Cybersecurity advisory built for Saudi regulation
Governance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.
No services available at this time.
Need a custom solution?
Talk to our team to discuss your specific requirements.
What each framework asks of you — and what we deliver
Pick a framework to see who it applies to, what it covers and what an engagement produces.
SAMA CSF
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
Applies to
Main areas
What we deliver
- Maturity assessment against every control
- Gap analysis and remediation roadmap
- Policies, standards and procedures
- Evidence pack for SAMA reviews
NCA ECC-2:2024
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
Applies to
Main areas
What we deliver
- Compliance assessment with evidence
- Remediation plan with owners and dates
- Policies and procedures set
- Support through the NCA self-assessment
PDPL
The Personal Data Protection Law and its regulations, overseen by SDAIA.
Applies to
Main areas
What we deliver
- Personal data inventory and mapping
- Privacy notice and records of processing
- Breach response procedure
- Staff awareness
SAMA BCM
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
Applies to
Main areas
What we deliver
- Business impact analysis
- Continuity and disaster-recovery plans
- Exercise design and reports
- Gap assessment against the framework
SAMA CRFR
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
Applies to
Main areas
What we deliver
- Gap assessment against the requirements
- Prioritized remediation roadmap
- Resilience policies, plans and playbooks
- Exercise program and evidence pack for SAMA
NCA CCC
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
Applies to
Main areas
What we deliver
- Cloud control assessment
- Shared-responsibility mapping
- Configuration review
- Remediation roadmap
SWIFT CSCF
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
Applies to
Main areas
What we deliver
- Independent assessment of the controls
- Architecture-type review
- Evidence for the attestation
- Remediation support
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
Applies to
Main areas
PCI DSS v4.0
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
Applies to
Main areas
NIST CSF 2.0
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Applies to
Main areas
How ready are you? Find out in two minutes
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
