Solution

Cybersecurity & Compliance

Security architecture, monitoring, and advisory aligned to Saudi regulatory frameworks.

Illustrative close view of hands integrating a vendor-neutral network environment
StanceDefence by designSupportPer active SLA

Saudi Arabia now supervises cybersecurity the way it supervises capital adequacy: named authorities, published control sets, documented evidence, recurring audit cycles. This is the operating detail beneath the capability summary above — what the NCA, SAMA and PDPL regimes expect in practice, how managed security operations is assembled and where its data lives, what a penetration-testing scope must contain, and the shape of a workable twelve-month programme.

The regulatory landscape you actually operate in

Most Saudi organisations answer to more than one cybersecurity authority at once, and the control sets overlap without being identical. A bank runs a SAMA programme while its personal-data processing sits under the PDPL. A ministry runs NCA controls while its clinical or academic data attracts a sector regulator too. The task is not choosing a framework but building one control environment that answers all of them from a single evidence base, so the same asset inventory, access reviews and incident records serve every audit that arrives.

NCA — Essential and Critical Systems Cybersecurity Controls

The National Cybersecurity Authority publishes the Essential Cybersecurity Controls (ECC-2:2024) as the national floor — four main domains, 28 subdomains, 108 main controls and 92 subcontrols — and the Critical Systems Cybersecurity Controls (CSCC-1:2019) as an extension for organisations that own or operate national critical systems, adding 32 main controls and 73 subcontrols across the same four domains: governance, defence, resilience, and third-party and cloud security. Operational technology and industrial control systems are covered separately by the Operational Technology Cybersecurity Controls (OTCC-1:2022).

What the regulator expects operationally is narrower than the control text suggests, and harder:

  • An asset inventory that is current rather than annual, covering cloud tenancies, operational technology and the systems nobody put through change control.
  • Vulnerability management with remediation windows defined by severity, plus evidence the windows are met rather than merely published.
  • Network segmentation that can be drawn on a diagram and then proven on the wire.
  • Privileged access management with session recording and periodic re-attestation, and encryption at rest and in transit with documented key custody.
  • An incident response capability that has been exercised and minuted, plus continuity and recovery testing on a stated cycle.
  • Third-party security assessment covering every supplier holding credentialed access to the estate.

The gap pattern is consistent. Visible controls get deployed — perimeter firewalls, endpoint agents, multi-factor authentication — and are then assumed to carry the rest of the control set. Findings concentrate instead in governance evidence, third-party assessment and tested resilience, because those controls produce paperwork rather than dashboards. Our NCA controls implementation guide works through the families in the order an assessor reads them; public-sector programmes carry further procurement and residency expectations, covered under government and public sector.

SAMA — the Cybersecurity Framework for regulated financial institutions

The Saudi Central Bank’s Cybersecurity Framework applies to banks, finance companies, insurers, payment service providers and most licensed fintech. It is organised into four domains — leadership and governance, risk management and compliance, operations and technology, and third-party cybersecurity — subdivided into sub-domains, and scored on a maturity scale rather than pass or fail.

Two features drive most of the work. The first is cadence: maturity is demonstrated by a rhythm of self-assessment and remediation that leaves a trail, not by a document produced in the weeks before an examination. A workable quarterly pattern rotates the effort across identity and access reviews, vulnerability and patch posture, incident readiness and continuity testing, then third-party and governance evidence, with the risk register updated throughout. Our SAMA quarterly self-assessment checklist sets out that cadence in detail.

The second is the third-party domain, which changes how technology suppliers are procured. A regulated institution must evidence due diligence over every vendor and contractor with credentialed access: control posture, sub-contractors, incident history, personnel screening, data handling. For an integrator, that means arriving with a maintained evidence pack rather than a capability slide. We keep that pack current as a standing deliverable, because in a regulated procurement it is examined before the technical proposal is.

PDPL — an operating capability, not a published policy

The Personal Data Protection Law is where the widest gap between stated and actual compliance sits. A privacy notice is a document; the regulator measures a capability. When a Saudi customer submits a data subject access request tomorrow morning, who receives it, which systems get searched, who performs the legal review, and what goes back?

Under the PDPL and its Implementing Regulations, a controller must respond to a data subject access request within 30 days of receipt, extendable once by a further 30 days for requests that need unusual effort or repeat requests from the same person, with the data subject told in advance, with the reasons, before the first period ends. Under the same regulations, a breach that may cause harm to personal data or to the data subjects’ rights must be notified to SDAIA within 72 hours of becoming aware of it, with affected individuals informed without undue delay where the breach may damage their data or rights. Meeting either window is an operations problem before it is a legal one, because the search has to run across every system that actually holds personal data: the CRM, the ticketing system, payroll, the consent store, surveillance retention and the file shares nobody has mapped.

