Home / Current Issue / Paper 1722199
Cyber Risk Management and Compliance Readiness for Large-Scale Smart City Infrastructure
Subject area: Science,Engineering and Technology · Area of research: Cyber Risk Management
DOI: https://doi.org/10.64388/IREV10I2-1722199
Abstract
Large-scale smart city infrastructure is emerging as a strategic urban asset; however, it also expands the attack surface by interconnecting mobility platforms, utilities, public safety systems, data exchanges, cloud services, operational technology, and artificial intelligence-enabled decision services. Cyber risk management in this context cannot be approached as a periodic audit exercise, as disruptions may simultaneously impact safety, privacy, service continuity, public trust, and regulatory compliance. This review develops a compliance-readiness framework for smart city infrastructure by synthesising recent literature and control guidance published between 2020 and 2025. The study examines cyber risk across assets, data, identities, vendors, operational technology, cloud platforms, incident response, and governance evidence. It contends that readiness depends on the integration of risk registers with technical controls, control ownership, verification evidence, incident rehearsals, and board-level decision-making. The paper presents a structured architecture and an operating cycle intended to guide city authorities, project owners, technology integrators, and critical service operators throughout planning, procurement, commissioning, and operational phases. The review concludes that resilient smart city programmes require risk-based design, zero-trust access, privacy-aware data governance, secure-by-design procurement, continuous monitoring, tested recovery procedures, and measurable compliance evidence. These capabilities are particularly essential for Saudi smart city programmes aligned with digital transformation, national cybersecurity priorities, and Vision 2030.
Keywords
Smart City Infrastructure, Cyber Risk Management, Compliance Readiness, Cyber Resilience, Data Governance, Operational Technology, Cloud Security, Saudi Arabia, Vision 2030
References
[1] Ismagilova, E., Hughes, L., Rana, N. P., & Dwivedi, Y. K. (2022). Security, privacy and risks within smart cities: Literature review and development of a smart city interaction framework. Information Systems Frontiers, 24(2), 393-414. https://doi.org/10.1007/s10796-020-10044-1
[2] Rizi, M. H. P., & Seno, S. A. H. (2022). A systematic review of technologies and solutions to improve security and privacy protection of citizens in the smart city. Internet of Things, 20, 100584. https://doi.org/10.1016/j.iot.2022.100584
[3] Kour, H., Karim, S., & colleagues. (2023). Cybersecurity and cyber forensics for smart cities: A comprehensive literature review and survey. Sensors, 23(7), 3681. https://doi.org/10.3390/s23073681
[4] Anwar, R., & Ali, S. (2022). Smart cities security threat landscape: A review. Computing and Informatics, 41(2), 405-423. https://doi.org/10.31577/cai_2022_2_405
[5] European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. ENISA, Athens.
[6] National Cybersecurity Authority. (2020). National cybersecurity strategy. Kingdom of Saudi Arabia.
[7] Saudi Data and Artificial Intelligence Authority. (2024). Personal Data Protection Law implementing regulations. SDAIA, Riyadh.
[8] National Cybersecurity Authority. (2022). Data Cybersecurity Controls (DCC-1:2022). Kingdom of Saudi Arabia.
[9] National Cybersecurity Authority. (2024). Cloud Cybersecurity Controls (CCC-2:2024). Kingdom of Saudi Arabia.
[10] National Cybersecurity Authority. (2022). Operational Technology Cybersecurity Controls (OTCC-1:2022). Kingdom of Saudi Arabia.
[11] National Institute of Standards and Technology. (2024). The Cybersecurity Framework (CSF) 2.0. NIST Cybersecurity White Paper, CSWP 29. https://doi.org/10.6028/NIST.CSWP.29
[12] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207
[13] Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2022). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST Special Publication 800-161 Revision 1. https://doi.org/10.6028/NIST.SP.800-161r1
[14] Cybersecurity and Infrastructure Security Agency. (2023). Cross-Sector Cybersecurity Performance Goals. CISA, Washington, DC.
