2023.2257168

27. National Institute of Standards and Technology. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Rev. 1). https://doi.org/10.6028/NIST.SP.800-160v2r1

28. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29

29. National Institute of Standards and Technology. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST Special Publication 800-61, Rev. 3). https://doi.org/10.6028/NIST.SP.800-61r3

30. Osei-Kyei, R., Almeida, L. M., Ampratwum, G., & Tam, V. (2023). Systematic review of critical infrastructure resilience indicators. Construction Innovation, 23(5), 1210–1231. https://doi.org/10.1108/ci-03-2021-0047

31. Owen, R., Bryant, A., Finch, L., Franklin, D., Abdollahi, M., & Abolhasan, M. (2025). Failures and resilience in the IP era: Navigating the fragility of modern telecommunications networks: The sovereign functions. IEEE Access, 13, 155759–155777. https://doi.org/10.1109/access.2025.3602054

32. Patriarca, R., Simone, F., & Di Gravio, G. (2022). Modelling cyber resilience in a water treatment and distribution system. Reliability Engineering & System Safety, 226, 108653. https://doi.org/10.1016/j.ress.2022.108653

33. Patterson, C. M., Nurse, J. R. C., & Franqueira, V. N. L. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. https://doi.org/10.1016/j.cose.2023.103309

34. Pinciroli, L., Baraldi, P., & Zio, E. (2023). Maintenance optimization in industry 4.0. Reliability Engineering & System Safety, 234, 109204. https://doi.org/10.1016/j.ress.2023.109204

35. Pursiainen, C., & Kytömaa, E. (2023). From European critical infrastructure protection to the resilience of European critical entities: What does it mean? Sustainable and Resilient Infrastructure, 8(sup1), 85–101. https://doi.org/10.1080/23789689.2022.2128562

36. Reporting Requirements for Disruptions to Communications, 47 C.F.R. pt. 4 (2025).

37. Saeed, S., Suayyid, S. A., Al-Ghamdi, M. S., Al-Muhaisen, H., & Almuhaideb, A. M. (2023). A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors, 23(16), 7273. https://doi.org/10.3390/s23167273

38. Sathurshan, M., Saja, A., Thamboo, J., Haraguchi, M., & Navaratnam, S. (2022). Resilience of critical infrastructure systems: A systematic literature review of measurement frameworks. Infrastructures, 7(5), 67. https://doi.org/10.3390/infrastructures7050067

39. Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4

40. Staves, A., Anderson, T., Balderstone, H., Green, B., Gouglidis, A., & Hutchison, D. (2022). A cyber incident response and recovery framework to support operators of industrial control systems. International Journal of Critical Infrastructure Protection, 37, 100505. https://doi.org/10.1016/j.ijcip.2021.100505

41. Steen, R., Haug, O. J., & Patriarca, R. (2024). Business continuity and resilience management: A conceptual framework. Journal of Contingencies and Crisis Management, 32(1), e12501. https://doi.org/10.1111/1468-5973.12501

42. Sterbenz, J. P. G., Hutchison, D., Çetinkaya, E. K., Jabbar, A., Rohrer, J. P., Schöller, M., & Smith, P. (2010). Resilience and survivability in communication networks: Strategies, principles, and survey of disciplines. Computer Networks, 54(8), 1245–1265. https://doi.org/10.1016/j.comnet.2010.03.005

43. Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center: A systematic study and open challenges. IEEE Access, 8, 227756–227779. https://doi.org/10.1109/access.2020.3045514

44. Wallis, T., & Dorey, P. (2023). Implementing partnerships in energy supply chain cybersecurity resilience. Energies, 16(4), 1868. https://doi.org/10.3390/en16041868

45. White House. (2024). National security memorandum on critical infrastructure security and resilience (NSM-22). https://www.presidency.ucsb.edu/documents/national-security-memorandum-critical-infrastructure-security-and-resilience

Downloads

Published

2026-08-25

How to Cite

Strengthening Telecommunications Resilience through Cybersecurity Governance, Preventive Maintenance, and Coordinated Incident Response. (2026). International Journal of Engineering & Extended Technologies Research (IJEETR), 8(4), 5619-5630. https://doi.org/10.15662/IJEETR.2026.0804009