شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Solutions & infrastructure

InfrastructureInfrastructure built secure, not secured afterwards

We design and deliver servers, storage, backup and networks with hardened configuration and logging ready for monitoring from handover.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • ISO 22301
  • CIS Controls
  • ISO 27001

Deliverables

  • Estate and capacity assessment report
  • Target design document and diagrams
  • Applied security baselines
  • Backup plan and restore test reports
  • Operations documentation and knowledge transfer

The challenge

The NCA Essential Cybersecurity Controls (ECC) require system hardening, patch management and tested backups, and the Critical Systems Cybersecurity Controls (CSCC) add isolation and high availability. ISO 22301 ties all of it to documented recovery objectives.

Infrastructure built only to run carries security debt: factory-default servers, backups whose restore was never tested, an open management network, and devices that send logs nowhere. That debt is paid at incident time.

We build to CIS benchmarks and NCA requirements from the design stage, with ransomware-isolated backup, managed patching and logs wired to the SOC.

How we work

  1. 1

    Assess and design

    We assess the current estate, capacity and risks, agree availability and recovery objectives with the business, and design the target architecture to hardening and isolation standards.

  2. 2

    Procure and implement

    We support technology selection and procurement, and carry out installation and migration in phases with minimal downtime and documented acceptance testing.

  3. 3

    Harden and hand over

    We apply security baselines, connect logs to SIEM, test restores, and hand over documentation and knowledge transfer or move into managed operation.

What is included

  • Data centres and HCI

    Design and delivery of HCI, virtualisation and small-to-medium data centre environments, with segregated management networks.

  • Servers and storage

    Servers and storage systems hardened to CIS benchmarks, with encryption at rest and capacity planning.

  • Backup and recovery

    3-2-1 backup with an immutable, network-isolated copy, and documented periodic restore tests against recovery objectives.

  • Wired and wireless networks

    Campus, branch and wireless network design and delivery with segmentation and access control from the start.

  • Patch management and VA tools

    Deployment of patch management and vulnerability scanning tools, linked to our vulnerability management service.

  • Security baselines

    Hardened templates for operating systems, databases and hypervisors, with periodic drift checks.

  • Logging and monitoring

    Every component configured to ship logs to SIEM and the monitoring platform, so the SOC sees the estate from day one.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • ISO 22301
  • CIS Controls
  • ISO 27001

Frequently asked questions

Do you work with our existing estate or start from scratch?

We work with what you have. The assessment determines what to keep and harden, what to replace and what to migrate, based on risk, age and cost.

How do you test backups?

By actually restoring selected systems into an isolated environment on an agreed schedule, documenting the time taken against recovery objectives.

Do you operate the infrastructure after handover?

Yes, through managed IT services and the NOC, or we hand over to your team with documentation and training.

Do you deliver outside Riyadh?

Yes, we deliver infrastructure projects across the Kingdom's regions, as defined in the project scope.

How do you protect backups against ransomware?

We follow the 3-2-1 approach with at least one immutable, network-isolated copy, and run backup administration on separate MFA-protected accounts, apart from the domain accounts attackers usually target first. The backup network is segregated from production, and restores are tested on an agreed schedule. For organisations within ECC scope, this supports the ECC-2:2024 Backup and Recovery Management requirement for periodic testing of backup recovery effectiveness.

What do you need from us before design starts?

An inventory of current servers, storage and network devices, existing diagrams, and access to the data centre or server rooms for a site survey. We also need business owners to set availability and recovery objectives for key systems, and to know the maintenance windows and change process we must work within. Existing vendor support contracts and licence details help us decide what can be kept.

What affects the cost of an infrastructure project?

The scale of the estate (sites, servers, storage capacity), the availability and recovery objectives you set, and the hardware and licensing choices. Migration complexity, the downtime windows available, any need for a secondary site, and whether we move into managed operation after handover also drive the effort. We size the project after the assessment and design stage.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.