The challenge
The NCA Essential Cybersecurity Controls (ECC) require a documented incident management and reporting plan, and the SAMA Cyber Security Framework (CSF) expects incidents to be classified and reported within defined windows. The Personal Data Protection Law (PDPL) adds a duty to notify the regulator and affected individuals when personal data is breached.
The first hours of an incident decide the damage: disconnect the server or watch it? Reboot and lose the evidence? Who briefs management and the regulator? Without a rehearsed plan these decisions are improvised.
We give you a ready response team with a written plan, procedures for each scenario and defined communication channels, so an incident is a managed event rather than a crisis.
How we work
- 1
Preparation
We review or write the response plan, define roles, contacts and notification templates for NCA, SAMA and SDAIA, and pre-stage evidence-collection tooling.
- 2
Containment and analysis
When an incident occurs we classify it, contain its spread, collect evidence from hosts, logs and SIEM such as Splunk, and establish the timeline, entry point and affected scope.
- 3
Recovery and lessons
We plan restoration with your teams, verify complete eradication, and hand over a final report with root causes, recommendations and a lessons-learned session.
What is included
Incident response plan
An approved plan covering classification, escalation, roles and communication, aligned with ECC, SAMA CSF and ISO 27001.
Scenario playbooks
Written procedures for ransomware, business email compromise, data exfiltration, compromised accounts and insider threats.
Digital forensics
Memory and disk acquisition, chain-of-custody preservation and artefact analysis to establish what happened, when and how.
Malware analysis
Sample analysis to extract indicators of compromise and push them to your detection tooling.
Regulatory notification
Templates and paths for notifying NCA, SAMA and SDAIA according to the nature of the incident and the data affected.
Tabletop exercises
Simulation sessions for management and technical teams on illustrative real-world scenarios, with a report on gaps found in the plan.
SOC coordination
Direct integration with our managed SOC and MDR service, so an incident moves from detection to response without hand-off gaps.
Retainer option
A standing arrangement that keeps the team ready and familiar with your environment before any incident occurs.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- PDPL
- ISO 27001
- ISO 22301
Frequently asked questions
Can we engage you during an active incident without a prior contract?
Yes. We start with an urgent scoping session and then agree the work plan. A retainer shortens contracting and environment familiarisation.
Do you notify regulators on our behalf?
Notification remains your legal responsibility. We prepare the content, evidence and timeline, and support you in the communication where needed.
Does this cover personal data incidents?
Yes. We establish whether personal data was affected and document it in a way that serves PDPL requirements.
What do we receive at the end of an incident?
A final report with timeline, root cause, impact and recommendations, the preserved evidence, and an update to the plan and playbooks based on lessons learned.
How quickly can your team respond to an incident?
Response terms, including how you reach the team, availability and escalation paths, are agreed in the contract, usually as part of a retainer, based on your environment and locations. We do not publish generic response times because they depend on what is agreed with each client. Without a prior agreement, we start with a scoping session and agree the engagement terms then.
What affects the cost of incident response?
For an active incident, the main drivers are the number of systems and locations affected, how deep the forensic work must go, whether malware analysis is needed, and how much recovery support you want from us. For a retainer, cost depends on the size of your environment, the response terms agreed and the readiness work included, such as plan reviews, playbooks and tabletop exercises. In both cases we agree the scope with you before work begins.
How is incident response different from MDR or a managed SOC?
A managed SOC and MDR monitor the environment continuously to detect threats and take initial response actions. Incident response is the deeper work once an incident is confirmed: forensic investigation, containment, eradication, recovery and lessons learned. Our managed SOC and MDR are delivered within the scope of our NCA Tier 2 licence and are not offered to government entities or to organisations that own, operate or host critical national infrastructure.
Related services
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Detect & respond
Managed Detection & Response (MDR)
Endpoint and identity detection and response run by analysts.
Detect & respond
Threat intelligence & brand protection
See what is said and sold about you beyond your perimeter, from fake domains to leaked credentials.
Govern & comply
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

