Evaluating the E/ectiveness of the Saudi National Cybersecurity Authority (NCA) in Mitigating Cyber Threats for SMEs
No Thumbnail Available
Date
2025
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
Small and medium-sized enterprises (SMEs) underpin Saudi Arabia’s Vision 2030, yet lean teams and tight budgets leave many exposed to routine cyber risk. This study assesses how far the National Cybersecurity Authority’s SME offer, including ECC-2:2024, practical toolkits, and Academy courses, translates into day-to-day practice. A bilingual, sector-stratified survey (
n
=
65
n=65) conducted over three weeks measured awareness, uptake of six baseline controls, and satisfaction, and examined firmographic predictors. Awareness proved uneven: respondents commonly recognised the NCA and procurement links, but far fewer reported reading ECC-2 or using the portal in the past year (mean awareness items 3.29–3.78 on a five-point scale). Adoption clustered around scheduled safeguards (patching, backups, routine scans) and lagged for behaviour-dependent steps, notably multi-factor authentication and recurring training. Overall satisfaction was positive but lower on clarity and sector fit. The study recommends a “use-of” communication shift, sector-specific minimum-viable ECCs, and post-incident accelerators to strengthen SME cyber resilience.
Description
This master's thesis presents an empirical evaluation of the Saudi National Cybersecurity Authority's (NCA) initiatives designed to protect Small and Medium-sized Enterprises (SMEs). Recognizing that SMEs are vital to Saudi Arabia's Vision 2030 but highly vulnerable to cyber threats due to limited resources, the research investigates the real-world effectiveness of the NCA's support programs.
The study employs a quantitative methodology, using a bilingual (Arabic/English), online survey administered to 65 Saudi SMEs across various sectors. It systematically measures three key outcomes: awareness of NCA resources (like the Essential Cybersecurity Controls ECC-2:2024 framework and training portal), actual adoption of six recommended baseline security controls, and overall satisfaction with the NCA's services.
Key findings reveal a notable gap between awareness and action: while SMEs are generally familiar with the NCA, direct engagement with its core tools is limited. Implementation is strongest for automated, system-enforced controls (e.g., patching, backups) and weakest for behavior-dependent measures like multi-factor authentication (MFA) and recurrent staff training. Satisfaction levels are positive overall but indicate a need for clearer, more sector-specific guidance.
Based on these results, the thesis concludes with evidence-based, practical recommendations for the NCA. These include shifting communication strategies from raising awareness to prompting specific use, developing simplified "minimum viable" checklists tailored to different industries, and creating rapid-response support packages for businesses that have experienced a breach, thereby converting incident salience into lasting security improvements.
Keywords
Cybersecurity Small and Medium-sized Enterprises (SMEs) Saudi Arabia National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) Cybersecurity Awareness
Citation
APA 7th edition
