Cybersecurity governance · Riyadh

Compliance you can prove. Security that holds.

Built forSAMA CSFNCA ECC-2:2024PDPLSAMA BCMSWIFT CSCF

We help Saudi banks and regulated institutions meet SAMA, NCA and SDAIA requirements — and turn compliance into lasting security capability.

More than 10regulatory frameworks
AR · ENevery deliverable
RiyadhSaudi limited company
SAMA CSFNCA ECCPDPLSWIFT CSCF
SAMA CSF Cyber Security FrameworkNCA ECC-2:2024 Essential Cybersecurity ControlsPDPL Personal Data Protection LawSAMA BCM Business ContinuityNCA CCC Cloud ControlsNCA CRFR Regulatory frameworkSWIFT CSCF Customer Security Controls
How we work

A disciplined path from exposure to assurance

01
Discover
Scope, regulatory obligations and current posture.
→
02
Assess
Evidence-based gap and maturity assessment.
→
03
Plan
A prioritized, costed remediation roadmap.
→
04
Implement
Controls, policies and processes delivered.
→
05
Sustain
Monitoring, reporting and re-assessment.
Why CISO Consulting

Local regulation.
Global discipline.

NCA-licensed and SAMA-aligned advisory team
Bilingual Arabic/English deliverables
Dedicated client portal for real-time tracking
Vision 2030 digital transformation alignment
About us →
CREST
Accredited
SANS
Partner
(ISC)²
Member
aws
Partner Network
Microsoft
Solutions Partner
NCA
National Cybersecurity Authority
Etimad
Official Consultant · Certified
Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks
Framework explorer

What each framework asks of you — and what we deliver

Pick a framework to see who it applies to, what it covers and what an engagement produces.

SAMA CSF

SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.

SAMA

Applies to

BanksInsurance companiesFinance companiesOther SAMA-regulated institutions

Main areas

Leadership and governanceRisk management and complianceOperations and technologyThird-party cyber security

What we deliver

  • Maturity assessment against every control
  • Gap analysis and remediation roadmap
  • Policies, standards and procedures
  • Evidence pack for SAMA reviews
Typical first engagement: 8–12 weeks
Readiness self-check

How ready are you? Find out in two minutes

Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.

Know where you stand before your regulator does.

Book a confidential consultation. We will map your obligations, identify your priorities and propose a clear path to compliance.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.