شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Govern & comply

GRC advisoryCybersecurity governance that stands up to the auditor and serves the business

We build your complete governance framework: strategy, policies, risk register and clear roles, mapped to the Kingdom's regulatory requirements.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • PDPL
  • CST CRF
  • ISO 27001

Deliverables

  • Cybersecurity strategy and roadmap
  • Approved policy and procedure set
  • Risk methodology and risk register
  • Unified regulatory requirements matrix
  • Governance committee charter and RACI
  • Periodic senior management report

The challenge

Organisations in the Kingdom answer to several regulators at once: the National Cybersecurity Authority (NCA) with its Essential (ECC) and Critical Systems (CSCC) controls, the Saudi Central Bank (SAMA) with its Cyber Security Framework (CSF), SDAIA and the National Data Management Office (NDMO) with the Personal Data Protection Law (PDPL), the Communications, Space and Technology Commission (CST) with its Cybersecurity Regulatory Framework (CRF), and the Capital Market Authority (CMA) with its rules for licensed entities.

Many policies are written to be signed and then forgotten. At audit it turns out the policy exists but the procedure does not, or risks are logged but nobody owns them. Real governance means defined roles, documented decisions and regular measurement.

We design one framework that meets all these regulators without duplication, and support you in operating it until it is part of how management works rather than a burden on it.

How we work

  1. 1

    Understand and map requirements

    We identify the regulators that apply to you, build a unified requirements matrix from ECC, CSCC, CCC, SAMA CSF, PDPL, CST CRF and ISO 27001, and assess the current state.

  2. 2

    Design and document

    We write the strategy, policies, procedures and standards in your teams' language, define roles and responsibilities, and build the risk methodology and register.

  3. 3

    Operate and measure

    We support approval of the documents, training of stakeholders, launch of governance committees, and definition of KPIs and periodic reporting to senior management.

What is included

  • Cybersecurity strategy

    A multi-year strategy tied to business objectives and NCA requirements, with a roadmap and indicators.

  • Policies and procedures

    A complete document set mapped to ECC, SAMA CSF and ISO 27001 controls, in Arabic and English where needed.

  • Cyber risk management

    An assessment methodology, a risk register with named owners, treatment plans and a management-approved risk appetite.

  • Personal data protection

    Records of processing, privacy impact assessments, privacy notices and data subject request procedures under PDPL and SDAIA regulations.

  • Sector-specific compliance

    SAMA requirements for banks and insurers, CMA rules for capital market licensees, and CST requirements for telecom and technology providers.

  • ISO management systems

    Building an information security management system (ISO 27001) and business continuity system (ISO 22301) and preparing for external audit.

  • vCISO

    A part-time cybersecurity leader who runs the programme and represents it before management and regulators.

  • Audit support

    Evidence preparation, responses to auditor and regulator queries, and tracking of observations to closure.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • PDPL
  • CST CRF
  • ISO 27001

Frequently asked questions

Do you serve government entities?

Yes. GRC, assessment and solutions services are available to government entities. Managed SOC services follow the Tier 2 licence scope and are not offered to government entities or critical national infrastructure.

Are the documents templates or custom?

We start from a control-mapped document library, then adapt it to your structure, systems and terminology, and review it with stakeholders before approval.

How do you handle overlap between regulators?

We build a unified matrix linking each control to every regulator's requirement, so a control is implemented once and cited to each.

Does this include obtaining ISO certification?

We build the system and prepare you for audit. The certificate is issued by an independent certification body based on its own audit; no consultant can guarantee it.

Can a vCISO fill our head of cybersecurity role?

Not if you are within ECC scope. Control 1-2-2 of ECC-2:2024 requires all cybersecurity positions to be filled by full-time, qualified Saudi professionals, so a part-time adviser cannot hold the position itself. A vCISO can support and mentor your appointed head of cybersecurity, run the programme alongside them and help build the internal team. Organisations outside ECC scope have more flexibility, subject to their own regulator's requirements.

What do you need from us to get started?

A senior management sponsor who approves documents and backs the programme, a coordinator on your side, and access to existing policies, the organisation chart and previous audit or assessment reports. We also need the list of licences you hold and the regulators you answer to, and time with the owners of key processes such as IT, HR, legal and procurement.

What affects the effort of a GRC engagement?

The number of regulators and frameworks that apply, the size and structure of the organisation (subsidiaries, business units, locations), and how much usable documentation already exists. Approval cycles, the number of stakeholders to interview and train, and whether you want ongoing support such as a vCISO after the documents are approved also shape the effort. We scope these with you before proposing.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Govern & comply

    Third-party risk & GRC platform

    Vendor assessment and compliance management on a single platform.

  • Govern & comply

    Awareness & training

    Awareness programmes and phishing simulations with measurable results.

  • Solutions & infrastructure

    Data security

    Data classification, loss prevention and encryption aligned with PDPL.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.