New

CISO ERA

One platform for governance, risk, compliance and security operations — built for the Kingdom.

Enterprise GRC, security operations and financial-crime control for Saudi regulated institutions.

Live demo See CISO ERA in action Explore the live demo at saudicisos.com.
Try the live demo
In depth

Inside CISO ERA

Why CISO ERA

Built for Saudi regulation
SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls (ECC-2:2024), the SAMA Counter-Fraud Framework and AML/CFT ready to assess, with PDPL operations — data subject requests, consent and breach notification — built in. International standards sit alongside: ISO/IEC 27001:2022, PCI DSS v4.0, NIST CSF 2.0 and CIS Controls v8.
GRC and security operations in one
Compliance, risk and audit share one data model with SOC operations, incident response, threat intelligence and vulnerability management — so what happens in operations shows up in your risk and compliance picture.
Financial crime included
AML/CFT alert handling with suspicious-transaction reporting, counter-fraud case management and SARIE governance run beside cybersecurity, not in a separate system.
Arabic and English, completely
Every screen, report and notification in both languages, with full right-to-left layout, Hijri and Gregorian dates, and KSA number and date formats.
Your data stays where you decide
Deploy on your own infrastructure or on KSA-hosted cloud. Licensing uses a cryptographically signed token that works fully offline — no call home required.
Enterprise-grade by design
SAML single sign-on, SCIM provisioning, multi-factor authentication, segregation of duties, a tamper-evident audit trail and multi-entity support for groups and their subsidiaries.

At a glance

59
modules
338
capabilities
9
regulatory frameworks
490
controls ready to assess
2
languages, full RTL
KSA
hosted or on-premises

Regulatory coverage

Frameworks ship pre-loaded, so assessment starts on the first day rather than after months of configuration. Controls map across frameworks, so evidence collected once supports every framework it satisfies.

Framework
SAMA Cyber Security Framework (SAMA CSF)
SAMA Business Continuity Management Framework (SAMA BCM)
SAMA IT Governance Framework (SAMA ITGF)

SAMA Counter-Fraud Framework (SAMA CFF)
NCA Essential Cybersecurity Controls (ECC-2:2024)
NCA Critical Systems CyberSecurity Controls (CSCC)
Anti-Money Laundering & Counter-Terrorist Financing (AML/CFT)
ISO/IEC 27001:2022
PCI DSS v4.0
NIST Cybersecurity Framework 2.0
CIS Critical Security Controls v8
Aramco CCC
CMA Cybersecurity
CST Cybersecurity Regulatory Framework (CRF)
and all other frameworks and regulations...

Governance, Risk & Compliance

Run the whole assurance cycle in one place — from the regulation to the control, the evidence, the finding and the board report.

12 modules · 73 capabilities

Audit Engagements (auditee)
Audits performed on us: incoming requests, what we submitted, findings raised against us, remediation and a reusable evidence library.
Engagement register · Incoming request tracker · Submission ledger · Findings raised against us · Remediation tracking · Reusable evidence library · Repeat-finding detection · Sensitive release approval · Meeting and commitment log · Multi-year audit history · Excel, PDF and slide export
Governance
Executive oversight, org policies, roles & responsibilities.
RACI matrices · Escalation matrices · Organization policies · Role definitions · Segregation of duties
Committee Management
Committee charters, membership, meeting minutes, action-item tracking.
Committee charters · Membership management · Meeting minutes · Action item tracking · Attendance tracking · Resolutions & voting
Risk Management
Risk register, assessment, treatment, KRIs, heat maps.
Risk register · Assessment workflow · Treatment plans · KRI dashboards · Heat maps · Risk aggregation · Risk appetite / tolerance · FAIR quantification
Compliance Controls
Control library, framework mapping, evidence, self-assessment, gap analysis, maturity.
Control library · Framework mapping · Evidence collection · Self-assessment · Gap analysis · Maturity assessment · Signed evidence vault · AI auto-mapping policies to controls
Audits
Internal audit plans, findings, corrective actions, reports.
Audit planning · Findings tracking · CAPA workflow · Evidence collection · Auditor management · Report generation
Regulatory Horizon
Track upcoming regulations, obligations, impact assessment.
Regulation tracking · Obligations mapping · Impact assessment · Regulatory alerts
Business Continuity (BCM/BIA)
BIA, continuity plans, dependencies, recovery objectives.
Business impact analysis · Continuity plans · Service dependencies · Plan exercises
PDPL Operations
DSR intake portal, consent reviews, reminders, exports (KSA PDPL).
Data subject requests · Consent reviews · Deadline reminders · Regulator exports
Security Posture
Posture scoring with historical trend charts.
Posture scoring · Trend charts
Cybersecurity Architecture
Security architecture blueprints, trust zones, component→control coverage, gaps and reviews with Mermaid diagrams.
Architecture blueprints · Trust zones · Component inventory · Mermaid diagrams · Control coverage mapping · Asset mapping · Gap register · Architecture reviews
Advisory Engagements
Outsourced GRC functions: scoped, time-boxed advisor access with SAMA oversight evidence.
Engagement register · Scope definition · Time-boxed access · Oversight reviews · Exit planning · Duty conflict check · Exports

