Cyber Resilience for Industrial Control Systems in Saudi Arabia: An Asset-Specific Framework for SCADA, PLC, DCS and HMI Protection and Trusted Recovery
Abstract
Industrial Control Systems (ICS) are increasingly connected to enterprise networks, cloud platforms, remote engineering services, and industrial Internet of Things devices. Saudi Arabia is a particularly relevant setting because NCA OTCC-1:2022 establishes minimum cybersecurity requirements for relevant government organizations and private-sector organizations owning, operating or hosting Critical National Infrastructures, while other organizations are encouraged to use the controls as guidance (NCA, 2022). This review synthesizes evidence published between 2020 and 2025 with emphasis on the ability to anticipate, withstand, detect and contain, recover from, and adapt after cyber incidents while preserving safety, availability, integrity, and deterministic operational requirements. Across the retained evidence set, recurring resilience practices include current asset and dependency visibility, segmentation, least privilege, controlled remote access, process-aware monitoring, disciplined engineering change control, safety-centered response, and verified restoration. These are evidence-supported findings from the reviewed literature and authoritative guidance. Building on that evidence, this study proposes a Saudi-oriented, asset-specific resilience framework that maps NCA OTCC/ECC requirements and complementary NIST and IEC guidance to SCADA, PLC, DCS, and HMI resilience functions, and extends the synthesis with recovery engineering, exercise-based validation, and a Proposed Saudi OT Cyber Resilience Measurement Set.