Compliance you can prove. Security that holds.
We help Saudi banks and regulated institutions meet SAMA, NCA and SDAIA requirements — and turn compliance into lasting security capability.
Security leadership, governance and assurance for regulated institutions
From board-level strategy to the evidence your regulator asks for — delivered by practitioners who know how Saudi regulators assess.
A disciplined path from exposure to assurance
Local regulation.
Global discipline.
Built around the regulators you answer to
What each framework asks of you — and what we deliver
Pick a framework to see who it applies to, what it covers and what an engagement produces.
SAMA CSF
SAMA’s Cyber Security Framework for the institutions it regulates, assessed on a maturity scale.
Applies to
Main areas
What we deliver
- Maturity assessment against every control
- Gap analysis and remediation roadmap
- Policies, standards and procedures
- Evidence pack for SAMA reviews
NCA ECC-2:2024
The Essential Cybersecurity Controls — the baseline the National Cybersecurity Authority sets for national entities.
Applies to
Main areas
What we deliver
- Compliance assessment with evidence
- Remediation plan with owners and dates
- Policies and procedures set
- Support through the NCA self-assessment
PDPL
The Personal Data Protection Law and its regulations, overseen by SDAIA.
Applies to
Main areas
What we deliver
- Personal data inventory and mapping
- Privacy notice and records of processing
- Breach response procedure
- Staff awareness
SAMA BCM
SAMA’s Business Continuity Management framework for keeping critical services running through disruption.
Applies to
Main areas
What we deliver
- Business impact analysis
- Continuity and disaster-recovery plans
- Exercise design and reports
- Gap assessment against the framework
SAMA CRFR
SAMA's fundamental requirements for cyber resilience: the baseline capabilities regulated institutions are expected to have in place to withstand, respond to and recover from cyber incidents.
Applies to
Main areas
What we deliver
- Gap assessment against the requirements
- Prioritized remediation roadmap
- Resilience policies, plans and playbooks
- Exercise program and evidence pack for SAMA
NCA CCC
The Cloud Cybersecurity Controls — NCA’s requirements for cloud service providers and the organizations that use them.
Applies to
Main areas
What we deliver
- Cloud control assessment
- Shared-responsibility mapping
- Configuration review
- Remediation roadmap
SWIFT CSCF
The Customer Security Controls Framework behind SWIFT’s yearly attestation.
Applies to
Main areas
What we deliver
- Independent assessment of the controls
- Architecture-type review
- Evidence for the attestation
- Remediation support
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS): how an organization sets, runs, measures and improves its information security, with certification by an accredited body.
Applies to
Main areas
PCI DSS v4.0
The security standard for any organization that stores, processes or transmits payment card data, maintained by the PCI Security Standards Council.
Applies to
Main areas
NIST CSF 2.0
A widely used framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
Applies to
Main areas
How ready are you? Find out in two minutes
Answer a few questions for your framework. You get a score, your biggest gaps and — if you want it — a detailed assessment from our team.
Know where you stand before your regulator does.
Book a confidential consultation. We will map your obligations, identify your priorities and propose a clear path to compliance.
Regulatory updates in your inbox
SAMA, NCA and SDAIA changes and what they mean for your institution — once a month.
We confirm by e-mail; unsubscribe any time.