Security Operations

Detect, respond and recover — with your SOC, incidents, threats and vulnerabilities connected to the risks they affect.

12 modules · 83 capabilities

Brand Protection
Register impersonation findings from any source and run takedowns to completion: authority directory, evidence capture, SLA tracking and escalation.
Impersonation register · Verdict and severity triage · Evidence capture and sealing · Takedown case management · Takedown authority directory · SLA tracking and escalation · Vendor feed intake · Excel and PDF export
Asset Management
Asset inventory with manual/upload/scan/discovery + CMDB, tagging, ownership, lifecycle.
Manual entry · CSV / bulk upload · Network scan · Auto-discovery · Cloud inventory sync · CMDB integration · Tagging + custom fields · Ownership tracking · Lifecycle management · Software inventory
Vulnerability Management
Vulnerability tracking, scanner integrations, SLA-driven remediation, exceptions.
Tracking · PT/VA CSV import · Tenable.io adapter · Qualys VMDR adapter · Rapid7 InsightVM adapter · Nessus XML parser · OpenVAS XML parser · SLA-driven workflow · Exception workflow · Fix verification · Auto-suggest mitigations · Bulk operations
Incident Management
Full incident lifecycle: detection → containment → recovery → post-mortem.
Full lifecycle · Playbooks · Regulator notifications · Post-mortem workflow · Root cause analysis · Timeline reconstruction · Stakeholder communications · Live war room · Chain-of-custody evidence
SOC Operations
Full SOC workflow: shifts, checklists, alerts, handoffs, sensors, metrics, playbooks.
Shift management · Shift checklists · Alert triage workflow · Shift handoffs · Sensor / tool inventory · Escalation rules · Shift post-mortem · SOC metrics dashboard · Playbook execution · Runbook management
Threat Intelligence
IOC feeds, threat actor tracking, TTP mapping, hunting queries, sharing.
IOC management · Threat actor tracking · TTP / MITRE mapping · External feed ingestion · Hunting queries · Threat sharing (STIX/TAXII) · Campaign tracking
Tabletop Exercises
Scenario-based crisis exercises, participant tracking, after-action reports.
Scenario library · Session facilitation · Participant tracking · After-action reports · Lessons learned
Insider Risk
Insider risk scoring, watchlist, behavioral indicators, remediation.
Risk scoring · Watchlist management · Behavioral indicators · Alert workflow · Remediation actions
Crown Jewel Analysis
Critical asset identification, threat modeling, business impact analysis.
Critical asset identification · Threat modeling · Business impact analysis
Penetration Testing
PT campaigns, finding import, remediation workflow, evidence.
PT campaigns · Findings import · Remediation workflow · Evidence attachments
Ticketing (ITSM)
Ticket queues, SLA tracking, assignment, settings.
Ticket queues · SLA tracking · Assignment rules
Visitor Management
Visitor requests, approvals, front-desk check-in and the physical security roster.
Visit requests and approvals · Front desk check-in and out · Badge inventory · Blocklist · Security officer roster · Visitor reporting and export · Physical security incident register

Financial Crime

Counter-fraud and AML/CFT operations beside cybersecurity, aligned to SAMA requirements.

2 modules · 8 capabilities

Counter-Fraud (SAMA CFF)
Fraud case management, typologies, four-eyes determination, SAMA CFF alignment.
Case management · Typologies · Four-eyes ruling · Approval chain
AML / CFT
AML alerts, STR four-eyes and chain, customer risk rating, sanctions screening log.
AML alerts · STR workflow · Customer risk rating · Sanctions screening

Assets & Technology

Know what you have, where it runs and whether it is healthy — from cloud accounts to OT networks.

