Some of our clients in this sector
More of our clientsThe logos shown are a selection of our clients, not a complete list. They show a working relationship with DataSec across our different services; they do not mean every organisation uses every service.
Regulatory drivers
NCA Essential Cybersecurity Controls (ECC)
The mandatory baseline for all government entities, in four domains in ECC-2:2024: governance, defence, resilience, and third-party and cloud security. Industrial control systems have their own controls (OTCC).
Critical Systems and Data Controls (NCA CSCC and NCA DCC)
The Critical Systems Cybersecurity Controls (CSCC) and Data Cybersecurity Controls (DCC) add stricter requirements for classified systems and data, and they call for operational evidence, not policies alone.
CST Cybersecurity Regulatory Framework (CRF)
For entities operating licensed communications or ICT services, the CST framework adds a regulatory layer that must be reconciled with NCA controls.
Personal Data Protection Law (PDPL) and national data governance
The PDPL and National Data Management Office (NDMO) policies require data classification, processing records and a route for data-subject requests.
Licence scope note: a Tier 2 licence authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure.
Recommended services
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Vulnerability management
Recurring scanning, prioritisation and remediation tracking through to closure.
Awareness & training
Awareness programmes and phishing simulations with measurable results.
Network security & micro-segmentation
Next-generation firewalls and segmentation that limit the blast radius of any breach.
Identity & access
Unified identity, managed privileged access and MFA with a zero-trust approach.
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Infrastructure
Data centres, servers, storage and networks built to security standards from day one.
How we work with this sector
- 1
Our licence scope with government
The Managed Security Operations Center (MSOC) Services Licence — Tier 2 authorises managed SOC services for any organisation other than government entities and organisations that own, operate or host critical national infrastructure. We therefore do not provide managed SOC services to government entities; we serve them through advisory, assessment and technology solutions.
- 2
From assessment to a prioritised remediation plan
We start with a gap assessment against the controls that apply to you, then turn the findings into a remediation plan ordered by impact and effort, with clear ownership and tracking indicators.
- 3
Evidence ready for the assessment cycle
Each control is documented with its evidence: an approved policy, an applied procedure and an operational record. You reach the assessment cycle with a complete file instead of collecting evidence at the last minute.
Frequently asked questions
Can you run a security operations centre for a government entity?
No. The Tier 2 licence scope excludes government entities and critical national infrastructure from managed SOC services. We instead provide assessment, governance and compliance, penetration testing, and network, identity and data solutions, including designing and equipping a SOC that you operate yourselves.
What do we need to start a compliance assessment?
The systems in scope, the controls that apply to you (ECC plus CSCC and DCC where required) and a point of contact with access to policies and configurations. We agree the work plan and schedule before any activity starts.
Is the work carried out inside the Kingdom?
Yes. Our team works from Riyadh, and assessments and advisory work are delivered inside the Kingdom under the access and confidentiality controls your entity requires.
Do you provide staff awareness programmes?
Yes. We design Arabic-language awareness programmes aligned with the awareness requirements in NCA controls, with phishing simulations and reports that show progress over time.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa



















