Research Article

Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority

by  Samo Tomažič, Blaž Markelj
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 123
Published: July 2026
Authors: Samo Tomažič, Blaž Markelj
10.5120/ijca5c7eb1350d1e
PDF

Samo Tomažič, Blaž Markelj . Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority. International Journal of Computer Applications. 187, 123 (July 2026), 14-20. DOI=10.5120/ijca5c7eb1350d1e

                        @article{ 10.5120/ijca5c7eb1350d1e,
                        author  = { Samo Tomažič,Blaž Markelj },
                        title   = { Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 123 },
                        pages   = { 14-20 },
                        doi     = { 10.5120/ijca5c7eb1350d1e },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Samo Tomažič
                        %A Blaž Markelj
                        %T Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 123
                        %P 14-20
                        %R 10.5120/ijca5c7eb1350d1e
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

The human factor remains one of the most significant vulnerabilities in cybersecurity, particularly in high-consequence environments such as the nuclear sector, where a single inappropriate action may compromise critical systems, cause financial damage, or undermine institutional credibility. To address this risk, the Slovenian Nuclear Safety Administration (SNSA) has maintained a structured information security awareness programme since 2011. Building on this foundation, the SAAT model (Systematic Approach to Awareness Training) was developed as an integrated framework that combines awareness, training, and testing into a continuous and adaptive process aimed at strengthening cybersecurity culture and mitigating human-related cyber risks. This paper presents a longitudinal evaluation of SAAT implementation between 2020 and 2025, based on controlled phishing simulations and systematic observation of employee behaviour. Using a descriptive and observational methodology, the study analyses how the type, timing, and frequency of awareness activities influence phishing susceptibility, reporting behaviour, and overall vigilance. The results indicate that awareness levels decline when reinforcement intervals are prolonged, increasing user interaction with phishing content. Conversely, regularly delivered and well-balanced awareness interventions significantly reduce risky behaviour while maintaining or improving reporting rates. The findings confirm that cybersecurity awareness must be treated as a continuous, carefully calibrated process. Excessive frequency, however, may lead to awareness fatigue, highlighting the need for optimised implementation strategies in critical infrastructure organisations.

References
  • Tomažič, S. (2026). Kibernetska varnost: Koncepti in pristopi k zaščiti kritične infrastrukture – jedrski sektor. Univerza Alma Mater Europaea.
  • International Atomic Energy Agency (Ur.). (2021a). Computer security for nuclear security: Implementation guide. International Atomic Energy Agency.
  • International Atomic Energy Agency (Ur.). (2021b). Computer security techniques for nuclear facilities: Technical guidance. International Atomic Energy Agency.
  • Lee, K., & Lim, J. (2016). The reality and response of cyber threats to critical infrastructure: A case study of the cyber-terror attack on the Korea Hydro & Nuclear Power Co., Ltd. KSII Transactions on Internet and Information Systems, 10(2), 24. https://doi.org/http://dx.doi.org/10.3837/tiis.2016.02.023
  • Joint Task Force Interagency Working Group. (2020). Security and Privacy Controls for Information Systems and Organizations (Revision 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
  • Tomažič, S., Mertik, M., & Šeruga, T. (2023). Systematic Approach to Awareness Training at Slovenian Nuclear Safety Administration. International Journal of Computer Applications, 185(3), 30–36. https://doi.org/10.5120/ijca2023922686
  • National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29; str. NIST CSWP 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
  • Office for Nuclear Regulation. (2022). Security Assessment Principles for the Civil Nuclear Industry. Office for Nuclear Regulation. http://www.onr.org.uk/syaps/index.htm
  • Joint Task Force Transformation Initiative. (2018). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy (NIST SP 800-37r2; str. NIST SP 800-37r2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-37r2
  • International Atomic Energy Agency. (2018). Computer Security of Instrumentation and Control Systems at Nuclear Facilities: Technical Guidance. IAEA.
  • International Atomic Energy Agency. (2016). Conducting computer security assessments at nuclear facilities. International Atomic Energy Agency.
  • Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST SP 800-61r3; str. NIST SP 800-61r3). National Institute of Standards and Technology (U.S.). https://doi.org/10.6028/NIST.SP.800-61r3
  • International Atomic Energy Agency. (2025). Information and Computer Security for Activities Involving Radioactive Material and for Associated Facilities. International Atomic Energy Agency.
  • Nuclear Energy Institute. (2024). Cyber Security Plan for Nuclear Power Reactors (NEI 08-09 [Revision 7]). Nuclear Energy Institute.
  • Boyens, J. M. (2024). Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (NIST SP 800-161r1-Upd1; str. NIST SP 800-161r1-upd1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-161r1-upd1
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Cybersecurity awareness phishing simulation human factor nuclear sector security culture

Powered by PhDFocusTM