Strengthening Telecommunications Resilience through Cybersecurity Governance, Preventive Maintenance, and Coordinated Incident Response
DOI:
https://doi.org/10.15662/IJEETR.2026.0804009Keywords:
telecommunications resilience, cybersecurity governance, preventive maintenance, incident response, critical digital infrastructure, service continuityAbstract
Telecommunications networks now underpin the delivery of financial, healthcare, government, and emergency services, which makes service continuity in this sector a matter of public as well as commercial consequence. Operators face disruption from two directions that they typically govern separately: physical and technical failure addressed through engineering maintenance, and adversarial activity addressed through information security. This article examines whether that separation is defensible and what an integrated alternative would involve. Using a structured narrative literature review of thirty peer reviewed sources, six core standards and guidance documents, and selected primary United States legal and regulatory materials, it synthesises four literatures that have developed largely in parallel, covering critical infrastructure resilience, maintenance optimisation, incident response, and cybersecurity governance. The review finds that resilience measurement weights heavily toward outcome indicators, that maintenance optimisation remains largely cyber agnostic, that incident response research centres on enterprise security operations rather than multi vendor field restoration, and that governance research is normative rather than operational. Drawing on management system logic, the governance function of the NIST Cybersecurity Framework 2.0, cyber resiliency engineering objectives, and organisational learning theory, the article proposes a thirteen stage integrated governance framework organised into phases of direction, prevention, response, and learning, together with nine performance indicators combining leading and outcome measures. Its central proposition is that preventive maintenance and security monitoring should share a governance cycle because both depend on asset inventory and behavioural baselining. The framework is proposed rather than empirically validated.References
1. Aghazadeh Ardebili, A., Lezzi, M., & Pourmadadkar, M. (2024). Risk assessment for cyber resilience of critical infrastructures: Methods, governance, and standards. Applied Sciences, 14(24), 11807. https://doi.org/10.3390/app142411807
2. Ahmad, A., Desouza, K. C., Maynard, S. B., Naseer, H., & Baskerville, R. L. (2020). How integration of cyber security management and incident response enables organizational learning. Journal of the Association for Information Science and Technology, 71(8), 939–953. https://doi.org/10.1002/asi.24311
3. Ahmad, A., Maynard, S. B., Desouza, K. C., Kotsias, J., Whitty, M. T., & Baskerville, R. L. (2021). How can organizations develop situation awareness for incident response: A case study of management practice. Computers & Security, 101, 102122. https://doi.org/10.1016/j.cose.2020.102122
4. Bi, S., Yuan, X., Hu, S., Li, K., Ni, W., Hossain, E., & Wang, X. (2026). Resilience and failure analysis in next-generation communication networks: A contemporary survey. IEEE Transactions on Network Science and Engineering, 13, 2793–2821. https://doi.org/10.1109/tnse.2025.3620950
5. Busetti, S., & Scanni, F. M. (2025). Evaluating incident reporting in cybersecurity: From threat detection to policy learning. Government Information Quarterly, 42(1), 102000. https://doi.org/10.1016/j.giq.2024.102000
6. Büyüközkan, G., & Güler, M. (2025). Cybersecurity maturity model: Systematic literature review and a proposed model. Technological Forecasting and Social Change, 213, 123996. https://doi.org/10.1016/j.techfore.2025.123996
7. Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/tqm-09-2020-0202
8. Cyber Incident Reporting for Critical Infrastructure Act of 2022, Pub. L. No. 117-103, div. Y, 136 Stat. 49, 1038 (2022) (codified at 6 U.S.C. §§ 681–681g).
