شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Government

Compliance you can evidence to the NCA

Government entities operate under specific national controls and recurring assessment cycles. We help you measure the gap, close it with a realistic plan and document compliance in the form the regulator expects.

Some of our clients in this sector

More of our clients
  • Board of Grievances
  • Communications, Space & Technology Commission
  • Royal Protocol
  • Emirate of Asir Region
  • Saudi Water Authority
  • General Entertainment Authority
  • MODON
  • King Saud Medical City
  • State Properties General Authority
  • KAPSARC
  • Tourism Development Fund
  • Cultural Development Fund
  • Saudi Irrigation Organization
  • Saudi Federation for Cybersecurity, Programming & Drones
  • Soudah Development
  • Sela
  • Tatweer Educational Technologies
  • Saudi Authority of Internal Auditors

The logos shown are a selection of our clients, not a complete list. They show a working relationship with DataSec across our different services; they do not mean every organisation uses every service.

Regulatory drivers

  • NCA Essential Cybersecurity Controls (ECC)

    The mandatory baseline for all government entities, in four domains in ECC-2:2024: governance, defence, resilience, and third-party and cloud security. Industrial control systems have their own controls (OTCC).

  • Critical Systems and Data Controls (NCA CSCC and NCA DCC)

    The Critical Systems Cybersecurity Controls (CSCC) and Data Cybersecurity Controls (DCC) add stricter requirements for classified systems and data, and they call for operational evidence, not policies alone.

  • CST Cybersecurity Regulatory Framework (CRF)

    For entities operating licensed communications or ICT services, the CST framework adds a regulatory layer that must be reconciled with NCA controls.

  • Personal Data Protection Law (PDPL) and national data governance

    The PDPL and National Data Management Office (NDMO) policies require data classification, processing records and a route for data-subject requests.

Licence scope note: a Tier 2 licence authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure.

Recommended services

  • GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Vulnerability management

    Recurring scanning, prioritisation and remediation tracking through to closure.

  • Awareness & training

    Awareness programmes and phishing simulations with measurable results.

  • Network security & micro-segmentation

    Next-generation firewalls and segmentation that limit the blast radius of any breach.

  • Identity & access

    Unified identity, managed privileged access and MFA with a zero-trust approach.

  • Data security

    Data classification, loss prevention and encryption aligned with PDPL.

  • Infrastructure

    Data centres, servers, storage and networks built to security standards from day one.

How we work with this sector

  1. 1

    Our licence scope with government

    The Managed Security Operations Center (MSOC) Services Licence — Tier 2 authorises managed SOC services for any organisation other than government entities and organisations that own, operate or host critical national infrastructure. We therefore do not provide managed SOC services to government entities; we serve them through advisory, assessment and technology solutions.

  2. 2

    From assessment to a prioritised remediation plan

    We start with a gap assessment against the controls that apply to you, then turn the findings into a remediation plan ordered by impact and effort, with clear ownership and tracking indicators.

  3. 3

    Evidence ready for the assessment cycle

    Each control is documented with its evidence: an approved policy, an applied procedure and an operational record. You reach the assessment cycle with a complete file instead of collecting evidence at the last minute.

Frequently asked questions

Can you run a security operations centre for a government entity?

No. The Tier 2 licence scope excludes government entities and critical national infrastructure from managed SOC services. We instead provide assessment, governance and compliance, penetration testing, and network, identity and data solutions, including designing and equipping a SOC that you operate yourselves.

What do we need to start a compliance assessment?

The systems in scope, the controls that apply to you (ECC plus CSCC and DCC where required) and a point of contact with access to policies and configurations. We agree the work plan and schedule before any activity starts.

Is the work carried out inside the Kingdom?

Yes. Our team works from Riyadh, and assessments and advisory work are delivered inside the Kingdom under the access and confidentiality controls your entity requires.

Do you provide staff awareness programmes?

Yes. We design Arabic-language awareness programmes aligned with the awareness requirements in NCA controls, with phishing simulations and reports that show progress over time.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.