CYBER RESILIENCE FOR LARGE-SCALE DATA CENTER MIGRATION IN SAUDI CRITICAL INFRASTRUCTURE UNDER VISION 2030: SECURE IP FABRIC SEGMENTATION, THREAT CONTAINMENT, AND OPERATIONAL CONTINUITY

Authors

  • Zakiuddin Mohammed

DOI:

https://doi.org/10.18623/rvd.v23.8114

Keywords:

Cyber Resilience, Data Center Migration, Saudi Vision 2030, EVPN-VXLAN, Ip Fabric, Microsegmentation, Zero Trust, Threat Containment, Operational Continuity, Critical Infrastructure

Abstract

Large-scale data center migration within Saudi critical infrastructure is not a conventional relocation of servers and applications. It is a time-bounded transformation of trust boundaries, routing domains, identity dependencies, recovery mechanisms, and operational accountability. During coexistence, legacy and target environments remain interconnected, which expands the attack surface precisely when configuration volume, change velocity, and service uncertainty are highest. This review examines how cyber resilience can be engineered into migration programmes through secure IP fabric segmentation, evidence-led threat containment, and continuity controls aligned with Saudi Vision 2030. An integrative review of peer-reviewed studies, standards, and regulatory documents published from 2020 to 2025 was undertaken. Evidence was synthesised around five analytical themes: migration risk, EVPN-VXLAN segmentation, zero-trust enforcement, containment and recovery, and governance. The review finds that resilient migration depends less on a single security product than on coordinated design decisions. These include separating management, replication, user, backup, security, and operational-technology flows; replacing inherited network trust with identity- and workload-aware policy; constraining migration corridors; maintaining cryptographically protected recovery copies; and releasing each migration wave only after observable technical and business evidence has been obtained. A reference operating model is proposed in which dual-running environments are governed through explicit security zones, continuous telemetry, policy-as-code, tested rollback, and service-level recovery objectives. The principal contribution is a practical review framework that treats migration as a sequence of reversible resilience decisions rather than a one-time cutover.

References

1. Kingdom of Saudi Arabia. (2025). Vision 2030 annual report 2024. Riyadh.

2. Digital Government Authority. (2024). Digital government policies, version 2.0. Riyadh.

3. Digital Government Authority. (2024). Cloud computing and its role in accelerating digital transformation and its sustainable impact in the government sector. Riyadh.

4. National Cybersecurity Authority. (2024). Essential cybersecurity controls (ECC 2:2024). Riyadh.

5. National Cybersecurity Authority. (2024). Cloud cybersecurity controls (CCC 2:2024). Riyadh.

6. National Cybersecurity Authority. (2024). Guide to cybersecurity controls for critical systems implementation. Riyadh.

7. Saudi Data and Artificial Intelligence Authority. (2023). Personal data protection law and implementing regulations. Riyadh.

8. Communications, Space and Technology Commission. (2023). Cloud computing services provisioning regulations, version 4. Riyadh.

9. Ministry of Communications and Information Technology. (2025). KSA: The national computing infrastructure. Riyadh.

10. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). https://doi.org/10.6028/NIST.SP.800-207

11. Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST SP 800-160 Volume 2 Revision 1). https://doi.org/10.6028/NIST.SP.800-160v2r1

12. National Institute of Standards and Technology. (2024). The cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

13. Chandramouli, R., & Butcher, Z. (2023). A zero trust architecture model for access control in cloud-native applications in multi-location environments (NIST SP 800-207A). https://doi.org/10.6028/NIST.SP.800-207A

14. Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST SP 800-53 Revision 5). https://doi.org/10.6028/NIST.SP.800-53r5

15. Chandramouli, R. (2020). Security guidelines for storage infrastructure (NIST SP 800-209). https://doi.org/10.6028/NIST.SP.800-209

16. National Cybersecurity Center of Excellence. (2020). Data integrity: Recovering from ransomware and other destructive events (NIST SP 1800-11).

17. Boyens, J., Smith, A., Bartol, N., Winkler, K., Holbrook, A., & Fallon, M. (2024). Cybersecurity supply chain risk management practices for systems and organizations (NIST SP 800-161 Revision 1 Update 1). https://doi.org/10.6028/NIST.SP.800-161r1-upd1

18. Cybersecurity and Infrastructure Security Agency. (2023). Zero trust maturity model, version 2.0. Washington, DC.

19. Cybersecurity and Infrastructure Security Agency. (2023). Cross-sector cybersecurity performance goals, version 1.0.1. Washington, DC.

20. Cybersecurity and Infrastructure Security Agency. (2025). #StopRansomware guide. Washington, DC.

21. European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. Athens.

22. International Organization for Standardization. (2022). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection—Information security management systems—Requirements. Geneva.

23. International Organization for Standardization. (2022). ISO/IEC 27002:2022 information security, cybersecurity and privacy protection—Information security controls. Geneva.

24. Hausken, K. (2020). Cyber resilience in firms, organizations and societies. Internet of Things, 11, 100204. https://doi.org/10.1016/j.iot.2020.100204

25. Sepulveda Estay, D. A., Sahay, R., Barfod, M. B., & Jensen, C. D. (2020). A systematic review of cyber-resilience assessment frameworks. Computers & Security, 97, 101996. https://doi.org/10.1016/j.cose.2020.101996

26. Radoi, A. E., & Rincu, C. I. (2022). Integration of data center network technologies VXLAN, BGP, EVPN. In 2022 14th International Conference on Communications. https://doi.org/10.1109/COMM54429.2022.9817218

27. Li, D., Yang, Z., Yu, S., Duan, M., & Yang, S. (2024). A micro-segmentation method based on VLAN-VXLAN mapping technology. Future Internet, 16(9), 320. https://doi.org/10.3390/fi16090320

28. Mani, S. K., Hsieh, K., Segarra, S., Chandra, R., Zhou, Y., & Kandula, S. (2025). Securing public cloud networks with efficient role-based micro-segmentation. In 22nd USENIX Symposium on Networked Systems Design and Implementation (pp. 1033–1048).

29. Verma, P., Newe, T., O'Mahony, G. D., Brennan, D., & O'Shea, D. (2025). Toward a unified understanding of cyber resilience: Concepts, strategies, and future directions. IEEE Access, 13, 49945–49965. https://doi.org/10.1109/ACCESS.2025.3551887

30. Sajassi, A., Salam, S., Thoria, S., Drake, J., & Rabadan, J. (2021). Integrated routing and bridging in Ethernet VPN (EVPN) (RFC 9135). https://doi.org/10.17487/RFC9135

Downloads

Published

2026-08-24

How to Cite

Mohammed, Z. (2026). CYBER RESILIENCE FOR LARGE-SCALE DATA CENTER MIGRATION IN SAUDI CRITICAL INFRASTRUCTURE UNDER VISION 2030: SECURE IP FABRIC SEGMENTATION, THREAT CONTAINMENT, AND OPERATIONAL CONTINUITY. Veredas Do Direito, 23(14), e238114. https://doi.org/10.18623/rvd.v23.8114