شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Solutions & infrastructure

Data securityData classified and protected wherever it travels

We help you find where your sensitive data is, classify it, stop it leaving without authorisation, and encrypt it across devices, cloud and email.

At a glance

Frameworks

  • PDPL
  • NCA DCC
  • NCA ECC
  • SAMA CSF
  • ISO 27001

Deliverables

  • Approved data classification policy
  • Sensitive data map and locations
  • Documented DLP and encryption policies
  • Solution design and implementation plan
  • Periodic data protection officer report

The challenge

The Personal Data Protection Law (PDPL) and its SDAIA regulations require personal data to be protected, restrict transfers outside the Kingdom and mandate breach notification. The NCA Data Cybersecurity Controls (DCC) and National Data Management Office (NDMO) policies require data to be classified and protected according to its level.

You cannot protect what you cannot locate. Personal data, contracts and designs are spread across file shares, email, collaboration platforms and personal devices, and usually leave by the simplest route: an attachment, a USB stick or an upload to a public cloud service.

We build an integrated data security programme: discovery and classification, then loss prevention, encryption and rights management policies, with reporting that shows management and the data protection officer the real picture.

How we work

  1. 1

    Discover and classify

    We set a classification policy aligned with NDMO and PDPL, and run discovery across file shares, email, cloud and databases to map sensitive data.

  2. 2

    Protect in phases

    We enable labelling, then DLP policies in monitor mode, then gradual blocking, with encryption and rights management for the most sensitive categories.

  3. 3

    Operate and report

    We tune policies to reduce false positives, connect incidents to the SOC, and issue periodic reports to the data protection officer and management.

What is included

  • Data discovery and classification (DC)

    Scanning of data at rest and in motion, with automatic and manual labelling by national classification levels and PDPL requirements.

  • Data loss prevention (DLP)

    Endpoint, email, web and cloud policies to detect and block classified data leaving, with an exception workflow.

  • Encryption and key management

    Disk, database, file and email encryption with centralised in-Kingdom key management.

  • Digital rights management (DRM)

    Protection that travels with the file: who opens it, prints it or forwards it, with the ability to revoke access.

  • Mobile security (MDM, MTD)

    Mobile device management and mobile threat defence, separating work data from personal data on staff devices.

  • Watermarking and tracking

    Dynamic watermarks on documents and screens to deter capture and trace the source of any leak.

  • Database security

    Database activity monitoring, data masking in test environments and control of administrator access.

  • PDPL alignment

    Linking technical controls to records of processing, impact assessments and cross-border transfer requirements, in coordination with our GRC services.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • PDPL
  • NCA DCC
  • NCA ECC
  • SAMA CSF
  • ISO 27001

Frequently asked questions

Must all data be classified before DLP is enabled?

No. We start with the highest-risk categories, such as personal and financial data, and expand gradually. DLP policies can rely on content patterns as well as labels.

Do the solutions work with Microsoft 365 and Google Workspace?

Yes. We use the capabilities built into those platforms and complement them with specialist tools where needed, depending on your licensing.

How do you handle staff resistance to the controls?

Gradually and with communication: monitor first, then explanatory user prompts, then blocking, integrated with the awareness programme.

Are encryption keys stored outside the Kingdom?

We design key management to stay in-Kingdom or under your control, meeting PDPL and sector regulator requirements.

Which Saudi regulations does data security help with?

PDPL requires adequate technical and organisational measures to protect personal data in storage and in transit. For government entities and organisations that own, operate or host critical national infrastructure, the NCA Data Cybersecurity Controls (DCC-1:2022) extend the ECC with requirements across the data lifecycle that vary by classification level: Public, Restricted, Secret and Top Secret. We map classification, DLP and encryption controls to whichever of these apply to you, alongside SAMA CSF for SAMA-regulated organisations.

What affects the effort of a data security programme?

The number of users and endpoints, how many data repositories and channels (endpoint, email, web, cloud) are in scope, and how many classification levels and policies you need. Your existing licences matter too, because built-in platform capabilities can reduce the need for additional tools. The number of departments onboarded and how far you move from monitoring to blocking also shape the effort.

How is this different from identity and access management?

Identity and access management, a separate DataSec service, controls who can reach a system and with what rights. Data security protects the information itself once someone has access: labels tell users and tools how sensitive it is, DLP stops it leaving through unapproved channels, and encryption and rights management keep it protected wherever the file goes. The two complement each other and are usually planned together.

  • Solutions & infrastructure

    Identity & access

    Unified identity, managed privileged access and MFA with a zero-trust approach.

  • Govern & comply

    GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Assess & test

    Cloud security assessment

    Review of cloud configuration, identity and data against recommended practice.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.