|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 123 |
| Published: July 2026 |
| Authors: Samo Tomažič, Blaž Markelj |
10.5120/ijca5c7eb1350d1e
|
Samo Tomažič, Blaž Markelj . Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority. International Journal of Computer Applications. 187, 123 (July 2026), 14-20. DOI=10.5120/ijca5c7eb1350d1e
@article{ 10.5120/ijca5c7eb1350d1e,
author = { Samo Tomažič,Blaž Markelj },
title = { Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority },
journal = { International Journal of Computer Applications },
year = { 2026 },
volume = { 187 },
number = { 123 },
pages = { 14-20 },
doi = { 10.5120/ijca5c7eb1350d1e },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2026
%A Samo Tomažič
%A Blaž Markelj
%T Evaluation of the SAAT Cybersecurity Awareness Model in a Nuclear Regulatory Authority%T
%J International Journal of Computer Applications
%V 187
%N 123
%P 14-20
%R 10.5120/ijca5c7eb1350d1e
%I Foundation of Computer Science (FCS), NY, USA
The human factor remains one of the most significant vulnerabilities in cybersecurity, particularly in high-consequence environments such as the nuclear sector, where a single inappropriate action may compromise critical systems, cause financial damage, or undermine institutional credibility. To address this risk, the Slovenian Nuclear Safety Administration (SNSA) has maintained a structured information security awareness programme since 2011. Building on this foundation, the SAAT model (Systematic Approach to Awareness Training) was developed as an integrated framework that combines awareness, training, and testing into a continuous and adaptive process aimed at strengthening cybersecurity culture and mitigating human-related cyber risks. This paper presents a longitudinal evaluation of SAAT implementation between 2020 and 2025, based on controlled phishing simulations and systematic observation of employee behaviour. Using a descriptive and observational methodology, the study analyses how the type, timing, and frequency of awareness activities influence phishing susceptibility, reporting behaviour, and overall vigilance. The results indicate that awareness levels decline when reinforcement intervals are prolonged, increasing user interaction with phishing content. Conversely, regularly delivered and well-balanced awareness interventions significantly reduce risky behaviour while maintaining or improving reporting rates. The findings confirm that cybersecurity awareness must be treated as a continuous, carefully calibrated process. Excessive frequency, however, may lead to awareness fatigue, highlighting the need for optimised implementation strategies in critical infrastructure organisations.