International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1723367

1723367 Vol 10 · Issue 3 Download Paper

Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response

Ishaq Siddiqui Mohammed

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

Abstract

Ransomware has evolved from being merely an IT problem into a cyber-physical resilience issue for industrial companies. In Saudi Arabia, industrial digitisation, cloud adoption, remote engineering and IT/OT convergence can improve efficiency while also expanding pathways through which cyber incidents may affect production, safety, quality and continuity (National Cybersecurity Authority, 2022; Kayan et al., 2022; Benmalek, 2024). This review examines how Saudi industrial organisations can improve ransomware resilience by integrating IT and OT cybersecurity with incident response. It uses a structured integrative review of 19 peer-reviewed, standards and government sources published mainly from 2020 to September 2026, with older or foundational guidance retained where necessary. The synthesis highlights five interdependent resilience themes: governance and risk ownership; asset visibility and architecture; identity, segmentation and secure access; detection and coordinated response; and trusted recovery of operational capability. The evidence indicates that enterprise ransomware controls need OT-specific adaptation because industrial environments place distinctive emphasis on availability, safety, legacy assets and process dependencies (Stouffer et al., 2023; Al-Hawawreh et al., 2024; Saini et al., 2026). Resilience therefore requires shared IT/OT decision structures, engineering-aware containment, protected and tested backups, dependency-aware recovery sequencing, supplier coordination and exercises that test degraded operations rather than data restoration alone (CISA, 2023a; Maysey et al., 2026). Saudi NCA controls provide a governance baseline within their applicable scope, while plant-level playbooks and explicit recovery acceptance criteria translate that baseline into operational capability (National Cybersecurity Authority, 2019, 2022, 2024). The paper proposes an integrated plant-centred resilience model linking preparation, detection, containment, recovery and organisational learning, and identifies practical metrics and future research priorities.

Keywords

ransomware; cyber resilience; operational technology; industrial control systems; IT/OT convergence; incident response; Saudi Arabia; critical infrastructure

References

[1] C. Y. Chiu, “From backup restoration to Minimum Viable Factory Recovery: A systematization of ransomware recovery in manufacturing systems,” International Journal of Critical Infrastructure Protection, vol. 54, Art. no. 100882, 2026, doi: 10.1016/j.ijcip.2026.100882. ScienceDirect

[2] Cybersecurity and Infrastructure Security Agency, #StopRansomware Guide, 2023. CISA

[3] Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals, 2023. CISA

[4] M. Souppaya, W. C. Barker, W. Fisher, and K. Kent, Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile, NIST IR 8374 Rev. 1. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2026.

[5] H. Kayan, M. Nunes, O. Rana, P. Burnap, and C. Perera, “Cybersecurity of Industrial Cyber-Physical Systems: A Review,” ACM Computing Surveys, vol. 54, no. 11s, Art. no. 229, pp. 1–35, 2022, doi: 10.1145/3510410. ACM

[6] T. Maysey, M. Powell, J. Steel, and S. Sarvia, OT Backup Quick Start Guide, NIST SP 1339. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2026, doi: 10.6028/NIST.SP.1339. NIST

[7] National Cybersecurity Authority, Critical Systems Cybersecurity Controls (CSCC-1:2019). Kingdom of Saudi Arabia, 2019. NCA

[8] National Cybersecurity Authority, Operational Technology Cybersecurity Controls (OTCC-1:2022). Kingdom of Saudi Arabia, 2022. NCA

[9] National Cybersecurity Authority, Essential Cybersecurity Controls (ECC 2:2024). Kingdom of Saudi Arabia, 2024. NCA

[10] National Cybersecurity Authority, “Cyber Incident Response,” Kingdom of Saudi Arabia, 2025. NCA

[11] C. Pascoe, S. Quinn, and K. Scarfone, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.CSWP.29. NIST

[12] A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, NIST SP 800-61 Rev. 3. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2025, doi: 10.6028/NIST.SP.800-61r3. NIST

[13] K. Stouffer, M. Pease, C. Tang, T. Zimmerman, V. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, Guide to Operational Technology (OT) Security, NIST SP 800-82 Rev. 3. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2023, doi: 10.6028/NIST.SP.800-82r3. NIST

