Cybersecurity advisory built for Saudi regulation

Governance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.

GRC Advisory

Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.

Learn More

vCISO Services

Strategic cybersecurity leadership on demand — your dedicated Virtual CISO aligned to your business objectives.

Learn More

Compliance Assessments

Comprehensive gap assessments and readiness reviews against SAMA CSF, NCA ECC, PDPL, and ISO 27001.

Learn More

Cybersecurity talent — recruitment and outsourcing

We find, assess and place cybersecurity people for you — permanent hires, or specialists on our payroll working on your team.

Learn More

Penetration Testing

Advanced adversarial testing to identify vulnerabilities before threat actors do, aligned to SAMA requirements.

Learn More

Cybersecurity Strategy & Roadmap

We translate your business priorities, regulatory obligations and threat landscape into a costed, prioritized cybersecurity strategy and multi-year roadmap.

Learn More

Cybersecurity Governance & Organization

We design or strengthen your cybersecurity governance: the function, its mandate, committees, roles and responsibilities, and how decisions reach the board.

Learn More

Policies, Standards & Procedures

We develop or update your cybersecurity policies, standards and procedures, mapped to the frameworks you must meet and written in Arabic and English.

Learn More

Cyber Risk Management

We establish or mature your cyber risk management: methodology, appetite, assessment, treatment and reporting — integrated with your enterprise risk framework.

Learn More

Regulatory Compliance Remediation Program

We run your remediation program after an assessment or regulatory review: prioritizing gaps, coordinating owners, implementing controls and building the evidence that closes each finding.

Learn More

Third-Party & Supply-Chain Cyber Risk

We set up and run your third-party cyber risk program: vendor tiering, due-diligence questionnaires, contract clauses, assessments and ongoing monitoring.

Learn More

Identity & Access Governance

We strengthen how access is granted, reviewed and removed — joiner-mover-leaver processes, privileged access, segregation of duties and periodic access reviews.

Learn More

Vulnerability Management Program

We run or mature your vulnerability management: scanning coverage, risk-based prioritization, remediation tracking against agreed timelines, and reporting.

Learn More

Security Architecture Review

We review the security of new and existing systems and network designs — segmentation, identity, data flows, integration and resilience — and recommend practical improvements.

Learn More

Incident Response Readiness & Tabletop Exercises

We prepare your organization to respond: incident response plan and playbooks, roles and escalation, regulatory notification, and tabletop exercises for technical teams and executives.

Learn More

Digital Forensics & Incident Investigation

When an incident happens, our specialists help contain it, preserve evidence, investigate root cause and scope, and support regulatory reporting and recovery.

Learn More

Security Operations (SOC) Maturity Assessment

We assess your security operations — in-house or outsourced — across people, process, technology, detection coverage and response, and give you a prioritized improvement plan.

Learn More

Internal Cybersecurity Audit

We perform cybersecurity audits on behalf of, or alongside, your internal audit function — planned, executed and reported to internal audit standards.

Learn More
Shield above a rising readiness gauge

Cyber Insurance Readiness Assessment

We assess your controls the way underwriters do, close the gaps that drive premiums and exclusions, and prepare the evidence before you go to market.

Learn More
Checklist panel with verified marks

Insurer Questionnaire and Underwriting Support

We complete insurer proposal forms and supplementary questionnaires with you, accurately and consistently, and support underwriting calls.

Learn More
Timeline from alert to completed claim

Cyber Claims and Incident Support

When an incident happens we help you meet the policy conditions: timely notification, panel firms, cost records and the evidence the insurer needs to pay.

Learn More

Need a custom solution?

Talk to our team to discuss your specific requirements.

Framework explorer

What each framework asks of you — and what we deliver

Pick a framework to see who it applies to, what it covers and what an engagement produces.

SAMA CSF

SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.

SAMA

Applies to

BanksInsurance companiesFinance companiesOther SAMA-regulated institutions

Main areas

Leadership and governanceRisk management and complianceOperations and technologyThird-party cyber security

What we deliver

  • Maturity assessment against every control
  • Gap analysis and remediation roadmap
  • Policies, standards and procedures
  • Evidence pack for SAMA reviews
Typical first engagement: 8–12 weeks
Readiness self-check

How ready are you? Find out in two minutes

Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment