Perimeter & endpoint
Layered defences across the network edge and every device, designed to contain and limit impact.
Solution
Security architecture, monitoring, and advisory aligned to Saudi regulatory frameworks.
Saudi Arabia now supervises cybersecurity the way it supervises capital adequacy: named authorities, published control sets, documented evidence, recurring audit cycles. This is the operating detail beneath the capability summary above — what the NCA, SAMA and PDPL regimes expect in practice, how managed security operations is assembled and where its data lives, what a penetration-testing scope must contain, and the shape of a workable twelve-month programme.
Most Saudi organisations answer to more than one cybersecurity authority at once, and the control sets overlap without being identical. A bank runs a SAMA programme while its personal-data processing sits under the PDPL. A ministry runs NCA controls while its clinical or academic data attracts a sector regulator too. The task is not choosing a framework but building one control environment that answers all of them from a single evidence base, so the same asset inventory, access reviews and incident records serve every audit that arrives.
The National Cybersecurity Authority publishes the Essential Cybersecurity Controls (ECC-2:2024) as the national floor — four main domains, 28 subdomains, 108 main controls and 92 subcontrols — and the Critical Systems Cybersecurity Controls (CSCC-1:2019) as an extension for organisations that own or operate national critical systems, adding 32 main controls and 73 subcontrols across the same four domains: governance, defence, resilience, and third-party and cloud security. Operational technology and industrial control systems are covered separately by the Operational Technology Cybersecurity Controls (OTCC-1:2022).
What the regulator expects operationally is narrower than the control text suggests, and harder:
The gap pattern is consistent. Visible controls get deployed — perimeter firewalls, endpoint agents, multi-factor authentication — and are then assumed to carry the rest of the control set. Findings concentrate instead in governance evidence, third-party assessment and tested resilience, because those controls produce paperwork rather than dashboards. Our NCA controls implementation guide works through the families in the order an assessor reads them; public-sector programmes carry further procurement and residency expectations, covered under government and public sector.
The Saudi Central Bank’s Cybersecurity Framework applies to banks, finance companies, insurers, payment service providers and most licensed fintech. It is organised into four domains — leadership and governance, risk management and compliance, operations and technology, and third-party cybersecurity — subdivided into sub-domains, and scored on a maturity scale rather than pass or fail.
Two features drive most of the work. The first is cadence: maturity is demonstrated by a rhythm of self-assessment and remediation that leaves a trail, not by a document produced in the weeks before an examination. A workable quarterly pattern rotates the effort across identity and access reviews, vulnerability and patch posture, incident readiness and continuity testing, then third-party and governance evidence, with the risk register updated throughout. Our SAMA quarterly self-assessment checklist sets out that cadence in detail.
The second is the third-party domain, which changes how technology suppliers are procured. A regulated institution must evidence due diligence over every vendor and contractor with credentialed access: control posture, sub-contractors, incident history, personnel screening, data handling. For an integrator, that means arriving with a maintained evidence pack rather than a capability slide. We keep that pack current as a standing deliverable, because in a regulated procurement it is examined before the technical proposal is.
The Personal Data Protection Law is where the widest gap between stated and actual compliance sits. A privacy notice is a document; the regulator measures a capability. When a Saudi customer submits a data subject access request tomorrow morning, who receives it, which systems get searched, who performs the legal review, and what goes back?
Under the PDPL and its Implementing Regulations, a controller must respond to a data subject access request within 30 days of receipt, extendable once by a further 30 days for requests that need unusual effort or repeat requests from the same person, with the data subject told in advance, with the reasons, before the first period ends. Under the same regulations, a breach that may cause harm to personal data or to the data subjects’ rights must be notified to SDAIA within 72 hours of becoming aware of it, with affected individuals informed without undue delay where the breach may damage their data or rights. Meeting either window is an operations problem before it is a legal one, because the search has to run across every system that actually holds personal data: the CRM, the ticketing system, payroll, the consent store, surveillance retention and the file shares nobody has mapped.
Operational readiness therefore means a documented request-handling workflow with named owners and a clock, a lawful-basis register, records of processing that survive contact with an auditor, impact assessments for higher-risk processing, transfer assessments where data leaves the Kingdom, processing terms in supplier contracts, and a rehearsed breach-notification path. Our PDPL data subject access request playbook is the operational template we work to.
Sector authorities add expectations for licensed operators, clinical data, academic records and invoicing retention, while large development programmes flow security schedules down the supply chain by contract. A control environment designed only for the first framework you were told about tends to fail at the second.
