Impact of Information Technology Risks on Security Controls: A Field Study in Telecommunications Companies in Sana'a
DOI:
https://doi.org/10.59222/ustjmhs.4.3.4Keywords:
security controls, information technology risks, telecommunication companies in Sana'aAbstract
This study aimed to assess the impact of information technology risks on security controls in telecommunications companies operating in Sana'a, following an analytical method. The study population consisted of telecommunications companies in Sana'a, and a comprehensive census method was used to collect data from 356 participants using a questionnaire. However, only 218 questionnaires were valid for analysis. Data were analyzed using partial least squares structural equation modeling (PLS-SEM). The study findings revealed that information technology risks have a negative impact on security controls. The study recommends the necessity of implementing strong multi-factor authentication, devoting especial attention to access control, and regularly identifying vulnerabilities in security controls.
References
الثورة نت. (2025، 31 يوليو)، ورشة بصنعاء حول المخاطر السيبرانية وطرق الحماية من الهجمات الإلكترونية. https://althawrah.ye/archives/1023009
الربيدي، محمد علي (2010)، حماية المعلومات المحاسبية في ظل مخاطر التكنولوجيا للعمليات المصرفية الإلكترونية: دراسة ميدانية في البنوك العاملة في اليمن، مجلة كلية التجارة والاقتصاد، 33، 1-45.
زويلف، انغام محسن حسن (2009)، طبيعة تهديدات أمن نظم المعلومات المحاسبية الإلكترونية: دراسة تطبيقية على شركات التأمين الأردنية، المجلة العربية للمحاسبة، 12(1)، 46-77.
سبأنت. (2014، 23 يونيو)، المؤتمر الأول لأمن المعلومات- صنعاء، المركز الوطني للمعلومات. https://yemennic.com/conferences/activ_detailsce9d.html?ID=69967
الشوكاني، غمدان (2016، مايو 11)، أكثر من 37 مليار ريال خسائر مؤسسة الاتصالات منذ بدء العدوان، وكالة الأنباء اليمنية سبأ. https://www.saba.ye/ar/news427488.htm
عدن الغد. (2014)، خلل بشبكة (MTN) يوقف حركة الاتصالات بعدن. https://adengad.net/public/posts/103375
فاضل، عبدالكريم محمد يحيى (2018)، تقييم مخاطر أمن نظم المعلومات المحاسبية المحوسبة لدى البنوك التجارية في اليمن: دراسة تطبيقية [أطروحة دكتوراه، جامعة دمشق، سوريا].
قانون رقم (13) لسنة 2012م بشأن حق الحصول على المعلومات. (2012). الجريدة الرسمية، الجمهورية اليمنية.
قانون رقم (40) لسنة 2006م بشأن أنظمة الدفع والعمليات المالية والمصرفية الإلكترونية. (2006)، الجريدة الرسمية، (24)، الجمهورية اليمنية.
القحطاني، ذيب بن عايض (2015)، أمن المعلومات، الرياض، السعودية: مكتبة الملك فهد الوطنية.
وزارة الاتصالات وتقنية المعلومات. (2020)، الاتصالات والبريد: خمسة أعوام من الصمود. https://mtit.gov.ye/co_sub_media_image/28-Arabic_2020_R2.pdf
Ahmed, A. W., Khan, O. A., Ahmed, M. M., & Shah, M. A. (2017). A comprehensive analysis on the security threats and their countermeasures of IoT. International Journal of Advanced Computer Science and Applications, 8(7), 489–501. https://doi.org/10.14569/IJACSA.2017.080768
Al-ghananeem, K. M. (2014). The impact of information security management standards to ensure information security. International Journal of Economics and Research, 5(1), 46-66.
