Regulatory Updates
Stay ahead of SAMA, NCA, and PDPL regulatory changes with timely intelligence, impact analysis, and practical implementation guidance.
Learn MoreGovernance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.
Stay ahead of SAMA, NCA, and PDPL regulatory changes with timely intelligence, impact analysis, and practical implementation guidance.
Learn MoreActionable cyber threat intelligence focused on the threats targeting Saudi organizations — not generic global feeds, but intelligence that informs real decisions.
Learn MoreCustomized training programs to build a security-first culture across your organization.
Learn MoreEnd-to-end cybersecurity policy and procedure development aligned to Saudi regulatory frameworks.
Learn MoreAn experienced CISO who leads your security function, reports to your board and represents you to regulators.
Learn MoreGovernance structures, risk management and compliance programs aligned to Saudi and international frameworks.
Learn MoreMaturity assessment, gap remediation and evidence preparation against the SAMA Cyber Security Framework.
Learn MoreCompliance assessment, remediation and self-assessment support for the NCA Essential Cybersecurity Controls.
Learn MorePDPL compliance programs: data mapping, records of processing, data-subject rights and breach response.
Learn MoreDesign, assessment and improvement of security operations, monitoring and incident response capabilities.
Learn MoreCloud security governance and assessment against NCA Cloud Cybersecurity Controls, and secure application practices.
Learn MoreAwareness programs, executive briefings and role-based training that meet regulatory requirements and change behavior.
Learn MoreTalk to our team to discuss your specific requirements.
Pick a framework to see who it applies to, what it covers and what an engagement produces.
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
The Personal Data Protection Law and its regulations, overseen by SDAIA.
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Tell us where you stand. We will show you the shortest path to what your regulator expects.
SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.
↑↓ to move↵ to openEsc to close