Home / Current Issue / Paper 1723367
Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
Ransomware has evolved from being merely an IT problem into a cyber-physical resilience issue for industrial companies. In Saudi Arabia, industrial digitisation, cloud adoption, remote engineering and IT/OT convergence can improve efficiency while also expanding pathways through which cyber incidents may affect production, safety, quality and continuity (National Cybersecurity Authority, 2022; Kayan et al., 2022; Benmalek, 2024). This review examines how Saudi industrial organisations can improve ransomware resilience by integrating IT and OT cybersecurity with incident response. It uses a structured integrative review of 19 peer-reviewed, standards and government sources published mainly from 2020 to September 2026, with older or foundational guidance retained where necessary. The synthesis highlights five interdependent resilience themes: governance and risk ownership; asset visibility and architecture; identity, segmentation and secure access; detection and coordinated response; and trusted recovery of operational capability. The evidence indicates that enterprise ransomware controls need OT-specific adaptation because industrial environments place distinctive emphasis on availability, safety, legacy assets and process dependencies (Stouffer et al., 2023; Al-Hawawreh et al., 2024; Saini et al., 2026). Resilience therefore requires shared IT/OT decision structures, engineering-aware containment, protected and tested backups, dependency-aware recovery sequencing, supplier coordination and exercises that test degraded operations rather than data restoration alone (CISA, 2023a; Maysey et al., 2026). Saudi NCA controls provide a governance baseline within their applicable scope, while plant-level playbooks and explicit recovery acceptance criteria translate that baseline into operational capability (National Cybersecurity Authority, 2019, 2022, 2024). The paper proposes an integrated plant-centred resilience model linking preparation, detection, containment, recovery and organisational learning, and identifies practical metrics and future research priorities.
Keywords
ransomware; cyber resilience; operational technology; industrial control systems; IT/OT convergence; incident response; Saudi Arabia; critical infrastructure
References
[1] C. Y. Chiu, “From backup restoration to Minimum Viable Factory Recovery: A systematization of ransomware recovery in manufacturing systems,” International Journal of Critical Infrastructure Protection, vol. 54, Art. no. 100882, 2026, doi: 10.1016/j.ijcip.2026.100882. ScienceDirect
[2] Cybersecurity and Infrastructure Security Agency, #StopRansomware Guide, 2023. CISA
[3] Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals, 2023. CISA
[4] M. Souppaya, W. C. Barker, W. Fisher, and K. Kent, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile, NIST IR 8374 Rev. 1. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2026.
[5] H. Kayan, M. Nunes, O. Rana, P. Burnap, and C. Perera, “Cybersecurity of Industrial Cyber-Physical Systems: A Review,” ACM Computing Surveys, vol. 54, no. 11s, Art. no. 229, pp. 1–35, 2022, doi: 10.1145/3510410. ACM
[6] T. Maysey, M. Powell, J. Steel, and S. Sarvia, OT Backup Quick Start Guide, NIST SP 1339. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2026, doi: 10.6028/NIST.SP.1339. NIST
[7] National Cybersecurity Authority, Critical Systems Cybersecurity Controls (CSCC-1:2019). Kingdom of Saudi Arabia, 2019. NCA
[8] National Cybersecurity Authority, Operational Technology Cybersecurity Controls (OTCC-1:2022). Kingdom of Saudi Arabia, 2022. NCA
[9] National Cybersecurity Authority, Essential Cybersecurity Controls (ECC 2:2024). Kingdom of Saudi Arabia, 2024. NCA
[10] National Cybersecurity Authority, “Cyber Incident Response,” Kingdom of Saudi Arabia, 2025. NCA
[11] C. Pascoe, S. Quinn, and K. Scarfone, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.CSWP.29. NIST
[12] A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST SP 800-61 Rev. 3. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2025, doi: 10.6028/NIST.SP.800-61r3. NIST