Al-shaibany, N. A., Al-sofi, T. A. B., & Al Gaphari, G. H. (2023). A model for enhancing the information security management systems in Yemen banks. Sana’a University Journal of Applied Sciences and Technology, 1(1), 1–12. https://doi.org/10.59628/jast.v1i1.14
Atyam, S. B. (2010). Effectiveness of security control risk assessments for enterprises: Assess on the business perspective of security risks. Information Security Journal: A Global Perspective, 19(6), 343–350. https://doi.org/10.1080/19393555.2010.514892
Australian Cyber Security Centre. (2015). 2015 cyber security survey: Major Australian businesses. https://www.cybersecurityhub.gov.za/cyberawareness/images/pdfs/2015-ACSC-Cyber-Security-Survey-Major-Australian-Businesses.pdf
Azees, M., Vijayakumar, P., & Jegatha Deborah, L. (2016). Comprehensive survey on security services in vehicular ad-hoc networks. IET Intelligent Transport Systems, 10(6), 379–388. https://doi.org/10.1049/iet-its.2015.0072
Banța, V. (2012). The strategic management of risk, threats and vulnerabilities, in an informational system. Valahian Journal of Economic Studies, 3(1), 7–16.
CERT Australia. (2014). Cyber crime & security survey report 2013. Commonwealth of Australia.
Chin, W. W. (1998). Issues and opinion on structural equation modeling. MIS Quarterly, 22(1), 7–16. https://doi.org/10.2307/249674
Choejey, P., Murray, D., & Fung, C. C. (2016). Exploring critical success factors for cybersecurity in Bhutan’s government organizations. Computer Science & Information Technology, 6(15), 49–61. https://doi.org/10.5121/csit.2016.61505
Citigate ICT PR. (2003, March 13). Fraud a major threat in telecoms industry. ITWeb.
Committee on National Security Systems. (2015). Committee on National Security Systems (CNSS) glossary (CNSSI No. 4009). https://nsarchive.gwu.edu/sites/default/files/documents/3238368/Document-08-Committee-on-National-Security.pdf
D’Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: A deterrence approach. Information Systems Research, 20(1), 79–98. https://doi.org/10.1287/isre.1070.0160
Daferighe, E. E., & Udih, M. (2014). Computerized accounting information systems and system risk management in Nigerian banks. International Journal of Research in Computer Application & Management, 4(7), 67-72.
Deloitte. (2006). Protecting the digital assets: The 2006 technology, media & telecommunications security survey. London: Deloitte Touche Tohmatsu Limited.
Deloitte. (2013). Blurring the lines: 2013 TMT global security study. London: Deloitte Touche Tohmatsu Limited.
Deloitte. (2014). Global cyber executive briefing. London: Deloitte Touche Tohmatsu Limited.
Department for Business, Innovation & Skills. (2013). Information security breaches survey 2013: Technical report (BIS/13/P184). https://www.gov.uk/government/publications/information-security-breaches-survey-2013-technical-report
Gordon, L. A., Loeb, M. P., & Zhou, L. (2011). The impact of information security breaches: Has there been a downward shift in costs? Journal of Computer Security, 19(1), 33–56. https://doi.org/10.3233/JCS-2009-0398
Hair, J. F., Jr., Hult, G. T. M., Ringle, C. M., & Sarstedt, M. (2017). A primer on partial least squares structural equation modeling (PLS-SEM) (2nd ed.). SAGE Publications.
Hair, J. F., Risher, J. J., Sarstedt, M., & Ringle, C. M. (2019). When to use and how to report the results of PLS-SEM. European Business Review, 31(1), 2–24. https://doi.org/10.1108/EBR-11-2018-0203
Hayale, T. H., & Abu Khadra, H. A. (2006). Evaluation of the effectiveness of control systems in computerized accounting information systems: An empirical research applied on Jordanian banking sector. Journal of Accounting, Business and Management, 13(1), 39–68.
