The challenge
The NCA Essential Cybersecurity Controls (ECC) require a periodic awareness programme for all staff and specialised training for sensitive roles, and the SAMA Cyber Security Framework (CSF) requires awareness effectiveness to be measured. The Personal Data Protection Law (PDPL) expects anyone handling personal data to know their obligations.
One Arabic phishing email impersonating a government body or bank is enough to bypass every technical control if a staff member clicks it. An annual slide deck does not change that behaviour.
Our programme targets behaviour: realistic simulations with local scenarios, immediate teaching at the point of failure, interactive workshops for high-risk departments, and indicators that show management where performance improves and where it does not.
How we work
- 1
Baseline
An unannounced first phishing campaign and a knowledge survey to establish the starting point per department and role.
- 2
Annual programme
A monthly Arabic and English content plan, simulation campaigns of increasing difficulty, and in-person workshops for sensitive departments (finance, HR, senior management).
- 3
Measure and adjust
Quarterly reports on click and reporting rates per department, and adjustment of content and scenarios based on the results.
What is included
Phishing simulations
Email, SMS and voice campaigns with illustrative local scenarios (data updates, invoices, messages from management), and an instant teaching page on click.
Awareness platform
Short learning modules in Arabic and English, with completion tracking, quizzes and reporting, on your platform or one we provide.
Interactive workshops
In-person or virtual sessions built around practical cases, like the awareness events we run on site for clients (illustrative).
Role-based training
Tailored content for senior management, finance, developers, system administrators and personal data handlers.
Phish-report button
A mail add-in for one-click reporting, routing reports to the SOC or your security team.
Internal campaigns
Posters, messages and short clips in your brand for occasions such as national cybersecurity awareness month.
Measurement and reporting
Click, reporting and completion metrics by department, and a report that serves ECC and SAMA CSF requirements on awareness effectiveness.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- PDPL
- ISO 27001
Frequently asked questions
Are the names of those who clicked published?
No. Management reports are aggregated by department. The aim is behaviour change, not punishment, and we agree a repeat-click policy with you in advance.
Is the content in Arabic?
Yes. Content and scenarios are written in Arabic first and available in English for non-Arabic-speaking staff.
How often are simulations run?
Frequency is set in the programme plan according to organisation size and baseline results, usually as several campaigns across the year with increasing difficulty.
Can the programme integrate with our learning platform?
Yes. We provide content in SCORM format or connect our platform to your LMS and staff directory.
Which Saudi regulations require security awareness training?
NCA ECC-2:2024, which applies to government entities and to organisations that own, operate or host critical national infrastructure, has a dedicated Cybersecurity Awareness and Training Program subdomain: a periodic, multi-channel programme covering threats such as phishing, plus specialised training for cybersecurity staff, IT and development staff, and executive and supervisory roles. SAMA CSF requires SAMA-regulated organisations to run an awareness programme for staff, third parties and customers, to train staff, and to evaluate the programme's effectiveness. We map the programme plan and reports to whichever of these applies to you.
What do you need from us before the first phishing simulation?
Written approval from management, a staff list with departments, and a named coordinator on your side. Your IT team adds our simulation domains and sending servers to the email gateway's allow-list so the messages are delivered, and your security team or SOC is told in advance so staff reports are recognised as part of the exercise. We also agree with you beforehand which scenarios are off limits and which organisations must not be impersonated.
What drives the effort and cost of an awareness programme?
Mainly the number of staff and sites, the simulation channels used (email, SMS, voice), and how many in-person workshops and role-based tracks you need. Whether content runs on your learning platform or ours, and how much material is produced specifically in your branding, also change the effort. We agree the scope with you in a scoping session before proposing.
Related services
Govern & comply
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Detect & respond
Threat intelligence & brand protection
See what is said and sold about you beyond your perimeter, from fake domains to leaked credentials.
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Detect & respond
Incident response
Contain, investigate and recover from incidents with documented procedures.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

