شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Insurance and finance

Protection that keeps pace with your growth and your supervisor

Insurers, fintechs and financing companies hold sensitive data and grow fast under close supervision. We give you continuous monitoring, periodic assessment and governance that keeps compliance ahead of growth.

Some of our clients in this sector

More of our clients
  • American Express Saudi Arabia
  • Al Rajhi Takaful
  • Geidea
  • Mutakamela Insurance
  • Jadwa Investment
  • Saudi Re
  • Arabia Insurance Cooperative
  • Gulf Union Alahlia Cooperative Insurance
  • Lean Technologies
  • HALA
  • Awqaf Investments
  • Quara Finance
  • Nama United Financing
  • Al Yusr Leasing and Financing
  • Themar
  • Sanad Finance
  • Insurance House Company
  • Elite Insurance & Reinsurance Brokers
  • Concord Insurance Brokerage
  • Circlys
  • SalesFine
  • Awaed

The logos shown are a selection of our clients, not a complete list. They show a working relationship with DataSec across our different services; they do not mean every organisation uses every service.

Regulatory drivers

  • SAMA Cybersecurity Framework (CSF)

    Applies to financing and fintech companies under SAMA supervision and requires documented maturity across governance, defence, resilience and third parties.

  • Insurance Authority requirements

    Insurers are subject to the Insurance Authority's cybersecurity and technology governance requirements, with expectations for business continuity and policyholder data protection.

  • Personal Data Protection Law (PDPL)

    Health and financial data of policyholders and customers is sensitive data that needs explicit consent, minimisation, cross-border transfer controls and a route for data-subject requests.

  • Capital Market Authority (CMA) where applicable

    Institutions licensed by the CMA are subject to its technology and security requirements alongside NCA controls.

Recommended services

How we work with this sector

  1. 1

    Managed monitoring sized to you

    We deliver managed SOC and managed detection and response under the Tier 2 licence, scoped to start with your most sensitive assets and expand as you grow. Managed SOC services are not provided to government entities or critical national infrastructure.

  2. 2

    One framework for several supervisors

    We build a single control register that maps SAMA, Insurance Authority, CMA and NCA requirements, so every supervisor is answered from one source of evidence.

  3. 3

    Data protection built into the product

    We review data flows in your digital products and customer portals and apply encryption, access controls and data minimisation that satisfy the PDPL without degrading the experience.

Frequently asked questions

We are an early-stage fintech. Are the services suited to our size?

Yes. We start with a short assessment that identifies the minimum required for licensing and supervision, then propose a managed scope covering only critical assets that expands later.

Do you help with the cybersecurity requirements in licence applications?

Yes. We prepare the policies, procedures and evidence required at the licensing stage and support you in responding to the supervisor's queries.

How do you handle policyholders' health data?

Most of our services do not require access to policyholder data. Where it is necessary, access is contractually limited to the narrowest scope, logged and governed by a data-processing agreement.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.