Henseler, J., Ringle, C. M., & Sarstedt, M. (2015). A new criterion for assessing discriminant validity in variance-based structural equation modeling. Journal of the Academy of Marketing Science, 43(1), 115–135. https://doi.org/10.1007/s11747-014-0403-8
Horne, C. A., Ahmad, A., & Maynard, S. B. (2016). A theory on information security. In Proceedings of the 27th Australasian Conference on Information Systems (ACIS 2016). University of Wollongong. https://aisel.aisnet.org/acis2016/87/
International Organization for Standardization. (2009). Information technology—Security techniques—Information security management systems—Overview and vocabulary (ISO/IEC Standard No. 27000:2009). https://www.iso.org/standard/41933.html
International Telecommunication Union. (2015). Global cybersecurity index & cyberwellness profiles. https://www.itu.int/pub/D-STR-SECU-2015
International Telecommunication Union. (2017). Global cybersecurity index 2017. https://www.itu.int/pub/D-STR-GCI.01-2017/en
International Telecommunication Union. (2019). Global cybersecurity index 2018. https://www.itu.int/pub/D-STR-GCI.01-2018
International Telecommunication Union. (2021). Global cybersecurity index 2020. https://www.itu.int/pub/D-STR-GCI.01-2021/en
International Telecommunication Union. (2024). Global cybersecurity index 2024 (5th ed.). https://www.itu.int/hub/publication/d-hdb-gci-01-2024/
Jadrić, M., Ćukušić, M., & Garača, Ž. (2016). Exploring the responsibilities and practices behind information security governance. In D. Tipurić & I. Kovač (Eds.), Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship (pp. 328–342). CIRU – Governance Research and Development Centre.
Joint Task Force Transformation Initiative. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30r1
Jouini, M., Rabai, L. B. A., & Aissa, A. B. (2014). Classification of security threats in information systems. Procedia Computer Science, 32, 489-496.
Kaspersky. (2016, August 22). Threat intelligence report for the telecommunications industry. Securelist. https://securelist.com/threat-intelligence-report-for-the-telecommunications-industry/75846/
Kaspersky. (2024, July 31). Kaspersky: Telecoms are prime targets for cyberattacks in 2024. https://www.kaspersky.co.uk/about/press-releases/kaspersky-telecoms-are-prime-targets-for-cyberattacks-in-2024
Kennedy, K. (2014). Phone phreaking history & impact on telecommunications. Kennedy Info Sec. http://kennedyinfosec.com/blog/?page_id=547
Kumar, R. L., Park, S., & Subramaniam, C. (2008). Understanding the value of countermeasure portfolios in information systems security. Journal of Management Information Systems, 25(2), 241-279. https://doi.org/10.2753/MIS0742-1222250210
Lee, S. (2025, March 27). Optimizing telecom security through effective privacy regulation steps. Number Analytics. https://www.numberanalytics.com/blog/optimizing-telecom-security
Lévy-Bencheton, C., & Darra, E. (2015). Cyber security for smart cities: An architecture model for public transport. European Union Agency for Network and Information Security. https://doi.org/10.2824/846575
Loch, K. D., Carr, H. H., & Warkentin, M. E. (1992). Threats to information systems: Today’s reality, yesterday’s understanding. MIS Quarterly, 16(2), 173–186. https://doi.org/10.2307/249574
Malyuk, A., & Miloslavskaya, N. G. (2014). Information security theory development. In Proceedings of the 7th International Conference on Security of Information and Networks (SIN ’14) (pp. 52–55). Association for Computing Machinery. https://doi.org/10.1145/2659651.2659659
Mbowe, J. E., Zlotnikova, I., Msanjila, S. S., & Oreku, G. S. (2014). A conceptual framework for threat assessment based on organization’s information security policy. Journal of Information Security, 5(4), 166–177. https://doi.org/10.4236/jis.2014.54016
Medina, M., Serna, J., Sfakianakis, A., Aguilá, J., & Fernández, L. Á. (2013). eID authentication methods in e-finance and e-payment services: Current practices and recommendations. European Union Agency for Network and Information Security. https://doi.org/10.2824/27272
Muhrtala, T. O., & Ogundeji, M. (2013). Computerized accounting information systems and perceived security threats in developing economies: The Nigerian case. Universal Journal of Accounting and Finance, 1(1), 9–18. https://doi.org/10.13189/ujaf.2013.010102
National Cyber Security Index. (2020). Yemen. https://ncsi.ega.ee/country/ye_2022/
National Institute of Standards and Technology. (2006). Minimum security requirements for federal information and information systems (Federal Information Processing Standards Publication 200). https://doi.org/10.6028/NIST.FIPS.200
Nhan, V. T. T., Dung, N. N. K., & Phuoc, T. (2025). A study on the impact of accounting information security controls on the effectiveness of internal controls in Vietnamese enterprises. Journal of Open Innovation: Technology, Market, and Complexity, 11(1), 100470. https://doi.org/10.1016/j.joitmc.2025.100470
Office of Management and Budget. (2016, March 18). Annual report to Congress: Federal Information Security Modernization Act. https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/final_fy_2015_fisma_report_to_congress_03_18_2016.pdf
Posthumus, S., & von Solms, R. (2004). A framework for the governance of information security. Computers & Security, 23(8), 638–646. https://doi.org/10.1016/j.cose.2004.10.006
PricewaterhouseCoopers. (2014, September 30). Managing cyber risks in an interconnected world: Key findings from the Global State of Information Security® Survey 2015. https://www.pwc.com/jg/en/publications/managing-cyber-risks-2015.pdf
Reuters. (2015). Millions of computers may be compromised by US spyware: Report. https://www.telegraph.co.uk/news/worldnews/northamerica/usa/11416985/Millions-of-computers-may-be-compromised-by-US-spyware-report.html
Rhodes-Ousley, M. (2013). Information security: The complete reference (2nd ed.). McGraw-Hill Education.
