شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Solutions & infrastructure

Identity & accessThe right person, the right access, only for as long as needed

We build a unified identity layer that governs who reaches what, protects privileged accounts, and documents it all for the auditor.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • ISO 27001
  • CIS Controls

Deliverables

  • Identity assessment and attack path report
  • Target identity architecture document
  • Approved access and authentication policies
  • PAM, MFA and SSO deployed and documented
  • Joiner-mover-leaver procedures
  • Periodic access review reports

The challenge

The NCA Essential Cybersecurity Controls (ECC) require multi-factor authentication, privileged account management and periodic access reviews, and the Critical Systems Cybersecurity Controls (CSCC) tighten this for critical systems. The SAMA Cyber Security Framework (CSF) expects full governance of the identity lifecycle from joining to leaving.

Most modern breaches do not break in; they log in: a leaked password, an account of a leaver never disabled, a service account with admin rights, or an administrator using the same account for email and server management.

We design identity as the central control point: single sign-on and strong authentication for everyone, privileged access that is temporary and recorded, and governance that reviews and revokes entitlements automatically.

How we work

  1. 1

    Identity assessment

    We review directories (Active Directory, Entra ID), privileged and service accounts, applications and their sign-in methods and escalation paths, and identify gaps against ECC and SAMA CSF.

  2. 2

    Design and implementation

    We design the target identity architecture and deploy SSO, MFA, PAM and identity governance in phases, starting with privileged accounts and critical applications.

  3. 3

    Ongoing governance

    We enable access review cycles, joiner-mover-leaver workflows and compliance reporting, and connect identity events to the SOC.

What is included

  • Privileged access management (PAM)

    Password vaulting, just-in-time access, session recording and service account management, for administrators and vendors alike.

  • Multi-factor authentication (MFA)

    Phishing-resistant authentication (FIDO2, certificates) for sensitive accounts, authenticator apps for everyone else, and conditional access policies.

  • Single sign-on and federation

    Connecting internal and cloud applications to one identity provider through SAML and OIDC, eliminating scattered passwords.

  • Identity governance (IGA)

    Automated provisioning and deprovisioning from HR, access certification campaigns and segregation of duties.

  • Active Directory hardening

    AD attack path assessment, the tiered administration model, privileged access workstations and monitoring of sensitive changes.

  • Zero-trust network access (ZTNA)

    Application access based on identity and device posture instead of broad VPN tunnels.

  • Identity threat detection

    Forwarding identity events to SIEM and building use cases for anomalous sign-ins and privilege escalation, integrated with MDR.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • ISO 27001
  • CIS Controls

Frequently asked questions

Where do we start if we have none of this?

With privileged accounts: MFA and PAM for administrators and vendors, then SSO and MFA for critical applications, then governance. That order addresses the highest risk first.

Does this cover vendor and contractor access?

Yes. Vendor access goes through PAM with temporary, recorded sessions and is revoked automatically when the contract ends.

Do you work with Entra ID and cloud identity?

Yes, with Entra ID, Active Directory and other identity providers, in hybrid or fully cloud environments.

How do you limit the impact of MFA on users?

Through conditional access: extra factors are requested when device, location or risk changes, not every time, and with methods such as FIDO2 keys that work with a touch.

Which Saudi regulations does this help with?

NCA ECC-2:2024, which applies to government entities and organisations that own, operate or host critical national infrastructure, has an Identity and Access Management subdomain requiring multi-factor authentication for remote access and privileged accounts, least privilege and segregation of duties, privileged access management, and periodic review of identities and access rights. SAMA CSF requires SAMA-regulated organisations to restrict access in line with business requirements, on need-to-know or need-to-have principles. We map the design and the evidence it produces to the frameworks that apply to you.

What affects the effort of an identity and access project?

The number of identities, including staff, contractors and service accounts, and how many directories or forests you run. The number of applications to integrate matters most: modern applications that support SAML or OIDC connect with less effort, while legacy ones need extra work. The number of privileged accounts, HR system integration for joiner-mover-leaver automation, and the number of phases you choose also shape the effort.

What about legacy applications that cannot support SSO or MFA?

We put them behind controls that add the missing protection: privileged access management can broker and record sessions using vaulted credentials, and zero-trust access or an access proxy can require MFA before the application is reached. Where none of that is possible, we document a formal exception with compensating controls and a named owner, so the risk stays on record until the application is replaced or upgraded.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.