The challenge
The NCA Cloud Cybersecurity Controls (CCC) set requirements for both cloud providers and subscribers, and the Personal Data Protection Law (PDPL) restricts transfers outside the Kingdom. The SAMA Cyber Security Framework (CSF) requires a security review before any cloud service is adopted.
Most cloud incidents come from misconfiguration, not a provider flaw: a public storage bucket, an old access key with broad rights, audit logging turned off, or a network open to the internet. These mistakes accumulate with every new project.
We provide an independent review that shows your real posture against CIS benchmarks and NCA controls, with a remediation plan your cloud teams can execute directly.
How we work
- 1
Scope and read-only access
We define the accounts, subscriptions and regions in scope, and obtain read-only access through dedicated roles revoked after the assessment.
- 2
Automated and manual review
Automated checks against CIS Benchmarks, then manual review of identities, permissions, networks, encryption, logging and data storage locations.
- 3
Report and remediation plan
A findings report ordered by severity and effort, mapped to CCC, SAMA CSF and PDPL controls, with a walkthrough for your cloud and security teams.
What is included
Cloud identity and access
Review of IAM roles, access keys, MFA, root accounts and excessive permissions.
Networking and internet exposure
Security groups, ACLs, virtual networks, open ports and exposed API gateways.
Storage and encryption
Public buckets, encryption at rest and in transit, key management and backup locations.
Logging and monitoring
Audit logging, network flow logs and their integration with your SIEM or the managed SOC.
Data residency
Mapping where data is stored, processed and backed up against PDPL and sector regulator requirements.
Containers and Kubernetes
Review of cluster configuration, in-cluster permissions, container images and stored secrets.
Infrastructure as code
Scanning of Terraform, CloudFormation and Bicep templates to catch misconfiguration before deployment.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA CCC
- SAMA CSF
- PDPL
- CIS Controls
- ISO 27001
Frequently asked questions
Does the assessment need write access?
No. We work with read-only access through dedicated roles, which are revoked once the work ends.
Do you cover local cloud providers?
Yes. The methodology applies to in-Kingdom regions of global and local providers, and we review the controls each provider makes available.
Do you carry out the remediation?
The assessment delivers the remediation plan. Your teams can execute it, or we can under our solutions and infrastructure services.
How often should we reassess?
Cloud configuration changes constantly, so a periodic review and one after every major project is advisable; continuous configuration monitoring can also run through the SOC.
Which Saudi regulations does a cloud assessment help with?
For government entities and organisations that own, operate or host critical national infrastructure, NCA ECC-2:2024 includes a Cloud Computing and Hosting Cybersecurity subdomain, and the Cloud Cybersecurity Controls (CCC-2:2024) add requirements for cloud tenants as well as providers. SAMA CSF requires SAMA-regulated organisations to carry out a cyber security risk assessment and obtain SAMA approval before using cloud services. Where personal data is involved PDPL also applies, and we map each finding to the frameworks that apply to you.
How is this different from a cloud penetration test?
The assessment reviews your configuration from the inside with read-only access, checking every account against benchmarks and controls to find misconfiguration across the whole estate. A penetration test, available through our Penetration Testing service, takes an attacker's view and tries to exploit what is reachable to show real impact. The two complement each other: the assessment gives breadth, and the test shows what an attacker could do with the gaps.
What affects the effort and cost of a cloud security assessment?
The number of accounts, subscriptions or projects and the regions they span, how many providers are in scope, and the services in use, since Kubernetes clusters, serverless functions and data platforms each add review work. Including infrastructure-as-code templates and mapping findings to several frameworks (for example CCC, SAMA CSF and PDPL) also adds effort. We confirm these in the scoping session and size the work accordingly.
Related services
Assess & test
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Solutions & infrastructure
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Solutions & infrastructure
Identity & access
Unified identity, managed privileged access and MFA with a zero-trust approach.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

