Saudi Arabia has developed one of the most comprehensive cybersecurity frameworks in the Gulf region — one that addresses network integrity, system vulnerabilities, and incident response with increasing sophistication. The progress is genuine and the institutional commitment behind it is not in question.
What this analysis seeks to explore is a dimension that formal frameworks across the region have found structurally difficult to capture — not from any absence of intent, but because of the inherent challenges of quantifying human behaviour within compliance architectures designed primarily around technical risk.
The human element — encompassing unintentional errors, behavioural inconsistencies, and the complex dynamics of insider risk — represents a category of exposure that does not readily translate into the metrics formal reporting systems are built to measure. This is not a challenge unique to Saudi Arabia.
It is a recognised gap in cybersecurity governance globally. What gives it particular relevance in the Saudi context is the scale of the Kingdom's ongoing digital transformation, which has placed the integrity of its digital infrastructure at the centre of its broader economic diversification strategy.
If the risk frameworks underpinning that infrastructure assign insufficient weight to the human dimension, the consequence is not simply a gap in security reporting. It is a potential miscalibration in how risk is understood.

Beyond the Firewall
The Saudi cybersecurity market is worth SAR 15.2 billion. But according to recent audit disclosures from the National Cybersecurity Authority, the way that money is being spent reveals a clear pattern — the overwhelming majority of it is going toward technology: hardware, software, and technical systems designed to defend networks and detect intrusions.
The market is then heavily skewed toward buying tools rather than addressing behaviour.
The investment is concentrated on the visible, measurable, and technically quantifiable dimensions of cybersecurity — firewalls, monitoring systems, encryption — while the human dimension receives a comparatively small share of attention and resources.
The concern is that the allocation reflects an implicit assumption that cybersecurity is primarily a technical problem, when the evidence consistently shows that human behaviour is the primary cause of serious breaches.

● Resources are concentrated on the visible threat while the dominant threat remains largely unquantified
● What cannot be measured tends not to be managed — and what is not managed tends to materialise.
The gap between reported risk and realised risk is not a technical failure. It is a governance one.
Academic consensus indicates that a staggering 95% of successful cyber intrusions are directly precipitated by human error.
This regional vulnerability is strongly corroborated by authoritative global metrics, which provide a clear empirical benchmark for accurate risk assessment.
Globally, 60% of all data breaches are inexorably linked to the human element. Within the highly regulated financial and insurance sectors, 74% of recorded breaches are attributed to a complex mix of system intrusions and human manipulation techniques.
This alarming trajectory is mirrored across the broader EMEA region, where 29% of data compromises are traced directly to internal personnel.
A more granular breakdown of cybercrime in EMEA shows that while overt system intrusions account for 53% of incidents, human manipulation and miscellaneous operational errors account for 22% and 19%, respectively.

The $7.29 Million Question
The Middle East's cybersecurity exposure carries a financial dimension that warrants serious attention. While the region accounts for 10% of global cybersecurity incidents — a share broadly proportionate to its economic footprint — the cost of each individual breach is significantly higher than the global norm.
Data covering more than 16 countries and regional markets places the Middle East second globally in average breach cost.
In 2025, the regional average stood at $7.29 million per incident — nearly double the global average of $4.44 million for the same year.
Although this represents a decline from the 2024 regional figure of $8.75 million, the gap between Middle Eastern breach costs and the global benchmark remains substantial.
In the global ranking, the Middle East sits directly below the United States, which recorded the highest average breach cost at $10.22 million, and meaningfully above the third-ranked Benelux region by a margin exceeding $1 million.
The implication is straightforward: the Middle East is not disproportionately exposed in terms of incident frequency, but it is significantly more exposed in terms of financial impact when breaches do occur.
Understanding why — and addressing the structural factors that drive that cost differential — is an important dimension of the region's broader cybersecurity agenda.


We Track the Breach. We Don’t Track Why
Saudi Arabia's financial sector cybersecurity framework, introduced by SAMA in 2017, has seen only incremental updates since its inception. A comprehensive revision has yet to be issued.
The current framework requires major financial institutions to report critical security incidents, including technical specifications and root cause analysis.
However, it does not include a dedicated classification for incidents attributable to human behaviour.
Identifying the root cause of a security incident should, in theory, lead investigators to ask why it happened — and in the majority of cases, the honest answer involves a human decision, error, or action somewhere in the chain.
If a bank's system was breached because an employee clicked a malicious link, the technical root cause might be recorded as "phishing email delivered to endpoint." But the deeper root cause is human.
Regulatory approaches in Western jurisdictions take diametrically opposed approaches.
Institutions such as the National Institute of Standards and Technology (NIST) and the European Union Agency for Cybersecurity (ENISA) strictly compel organizations to log specific employee actions during security events.
For instance, the NIST framework explicitly incorporates analytical methodologies such as the Phish Scale, compelling enterprises to rigorously quantify human vulnerability metrics—including specific phishing click rates and reporting frequencies—thereby establishing a granular baseline for behavioral risk assessment.
● Human failures get reclassified as external technical intrusions instead.
● Regulators receive systematically distorted data about actual risk exposure.
● Vulnerabilities persist unaddressed because accountability never reaches the source.
When the framework does not require the truth, institutions are not lying — they are simply filing what the system accepts. And what the system accepts becomes, over time, what everyone believes.
✧ Conclusion ✧
Regulators see a complete picture of what broke, but an incomplete picture of why it broke — which means the same human vulnerability can be exploited again without ever appearing in the risk record.
This structural gap causes financial institutions to severely underinvest in human-centric risk mitigation strategies. When the data going into risk models is wrong, everything built on top of it is wrong too.
If banks are systematically recording human-caused breaches as technical failures, the historical record that insurers, regulators, and analysts rely on to price risk and allocate capital is quietly wrong.
The practical consequences are concrete. Insurance companies charge the wrong premiums because they are modelling the wrong risks. Regulators design policy responses to a threat picture that does not fully exist.
And because every institution in the system is drawing from the same distorted pool of reported data, the problem does not stay contained. It spreads — silently and systematically — across the entire financial ecosystem.