GRC Advisory
Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.
Learn MoreGovernance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.
Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.
Learn MoreComprehensive gap assessments and readiness reviews against SAMA CSF, NCA ECC, PDPL, and ISO 27001.
Learn MoreWe design or strengthen your cybersecurity governance: the function, its mandate, committees, roles and responsibilities, and how decisions reach the board.
Learn MoreWe develop or update your cybersecurity policies, standards and procedures, mapped to the frameworks you must meet and written in Arabic and English.
Learn MoreWe establish or mature your cyber risk management: methodology, appetite, assessment, treatment and reporting — integrated with your enterprise risk framework.
Learn MoreWe run your remediation program after an assessment or regulatory review: prioritizing gaps, coordinating owners, implementing controls and building the evidence that closes each finding.
Learn MoreWe set up and run your third-party cyber risk program: vendor tiering, due-diligence questionnaires, contract clauses, assessments and ongoing monitoring.
Learn MoreWe strengthen how access is granted, reviewed and removed — joiner-mover-leaver processes, privileged access, segregation of duties and periodic access reviews.
Learn MoreWe implement your ISO/IEC 27001:2022 ISMS: scope, risk assessment, Statement of Applicability, policies, internal audit and management review — ready for certification.
Learn MoreTalk to our team to discuss your specific requirements.
Pick a framework to see who it applies to, what it covers and what an engagement produces.
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
The Personal Data Protection Law and its regulations, overseen by SDAIA.
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Tell us where you stand. We will show you the shortest path to what your regulator expects.
SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.
↑↓ to move↵ to openEsc to close