9. Cybersecurity and Infrastructure Security Agency. (n.d.). Public safety communications and cyber resiliency toolkit (Version 24.2). Retrieved August 6, 2026, from https://www.cisa.gov/resources-tools/resources/communications-and-cyber-resiliency-toolkit
10. Cybersecurity and Infrastructure Security Agency. (2024). Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) reporting requirements: Notice of proposed rulemaking (89 Fed. Reg. 23644, April 4, 2024). https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements
11. Cybersecurity and Infrastructure Security Agency. (2025). Cross-sector cybersecurity performance goals. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
12. Cybersecurity and Infrastructure Security Agency. (n.d.). Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA): Frequently asked questions. Retrieved August 19, 2026, from https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs
13. Federal Communications Commission. (2024). Resilient networks; disruptions to communications (Second Report and Order, FCC 24-5; 89 Fed. Reg. 25542, April 11, 2024). https://www.federalregister.gov/documents/2024/04/11/2024-07402/resilient-networks-disruptions-to-communications
14. Federal Communications Commission. (2025). Protecting the nation’s communications systems from cybersecurity threats (Order on Reconsideration, PS Docket No. 22-329, FCC 25-81; 90 Fed. Reg. 58006, December 15, 2025). https://www.federalregister.gov/documents/2025/12/15/2025-22830/protecting-the-nations-communications-systems-from-cybersecurity-threats
15. Federal Communications Commission. (n.d.). Network Outage Reporting System (NORS). Retrieved August 19, 2026, from https://www.fcc.gov/general/network-outage-reporting-system-nors
16. Galaitsi, S. E., Pinigina, E., Keisler, J. M., Pescaroli, G., Keenan, J. M., & Linkov, I. (2023). Business continuity management, operational resilience, and organizational resilience: Commonalities, distinctions, and synthesis. International Journal of Disaster Risk Science, 14(5), 713–721. https://doi.org/10.1007/s13753-023-00494-x
17. Gallarno, G., Muniz, J., Parnell, G. S., Pohl, E. A., & Wu, J. (2024). Development and assessment of a resilient telecoms system. The Journal of Defense Modeling and Simulation: Applications, Methodology, Technology, 21(4), 405–420. https://doi.org/10.1177/15485129221143791
18. Ghadge, A., Weiß, M., Caldwell, N. D., & Wilding, R. (2020). Managing cyber risk in supply chains: A review and research agenda. Supply Chain Management: An International Journal, 25(2), 223–240. https://doi.org/10.1108/scm-10-2018-0357
19. International Organization for Standardization. (2019). ISO 22301:2019. Security and resilience: Business continuity management systems, requirements.
20. International Organization for Standardization. (2022). ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection: Information security management systems, requirements.
21. Jiang, P., Rowsell, J., & Schmidt, S. (2025). Crisis-ready telecom: Global approaches to emergency management in telecommunications. Telecommunications Policy, 49(4), 102914. https://doi.org/10.1016/j.telpol.2025.102914
22. Miller, T., Staves, A., Maesschalck, S., Sturdee, M., & Green, B. (2021). Looking back to look forward: Lessons learnt from cyber-attacks on industrial control systems. International Journal of Critical Infrastructure Protection, 35, 100464. https://doi.org/10.1016/j.ijcip.2021.100464
23. Mottahedi, A., Sereshki, F., Ataei, M., Nouri Qarahasanlou, A., & Barabadi, A. (2021). The resilience of critical infrastructure systems: A systematic literature review. Energies, 14(6), 1571. https://doi.org/10.3390/en14061571
24. Naseer, A., Naseer, H., Ahmad, A., Maynard, S. B., & Masood Siddiqui, A. (2021). Real-time analytics, incident response process agility and enterprise cybersecurity performance: A contingent resource-based analysis. International Journal of Information Management, 59, 102334. https://doi.org/10.1016/j.ijinfomgt.2021.102334
25. Naseer, A., Naseer, H., Ahmad, A., Maynard, S. B., & Siddiqui, A. M. (2023). Moving towards agile cybersecurity incident response: A case study exploring the enabling role of big data analytics-embedded dynamic capabilities. Computers & Security, 135, 103525. https://doi.org/10.1016/j.cose.2023.103525