5 modules · 22 capabilities

Monitoring
Uptime + availability monitoring — active probes (URL/TCP/DNS/SSL/ping) or passive events.
Active URL probes · TCP port probes · DNS probes · SSL certificate probes · ICMP ping probes · Passive event reception · Alert rules · SLA / uptime reports
CCM Cloud
AWS/Azure/GCP inventory, drift detection, compliance mapping.
AWS adapter · Azure adapter · GCP adapter · Drift detection · Compliance mapping · Continuous inventory
OT / ICS
Operational technology / industrial control systems inventory and risk.
OT inventory · ICS discovery · Modbus/DNP3 monitoring · OT risk assessment
Digital Certificates
TLS/PKI certificate inventory with expiry alerts.
Certificate inventory · Expiry alerts
Lifecycle & Renewals
Asset / contract / certificate lifecycle and renewal tracking.
Renewal pipeline · Lifecycle imports

Change, Documents & Reporting

Control change, govern documents and give the board a clear, consistent picture.

6 modules · 33 capabilities

Change Management
Change requests, CAB approvals, risk assessment, implementation, rollback, calendar.
Change requests · CAB approvals · Change risk assessment · Implementation tracking · Rollback planning · Change calendar
Documents Library
Policies, procedures, standards, charters, guidelines with versioning, review, AI drafting.
Version control · Review workflow · Approval workflow · AI drafting assist · AI review + suggestions · Template library · Regulatory mapping · Digital signatures
Board Reports
Executive dashboards, board-ready packs, KPI trending, AI narration.
Executive dashboards · Board-ready packs · KPI trending · AI narrative generation · Scheduled distribution
Release Management
Release planning and approval tracking.
Release planning · Release approvals
Evidence Vault
Central evidence repository with request workflow.
Evidence repository · Evidence requests
Secure Exchange
Encrypted document sharing, data rooms, external guests, OTP/passcode/NDA gates, watermark view-only, DLP and lifetime controls.
Secure shares (links) · Data rooms · External guests · Inbound file requests · OTP / passcode access · NDA gate · Watermark view-only · DLP pre-send · Envelope encryption (KMS/HSM) · Lifetime & auto-expiry

Programs, Vendors & Finance

Deliver your security program on time and on budget, and govern every third party you depend on.

5 modules · 33 capabilities

Business Center
Business demand intake — requests with justification and budget, line-manager endorsement, SLA-tracked cybersecurity evaluation, and conversion to projects.
Request intake & threads · Line-manager endorsement · Evaluation SLA & escalation · Multi-department review · Convert to project
Projects
Project portfolio, budgets, Gantt charts, milestones, resource allocation.
Portfolio management · Budget tracking · Gantt charts · Milestones · Resource allocation · Financial tracking · RFP tendering & bidding · Open tender (EOI) · Vendor approval workflow
Vendor Management
Vendor register, risk tier, contract lifecycle, VSQ, renewals, on/offboarding.
Vendor register · VSQ (Vendor Security Questionnaire) · Contract lifecycle · Risk tiering · SLA tracking · Renewal alerts · Onboarding workflow · Offboarding workflow
Third-Party 360
Federated third-party hub: 360 record, wire-to-any-module, registers, evaluation scorecard, obligations & portfolio.
360 hub & federation · Wire to any module · Registers & action center · Obligations register · Evaluation scorecard · Portfolio view · Gated onboarding
Security Finance
Budgets, expenses, purchase orders, cost centers, cyber insurance.
Budgets · Expenses · Purchase orders · Cyber insurance

People & Awareness

Build a security-aware workforce and manage the people behind the program.

7 modules · 39 capabilities

Organization Chart
Position-based org structure with reporting lines, acting arrangements, approval-controlled changes and published versions.
Position register · Interactive chart · Assignments and acting arrangements · Change approval workflow · Published chart versions · Succession and key-person tracking · Excel, PDF and slide export
Users & HR
User profiles, org chart, roles/permissions, MFA, SSO configuration.
User profiles + CV parsing · Interactive org chart · Role management · Granular permissions · MFA / 2FA · SSO / SAML · LDAP / Active Directory · Employment segmentation badges
Awareness & Maturity
Security awareness training, phishing sims, maturity assessments, courses.
Training tracking · Phishing simulations · Maturity assessments · Course library · Certificates issuance · Gamification · Instructor authoring
Overtime & Leave
KSA Labor Law-compliant leave + overtime workflow, MHRSD reporting.
Leave request workflow · Overtime interest solicitation · Approval delegation · Auto-escalation · Ramadan mode hours · Hijri + Gregorian calendars · MHRSD reporting export · AI staffing predictions
Phishing Simulation
Phishing campaigns, templates, click tracking.
Campaigns · Templates · Click tracking
Training & Quizzes
Courses, quiz engine, learner tracking, quiz reports.
Courses · Quiz engine · Quiz reports
Employee Performance
KPI scorecards, department scorecards, employee-of-the-month.
KPI tracking · Department scorecards · Employee of the month

Platform & Integration

The foundation: auditability, automation, integration and full Arabic support.

