Zero Trust Adoption in Saudi Critical Infrastructure Systems of the Energy Sector
No Thumbnail Available
Date
2026
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Saudi Digital Library
Abstract
This study critically examines the practicality and contextual application of Zero Trust
Architecture (ZTA) within Saudi Arabia’s critical energy infrastructure and develops a
literature-based adoption strategy tailored to this environment. The research is motivated by
the increasing cybersecurity risks associated with IT/OT convergence, smart grid expansion,
and the growing reliance on interconnected energy systems under Saudi Vision 2030.
A qualitative research design was adopted, based on a Systematic Literature Review (SLR)
supported by PRISMA guidelines and thematic analysis following Braun and Clarke. A total
of 20 high-quality studies were selected and analysed to identify key patterns related to Zero
Trust principles, cybersecurity threats, and implementation challenges in energy-critical
environments.
The findings show that ZTA provides a strong conceptual foundation through continuous
authentication, identity-based access control, micro-segmentation, and adaptive security
mechanisms. However, its implementation in Saudi energy systems is constrained by
technical limitations in legacy OT environments, organisational resistance, and fragmented
regulatory frameworks. The study further reveals that IT/OT convergence and IoT integration
significantly expand the attack surface, reinforcing the need for advanced and adaptive
security models.
In response, this research proposes a phased, risk-based ZTA adoption approach aligned
with national cybersecurity governance frameworks and operational constraints of OT
systems. The study concludes that while ZTA is highly relevant and feasible, its successful
implementation requires contextual adaptation, gradual deployment, and strong
organisational alignment.
Description
Keywords
Zero Trust Architecture (ZTA), Saudi Arabia, Energy Infrastructure, IT/OT Convergence, Cybersecurity
