Impact of Information Technology Risks on Security Controls: A Field Study in Telecommunications Companies in Sana'a

Authors

  • Nabil Hassan Abdo Al-Hemyari University of Science and Technology, Sana’a image/svg+xml

DOI:

https://doi.org/10.59222/ustjmhs.4.3.4

Keywords:

security controls, information technology risks, telecommunication companies in Sana'a

Abstract

This study aimed to assess the impact of information technology risks on security controls in telecommunications companies operating in Sana'a, following an analytical method. The study population consisted of telecommunications companies in Sana'a, and a comprehensive census method was used to collect data from 356 participants using a questionnaire. However, only 218 questionnaires were valid for analysis. Data were analyzed using partial least squares structural equation modeling (PLS-SEM). The study findings revealed that information technology risks have a negative impact on security controls. The study recommends the necessity of implementing strong multi-factor authentication, devoting especial attention to access control, and regularly identifying vulnerabilities in security controls.

Author Biography

  • Nabil Hassan Abdo Al-Hemyari, University of Science and Technology, Sana’a

    Assistant Professor of Accounting, University of Science and Technology, Sana’a, Yemen

References

الثورة نت. (2025، 31 يوليو)، ورشة بصنعاء حول المخاطر السيبرانية وطرق الحماية من الهجمات الإلكترونية. https://althawrah.ye/archives/1023009

الربيدي، محمد علي (2010)، حماية المعلومات المحاسبية في ظل مخاطر التكنولوجيا للعمليات المصرفية الإلكترونية: دراسة ميدانية في البنوك العاملة في اليمن، مجلة كلية التجارة والاقتصاد، 33، 1-45.

زويلف، انغام محسن حسن (2009)، طبيعة تهديدات أمن نظم المعلومات المحاسبية الإلكترونية: دراسة تطبيقية على شركات التأمين الأردنية، المجلة العربية للمحاسبة، 12(1)، 46-77.

سبأنت. (2014، 23 يونيو)، المؤتمر الأول لأمن المعلومات- صنعاء، المركز الوطني للمعلومات. https://yemennic.com/conferences/activ_detailsce9d.html?ID=69967

الشوكاني، غمدان (2016، مايو 11)، أكثر من 37 مليار ريال خسائر مؤسسة الاتصالات منذ بدء العدوان، وكالة الأنباء اليمنية سبأ. https://www.saba.ye/ar/news427488.htm

عدن الغد. (2014)، خلل بشبكة (MTN) يوقف حركة الاتصالات بعدن. https://adengad.net/public/posts/103375

فاضل، عبدالكريم محمد يحيى (2018)، تقييم مخاطر أمن نظم المعلومات المحاسبية المحوسبة لدى البنوك التجارية في اليمن: دراسة تطبيقية [أطروحة دكتوراه، جامعة دمشق، سوريا].

قانون رقم (13) لسنة 2012م بشأن حق الحصول على المعلومات. (2012). الجريدة الرسمية، الجمهورية اليمنية.

قانون رقم (40) لسنة 2006م بشأن أنظمة الدفع والعمليات المالية والمصرفية الإلكترونية. (2006)، الجريدة الرسمية، (24)، الجمهورية اليمنية.

القحطاني، ذيب بن عايض (2015)، أمن المعلومات، الرياض، السعودية: مكتبة الملك فهد الوطنية.

وزارة الاتصالات وتقنية المعلومات. (2020)، الاتصالات والبريد: خمسة أعوام من الصمود. https://mtit.gov.ye/co_sub_media_image/28-Arabic_2020_R2.pdf

Ahmed, A. W., Khan, O. A., Ahmed, M. M., & Shah, M. A. (2017). A comprehensive analysis on the security threats and their countermeasures of IoT. International Journal of Advanced Computer Science and Applications, 8(7), 489–501. https://doi.org/10.14569/IJACSA.2017.080768

Al-ghananeem, K. M. (2014). The impact of information security management standards to ensure information security. International Journal of Economics and Research, 5(1), 46-66.

Al-shaibany, N. A., Al-sofi, T. A. B., & Al Gaphari, G. H. (2023). A model for enhancing the information security management systems in Yemen banks. Sana’a University Journal of Applied Sciences and Technology, 1(1), 1–12. https://doi.org/10.59628/jast.v1i1.14

Atyam, S. B. (2010). Effectiveness of security control risk assessments for enterprises: Assess on the business perspective of security risks. Information Security Journal: A Global Perspective, 19(6), 343–350. https://doi.org/10.1080/19393555.2010.514892

Australian Cyber Security Centre. (2015). 2015 cyber security survey: Major Australian businesses. https://www.cybersecurityhub.gov.za/cyberawareness/images/pdfs/2015-ACSC-Cyber-Security-Survey-Major-Australian-Businesses.pdf

Azees, M., Vijayakumar, P., & Jegatha Deborah, L. (2016). Comprehensive survey on security services in vehicular ad-hoc networks. IET Intelligent Transport Systems, 10(6), 379–388. https://doi.org/10.1049/iet-its.2015.0072

Banța, V. (2012). The strategic management of risk, threats and vulnerabilities, in an informational system. Valahian Journal of Economic Studies, 3(1), 7–16.

CERT Australia. (2014). Cyber crime & security survey report 2013. Commonwealth of Australia.

Chin, W. W. (1998). Issues and opinion on structural equation modeling. MIS Quarterly, 22(1), 7–16. https://doi.org/10.2307/249674

Choejey, P., Murray, D., & Fung, C. C. (2016). Exploring critical success factors for cybersecurity in Bhutan’s government organizations. Computer Science & Information Technology, 6(15), 49–61. https://doi.org/10.5121/csit.2016.61505

Citigate ICT PR. (2003, March 13). Fraud a major threat in telecoms industry. ITWeb.

Committee on National Security Systems. (2015). Committee on National Security Systems (CNSS) glossary (CNSSI No. 4009). https://nsarchive.gwu.edu/sites/default/files/documents/3238368/Document-08-Committee-on-National-Security.pdf

D’Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79–98. https://doi.org/10.1287/isre.1070.0160

Daferighe, E. E., & Udih, M. (2014). Computerized accounting information systems and system risk management in Nigerian banks. International Journal of Research in Computer Application & Management, 4(7), 67-72.

Deloitte. (2006). Protecting the digital assets: The 2006 technology, media & telecommunications security survey. London: Deloitte Touche Tohmatsu Limited.

Deloitte. (2013). Blurring the lines: 2013 TMT global security study. London: Deloitte Touche Tohmatsu Limited.

Deloitte. (2014). Global cyber executive briefing. London: Deloitte Touche Tohmatsu Limited.

Department for Business, Innovation & Skills. (2013). Information security breaches survey 2013: Technical report (BIS/13/P184). https://www.gov.uk/government/publications/information-security-breaches-survey-2013-technical-report

Gordon, L. A., Loeb, M. P., & Zhou, L. (2011). The impact of information security breaches: Has there been a downward shift in costs? Journal of Computer Security, 19(1), 33–56. https://doi.org/10.3233/JCS-2009-0398

Hair, J. F., Jr., Hult, G. T. M., Ringle, C. M., & Sarstedt, M. (2017). A primer on partial least squares structural equation modeling (PLS-SEM) (2nd ed.). SAGE Publications.

Hair, J. F., Risher, J. J., Sarstedt, M., & Ringle, C. M. (2019). When to use and how to report the results of PLS-SEM. European Business Review, 31(1), 2–24. https://doi.org/10.1108/EBR-11-2018-0203

Hayale, T. H., & Abu Khadra, H. A. (2006). Evaluation of the effectiveness of control systems in computerized accounting information systems: An empirical research applied on Jordanian banking sector. Journal of Accounting, Business and Management, 13(1), 39–68.

Henseler, J., Ringle, C. M., & Sarstedt, M. (2015). A new criterion for assessing discriminant validity in variance-based structural equation modeling. Journal of the Academy of Marketing Science, 43(1), 115–135. https://doi.org/10.1007/s11747-014-0403-8

Horne, C. A., Ahmad, A., & Maynard, S. B. (2016). A theory on information security. In Proceedings of the 27th Australasian Conference on Information Systems (ACIS 2016). University of Wollongong. https://aisel.aisnet.org/acis2016/87/

International Organization for Standardization. (2009). Information technology—Security techniques—Information security management systems—Overview and vocabulary (ISO/IEC Standard No. 27000:2009). https://www.iso.org/standard/41933.html

International Telecommunication Union. (2015). Global cybersecurity index & cyberwellness profiles. https://www.itu.int/pub/D-STR-SECU-2015

International Telecommunication Union. (2017). Global cybersecurity index 2017. https://www.itu.int/pub/D-STR-GCI.01-2017/en

International Telecommunication Union. (2019). Global cybersecurity index 2018. https://www.itu.int/pub/D-STR-GCI.01-2018

International Telecommunication Union. (2021). Global cybersecurity index 2020. https://www.itu.int/pub/D-STR-GCI.01-2021/en

International Telecommunication Union. (2024). Global cybersecurity index 2024 (5th ed.). https://www.itu.int/hub/publication/d-hdb-gci-01-2024/

Jadrić, M., Ćukušić, M., & Garača, Ž. (2016). Exploring the responsibilities and practices behind information security governance. In D. Tipurić & I. Kovač (Eds.), Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship (pp. 328–342). CIRU – Governance Research and Development Centre.

Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1

Jouini, M., Rabai, L. B. A., & Aissa, A. B. (2014). Classification of security threats in information systems. Procedia Computer Science, 32, 489-496.

Kaspersky. (2016, August 22). Threat intelligence report for the telecommunications industry. Securelist. https://securelist.com/threat-intelligence-report-for-the-telecommunications-industry/75846/

Kaspersky. (2024, July 31). Kaspersky: Telecoms are prime targets for cyberattacks in 2024. https://www.kaspersky.co.uk/about/press-releases/kaspersky-telecoms-are-prime-targets-for-cyberattacks-in-2024

Kennedy, K. (2014). Phone phreaking history & impact on telecommunications. Kennedy Info Sec. http://kennedyinfosec.com/blog/?page_id=547

Kumar, R. L., Park, S., & Subramaniam, C. (2008). Understanding the value of countermeasure portfolios in information systems security. Journal of Management Information Systems, 25(2), 241-279. https://doi.org/10.2753/MIS0742-1222250210

Lee, S. (2025, March 27). Optimizing telecom security through effective privacy regulation steps. Number Analytics. https://www.numberanalytics.com/blog/optimizing-telecom-security

Lévy-Bencheton, C., & Darra, E. (2015). Cyber security for smart cities: An architecture model for public transport. European Union Agency for Network and Information Security. https://doi.org/10.2824/846575

Loch, K. D., Carr, H. H., & Warkentin, M. E. (1992). Threats to information systems: Today’s reality, yesterday’s understanding. MIS Quarterly, 16(2), 173–186. https://doi.org/10.2307/249574

Malyuk, A., & Miloslavskaya, N. G. (2014). Information security theory development. In Proceedings of the 7th International Conference on Security of Information and Networks (SIN ’14) (pp. 52–55). Association for Computing Machinery. https://doi.org/10.1145/2659651.2659659

Mbowe, J. E., Zlotnikova, I., Msanjila, S. S., & Oreku, G. S. (2014). A conceptual framework for threat assessment based on organization’s information security policy. Journal of Information Security, 5(4), 166–177. https://doi.org/10.4236/jis.2014.54016

Medina, M., Serna, J., Sfakianakis, A., Aguilá, J., & Fernández, L. Á. (2013). eID authentication methods in e-finance and e-payment services: Current practices and recommendations. European Union Agency for Network and Information Security. https://doi.org/10.2824/27272

Muhrtala, T. O., & Ogundeji, M. (2013). Computerized accounting information systems and perceived security threats in developing economies: The Nigerian case. Universal Journal of Accounting and Finance, 1(1), 9–18. https://doi.org/10.13189/ujaf.2013.010102

National Cyber Security Index. (2020). Yemen. https://ncsi.ega.ee/country/ye_2022/

National Institute of Standards and Technology. (2006). Minimum security requirements for federal information and information systems (Federal Information Processing Standards Publication 200). https://doi.org/10.6028/NIST.FIPS.200

Nhan, V. T. T., Dung, N. N. K., & Phuoc, T. (2025). A study on the impact of accounting information security controls on the effectiveness of internal controls in Vietnamese enterprises. Journal of Open Innovation: Technology, Market, and Complexity, 11(1), 100470. https://doi.org/10.1016/j.joitmc.2025.100470