Operational readiness therefore means a documented request-handling workflow with named owners and a clock, a lawful-basis register, records of processing that survive contact with an auditor, impact assessments for higher-risk processing, transfer assessments where data leaves the Kingdom, processing terms in supplier contracts, and a rehearsed breach-notification path. Our PDPL data subject access request playbook is the operational template we work to.

Sector regulators layered on top

Sector authorities add expectations for licensed operators, clinical data, academic records and invoicing retention, while large development programmes flow security schedules down the supply chain by contract. A control environment designed only for the first framework you were told about tends to fail at the second.

Managed security operations — what the capability actually involves

Managed security operations means collecting security telemetry across an estate, deciding what matters, and acting on it within an agreed timeframe. Organisations reach for it because internal coverage, tooling and retention exceed most mid-market budgets, and because the NCA and SAMA control sets expect monitoring to be continuous. A serious capability is more than a console:

  • Log source coverage — identity providers, endpoints, servers, network devices, cloud control planes, SaaS audit logs and critical applications, with a documented view of what is not covered and why.
  • Detection engineering — rules and analytics tuned to the organisation’s environment, not a default rule pack producing noise nobody reads.
  • Triage discipline — defined severity criteria, enrichment steps, and an escalation path naming who on the customer side can authorise containment at two in the morning.
  • Containment authority — agreed in writing in advance: which actions may be taken unilaterally, such as isolating a host, and which need customer approval.
  • Runbooks and threat intelligence — scenario runbooks tested in tabletop exercises with the business, and intelligence that feeds detection content instead of a newsletter.
  • Reporting mapped to the frameworks — so monitoring evidence lifts straight into NCA or SAMA self-assessment work instead of being rebuilt for each audit.

Coverage hours, escalation timings and reporting frequency vary by risk profile. We set monitoring and response targets governed by each customer’s service agreement, held to the evidence standard the regulator applies.

The data-residency decision that has to come first

The question that defines a managed security operations engagement in Saudi Arabia is where the telemetry lives. Answer it before platform selection: reversing it is a rebuild.

  • In-Kingdom. Where classification, sector regulation or contract requires raw telemetry — event logs, packet captures, forensic artefacts — to remain in Saudi Arabia, the platform, its retention and the analysts who touch the data all sit in-Kingdom. The common profile for government, critical infrastructure and regulated financial institutions.
  • Hybrid. Where raw data must stay in-Kingdom but derived metadata and case records may be processed regionally, a local platform with regional analytic support and in-Kingdom escalation works, provided the boundary is enforced technically and not by contract alone.
  • Regional. Where no residency restriction applies to the data in scope, a shared regional platform with in-Kingdom escalation is appropriate and usually most economical.

Getting this wrong is expensive: the discovery usually comes during a regulator conversation or a customer security review, long after the platform has been bought, and the fix is a migration rather than a setting.

Penetration testing: scope types and audit-ready reporting

Testing expectations have tightened. A report asserting that a test occurred no longer satisfies an assessor. What is wanted is methodology, scope boundary, findings with severity reasoning, remediation record and retest evidence, tied to the production estate rather than a convenient subset.

Scope types

  • External infrastructure — internet-exposed services, remote access, mail and DNS, and the exposed information that supports reconnaissance.
  • Internal and assumed-breach — starting from a foothold inside the network to test lateral movement, privilege escalation, segmentation and the paths to data.
  • Web and API application testing — authentication and session handling, object-level authorisation, injection classes, and the business-logic flaws scanners never find.
  • Cloud configuration and identity — tenancy configuration, entitlement paths, storage exposure, workload isolation, privilege chains between services.
  • Wireless — segmentation between guest, corporate and device networks, rogue access point detection, authentication implementation.
  • Adversary emulation — multi-vector, objective-led engagements, suitable only where detection and response are mature enough to learn from the exercise.

What audit-ready reporting means

  • A stated methodology and an explicit scope boundary, including what was excluded and on whose instruction.
  • Findings with reproducible evidence and severity reasoning, not a scanner score reprinted as a verdict.
  • A remediation log with a named owner and a target date against every finding.
  • Retest evidence closing the loop, the artefact assessors most often ask for and least often receive.
  • An executive narrative for the board, separated from the technical detail engineering needs.

A twelve-month compliance programme

The programme below is EIE’s indicative planning model, not a statutory timetable; each regulator sets its expectations through its own correspondence and instruments.

Compliance failures are usually scheduling failures: two quiet years, then a panicked quarter. The alternative spreads effort across a year an ordinary IT team can sustain, producing evidence continuously rather than in retrospect.