[15] International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements. ISO, Geneva.
[16] National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, Gaithersburg, MD. https://doi.org/10.6028/NIST.AI.100-1
[17] International Organization for Standardization. (2022). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls. ISO, Geneva.
[18] Fagan, M., Marron, J., Brady, K., Jr., Cuthill, B., Megas, K., & Herold, R. (2021). IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements. NIST Special Publication 800-213. https://doi.org/10.6028/NIST.SP.800-213
[19] Cybersecurity and Infrastructure Security Agency. (2023). Zero Trust Maturity Model, Version 2.0. CISA, Washington, DC.
[20] Saudi Data and Artificial Intelligence Authority. (2020). National Data Governance Policies. SDAIA, Riyadh.
[21] National Institute of Standards and Technology. (2022). Secure Software Development Framework (SSDF), Version 1.1. NIST Special Publication 800-218. https://doi.org/10.6028/NIST.SP.800-218
[22] Cybersecurity and Infrastructure Security Agency. (2021). Federal Government Cybersecurity Incident and Vulnerability Response Playbooks. CISA, Washington, DC.
[23] United Nations Human Settlements Programme. (2022). People-centered smart cities: A thematic guide. UN-Habitat, Nairobi.
[24] European Parliament and Council. (2024). Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements. Official Journal of the European Union.
[25] The Institute of Internal Auditors. (2020). The IIA's Three Lines Model: An update of the Three Lines of Defense. IIA, Lake Mary, FL.
[26] European Union Agency for Cybersecurity. (2023). Cybersecurity exercises: Good practice guide. ENISA, Athens.
[27] European Parliament and Council. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. Official Journal of the European Union.
[28] European Parliament and Council. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. Official Journal of the European Union.
[29] Tariq, U., Ahmed, I., Bashir, A. K., & Shaukat, K. (2023). A critical cybersecurity analysis and future research directions for the Internet of Things: A comprehensive review. Sensors, 23(8), 4117. https://doi.org/10.3390/s23084117
[30] World Economic Forum. (2021). Governing smart cities: Policy benchmarks for ethical and responsible smart city development. WEF, Geneva.
How to cite this paper
@article{1722199,
author = {Munir Ahmed Mohammed},
title = {Cyber Risk Management and Compliance Readiness for Large-Scale Smart City Infrastructure},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {2},
pages = {824-835},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722199.pdf},
abstract = {Large-scale smart city infrastructure is emerging as a strategic urban asset; however, it also expands the attack surface by interconnecting mobility platforms, utilities, public safety systems, data exchanges, cloud services, operational technology, and artificial intelligence-enabled decision services. Cyber risk management in this context cannot be approached as a periodic audit exercise, as disruptions may simultaneously impact safety, privacy, service continuity, public trust, and regulatory compliance. This review develops a compliance-readiness framework for smart city infrastructure by synthesising recent literature and control guidance published between 2020 and 2025. The study examines cyber risk across assets, data, identities, vendors, operational technology, cloud platforms, incident response, and governance evidence. It contends that readiness depends on the integration of risk registers with technical controls, control ownership, verification evidence, incident rehearsals, and board-level decision-making. The paper presents a structured architecture and an operating cycle intended to guide city authorities, project owners, technology integrators, and critical service operators throughout planning, procurement, commissioning, and operational phases. The review concludes that resilient smart city programmes require risk-based design, zero-trust access, privacy-aware data governance, secure-by-design procurement, continuous monitoring, tested recovery procedures, and measurable compliance evidence. These capabilities are particularly essential for Saudi smart city programmes aligned with digital transformation, national cybersecurity priorities, and Vision 2030.},
keywords = {Smart City Infrastructure, Cyber Risk Management, Compliance Readiness, Cyber Resilience, Data Governance, Operational Technology, Cloud Security, Saudi Arabia, Vision 2030},
month = {August},
doi = {https://doi.org/10.64388/IREV10I2-1722199}
}