Skip to content
Review Open access

A Threat-Driven Cyber Resilience Framework for Saudi Government Digital Services: Integrating Zero Trust, Security Operations and Adaptive Intelligence under Vision 2030

Sep 2026 · Iconic research and engineering journals · 0 citations · 23 references

Abstract

-Saudi Arabia's rapid expansion of digital government has made cyber resilience a matter of public-service continuity rather than a purely technical security concern. Government platforms now depend on cloud services, shared data environments, mobile access, Internet of Things (IoT) devices, artificial intelligence, and increasingly interconnected critical systems. These developments improve the reach and efficiency of public services, but they also create dependencies that can amplify the effect of a cyber-incident. This review examines how a threat-driven cyber resilience approach combining integrated security architecture, cyber-threat intelligence (CTI), zero-trust principles, and adaptive security operations can enhance the continuity and protection of Saudi government digital services within the wider objectives of Vision 2030. A structured integrative review of 30 peer-reviewed studies, international cybersecurity frameworks, and Saudi regulatory publications issued between 2020 and 2025 was used to examine the relationship between governance, zero-trust access, security architecture, threat intelligence, security operations, and recovery. The evidence indicates that compliance controls are necessary but insufficient when identity, network, cloud, endpoint, data, and operational-technology protections operate as separate functions. Resilience improves when those controls are connected through common telemetry, context-aware access decisions, intelligence-led detection, governed automation, tested recovery, and post-incident learning. Saudi Arabia's National Cybersecurity Strategy and National Cybersecurity Authority (NCA) control families provide the national governance foundation, while NIST and CISA frameworks offer useful architectural and maturity guidance. Based on the synthesis, the paper proposes the Saudi Adaptive Cyber Resilience Architecture (SACRA), a threat-driven framework that connects mission assurance, zero-trust identity

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.