Some of our clients in this sector
More of our clientsThe logos shown are a selection of our clients, not a complete list. They show a working relationship with DataSec across our different services; they do not mean every organisation uses every service.
Regulatory drivers
SAMA Cybersecurity Framework (CSF)
Applies to financing and fintech companies under SAMA supervision and requires documented maturity across governance, defence, resilience and third parties.
Insurance Authority requirements
Insurers are subject to the Insurance Authority's cybersecurity and technology governance requirements, with expectations for business continuity and policyholder data protection.
Personal Data Protection Law (PDPL)
Health and financial data of policyholders and customers is sensitive data that needs explicit consent, minimisation, cross-border transfer controls and a route for data-subject requests.
Capital Market Authority (CMA) where applicable
Institutions licensed by the CMA are subject to its technology and security requirements alongside NCA controls.
Recommended services
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Managed Detection & Response (MDR)
Endpoint and identity detection and response run by analysts.
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Third-party risk & GRC platform
Vendor assessment and compliance management on a single platform.
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Awareness & training
Awareness programmes and phishing simulations with measurable results.
How we work with this sector
- 1
Managed monitoring sized to you
We deliver managed SOC and managed detection and response under the Tier 2 licence, scoped to start with your most sensitive assets and expand as you grow. Managed SOC services are not provided to government entities or critical national infrastructure.
- 2
One framework for several supervisors
We build a single control register that maps SAMA, Insurance Authority, CMA and NCA requirements, so every supervisor is answered from one source of evidence.
- 3
Data protection built into the product
We review data flows in your digital products and customer portals and apply encryption, access controls and data minimisation that satisfy the PDPL without degrading the experience.
Frequently asked questions
We are an early-stage fintech. Are the services suited to our size?
Yes. We start with a short assessment that identifies the minimum required for licensing and supervision, then propose a managed scope covering only critical assets that expands later.
Do you help with the cybersecurity requirements in licence applications?
Yes. We prepare the policies, procedures and evidence required at the licensing stage and support you in responding to the supervisor's queries.
How do you handle policyholders' health data?
Most of our services do not require access to policyholder data. Where it is necessary, access is contractually limited to the narrowest scope, logged and governed by a data-processing agreement.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa























