About CISO Consulting

Cybersecurity governance for the institutions the Kingdom relies on

We are a Saudi cybersecurity governance, risk and compliance consultancy. We help banks, insurers, payment providers and other regulated institutions meet SAMA, NCA and SDAIA requirements — and turn compliance into security capability that lasts.

Legal name
CISO Consulting for CYberSecurity
Legal form
Limited liability company
Commercial Registration
7053022526
VAT registration
333333333333333
Headquarters
Saudi Arabia

Who we are

CISO Consulting is the trading name of CISO Consulting Company for Cybersecurity, a limited liability company established in Riyadh. We exist for one purpose: to help regulated institutions in the Kingdom build cybersecurity programs that stand up to their regulator, their board and real-world threats.

Our consultants are practitioners. They have led security functions, run assessments and answered regulators from inside the institutions we now serve, so our advice is grounded in how controls are actually operated and evidenced — not only in how they are written.

We work in Arabic and English, we deliver every document in the language the reader needs, and we keep every engagement under a non-disclosure agreement from the first conversation.

Mission

To make cybersecurity compliance in the Kingdom measurable, evidenced and owned by the institutions themselves.

Vision

To be the partner Saudi regulated institutions trust most for cybersecurity governance — and to contribute to the Kingdom’s Vision 2030 goal of a secure and trusted digital economy.

What we stand for

Integrity

We tell clients what their regulator would tell them, before the regulator does.

Confidentiality

Nothing is shared before an NDA; client information is used only for the engagement it was given for.

Evidence over assertion

A control is in place when it can be shown to work, not when a policy says so.

Ownership

We build capability inside the client, so results last after we leave.

Respect for the Kingdom’s context

Saudi regulation, language and ways of working come first, not as a translation.

What we do

Governance, risk and compliance

Maturity assessments against SAMA, NCA and SDAIA requirements, gap analysis, remediation roadmaps, policies and procedures, and evidence packs for regulator reviews.

Security leadership

Virtual CISO services, board and committee reporting, and security strategy aligned to the institution’s risk appetite.

Security assurance

Control testing, third-party risk reviews and readiness assessments before regulatory and external audits.

Privacy and data protection

Personal Data Protection Law programs: records of processing, data-subject rights, consent, breach notification and transfers.

Technology

CISO ERA, our platform for governance, risk, compliance and security operations, built for Saudi regulation.

All services · Build your indicative scope

How we work

  1. 1DiscoverScope, regulatory obligations and current posture.
  2. 2AssessEvidence-based gap and maturity assessment.
  3. 3PlanA prioritized, costed remediation roadmap.
  4. 4ImplementControls, policies and processes delivered.
  5. 5SustainMonitoring, reporting and re-assessment.

The frameworks we work with

How we conduct ourselves

Independence and objectivity

We declare any conflict of interest before an engagement starts and do not assess work we designed for the same client without disclosing it.

Confidentiality

Every engagement runs under a signed non-disclosure agreement. Documents are exchanged through our secure client portal, and access is limited to the people working on the engagement.

Personal data protection

We process personal data in line with the Personal Data Protection Law and its implementing regulations, only for the purposes we state, and we keep it only as long as needed.

Security of our own operations

We apply to ourselves the controls we recommend: role-based access, multi-factor authentication, encryption, logging and tested backups.

Anti-bribery and fair dealing

We do not offer or accept anything of value to influence a decision, and we compete on the quality of our work.

Quality assurance

Every deliverable is reviewed by a second senior consultant before it reaches the client.

Let’s talk about your regulatory picture

A confidential first conversation, under an NDA, with a senior consultant.

Book a consultation
Trust

Built around the regulators you answer to

SAMA
Saudi Central BankCSF · BCM
NCA
National Cybersecurity AuthorityECC · CCC · CRFR
SDAIA
Data & AI AuthorityPDPL
SWIFT
Customer Security ProgrammeCSCF
7regulatory frameworks

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment