The challenge
The NCA Essential Cybersecurity Controls (ECC) require system hardening, patch management and tested backups, and the Critical Systems Cybersecurity Controls (CSCC) add isolation and high availability. ISO 22301 ties all of it to documented recovery objectives.
Infrastructure built only to run carries security debt: factory-default servers, backups whose restore was never tested, an open management network, and devices that send logs nowhere. That debt is paid at incident time.
We build to CIS benchmarks and NCA requirements from the design stage, with ransomware-isolated backup, managed patching and logs wired to the SOC.
How we work
- 1
Assess and design
We assess the current estate, capacity and risks, agree availability and recovery objectives with the business, and design the target architecture to hardening and isolation standards.
- 2
Procure and implement
We support technology selection and procurement, and carry out installation and migration in phases with minimal downtime and documented acceptance testing.
- 3
Harden and hand over
We apply security baselines, connect logs to SIEM, test restores, and hand over documentation and knowledge transfer or move into managed operation.
What is included
Data centres and HCI
Design and delivery of HCI, virtualisation and small-to-medium data centre environments, with segregated management networks.
Servers and storage
Servers and storage systems hardened to CIS benchmarks, with encryption at rest and capacity planning.
Backup and recovery
3-2-1 backup with an immutable, network-isolated copy, and documented periodic restore tests against recovery objectives.
Wired and wireless networks
Campus, branch and wireless network design and delivery with segmentation and access control from the start.
Patch management and VA tools
Deployment of patch management and vulnerability scanning tools, linked to our vulnerability management service.
Security baselines
Hardened templates for operating systems, databases and hypervisors, with periodic drift checks.
Logging and monitoring
Every component configured to ship logs to SIEM and the monitoring platform, so the SOC sees the estate from day one.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- NCA CSCC
- ISO 22301
- CIS Controls
- ISO 27001
Frequently asked questions
Do you work with our existing estate or start from scratch?
We work with what you have. The assessment determines what to keep and harden, what to replace and what to migrate, based on risk, age and cost.
How do you test backups?
By actually restoring selected systems into an isolated environment on an agreed schedule, documenting the time taken against recovery objectives.
Do you operate the infrastructure after handover?
Yes, through managed IT services and the NOC, or we hand over to your team with documentation and training.
Do you deliver outside Riyadh?
Yes, we deliver infrastructure projects across the Kingdom's regions, as defined in the project scope.
How do you protect backups against ransomware?
We follow the 3-2-1 approach with at least one immutable, network-isolated copy, and run backup administration on separate MFA-protected accounts, apart from the domain accounts attackers usually target first. The backup network is segregated from production, and restores are tested on an agreed schedule. For organisations within ECC scope, this supports the ECC-2:2024 Backup and Recovery Management requirement for periodic testing of backup recovery effectiveness.
What do you need from us before design starts?
An inventory of current servers, storage and network devices, existing diagrams, and access to the data centre or server rooms for a site survey. We also need business owners to set availability and recovery objectives for key systems, and to know the maintenance windows and change process we must work within. Existing vendor support contracts and licence details help us decide what can be kept.
What affects the cost of an infrastructure project?
The scale of the estate (sites, servers, storage capacity), the availability and recovery objectives you set, and the hardware and licensing choices. Migration complexity, the downtime windows available, any need for a secondary site, and whether we move into managed operation after handover also drive the effort. We size the project after the assessment and design stage.
Related services
Solutions & infrastructure
Network security & micro-segmentation
Next-generation firewalls and segmentation that limit the blast radius of any breach.
Operate & outsource
Managed IT services
IT operations and support with clear service levels and regular reporting.
Detect & respond
Network Operations Center (NOC)
Network availability and performance monitoring, handling faults before users notice.
Assess & test
Vulnerability management
Recurring scanning, prioritisation and remediation tracking through to closure.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

