International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1723364

1723364 Vol 10 · Issue 3 Download Paper

A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030

Ilyas Siddiqui Mohammad

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Resilience Framework

Abstract

Saudi Arabia's rapid expansion of digital government has made cyber resilience a matter of public-service continuity rather than a purely technical security concern. Government platforms now depend on cloud services, shared data environments, mobile access, Internet of Things (IoT) devices, artificial intelligence, and increasingly interconnected critical systems. These developments improve the reach and efficiency of public services, but they also create dependencies that can amplify the effect of a cyber-incident. This review examines how a threat-driven cyber resilience approach combining integrated security architecture, cyber-threat intelligence (CTI), zero-trust principles, and adaptive security operations can enhance the continuity and protection of Saudi government digital services within the wider objectives of Vision 2030. A structured integrative review of 30 peer-reviewed studies, international cybersecurity frameworks, and Saudi regulatory publications issued between 2020 and 2025 was used to examine the relationship between governance, zero-trust access, security architecture, threat intelligence, security operations, and recovery. The evidence indicates that compliance controls are necessary but insufficient when identity, network, cloud, endpoint, data, and operational-technology protections operate as separate functions. Resilience improves when those controls are connected through common telemetry, context-aware access decisions, intelligence-led detection, governed automation, tested recovery, and post-incident learning. Saudi Arabia's National Cybersecurity Strategy and National Cybersecurity Authority (NCA) control families provide the national governance foundation, while NIST and CISA frameworks offer useful architectural and maturity guidance. Based on the synthesis, the paper proposes the Saudi Adaptive Cyber Resilience Architecture (SACRA), a threat-driven framework that connects mission assurance, zero-trust identity, protected infrastructure, intelligence-led security operations, adaptive response, recovery, and continuous evolution. The model is intended to support reliable public services, strengthen institutional readiness, and preserve confidence in the Kingdom's long-term digital transformation.

Keywords

cyber resilience; Saudi Vision 2030; digital government; integrated security architecture; cyber-threat intelligence; zero trust; NCA; security operations.

References

[1] Z. Adahman, A. W. Malik, and Z. Anwar, “An analysis of zero-trust architecture and its cost-effectiveness for organizational security,” Computers & Security, vol. 122, Art. no. 102911, 2022, doi: 10.1016/j.cose.2022.102911. ScienceDirect

[2] S. Ainslie, D. Thompson, S. B. Maynard, and A. Ahmad, “Cyber-threat intelligence for security decision-making: A review and research agenda for practice,” Computers & Security, vol. 132, Art. no. 103352, 2023, doi: 10.1016/j.cose.2023.103352. ScienceDirect

[3] S. M. Alhidaifi, M. R. Asghar, and I. S. Ansari, “A Survey on Cyber Resilience: Key Strategies, Research Challenges, and Future Directions,” ACM Computing Surveys, vol. 56, no. 8, Art. no. 196, pp. 1–48, 2024, doi: 10.1145/3649218. ACM

[4] G. Cascavilla, D. A. Tamburri, and W.-J. Van Den Heuvel, “Cybercrime threat intelligence: A systematic multi-vocal literature review,” Computers & Security, vol. 105, Art. no. 102258, 2021, doi: 10.1016/j.cose.2021.102258. Crossref

[5] Cybersecurity and Infrastructure Security Agency, Zero Trust Maturity Model, Version 2.0. Washington, DC, USA: CISA, 2023. CISA

[6] A. S. Dina and D. Manivannan, “Intrusion detection based on Machine Learning techniques in computer networks,” Internet of Things, vol. 16, Art. no. 100462, 2021, doi: 10.1016/j.iot.2021.100462. Crossref

[7] Y. He, D. Huang, L. Chen, Y. Ni, and X. Ma, “A Survey on Zero Trust Architecture: Challenges and Future Trends,” Wireless Communications and Mobile Computing, vol. 2022, Art. no. 6476274, 2022, doi: 10.1155/2022/6476274. Crossref

[8] Y. Jiang, M. A. Jeusfeld, M. Mosaad, and N. Oo, “Enterprise architecture modeling for cybersecurity analysis in critical infrastructures—A systematic literature review,” International Journal of Critical Infrastructure Protection, vol. 46, Art. no. 100700, 2024, doi: 10.1016/j.ijcip.2024.100700. ScienceDirect

[9] H. Kang, G. Liu, Q. Wang, L. Meng, and J. Liu, “Theory and Application of Zero Trust Security: A Brief Survey,” Entropy, vol. 25, no. 12, Art. no. 1595, 2023, doi: 10.3390/e25121595. MDPI

[10] R. Kaur, D. Gabrijelčič, and T. Klobučar, “Artificial intelligence for cybersecurity: Literature review and future research directions,” Information Fusion, vol. 97, Art. no. 101804, 2023, doi: 10.1016/j.inffus.2023.101804. Crossref

[11] J. Kinyua and L. Awuah, “AI/ML in Security Orchestration, Automation and Response: Future Research Directions,” Intelligent Automation & Soft Computing, vol. 28, no. 2, pp. 527–545, 2021, doi: 10.32604/iasc.2021.016240. Tech Science Press

[12] A. N. Lone, S. Mustajab, and M. Alam, “A comprehensive study on cybersecurity challenges and opportunities in the IoT world,” Security and Privacy, vol. 6, no. 6, Art. no. e318, 2023, doi: 10.1002/spy2.318. Wiley

[13] M. Malatji, A. L. Marnewick, and S. von Solms, “Cybersecurity capabilities for critical infrastructure resilience,” Information & Computer Security, vol. 30, no. 2, pp. 255–279, 2022, doi: 10.1108/ICS-06-2021-0091. Emerald

[14] National Cybersecurity Authority, National Cybersecurity Strategy. Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2020.

[15] National Cybersecurity Authority, Cloud Cybersecurity Controls (CCC-1:2020). Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2020. NCA

[16] National Cybersecurity Authority, Data Cybersecurity Controls (DCC-1:2022). Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2022. NCA

[17] National Cybersecurity Authority, Operational Technology Cybersecurity Controls (OTCC-1:2022). Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2022. NCA

[18] National Cybersecurity Authority, Essential Cybersecurity Controls (ECC 2-2024). Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2024. NCA

[19] National Cybersecurity Authority, Cloud Cybersecurity Controls (CCC-2:2024). Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2024. NCA

[20] National Cybersecurity Authority, Report on Key Economic Indicators in the Cybersecurity Sector of 2024. Riyadh, Saudi Arabia: Kingdom of Saudi Arabia, 2024. NCA

[21] C. Pascoe, S. Quinn, and K. Scarfone, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.CSWP.29. NIST

[22] B. M. Reichert and R. R. Obelheiro, “Software supply chain security: a systematic literature review,” International Journal of Computers and Applications, vol. 46, no. 10, pp. 853–867, 2024, doi: 10.1080/1206212X.2024.2390978. Taylor & Francis

[23] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, Zero Trust Architecture, NIST Special Publication 800-207. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2020, doi: 10.6028/NIST.SP.800-207. NIST

[24] R. S. Ross and V. Y. Pillitteri, Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53 Revision 5. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2020, doi: 10.6028/NIST.SP.800-53r5. NIST

[25] S. Saeed, “Digital Transformation in Governmental Public Service Provision and Usable Security Perception in Saudi Arabia,” Information, vol. 16, no. 3, Art. no. 247, 2025, doi: 10.3390/info16030247. MDPI

[26] S. Saeed, S. A. Suayyid, M. S. Al-Ghamdi, H. Al-Muhaisen, and A. M. Almuhaideb, “A Systematic Literature Review on Cyber Threat Intelligence for Organizational Cybersecurity Resilience,” Sensors, vol. 23, no. 16, Art. no. 7273, 2023, doi: 10.3390/s23167273. MDPI

[27] A. H. Salem, S. M. Azzam, O. E. Emam, and A. A. Abohany, “Advancing cybersecurity: a comprehensive review of AI-driven detection techniques,” Journal of Big Data, vol. 11, Art. no. 105, 2024, doi: 10.1186/s40537-024-00957-y. Springer

[28] Saudi Data and Artificial Intelligence Authority, Data Management and Personal Data Protection Standards, Version 1.5. Riyadh, Saudi Arabia: National Data Management Office, 2021.

[29] D. A. Sepúlveda Estay, R. Sahay, M. B. Barfod, and C. D. Jensen, “A systematic review of cyber-resilience assessment frameworks,” Computers & Security, vol. 97, Art. no. 101996, 2020, doi: 10.1016/j.cose.2020.101996. ScienceDirect

[30] Q. Tang, O. Ermis, C. D. Nguyen, A. De Oliveira, and A. Hirtzig, “A Systematic Analysis of 5G Networks With a Focus on 5G Core Security,” IEEE Access, vol. 10, pp. 18298–18319, 2022, doi: 10.1109/ACCESS.2022.3151000. IEEE

How to cite this paper

Ilyas Siddiqui Mohammad "A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 2817-2833
Ilyas Siddiqui Mohammad "A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026
Ilyas Siddiqui Mohammad (2026). A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030. Iconic Research And Engineering Journals, 10(3).
Ilyas Siddiqui Mohammad "A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026.
@article{1723364,
      author = {Ilyas Siddiqui Mohammad},
      title = {A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {2817-2833},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1723364.pdf},
      abstract = {Saudi Arabia's rapid expansion of digital government has made cyber resilience a matter of public-service continuity rather than a purely technical security concern. Government platforms now depend on cloud services, shared data environments, mobile access, Internet of Things (IoT) devices, artificial intelligence, and increasingly interconnected critical systems. These developments improve the reach and efficiency of public services, but they also create dependencies that can amplify the effect of a cyber-incident. This review examines how a threat-driven cyber resilience approach combining integrated security architecture, cyber-threat intelligence (CTI), zero-trust principles, and adaptive security operations can enhance the continuity and protection of Saudi government digital services within the wider objectives of Vision 2030. A structured integrative review of 30 peer-reviewed studies, international cybersecurity frameworks, and Saudi regulatory publications issued between 2020 and 2025 was used to examine the relationship between governance, zero-trust access, security architecture, threat intelligence, security operations, and recovery. The evidence indicates that compliance controls are necessary but insufficient when identity, network, cloud, endpoint, data, and operational-technology protections operate as separate functions. Resilience improves when those controls are connected through common telemetry, context-aware access decisions, intelligence-led detection, governed automation, tested recovery, and post-incident learning. Saudi Arabia's National Cybersecurity Strategy and National Cybersecurity Authority (NCA) control families provide the national governance foundation, while NIST and CISA frameworks offer useful architectural and maturity guidance. Based on the synthesis, the paper proposes the Saudi Adaptive Cyber Resilience Architecture (SACRA), a threat-driven framework that connects mission assurance, zero-trust identity, protected infrastructure, intelligence-led security operations, adaptive response, recovery, and continuous evolution.
The model is intended to support reliable public services, strengthen institutional readiness, and preserve confidence in the Kingdom's long-term digital transformation.},
      keywords = {cyber resilience; Saudi Vision 2030; digital government; integrated security architecture; cyber-threat intelligence; zero trust; NCA; security operations.},
      month = {September},
  }