26. Naseer, H., Desouza, K. C., Maynard, S. B., & Ahmad, A. (2024). Enabling cybersecurity incident response agility through dynamic capabilities: The role of real-time analytics. European Journal of Information Systems, 33(2), 200–220. https://doi.org/10.1080/0960085x.2023.2257168
27. National Institute of Standards and Technology. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Rev. 1). https://doi.org/10.6028/NIST.SP.800-160v2r1
28. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29
29. National Institute of Standards and Technology. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST Special Publication 800-61, Rev. 3). https://doi.org/10.6028/NIST.SP.800-61r3
30. Osei-Kyei, R., Almeida, L. M., Ampratwum, G., & Tam, V. (2023). Systematic review of critical infrastructure resilience indicators. Construction Innovation, 23(5), 1210–1231. https://doi.org/10.1108/ci-03-2021-0047
31. Owen, R., Bryant, A., Finch, L., Franklin, D., Abdollahi, M., & Abolhasan, M. (2025). Failures and resilience in the IP era: Navigating the fragility of modern telecommunications networks: The sovereign functions. IEEE Access, 13, 155759–155777. https://doi.org/10.1109/access.2025.3602054
32. Patriarca, R., Simone, F., & Di Gravio, G. (2022). Modelling cyber resilience in a water treatment and distribution system. Reliability Engineering & System Safety, 226, 108653. https://doi.org/10.1016/j.ress.2022.108653
33. Patterson, C. M., Nurse, J. R. C., & Franqueira, V. N. L. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. https://doi.org/10.1016/j.cose.2023.103309
34. Pinciroli, L., Baraldi, P., & Zio, E. (2023). Maintenance optimization in industry 4.0. Reliability Engineering & System Safety, 234, 109204. https://doi.org/10.1016/j.ress.2023.109204
35. Pursiainen, C., & Kytömaa, E. (2023). From European critical infrastructure protection to the resilience of European critical entities: What does it mean? Sustainable and Resilient Infrastructure, 8(sup1), 85–101. https://doi.org/10.1080/23789689.2022.2128562
36. Reporting Requirements for Disruptions to Communications, 47 C.F.R. pt. 4 (2025).
37. Saeed, S., Suayyid, S. A., Al-Ghamdi, M. S., Al-Muhaisen, H., & Almuhaideb, A. M. (2023). A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors, 23(16), 7273. https://doi.org/10.3390/s23167273
38. Sathurshan, M., Saja, A., Thamboo, J., Haraguchi, M., & Navaratnam, S. (2022). Resilience of critical infrastructure systems: A systematic literature review of measurement frameworks. Infrastructures, 7(5), 67. https://doi.org/10.3390/infrastructures7050067
39. Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4
40. Staves, A., Anderson, T., Balderstone, H., Green, B., Gouglidis, A., & Hutchison, D. (2022). A cyber incident response and recovery framework to support operators of industrial control systems. International Journal of Critical Infrastructure Protection, 37, 100505. https://doi.org/10.1016/j.ijcip.2021.100505
41. Steen, R., Haug, O. J., & Patriarca, R. (2024). Business continuity and resilience management: A conceptual framework. Journal of Contingencies and Crisis Management, 32(1), e12501. https://doi.org/10.1111/1468-5973.12501
42. Sterbenz, J. P. G., Hutchison, D., Çetinkaya, E. K., Jabbar, A., Rohrer, J. P., Schöller, M., & Smith, P. (2010). Resilience and survivability in communication networks: Strategies, principles, and survey of disciplines. Computer Networks, 54(8), 1245–1265. https://doi.org/10.1016/j.comnet.2010.03.005
43. Vielberth, M., Böhm, F., Fichtinger, I., & Pernul, G. (2020). Security operations center: A systematic study and open challenges. IEEE Access, 8, 227756–227779. https://doi.org/10.1109/access.2020.3045514
44. Wallis, T., & Dorey, P. (2023). Implementing partnerships in energy supply chain cybersecurity resilience. Energies, 16(4), 1868. https://doi.org/10.3390/en16041868
45. White House. (2024). National security memorandum on critical infrastructure security and resilience (NSM-22). https://www.presidency.ucsb.edu/documents/national-security-memorandum-critical-infrastructure-security-and-resilience





