شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Govern & comply

Awareness & trainingStaff who recognise an attack and report it, with measured results

We build an annual awareness programme that combines content, simulation and workshops, and measure the change in staff behaviour rather than course completions.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001

Deliverables

  • Baseline assessment report
  • Annual awareness programme plan
  • Simulation campaigns with teaching pages
  • Workshop and internal campaign materials
  • Quarterly behaviour metrics report

The challenge

The NCA Essential Cybersecurity Controls (ECC) require a periodic awareness programme for all staff and specialised training for sensitive roles, and the SAMA Cyber Security Framework (CSF) requires awareness effectiveness to be measured. The Personal Data Protection Law (PDPL) expects anyone handling personal data to know their obligations.

One Arabic phishing email impersonating a government body or bank is enough to bypass every technical control if a staff member clicks it. An annual slide deck does not change that behaviour.

Our programme targets behaviour: realistic simulations with local scenarios, immediate teaching at the point of failure, interactive workshops for high-risk departments, and indicators that show management where performance improves and where it does not.

How we work

  1. 1

    Baseline

    An unannounced first phishing campaign and a knowledge survey to establish the starting point per department and role.

  2. 2

    Annual programme

    A monthly Arabic and English content plan, simulation campaigns of increasing difficulty, and in-person workshops for sensitive departments (finance, HR, senior management).

  3. 3

    Measure and adjust

    Quarterly reports on click and reporting rates per department, and adjustment of content and scenarios based on the results.

What is included

  • Phishing simulations

    Email, SMS and voice campaigns with illustrative local scenarios (data updates, invoices, messages from management), and an instant teaching page on click.

  • Awareness platform

    Short learning modules in Arabic and English, with completion tracking, quizzes and reporting, on your platform or one we provide.

  • Interactive workshops

    In-person or virtual sessions built around practical cases, like the awareness events we run on site for clients (illustrative).

  • Role-based training

    Tailored content for senior management, finance, developers, system administrators and personal data handlers.

  • Phish-report button

    A mail add-in for one-click reporting, routing reports to the SOC or your security team.

  • Internal campaigns

    Posters, messages and short clips in your brand for occasions such as national cybersecurity awareness month.

  • Measurement and reporting

    Click, reporting and completion metrics by department, and a report that serves ECC and SAMA CSF requirements on awareness effectiveness.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001

Frequently asked questions

Are the names of those who clicked published?

No. Management reports are aggregated by department. The aim is behaviour change, not punishment, and we agree a repeat-click policy with you in advance.

Is the content in Arabic?

Yes. Content and scenarios are written in Arabic first and available in English for non-Arabic-speaking staff.

How often are simulations run?

Frequency is set in the programme plan according to organisation size and baseline results, usually as several campaigns across the year with increasing difficulty.

Can the programme integrate with our learning platform?

Yes. We provide content in SCORM format or connect our platform to your LMS and staff directory.

Which Saudi regulations require security awareness training?

NCA ECC-2:2024, which applies to government entities and to organisations that own, operate or host critical national infrastructure, has a dedicated Cybersecurity Awareness and Training Program subdomain: a periodic, multi-channel programme covering threats such as phishing, plus specialised training for cybersecurity staff, IT and development staff, and executive and supervisory roles. SAMA CSF requires SAMA-regulated organisations to run an awareness programme for staff, third parties and customers, to train staff, and to evaluate the programme's effectiveness. We map the programme plan and reports to whichever of these applies to you.

What do you need from us before the first phishing simulation?

Written approval from management, a staff list with departments, and a named coordinator on your side. Your IT team adds our simulation domains and sending servers to the email gateway's allow-list so the messages are delivered, and your security team or SOC is told in advance so staff reports are recognised as part of the exercise. We also agree with you beforehand which scenarios are off limits and which organisations must not be impersonated.

What drives the effort and cost of an awareness programme?

Mainly the number of staff and sites, the simulation channels used (email, SMS, voice), and how many in-person workshops and role-based tracks you need. Whether content runs on your learning platform or ours, and how much material is produced specifically in your branding, also change the effort. We agree the scope with you in a scoping session before proposing.

  • Govern & comply

    GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Detect & respond

    Threat intelligence & brand protection

    See what is said and sold about you beyond your perimeter, from fake domains to leaked credentials.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Detect & respond

    Incident response

    Contain, investigate and recover from incidents with documented procedures.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.