Riad, N. I. (2009). Security of accounting information systems: A cross-sector study of UK companies [Doctoral dissertation, Cardiff University, Cardiff, Wales].
Schuessler, J. H. (2009). General deterrence theory: Assessing information systems security effectiveness in large versus small businesses [Doctoral dissertation, University of North Texas, Denton, Texas].
Schuessler, J. H. (2013). Contemporary Threats Countermeasuresi. Journal of Information Privacy and Security, 9(2), 3-20.
Schwartz, M. J. (2011, September 21). Social engineering attacks cost companies. Dark Reading. https://www.darkreading.com/vulnerabilities-threats/social-engineering-attacks-cost-companies
Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk management guide for information technology systems (NIST Special Publication 800-30). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-30
Straub, D. W., & Welke, R. J. (1998). Coping with systems risk: Security planning models for management decision making. MIS Quarterly, 22(4), 441–469. https://doi.org/10.2307/249551
Straub, D. W., Jr. (1987). Controlling computer abuse: An empirical study of effective security countermeasures. Proceedings of the 8th International Conference on Information Systems (ICIS 1987) (pp. 277–289). Pittsburgh, Pennsylvania. https://aisel.aisnet.org/icis1987/32/
Straub, D. W., Jr. (1990). Effective IS security: An empirical study. Information Systems Research, 1(3), 255–276. https://doi.org/10.1287/isre.1.3.255
Swanson, M. M., Bowen, P., Phillips, A. W., Gallup, D., & Lynes, D. (2010). Contingency planning guide for federal information systems (NIST Special Publication 800-34 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-34r1
Symantec Corporation. (2016, April). Internet security threat report (Vol. 21). https://www.symantec.com/content/dam/symantec/docs/reports/istr-21-2016-en.pdf
Tarmidi, M., Rashid, A. A., Deris, M. S. B., & Roni, R. A. (2013). Computerized accounting system threats in Malaysian public services. International Journal of Finance and Accounting, 2(2), 109–113.
U.S. Government Accountability Office. (2015, July 8). Information security: Cyber threats and data breaches illustrate need for stronger controls across federal agencies (GAO-15-758T). https://www.gao.gov/products/gao-15-758t
U.S. Government Accountability Office. (2016, May 18). Information security: Agencies need to improve controls over selected high-impact systems (GAO-16-501). https://www.gao.gov/products/gao-16-501
Verizon. (2023). 2023 data breach investigations report. https://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf
Verizon. (2025). 2025 data breach investigations report. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
von Solms, R., & van Niekerk, J. (2013). From information security to cyber security. Computers & Security, 38, 97–102. https://doi.org/10.1016/j.cose.2013.04.004
Whitman, M. E. (2004). In defense of the realm: Understanding the threats to information security. International Journal of Information Management, 24(1), 43–57. https://doi.org/10.1016/j.ijinfomgt.2003.12.003
Yau, H. K. (2014). Information security controls. Advances in Robotics & Automation, 3(2), e118.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 The copyright is transferred to the University of Science and Technology, Sana’a, Yemen.

This work is licensed under a Creative Commons Attribution 4.0 International License.