Office of Management and Budget. (2016, March 18). Annual report to Congress: Federal Information Security Modernization Act. https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/final_fy_2015_fisma_report_to_congress_03_18_2016.pdf

Posthumus, S., & von Solms, R. (2004). A framework for the governance of information security. Computers & Security, 23(8), 638–646. https://doi.org/10.1016/j.cose.2004.10.006

PricewaterhouseCoopers. (2014, September 30). Managing cyber risks in an interconnected world: Key findings from the Global State of Information Security® Survey 2015. https://www.pwc.com/jg/en/publications/managing-cyber-risks-2015.pdf

Reuters. (2015). Millions of computers may be compromised by US spyware: Report. https://www.telegraph.co.uk/news/worldnews/northamerica/usa/11416985/Millions-of-computers-may-be-compromised-by-US-spyware-report.html

Rhodes-Ousley, M. (2013). Information security: The complete reference (2nd ed.). McGraw-Hill Education.

Riad, N. I. (2009). Security of accounting information systems: A cross-sector study of UK companies [Doctoral dissertation, Cardiff University, Cardiff, Wales].

Schuessler, J. H. (2009). General deterrence theory: Assessing information systems security effectiveness in large versus small businesses [Doctoral dissertation, University of North Texas, Denton, Texas].

Schuessler, J. H. (2013). Contemporary Threats Countermeasuresi. Journal of Information Privacy and Security, 9(2), 3-20.

Schwartz, M. J. (2011, September 21). Social engineering attacks cost companies. Dark Reading. https://www.darkreading.com/vulnerabilities-threats/social-engineering-attacks-cost-companies

Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk management guide for information technology systems (NIST Special Publication 800-30). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30

Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: Security planning models for management decision making. MIS Quarterly, 22(4), 441–469. https://doi.org/10.2307/249551

Straub, D. W., Jr. (1987). Controlling computer abuse: An empirical study of effective security countermeasures. Proceedings of the 8th International Conference on Information Systems (ICIS 1987) (pp. 277–289). Pittsburgh, Pennsylvania. https://aisel.aisnet.org/icis1987/32/

Straub, D. W., Jr. (1990). Effective IS security: An empirical study. Information Systems Research, 1(3), 255–276. https://doi.org/10.1287/isre.1.3.255

Swanson, M. M., Bowen, P., Phillips, A. W., Gallup, D., & Lynes, D. (2010). Contingency planning guide for federal information systems (NIST Special Publication 800-34 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-34r1

Symantec Corporation. (2016, April). Internet security threat report (Vol. 21). https://www.symantec.com/content/dam/symantec/docs/reports/istr-21-2016-en.pdf

Tarmidi, M., Rashid, A. A., Deris, M. S. B., & Roni, R. A. (2013). Computerized accounting system threats in Malaysian public services. International Journal of Finance and Accounting, 2(2), 109–113.

U.S. Government Accountability Office. (2015, July 8). Information security: Cyber threats and data breaches illustrate need for stronger controls across federal agencies (GAO-15-758T). https://www.gao.gov/products/gao-15-758t

U.S. Government Accountability Office. (2016, May 18). Information security: Agencies need to improve controls over selected high-impact systems (GAO-16-501). https://www.gao.gov/products/gao-16-501

Verizon. (2023). 2023 data breach investigations report. https://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf

Verizon. (2025). 2025 data breach investigations report. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf

von Solms, R., & van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97–102. https://doi.org/10.1016/j.cose.2013.04.004

Whitman, M. E. (2004). In defense of the realm: Understanding the threats to information security. International Journal of Information Management, 24(1), 43–57. https://doi.org/10.1016/j.ijinfomgt.2003.12.003

Yau, H. K. (2014). Information security controls. Advances in Robotics & Automation, 3(2), e118.

Downloads

Published

2026-09-30

Issue

Section

Articles

How to Cite

Al-Hemyari, N. H. A. (2026). Impact of Information Technology Risks on Security Controls: A Field Study in Telecommunications Companies in Sana’a. University of Science and Technology Journal for Management and Human Sciences, 4(3), 87-124. https://doi.org/10.59222/ustjmhs.4.3.4

Similar Articles

51-60 of 72

You may also start an advanced similarity search for this article.