Article reader Listen + reading controls
Article reader
Preparing the reader…
Reading settings
A digital twin can preserve operational judgment¶
The National Institute of Standards and Technology (NIST) is exploring how digital twins could help manufacturers detect cyberattacks. By comparing a physical process with its virtual representation, a team may recognize changes that ordinary information-technology monitoring misses: a machine behaving differently, a process drifting, or a control command producing an unexpected physical result.
The cybersecurity potential is important. So is the knowledge-management lesson. A useful digital twin does not merely mirror equipment. It preserves an organization's understanding of what normal operation means.
Normal is partly tacit¶
A manufacturing line produces abundant data, but experienced operators often recognize trouble before a dashboard does. They notice a vibration, timing change, sound, sequence, or combination of small deviations that does not yet cross a formal threshold. That recognition is tacit knowledge: difficult to state fully, learned through participation, and closely tied to context.
A digital twin can help make some of that knowledge explicit. Engineers can encode expected relationships among sensor readings, process states, control actions, and physical outcomes. Cybersecurity teams can then use the model to ask whether the system is merely unusual or behaving inconsistently with its designed process.
Nonaka's theory of organizational knowledge creation explains why this matters. Organizations learn by moving between tacit experience and explicit representation, then returning those representations to practice. A twin can support that movement, but it cannot automate it. Someone must translate operator insight into scenarios and rules, and operators must test whether the representation still makes sense.
The twin creates a new attack and assurance surface¶
A digital twin is not an incorruptible reference. Its data feeds, configuration, assumptions, and update process can be wrong or compromised. If defenders trust it automatically, an attacker may exploit the comparison mechanism itself.
The twin therefore needs its own assurance case:
- provenance for the data and configuration that define expected behavior;
- separation between observation, control, and model-management functions;
- access controls for changes to thresholds and process logic;
- validation against physical performance after meaningful changes; and
- records of disagreements between the model and operator judgment.
The last item is particularly valuable. A disagreement is not simply noise to suppress. It may reveal an incomplete model, a changing process, a sensor problem, or a novel attack. Treating it as a learning event keeps the twin from becoming an unquestioned authority.
Build the handoff between three communities¶
Operational technology (OT) engineers, cybersecurity specialists, and operators often describe the same event differently. The engineer sees process states. The cyber analyst sees indicators and attack paths. The operator sees whether the system can still accomplish the work safely.
A digital twin can become a boundary object among these communities if the organization creates a common incident record. For each anomaly, capture:
- the physical observation;
- the expected model behavior;
- the relevant cyber evidence;
- the operator's interpretation;
- the decision taken; and
- whether the twin, detector, procedure, or training must change.
This structure turns a one-time investigation into organizational memory. It also reduces a common failure in critical systems: the technical team fixes the immediate fault, while the reason it mattered remains with the person who noticed it.
Digital twins will not replace experienced people. Used well, they can make experience easier to share, test, and retain. Their real promise for cybersecurity is not a perfect virtual copy. It is a disciplined conversation between the physical process, the model, and the people who know when neither is telling the whole story.
Sources and research trail¶
- National Institute of Standards and Technology, “How Digital Twins Could Protect Manufacturers From Cyberattacks” (February 23, 2023).
- National Institute of Standards and Technology, Guide to Operational Technology Security (2015).
- Nonaka, “A Dynamic Theory of Organizational Knowledge Creation” (1994).
- Argote and Ingram, “Knowledge Transfer: A Basis for Competitive Advantage in Firms” (2000).
- Star and Griesemer, “Institutional Ecology, ‘Translations’ and Boundary Objects” (1989).