Cybersecurity Risk in Building Automation Systems on Saudi Arabian Giga Construction Projects: A Risk Governance Framework

Authors

  • Waqar Hussnain Abdul Mohsin Al Tamimi Group, Prince Humud Ibn Abdulaziz Street, Al Khobar City, Building No. 6971, Kingdom of Saudi Arabia
  • Mohammad Obeidat Abdul Mohsin Al Tamimi Group, Prince Humud Ibn Abdulaziz Street, Al Khobar City, Building No. 6971, Kingdom of Saudi Arabia
  • Anood Ali Department of Computer Science, Shaheed Benazir Bhutto Woman University, Peshawar, Pakistan

DOI:

https://doi.org/10.54692/ijeci.2026.1002/279

Keywords:

Building automation system security, cybersecurity risk governance, industrial control systems, giga-project delivery, cyber-risk index.

Abstract

Saudi Arabia’s Vision 2030 giga-projects are connecting building automation systems (BAS) to corporate networks, cloud platforms, and remote vendor access at a rate that has outpaced the cybersecurity governance traditionally applied to operational technology. BAS field protocols such as BACnet, Modbus, and KNX were designed primarily for interoperability rather than operation in adversarial network environments, and legacy deployments often provide limited native authentication and encryption. This paper develops the Building Automation Cybersecurity Risk Framework (BACRF), a six-layer governance model that classifies BAS-specific threats, assigns responsibility across the fragmented delivery chain of owner, project management consultant, contractor, mechanical-electrical-plumbing (MEP) subcontractor, and vendor, and prioritizes mitigation measures through a Cyber-Risk Index (CRI). The framework was built from a structured literature review of 25 sources, screened from an initial pool of database records to a final set spanning industrial control system, cyber-physical systems, and construction cybersecurity literature, together with an illustrative scenario informed by the authors’ professional experience. Applying the CRI to a representative giga-project scenario, with explicitly reported likelihood, consequence, and weighting inputs, identifies network segmentation failure as having the highest priority among unauthorised remote access and supply-chain exposure as the leading risk. The framework provides giga-project owners and delivery teams a reproducible basis suitable for contractual implementation for prioritising BAS cybersecurity investment, although the scoring weights remain illustrative pending calibration against documented incident data.

Downloads

Published

2026-09-26

Issue

Section

Articles