Phase Months Focus Evidence produced
Baseline 1 to 2 Applicability determination, control-by-control gap assessment, asset and data discovery, risk register established Scored current-state map, prioritised gap list, board briefing
Foundations 3 to 5 Governance documents, policy set, roles and ownership, identity and privileged access remediation, logging coverage Approved policy library, access review records, log source inventory
Technical remediation 6 to 9 Segmentation, encryption and key custody, vulnerability and patch cadence, monitoring onboarding, third-party assessment programme Architecture records, remediation log, supplier assessment file
Assurance 10 to 12 Penetration testing and retest, incident and continuity exercises, self-assessment refresh, audit rehearsal Test and retest reports, exercise minutes, updated maturity scoring

Programmes that follow this shape enter an audit with a known remediation list and a date against each item, which is a very different conversation from discovering the same gaps under examination.

Who this is for

  • Government and public sector — NCA control sets with procurement, residency and reporting obligations attached.
  • Banking, finance and insurance — SAMA-regulated institutions needing quarterly cadence, third-party evidence and examination readiness.
  • Healthcare and education — clinical, student and academic records under a sector authority alongside the national controls and the PDPL.
  • Hospitality and retail — cardholder data scope, guest personal data, segmentation across guest, staff and payment networks.
  • Industrial, energy and utilities — critical-sector designation, converged IT and operational technology, continuity that tolerates no planned outage.
  • Development and destination programmes — organisations inheriting security schedules by contract flow-down and evidencing compliance to a programme management team.

How an engagement starts

We start with an assessment, and we scope it before we quote it. A short conversation establishes which regimes apply, what has been done already, where evidence lives and what deadline is driving the work. The assessment is scoped and priced before it starts: control-by-control scoring against the applicable frameworks, a data and asset picture, a gap list ranked by risk and remediation effort, and a costed roadmap with dependencies made explicit.

That roadmap deliverable is complete and self-contained. Customers may remediate with their internal team, engage another supplier, or ask us to deliver it. We treat this as an engineering practice rather than a documentation exercise, building on a technology heritage dating to 1985 through predecessor ETE. Delivery runs from our Jeddah headquarters, with Kingdom-wide service coverage.

Frequently asked questions

Do the NCA controls apply to a private mid-market company, or only to critical infrastructure?

Applicability follows designation and contract, not company size. Many mid-market organisations come into scope indirectly, when a critical-sector customer flows its third-party obligations down the contract. If you supply government, energy, telecommunications, healthcare or a major development programme, an ECC-aligned posture is increasingly a condition of award.

Can a managed security operations capability run from outside the Kingdom?

It depends on the data classes in scope and your designation. Some organisations must keep raw telemetry, retention and analyst access in-Kingdom; others may process derived data regionally; others face no restriction. Make the determination before platform selection: it decides the architecture, not merely the hosting location.

We already publish a privacy policy. Is that PDPL compliance?

No. A privacy notice is one required artefact among many, and the easiest one. What gets measured is whether you can locate an individual’s personal data across every system holding it, respond within the statutory window, evidence a lawful basis for each processing activity, and notify a qualifying breach through a tested path.

How often should penetration testing be repeated?

Frequency follows risk classification and change. Internet-facing estates and systems handling regulated data are commonly tested at least annually, with extra testing triggered by architectural change, a newly exposed application, or a migration. The more useful discipline is retesting: a finding is not closed until it has been retested and the evidence filed.

What we deliver

Identity & access

Access governance and identity controls that enforce least privilege without slowing the business.

Monitoring & response

Continuous monitoring and incident readiness so anomalies are seen and acted on quickly.

Compliance advisory

Controls and documentation aligned to recognised Saudi regulatory frameworks.

Operating model

Accountable from assessment to operations.

EIE takes ownership of your technology lifecycle — one partner, one SLA, from the first site audit through long-term managed services.

Assess

Audit the existing environment, identify gaps, map risks, and define measurable requirements aligned with operational priorities.

Architect

Design vendor-neutral solutions across all technology layers — network, security, communications, and building systems — integrated from day one.

Deploy

Procure, install, configure, and commission — with structured cabling, testing, and acceptance protocols across every discipline.

Operate

Ongoing managed services, proactive monitoring, SLA-driven support, and continuous optimization — your technology runs, we are accountable.

Security operations

From signal to response, on one command surface

1

Detect

Continuous monitoring surfaces the signal early, before it becomes an incident.

Monitored
2

Triage

We assess scope and priority against the posture before anyone acts.

Prioritised
3

Contain

Movement is isolated and the blast radius held — by design, not improvisation.

Isolated
4

Recover

Service is restored and the lesson engineered back into the posture.

Restored
Perimeter & edgeSecure boundaries and controlled entry to the estate.Hardened
Network segmentationMovement contained, blast radius minimised by design.Enforced
Identity & accessThe right people, the right access, verified continuously.Monitored
Data protectionSensitive data guarded at rest and in motion, residency by design.Guarded
Detection & responseThreats seen early and answered by a rehearsed, named team.Watched

Discuss your project

Tell us about your environment and an EIE engineer will design the right solution.