شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Assess & test

Cloud security assessmentA tightly configured cloud, with data kept where it must stay

We review your cloud accounts item by item, identities, networks, storage and logging, and hand you a remediation list ordered by severity.

At a glance

Frameworks

  • NCA CCC
  • SAMA CSF
  • PDPL
  • CIS Controls
  • ISO 27001

Deliverables

  • Findings report ordered by severity and effort
  • Compliance matrix against CIS, CCC and SAMA CSF
  • Data residency map
  • Actionable remediation plan

The challenge

The NCA Cloud Cybersecurity Controls (CCC) set requirements for both cloud providers and subscribers, and the Personal Data Protection Law (PDPL) restricts transfers outside the Kingdom. The SAMA Cyber Security Framework (CSF) requires a security review before any cloud service is adopted.

Most cloud incidents come from misconfiguration, not a provider flaw: a public storage bucket, an old access key with broad rights, audit logging turned off, or a network open to the internet. These mistakes accumulate with every new project.

We provide an independent review that shows your real posture against CIS benchmarks and NCA controls, with a remediation plan your cloud teams can execute directly.

How we work

  1. 1

    Scope and read-only access

    We define the accounts, subscriptions and regions in scope, and obtain read-only access through dedicated roles revoked after the assessment.

  2. 2

    Automated and manual review

    Automated checks against CIS Benchmarks, then manual review of identities, permissions, networks, encryption, logging and data storage locations.

  3. 3

    Report and remediation plan

    A findings report ordered by severity and effort, mapped to CCC, SAMA CSF and PDPL controls, with a walkthrough for your cloud and security teams.

What is included

  • Cloud identity and access

    Review of IAM roles, access keys, MFA, root accounts and excessive permissions.

  • Networking and internet exposure

    Security groups, ACLs, virtual networks, open ports and exposed API gateways.

  • Storage and encryption

    Public buckets, encryption at rest and in transit, key management and backup locations.

  • Logging and monitoring

    Audit logging, network flow logs and their integration with your SIEM or the managed SOC.

  • Data residency

    Mapping where data is stored, processed and backed up against PDPL and sector regulator requirements.

  • Containers and Kubernetes

    Review of cluster configuration, in-cluster permissions, container images and stored secrets.

  • Infrastructure as code

    Scanning of Terraform, CloudFormation and Bicep templates to catch misconfiguration before deployment.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA CCC
  • SAMA CSF
  • PDPL
  • CIS Controls
  • ISO 27001

Frequently asked questions

Does the assessment need write access?

No. We work with read-only access through dedicated roles, which are revoked once the work ends.

Do you cover local cloud providers?

Yes. The methodology applies to in-Kingdom regions of global and local providers, and we review the controls each provider makes available.

Do you carry out the remediation?

The assessment delivers the remediation plan. Your teams can execute it, or we can under our solutions and infrastructure services.

How often should we reassess?

Cloud configuration changes constantly, so a periodic review and one after every major project is advisable; continuous configuration monitoring can also run through the SOC.

Which Saudi regulations does a cloud assessment help with?

For government entities and organisations that own, operate or host critical national infrastructure, NCA ECC-2:2024 includes a Cloud Computing and Hosting Cybersecurity subdomain, and the Cloud Cybersecurity Controls (CCC-2:2024) add requirements for cloud tenants as well as providers. SAMA CSF requires SAMA-regulated organisations to carry out a cyber security risk assessment and obtain SAMA approval before using cloud services. Where personal data is involved PDPL also applies, and we map each finding to the frameworks that apply to you.

How is this different from a cloud penetration test?

The assessment reviews your configuration from the inside with read-only access, checking every account against benchmarks and controls to find misconfiguration across the whole estate. A penetration test, available through our Penetration Testing service, takes an attacker's view and tries to exploit what is reachable to show real impact. The two complement each other: the assessment gives breadth, and the test shows what an attacker could do with the gaps.

What affects the effort and cost of a cloud security assessment?

The number of accounts, subscriptions or projects and the regions they span, how many providers are in scope, and the services in use, since Kubernetes clusters, serverless functions and data platforms each add review work. Including infrastructure-as-code templates and mapping findings to several frameworks (for example CCC, SAMA CSF and PDPL) also adds effort. We confirm these in the scoping session and size the work accordingly.

  • Assess & test

    Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Solutions & infrastructure

    Data security

    Data classification, loss prevention and encryption aligned with PDPL.

  • Solutions & infrastructure

    Identity & access

    Unified identity, managed privileged access and MFA with a zero-trust approach.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.