[14] T. Zhukabayeva, L. Zholshiyeva, N. Karabayev, S. Khan, and N. Alnazzawi, “Cybersecurity Solutions for Industrial Internet of Things-Edge Computing Integration: Challenges, Threats, and Future Directions,” Sensors, vol. 25, no. 1, Art. no. 213, 2025, doi: 10.3390/s25010213. MDPI

[15] M. Al-Hawawreh, M. Alazab, M. A. Ferrag, and M. S. Hossain, “Securing the Industrial Internet of Things against ransomware attacks: A comprehensive analysis of the emerging threat landscape and detection mechanisms,” Journal of Network and Computer Applications, vol. 223, Art. no. 103809, 2024, doi: 10.1016/j.jnca.2023.103809. ScienceDirect

[16] M. Benmalek, “Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges,” Internet of Things and Cyber-Physical Systems, vol. 4, pp. 186–202, 2024, doi: 10.1016/j.iotcps.2023.12.001. ScienceDirect

[17] P. Yan and T. Talaei Khoei, “Securing the internet of things: A comprehensive review of ransomware attacks, detection, countermeasures, and future prospects,” Franklin Open, vol. 11, Art. no. 100256, 2025, doi: 10.1016/j.fraope.2025.100256. ScienceDirect

[18] A. Saini, K. Krishan, and M. S. Gaur, “Analyzing ICS security: A survey of design principles, risks, threats, and mitigation methods,” Computers & Electrical Engineering, vol. 132, Art. no. 110967, 2026, doi: 10.1016/j.compeleceng.2026.110967. Crossref

[19] K. K. Castillo-Villar, H. Dai, G. Martinez Medina, and H. Mehrzadi, “Cybersecurity for smart and resilient manufacturing and supply chains: A systematic review of the evolving knowledge base,” Computers & Industrial Engineering, vol. 220, Art. no. 112244, 2026, doi: 10.1016/j.cie.2026.112244. ScienceDirect

How to cite this paper

Ishaq Siddiqui Mohammed "Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 2871-2887
Ishaq Siddiqui Mohammed "Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026
Ishaq Siddiqui Mohammed (2026). Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response. Iconic Research And Engineering Journals, 10(3).
Ishaq Siddiqui Mohammed "Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026.
@article{1723367,
      author = {Ishaq Siddiqui Mohammed},
      title = {Enhancing Ransomware Resilience in Saudi Industrial Organizations Through Integrated It/Ot Cybersecurity and Incident Response},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {2871-2887},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1723367.pdf},
      abstract = {Ransomware has evolved from being merely an IT problem into a cyber-physical resilience issue for industrial companies. In Saudi Arabia, industrial digitisation, cloud adoption, remote engineering and IT/OT convergence can improve efficiency while also expanding pathways through which cyber incidents may affect production, safety, quality and continuity (National Cybersecurity Authority, 2022; Kayan et al., 2022; Benmalek, 2024). This review examines how Saudi industrial organisations can improve ransomware resilience by integrating IT and OT cybersecurity with incident response. It uses a structured integrative review of 19 peer-reviewed, standards and government sources published mainly from 2020 to September 2026, with older or foundational guidance retained where necessary. The synthesis highlights five interdependent resilience themes: governance and risk ownership; asset visibility and architecture; identity, segmentation and secure access; detection and coordinated response; and trusted recovery of operational capability. The evidence indicates that enterprise ransomware controls need OT-specific adaptation because industrial environments place distinctive emphasis on availability, safety, legacy assets and process dependencies (Stouffer et al., 2023; Al-Hawawreh et al., 2024; Saini et al., 2026). Resilience therefore requires shared IT/OT decision structures, engineering-aware containment, protected and tested backups, dependency-aware recovery sequencing, supplier coordination and exercises that test degraded operations rather than data restoration alone (CISA, 2023a; Maysey et al., 2026). Saudi NCA controls provide a governance baseline within their applicable scope, while plant-level playbooks and explicit recovery acceptance criteria translate that baseline into operational capability (National Cybersecurity Authority, 2019, 2022, 2024). The paper proposes an integrated plant-centred resilience model linking preparation, detection, containment, recovery and organisational learning, and identifies practical metrics and future research priorities.},
      keywords = {ransomware; cyber resilience; operational technology; industrial control systems; IT/OT convergence; incident response; Saudi Arabia; critical infrastructure},
      month = {September},
  }