Cybersecurity advisory built for Saudi regulation

Governance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.

GRC Advisory

Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.

Learn More

vCISO Services

Strategic cybersecurity leadership on demand — your dedicated Virtual CISO aligned to your business objectives.

Learn More

Compliance Assessments

Comprehensive gap assessments and readiness reviews against SAMA CSF, NCA ECC, PDPL, and ISO 27001.

Learn More

Cybersecurity talent — recruitment and outsourcing

We find, assess and place cybersecurity people for you — permanent hires, or specialists on our payroll working on your team.

Learn More

Regulatory Updates

Stay ahead of SAMA, NCA, and PDPL regulatory changes with timely intelligence, impact analysis, and practical implementation guidance.

Learn More

Threat Intelligence

Actionable cyber threat intelligence focused on the threats targeting Saudi organizations — not generic global feeds, but intelligence that informs real decisions.

Learn More

Penetration Testing

Advanced adversarial testing to identify vulnerabilities before threat actors do, aligned to SAMA requirements.

Learn More

Security Awareness

Customized training programs to build a security-first culture across your organization.

Learn More

Policy Development

End-to-end cybersecurity policy and procedure development aligned to Saudi regulatory frameworks.

Learn More

Virtual CISO & Security Leadership

An experienced CISO who leads your security function, reports to your board and represents you to regulators.

Learn More

Governance, Risk & Compliance

Governance structures, risk management and compliance programs aligned to Saudi and international frameworks.

Learn More

SAMA Cyber Security Framework

Maturity assessment, gap remediation and evidence preparation against the SAMA Cyber Security Framework.

Learn More

NCA Essential Cybersecurity Controls

Compliance assessment, remediation and self-assessment support for the NCA Essential Cybersecurity Controls.

Learn More

Personal Data Protection (PDPL)

PDPL compliance programs: data mapping, records of processing, data-subject rights and breach response.

Learn More

Security Operations Advisory

Design, assessment and improvement of security operations, monitoring and incident response capabilities.

Learn More

Cloud & Application Security

Cloud security governance and assessment against NCA Cloud Cybersecurity Controls, and secure application practices.

Learn More

Cybersecurity Awareness & Training

Awareness programs, executive briefings and role-based training that meet regulatory requirements and change behavior.

Learn More

Cybersecurity Strategy & Roadmap

We translate your business priorities, regulatory obligations and threat landscape into a costed, prioritized cybersecurity strategy and multi-year roadmap.

Learn More

Cybersecurity Governance & Organization

We design or strengthen your cybersecurity governance: the function, its mandate, committees, roles and responsibilities, and how decisions reach the board.

Learn More

Policies, Standards & Procedures

We develop or update your cybersecurity policies, standards and procedures, mapped to the frameworks you must meet and written in Arabic and English.

Learn More

Cyber Risk Management

We establish or mature your cyber risk management: methodology, appetite, assessment, treatment and reporting — integrated with your enterprise risk framework.

Learn More

Regulatory Compliance Remediation Program

We run your remediation program after an assessment or regulatory review: prioritizing gaps, coordinating owners, implementing controls and building the evidence that closes each finding.

Learn More

Personal Data Protection (PDPL) Program

We build your PDPL compliance program: data inventory and records of processing, lawful bases, notices, data-subject rights, breach notification, transfers and DPO support.

Learn More

Business Continuity & Cyber Resilience

We build and test your business continuity and cyber resilience capability in line with SAMA BCM and SAMA cyber resilience requirements: impact analysis, recovery strategies, plans and exercises.

Learn More

Third-Party & Supply-Chain Cyber Risk

We set up and run your third-party cyber risk program: vendor tiering, due-diligence questionnaires, contract clauses, assessments and ongoing monitoring.

Learn More

Identity & Access Governance

We strengthen how access is granted, reviewed and removed — joiner-mover-leaver processes, privileged access, segregation of duties and periodic access reviews.

Learn More

Vulnerability Management Program

We run or mature your vulnerability management: scanning coverage, risk-based prioritization, remediation tracking against agreed timelines, and reporting.

Learn More

Security Architecture Review

We review the security of new and existing systems and network designs — segmentation, identity, data flows, integration and resilience — and recommend practical improvements.

Learn More

Red Teaming & Adversary Simulation

We simulate a determined attacker pursuing agreed objectives — from initial access to impact — to test your people, processes and technology end to end.

Learn More

Incident Response Readiness & Tabletop Exercises

We prepare your organization to respond: incident response plan and playbooks, roles and escalation, regulatory notification, and tabletop exercises for technical teams and executives.

Learn More

Digital Forensics & Incident Investigation

When an incident happens, our specialists help contain it, preserve evidence, investigate root cause and scope, and support regulatory reporting and recovery.

Learn More

Security Operations (SOC) Maturity Assessment

We assess your security operations — in-house or outsourced — across people, process, technology, detection coverage and response, and give you a prioritized improvement plan.

Learn More

SWIFT CSCF Assessment & Attestation

We independently assess your SWIFT environment against the current Customer Security Controls Framework, identify gaps and support remediation and your annual attestation.

Learn More

PCI DSS Readiness & Compliance

We prepare you for PCI DSS v4.0: scoping and segmentation, gap assessment, remediation support and readiness for your QSA assessment or self-assessment questionnaire.

Learn More

ISO/IEC 27001 ISMS Implementation

We implement your ISO/IEC 27001:2022 ISMS: scope, risk assessment, Statement of Applicability, policies, internal audit and management review — ready for certification.

Learn More

Internal Cybersecurity Audit

We perform cybersecurity audits on behalf of, or alongside, your internal audit function — planned, executed and reported to internal audit standards.

Learn More
Network of connected points with flagged nodes around a shield

Fraud Assessment

An enterprise-wide assessment of internal and external fraud risk across products, channels and processes, scored against the SAMA Counter-Fraud Framework.

Learn More
Stacked solution layers with signal bars and status points

Fraud Management Solution

Vendor-independent selection and implementation of a fraud management system: requirements, vendor evaluation, rules and models, integration and go-live.

Learn More
Three connected framework blocks with a shield

SAMA Counter-Fraud Framework Implementation

We design and implement the governance, policies, roles, processes and reporting your institution needs to meet the SAMA Counter-Fraud Framework.

Learn More
Transaction lanes with highlighted alerts under a monitoring ring

Fraud Detection and Transaction Monitoring Optimization

Review and tune the rules, scores and workflows of your fraud monitoring system across cards, mada, SARIE, instant payments and digital channels.

Learn More
Mobile device outline with a shield inside a protective ring

Digital Banking and Payment Fraud Controls Review

An end-to-end review of fraud controls in mobile and internet banking, eKYC onboarding (Nafath), device binding, transaction signing and customer notifications.

Learn More
Investigation lens over a network of connected points

Fraud Investigation and Forensic Accounting

Independent investigation of suspected internal or external fraud, with evidence handling suitable for disciplinary, regulatory and legal action.

Learn More
Concentric rings around a shield with connected points

AML Assessment

An independent assessment of your AML/CTF program against the SAMA rules and the FATF Recommendations: governance, risk assessment, KYC, monitoring, reporting and training.

Learn More
Three connected modules with a network, bars and a shield

AML Compliance Solution

Vendor-independent selection and implementation of AML technology: customer risk scoring, sanctions screening, transaction monitoring and case management.

Learn More
Bar series against a highlighted threshold line

AML Monitoring and Screening Model Validation

Independent validation of transaction monitoring scenarios and name-screening tools: data quality, thresholds, fuzzy-matching performance and coverage of your risk assessment.

Learn More
Identity card outline within a dashed ring

KYC, CDD and eKYC Program Review

Review of customer due diligence, enhanced due diligence, beneficial ownership, PEP handling and digital onboarding through Nafath against SAMA requirements.

Learn More
Radar-style rings with highlighted arcs and a center point

Sanctions Compliance Program

Design or review of your sanctions compliance program covering UN, local, OFAC and EU regimes: screening, trade and payment controls, escalation and reporting.

Learn More
Ascending steps leading to a highlighted step and a shield

Financial Crime Awareness Training

Role-based AML/CTF, sanctions and fraud training for the board, front line, operations and compliance teams, with completion evidence for regulators.

Learn More
Shield above a rising readiness gauge

Cyber Insurance Readiness Assessment

We assess your controls the way underwriters do, close the gaps that drive premiums and exclusions, and prepare the evidence before you go to market.

Learn More
Checklist panel with verified marks

Insurer Questionnaire and Underwriting Support

We complete insurer proposal forms and supplementary questionnaires with you, accurately and consistently, and support underwriting calls.

Learn More
Coverage layers with a highlighted gap

Cyber Insurance Coverage Review

A broker-neutral review of your cyber policy against your actual risks: limits, sub-limits, retentions, waiting periods, exclusions and conditions.

Learn More
Timeline from alert to completed claim

Cyber Claims and Incident Support

When an incident happens we help you meet the policy conditions: timely notification, panel firms, cost records and the evidence the insurer needs to pay.

Learn More
Distribution curve with a marked limit line

Cyber Risk Quantification for Insurance

We estimate the financial impact of your most likely and most severe cyber scenarios, so limits, retentions and budgets rest on numbers the board can trust.

Learn More

Need a custom solution?

Talk to our team to discuss your specific requirements.

Framework explorer

What each framework asks of you — and what we deliver

Pick a framework to see who it applies to, what it covers and what an engagement produces.

SAMA CSF

SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.

SAMA

Applies to

BanksInsurance companiesFinance companiesOther SAMA-regulated institutions

Main areas

Leadership and governanceRisk management and complianceOperations and technologyThird-party cyber security

What we deliver

  • Maturity assessment against every control
  • Gap analysis and remediation roadmap
  • Policies, standards and procedures
  • Evidence pack for SAMA reviews
Typical first engagement: 8–12 weeks
Readiness self-check

How ready are you? Find out in two minutes

Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.

Ready to talk about your compliance?

Tell us where you stand. We will show you the shortest path to what your regulator expects.

Regulatory updates in your inbox

SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.

We confirm by e-mail; unsubscribe any time.

Schedule a Free Assessment