GRC Advisory
Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.
Learn MoreGovernance, risk, compliance and security leadership services aligned to SAMA, NCA and SDAIA requirements — scoped to your institution and delivered with evidence.
Governance, Risk & Compliance frameworks tailored to Saudi regulatory requirements including SAMA CSF and NCA ECC.
Learn MoreStrategic cybersecurity leadership on demand — your dedicated Virtual CISO aligned to your business objectives.
Learn MoreComprehensive gap assessments and readiness reviews against SAMA CSF, NCA ECC, PDPL, and ISO 27001.
Learn More
We find, assess and place cybersecurity people for you — permanent hires, or specialists on our payroll working on your team.
Learn MoreStay ahead of SAMA, NCA, and PDPL regulatory changes with timely intelligence, impact analysis, and practical implementation guidance.
Learn MoreActionable cyber threat intelligence focused on the threats targeting Saudi organizations — not generic global feeds, but intelligence that informs real decisions.
Learn MoreAdvanced adversarial testing to identify vulnerabilities before threat actors do, aligned to SAMA requirements.
Learn MoreCustomized training programs to build a security-first culture across your organization.
Learn MoreEnd-to-end cybersecurity policy and procedure development aligned to Saudi regulatory frameworks.
Learn MoreAn experienced CISO who leads your security function, reports to your board and represents you to regulators.
Learn MoreGovernance structures, risk management and compliance programs aligned to Saudi and international frameworks.
Learn MoreMaturity assessment, gap remediation and evidence preparation against the SAMA Cyber Security Framework.
Learn MoreCompliance assessment, remediation and self-assessment support for the NCA Essential Cybersecurity Controls.
Learn MorePDPL compliance programs: data mapping, records of processing, data-subject rights and breach response.
Learn MoreDesign, assessment and improvement of security operations, monitoring and incident response capabilities.
Learn MoreCloud security governance and assessment against NCA Cloud Cybersecurity Controls, and secure application practices.
Learn MoreAwareness programs, executive briefings and role-based training that meet regulatory requirements and change behavior.
Learn MoreWe translate your business priorities, regulatory obligations and threat landscape into a costed, prioritized cybersecurity strategy and multi-year roadmap.
Learn MoreWe design or strengthen your cybersecurity governance: the function, its mandate, committees, roles and responsibilities, and how decisions reach the board.
Learn MoreWe develop or update your cybersecurity policies, standards and procedures, mapped to the frameworks you must meet and written in Arabic and English.
Learn MoreWe establish or mature your cyber risk management: methodology, appetite, assessment, treatment and reporting — integrated with your enterprise risk framework.
Learn MoreWe run your remediation program after an assessment or regulatory review: prioritizing gaps, coordinating owners, implementing controls and building the evidence that closes each finding.
Learn MoreWe build your PDPL compliance program: data inventory and records of processing, lawful bases, notices, data-subject rights, breach notification, transfers and DPO support.
Learn MoreWe build and test your business continuity and cyber resilience capability in line with SAMA BCM and SAMA cyber resilience requirements: impact analysis, recovery strategies, plans and exercises.
Learn MoreWe set up and run your third-party cyber risk program: vendor tiering, due-diligence questionnaires, contract clauses, assessments and ongoing monitoring.
Learn MoreWe strengthen how access is granted, reviewed and removed — joiner-mover-leaver processes, privileged access, segregation of duties and periodic access reviews.
Learn MoreWe run or mature your vulnerability management: scanning coverage, risk-based prioritization, remediation tracking against agreed timelines, and reporting.
Learn MoreWe review the security of new and existing systems and network designs — segmentation, identity, data flows, integration and resilience — and recommend practical improvements.
Learn MoreWe simulate a determined attacker pursuing agreed objectives — from initial access to impact — to test your people, processes and technology end to end.
Learn MoreWe prepare your organization to respond: incident response plan and playbooks, roles and escalation, regulatory notification, and tabletop exercises for technical teams and executives.
Learn MoreWhen an incident happens, our specialists help contain it, preserve evidence, investigate root cause and scope, and support regulatory reporting and recovery.
Learn MoreWe assess your security operations — in-house or outsourced — across people, process, technology, detection coverage and response, and give you a prioritized improvement plan.
Learn MoreWe independently assess your SWIFT environment against the current Customer Security Controls Framework, identify gaps and support remediation and your annual attestation.
Learn MoreWe prepare you for PCI DSS v4.0: scoping and segmentation, gap assessment, remediation support and readiness for your QSA assessment or self-assessment questionnaire.
Learn MoreWe implement your ISO/IEC 27001:2022 ISMS: scope, risk assessment, Statement of Applicability, policies, internal audit and management review — ready for certification.
Learn MoreWe perform cybersecurity audits on behalf of, or alongside, your internal audit function — planned, executed and reported to internal audit standards.
Learn More
An enterprise-wide assessment of internal and external fraud risk across products, channels and processes, scored against the SAMA Counter-Fraud Framework.
Learn More
Vendor-independent selection and implementation of a fraud management system: requirements, vendor evaluation, rules and models, integration and go-live.
Learn More
We design and implement the governance, policies, roles, processes and reporting your institution needs to meet the SAMA Counter-Fraud Framework.
Learn More
Review and tune the rules, scores and workflows of your fraud monitoring system across cards, mada, SARIE, instant payments and digital channels.
Learn More
An end-to-end review of fraud controls in mobile and internet banking, eKYC onboarding (Nafath), device binding, transaction signing and customer notifications.
Learn More
Independent investigation of suspected internal or external fraud, with evidence handling suitable for disciplinary, regulatory and legal action.
Learn More
An independent assessment of your AML/CTF program against the SAMA rules and the FATF Recommendations: governance, risk assessment, KYC, monitoring, reporting and training.
Learn More
Vendor-independent selection and implementation of AML technology: customer risk scoring, sanctions screening, transaction monitoring and case management.
Learn More
Independent validation of transaction monitoring scenarios and name-screening tools: data quality, thresholds, fuzzy-matching performance and coverage of your risk assessment.
Learn More
Review of customer due diligence, enhanced due diligence, beneficial ownership, PEP handling and digital onboarding through Nafath against SAMA requirements.
Learn More
Design or review of your sanctions compliance program covering UN, local, OFAC and EU regimes: screening, trade and payment controls, escalation and reporting.
Learn More
Role-based AML/CTF, sanctions and fraud training for the board, front line, operations and compliance teams, with completion evidence for regulators.
Learn More
We assess your controls the way underwriters do, close the gaps that drive premiums and exclusions, and prepare the evidence before you go to market.
Learn More
We complete insurer proposal forms and supplementary questionnaires with you, accurately and consistently, and support underwriting calls.
Learn More
A broker-neutral review of your cyber policy against your actual risks: limits, sub-limits, retentions, waiting periods, exclusions and conditions.
Learn More
When an incident happens we help you meet the policy conditions: timely notification, panel firms, cost records and the evidence the insurer needs to pay.
Learn More
We estimate the financial impact of your most likely and most severe cyber scenarios, so limits, retentions and budgets rest on numbers the board can trust.
Learn MoreTalk to our team to discuss your specific requirements.
Pick a framework to see who it applies to, what it covers and what an engagement produces.
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
The Personal Data Protection Law and its regulations, overseen by SDAIA.
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Tell us where you stand. We will show you the shortest path to what your regulator expects.
SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.
↑↓ to move↵ to openEsc to close