10 modules · 47 capabilities

Multi-organization (subsidiaries)
Parent entity with isolated subsidiary / sister organizations.
Audit Log
Immutable system audit trail with export + retention policies.
System audit trail · Immutability · CSV/JSON/PDF export · Retention policies · Advanced search / filter
API Access
REST API with token management, rate limits, documentation.
REST API · Token management · Interactive API docs · GraphQL endpoint
Webhooks
Outbound HTTP push on events with retry logic + signature verification.
Outbound push · Event subscriptions · Retry logic · HMAC signature
External Integrations
Slack, Teams, Jira, PagerDuty, Zapier, ServiceNow, SIEM outbound.
Slack · Microsoft Teams · Jira · PagerDuty · Zapier · ServiceNow · SIEM outbound (Splunk/QRadar/Sentinel) · WhatsApp Business · SMS (Twilio/SNS)
Bulk Operations
Mass edit / delete / import / export across every module.
Mass edit · Mass delete · Bulk import · Bulk export
Saved Views
Persistent filtered views + custom dashboards + shared views across modules.
Personal saved views · Team-shared views · Custom dashboards · Widget builder
Notifications Engine
Email + in-app notifications with templates, schedules, escalation rules.
Email notifications · In-app notifications · Template management · Scheduled notifications · Escalation rules · Daily / weekly digests · CISO morning briefing
Localization & KSA Formats
Arabic UI, RTL, Hijri calendar, KSA compliance date/number formats.
Arabic UI · Right-to-left layout · Hijri + Gregorian dates · KSA number/date formats
Organization Circulars
Publish org-wide circulars & memos, target by role/division, with read-acknowledgement tracking (bilingual EN/AR).
Publish circulars/memos · Role/division targeting · Read-acknowledgement · Attachments · Publish scheduling & expiry · Bilingual EN/AR

Deployment, security & integration

Deployment
On-premises installation on your own infrastructure, or KSA-hosted cloud. · Cryptographically signed licensing that verifies fully offline. · Separate license entitlements per module, with usage limits set by plan.
Identity & access
SAML 2.0 single sign-on and SCIM user provisioning. · Multi-factor authentication and custom password policy. · Role-based permissions with segregation-of-duties rules and delegation of authority.
Assurance
Tamper-evident, hash-chained audit trail of every significant action. · Evidence vault with retention policies and version history. · Verified backups — every backup can be checked table by table against the live system.
Integration
REST and GraphQL APIs with token management and rate limiting. · Outbound webhooks and SIEM forwarding to Splunk, QRadar and Microsoft Sentinel. · Slack, Microsoft Teams, Jira, PagerDuty, ServiceNow, Zapier, WhatsApp Business and SMS.
Intelligence
AI auto-mapping of policies to controls. · AI drafting assistance and review suggestions for documents. · AI-generated narrative for board reports.

Who it is for

  • Banks, finance companies and payment providers regulated by SAMA.
  • Government entities and critical-infrastructure operators under NCA.
  • Insurance companies and fintechs building their security and compliance function.
  • Groups managing several subsidiaries from one platform.
  • CISOs, chief risk officers, compliance heads, internal audit and SOC teams.

Book a demonstration with CISO Consulting and see your own regulatory picture in CISO ERA.

See CISO ERA in action

CISO ERA is an enterprise platform that brings governance, risk, compliance, security operations and financial-crime control together in a single system. It is built in Riyadh by CISO Consulting for institutions regulated in the Kingdom of Saudi Arabia, and it works the way those institutions are regulated: SAMA and NCA frameworks ready from day one, Arabic and English throughout, and deployment inside the Kingdom or on your own infrastructure.

Most institutions run these functions across separate tools — a GRC system, a ticketing tool, spreadsheets for committees, one product for awareness and another for vendor risk. Each holds part of the picture, and the security team reconciles them by hand before every board meeting and every regulator review.

CISO ERA replaces that patchwork with one connected platform. A gap in a control becomes a risk; the risk becomes a treatment plan; an incident links back to the control it tested; and the board sees one consistent view, in the language it reads.

Key features

Built for Saudi regulation
GRC and security operations in one
Financial crime included
Arabic and English, completely
Your data stays where you decide
Enterprise-grade by design

Specifications

modules59
capabilities338
regulatory frameworks9
controls ready to assess490
languages, full RTL2
hosted or on-premisesKSA

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment