شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Banking

Operational security at the maturity SAMA expects

Banks are measured against defined maturity levels, reviewed periodically and held responsible for their third parties. We help you monitor and respond, test your defences and evidence maturity with documented proof.

Some of our clients in this sector

More of our clients
  • Saudi Central Bank
  • Capital Market Authority
  • Riyad Bank
  • Banque Saudi Fransi
  • Alinma Bank
  • Saudi EXIM Bank
  • Saudi Payments
  • Arabian Shield Cooperative Insurance

The logos shown are a selection of our clients, not a complete list. They show a working relationship with DataSec across our different services; they do not mean every organisation uses every service.

Regulatory drivers

  • SAMA Cybersecurity Framework (CSF)

    The framework defines maturity levels per control domain and expects periodic self-assessment and independent review. Target maturity requires continuous operational proof, not documents alone.

  • NCA Essential Cybersecurity Controls (ECC)

    Alongside SAMA CSF, NCA controls apply to banks within their scope, and both frameworks need reconciling in a single control register.

  • Personal Data Protection Law (PDPL)

    Customer financial data is highly sensitive personal data. The law requires a legal basis for processing, rights for data subjects and breach notification to the Saudi Data and AI Authority (SDAIA).

  • Third-party and outsourcing risk

    SAMA expects vendors to be assessed before and during the contract, outsourced services to be classified and the security of fintech partners connected to your systems to be monitored.

Recommended services

How we work with this sector

  1. 1

    Licensed monitoring and documented response

    We deliver managed SOC services under the NCA Tier 2 licence, with documented response procedures that map each incident to SAMA reporting requirements. If your organisation is classified as critical national infrastructure, we serve you through assessment, governance and solutions rather than managed SOC services.

  2. 2

    Testing that mirrors a real adversary

    Penetration tests and red-team exercises are planned with your teams under a clear scope and written rules of engagement, and end with a report that links every finding to a framework control and a remediation step.

  3. 3

    Third parties on one platform

    We help you build a third-party risk programme: vendor tiering, assessment questionnaires and tracking of evidence and exceptions on a GRC platform that produces review-ready reports.

Frequently asked questions

Does the managed SOC integrate with our existing tools?

Yes. We work on your existing SIEM, EDR and identity tooling wherever possible and add only what is missing. We have installation and operations experience on Splunk and on other platforms common in the sector.

How do you support the SAMA CSF self-assessment?

We assess the current maturity of each domain, identify missing evidence, set a plan to reach the target level and then help you prepare the file for independent review.

Where is monitoring data processed?

Managed SOC services operate under the requirements of the NCA licensing framework, including location and in-Kingdom data handling requirements. Architecture details and environment separation are provided in the due-diligence pack.

Do you publish the names of your banking clients?

No. We do not publish the names of managed SOC beneficiaries or data about their incidents, in line with the licence conditions and confidentiality agreements. References can be arranged with the client's written approval.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.