Skip to content
Review Open access

Cyber Resilience Maturity Model for Multi-Site Construction and Energy Enterprises in Saudi Arabia under Vision 2030

Sep 2026 · Global academic journal of economics and business · 0 citations

Abstract

Saudi Arabia's Vision 2030 is accelerating the digital integration of construction programmes, energy assets, cloud platforms, industrial control systems, and geographically dispersed project sites. This integration creates operational value but also expands the number of pathways through which cyber events can disrupt safety, productivity, data integrity, and service continuity. Existing cybersecurity frameworks provide strong control baselines, yet they do not fully express how a multi-site enterprise should measure resilience when temporary construction networks, contractor identities, common data environments, operational technology, remote access, and central security operations coexist. This review therefore develops a Cyber Resilience Maturity Model for multi-site construction and energy enterprises in Saudi Arabia. Evidence published between 2020 and 2025 was synthesized from peer-reviewed construction, industrial control, cyber-physical, and power-system research together with Saudi and international control frameworks. The review translates recurring evidence into eight maturity dimensions: governance and regulatory alignment; asset, identity, and architecture visibility; IT/OT segmentation and secure access; third-party and project supply-chain security; detection and security operations integration; incident response and cyber-physical recovery; workforce and contractor competence; and metrics, assurance, and adaptive improvement. Five maturity levels are proposed, progressing from fragmented practice to adaptive resilience. A criticality-weighted cross-site scoring method and minimum capability gates are introduced to prevent strong corporate controls from masking weaknesses at high-consequence locations. It provides Saudi enterprises with a practical basis for comparing sites, prioritizing investment, and linking cybersecurity improvement to continuity, safety, and Vision 2030 delivery.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.