[13] K. Stouffer, M. Pease, C. Tang, T. Zimmerman, V. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, Guide to Operational Technology (OT) Security, NIST SP 800-82 Rev. 3. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2023, doi: 10.6028/NIST.SP.800-82r3. NIST
[14] T. Zhukabayeva, L. Zholshiyeva, N. Karabayev, S. Khan, and N. Alnazzawi, “Cybersecurity Solutions for Industrial Internet of Things-Edge Computing Integration: Challenges, Threats, and Future Directions,” Sensors, vol. 25, no. 1, Art. no. 213, 2025, doi: 10.3390/s25010213. MDPI
[15] M. Al-Hawawreh, M. Alazab, M. A. Ferrag, and M. S. Hossain, “Securing the Industrial Internet of Things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms,” Journal of Network and Computer Applications, vol. 223, Art. no. 103809, 2024, doi: 10.1016/j.jnca.2023.103809. ScienceDirect
[16] M. Benmalek, “Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges,” Internet of Things and Cyber-Physical Systems, vol. 4, pp. 186–202, 2024, doi: 10.1016/j.iotcps.2023.12.001. ScienceDirect
[17] P. Yan and T. Talaei Khoei, “Securing the internet of things: A comprehensive review of ransomware attacks, detection, countermeasures, and future prospects,” Franklin Open, vol. 11, Art. no. 100256, 2025, doi: 10.1016/j.fraope.2025.100256. ScienceDirect
[18] A. Saini, K. Krishan, and M. S. Gaur, “Analyzing ICS security: A survey of design principles, risks, threats, and mitigation methods,” Computers & Electrical Engineering, vol. 132, Art. no. 110967, 2026, doi: 10.1016/j.compeleceng.2026.110967. Crossref
[19] K. K. Castillo-Villar, H. Dai, G. Martinez Medina, and H. Mehrzadi, “Cybersecurity for smart and resilient manufacturing and supply chains: A systematic review of the evolving knowledge base,” Computers & Industrial Engineering, vol. 220, Art. no. 112244, 2026, doi: 10.1016/j.cie.2026.112244. ScienceDirect
How to cite this paper
@article{1723367,
author = {Ishaq Siddiqui Mohammed},
title = {Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {2871-2887},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723367.pdf},
abstract = {Ransomware has evolved from being merely an IT problem into a cyber-physical resilience issue for industrial companies. In Saudi Arabia, industrial digitisation, cloud adoption, remote engineering and IT/OT convergence can improve efficiency while also expanding pathways through which cyber incidents may affect production, safety, quality and continuity (National Cybersecurity Authority, 2022; Kayan et al., 2022; Benmalek, 2024). This review examines how Saudi industrial organisations can improve ransomware resilience by integrating IT and OT cybersecurity with incident response. It uses a structured integrative review of 19 peer-reviewed, standards and government sources published mainly from 2020 to September 2026, with older or foundational guidance retained where necessary. The synthesis highlights five interdependent resilience themes: governance and risk ownership; asset visibility and architecture; identity, segmentation and secure access; detection and coordinated response; and trusted recovery of operational capability. The evidence indicates that enterprise ransomware controls need OT-specific adaptation because industrial environments place distinctive emphasis on availability, safety, legacy assets and process dependencies (Stouffer et al., 2023; Al-Hawawreh et al., 2024; Saini et al., 2026). Resilience therefore requires shared IT/OT decision structures, engineering-aware containment, protected and tested backups, dependency-aware recovery sequencing, supplier coordination and exercises that test degraded operations rather than data restoration alone (CISA, 2023a; Maysey et al., 2026). Saudi NCA controls provide a governance baseline within their applicable scope, while plant-level playbooks and explicit recovery acceptance criteria translate that baseline into operational capability (National Cybersecurity Authority, 2019, 2022, 2024). The paper proposes an integrated plant-centred resilience model linking preparation, detection, containment, recovery and organisational learning, and identifies practical metrics and future research priorities.},
keywords = {ransomware; cyber resilience; operational technology; industrial control systems; IT/OT convergence; incident response; Saudi Arabia; critical infrastructure},
month = {September},
}