Shield-Aware: A Practical Roadmap to Elevate SME Cyber Readiness in Line with Saudi Vision 2030
Main Article Content
Abstract
Saudi Arabia’s rapid digitalization has increased exposure to cyber risks across individuals, organizations, and SMEs. This study consolidates fragmented local evidence into a practical national framework (“Shield-Aware”) that couples security awareness and behavior with regulatory compliance (ECC-1:2018). We employed an evidence-synthesis methodology: coding quantitative and behavioral findings from Saudi studies and a national dataset (N=1,230), then operationally mapping them to ECC-1:2018 domains to design measurable intervention packages and a monitoring dashboard. The findings reveal recurring individual gaps (public Wi-Fi use, weak/password reuse, limited phishing literacy), demographic disparities in awareness, and shortfalls in policy and periodic training within some organizations—especially SMEs. Shield-Aware prescribes multilevel interventions: microlearning, phishing simulations, and 2FA enablement for individuals; enforceable policies, role-based training, and compliance monitoring for organizations; and lightweight ECC readiness checks and enablement pathways for SMEs at the governance layer. The framework delivers dual scientific and practical impact: it translates awareness/behavior indicators into measurable, actionable decisions and provides a direct operational alignment with ECC-1:2018 controls—ultimately strengthening national cyber readiness and supporting Vision 2030 priorities.