Managed security operations means collecting security telemetry across an estate, deciding what matters, and acting on it within an agreed timeframe. Organisations reach for it because internal coverage, tooling and retention exceed most mid-market budgets, and because the NCA and SAMA control sets expect monitoring to be continuous. A serious capability is more than a console:
Coverage hours, escalation timings and reporting frequency vary by risk profile. We set monitoring and response targets governed by each customer’s service agreement, held to the evidence standard the regulator applies.
The question that defines a managed security operations engagement in Saudi Arabia is where the telemetry lives. Answer it before platform selection: reversing it is a rebuild.
Getting this wrong is expensive: the discovery usually comes during a regulator conversation or a customer security review, long after the platform has been bought, and the fix is a migration rather than a setting.
Testing expectations have tightened. A report asserting that a test occurred no longer satisfies an assessor. What is wanted is methodology, scope boundary, findings with severity reasoning, remediation record and retest evidence, tied to the production estate rather than a convenient subset.
The programme below is EIE’s indicative planning model, not a statutory timetable; each regulator sets its expectations through its own correspondence and instruments.
Compliance failures are usually scheduling failures: two quiet years, then a panicked quarter. The alternative spreads effort across a year an ordinary IT team can sustain, producing evidence continuously rather than in retrospect.
| Phase | Months | Focus | Evidence produced |
|---|---|---|---|
| Baseline | 1 to 2 | Applicability determination, control-by-control gap assessment, asset and data discovery, risk register established | Scored current-state map, prioritised gap list, board briefing |
| Foundations | 3 to 5 | Governance documents, policy set, roles and ownership, identity and privileged access remediation, logging coverage | Approved policy library, access review records, log source inventory |
| Technical remediation | 6 to 9 | Segmentation, encryption and key custody, vulnerability and patch cadence, monitoring onboarding, third-party assessment programme | Architecture records, remediation log, supplier assessment file |
| Assurance | 10 to 12 | Penetration testing and retest, incident and continuity exercises, self-assessment refresh, audit rehearsal | Test and retest reports, exercise minutes, updated maturity scoring |
Programmes that follow this shape enter an audit with a known remediation list and a date against each item, which is a very different conversation from discovering the same gaps under examination.
We start with an assessment, and we scope it before we quote it. A short conversation establishes which regimes apply, what has been done already, where evidence lives and what deadline is driving the work. The assessment is scoped and priced before it starts: control-by-control scoring against the applicable frameworks, a data and asset picture, a gap list ranked by risk and remediation effort, and a costed roadmap with dependencies made explicit.
That roadmap deliverable is complete and self-contained. Customers may remediate with their internal team, engage another supplier, or ask us to deliver it. We treat this as an engineering practice rather than a documentation exercise, building on a technology heritage dating to 1985 through predecessor ETE. Delivery runs from our Jeddah headquarters, with Kingdom-wide service coverage.
Applicability follows designation and contract, not company size. Many mid-market organisations come into scope indirectly, when a critical-sector customer flows its third-party obligations down the contract. If you supply government, energy, telecommunications, healthcare or a major development programme, an ECC-aligned posture is increasingly a condition of award.
It depends on the data classes in scope and your designation. Some organisations must keep raw telemetry, retention and analyst access in-Kingdom; others may process derived data regionally; others face no restriction. Make the determination before platform selection: it decides the architecture, not merely the hosting location.
No. A privacy notice is one required artefact among many, and the easiest one. What gets measured is whether you can locate an individual’s personal data across every system holding it, respond within the statutory window, evidence a lawful basis for each processing activity, and notify a qualifying breach through a tested path.
Frequency follows risk classification and change. Internet-facing estates and systems handling regulated data are commonly tested at least annually, with extra testing triggered by architectural change, a newly exposed application, or a migration. The more useful discipline is retesting: a finding is not closed until it has been retested and the evidence filed.
Layered defences across the network edge and every device, designed to contain and limit impact.
Access governance and identity controls that enforce least privilege without slowing the business.
Continuous monitoring and incident readiness so anomalies are seen and acted on quickly.
Controls and documentation aligned to recognised Saudi regulatory frameworks.
Security operations
Continuous monitoring surfaces the signal early, before it becomes an incident.
MonitoredWe assess scope and priority against the posture before anyone acts.
PrioritisedMovement is isolated and the blast radius held — by design, not improvisation.
IsolatedService is restored and the lesson engineered back into the posture.
RestoredTell us about your environment and an EIE engineer will design the right solution.