The challenge
The NCA Essential Cybersecurity Controls (ECC) require patching, change management, backup and event logging as ongoing processes, and the SAMA Cyber Security Framework (CSF) requires outsourced IT providers to be held to the same controls.
Small IT teams are consumed by daily support, so patches slip, backups are neglected and little gets documented. Those are exactly the gaps an attacker exploits and an auditor notices.
We provide a managed team working to written procedures, a ticketing system and monthly reports, running IT the way regulators expect, integrated with the SOC and NOC.
How we work
- 1
Assessment and transition
We inventory assets, services and existing contracts, document current procedures, agree service scope, levels and the authority matrix, then transition in phases.
- 2
Daily operation
An Arabic and English help desk, first- to third-line support, and patching, backup and change management within approved windows.
- 3
Review and improve
A monthly report on service levels, incidents, patching and backup, and a periodic review meeting to address recurring problems and plan capacity.
What is included
Help desk and end-user support
A single point of contact by phone, email and portal, with a ticketing system, agreed priorities and support for devices and office applications.
Server and infrastructure management
Operation of physical and virtual servers, storage and HCI environments, with capacity and health monitoring through the NOC.
Patch management
A documented patch cycle for operating systems, applications and devices, with testing, maintenance windows and compliance reporting.
Backup and restore
Daily backup operation and monitoring, with documented periodic restore tests against agreed recovery objectives.
Endpoint management
Device provisioning, hardening and management through Intune or equivalent, with disk encryption and permission control.
Microsoft 365 and email
Account, licence, email and collaboration management, with SPF, DKIM and DMARC and security policy configuration.
Change and configuration management
An approved change log, a configuration database and documentation updated with every change.
Vendor and licence management
Tracking of support contracts, licences and renewal dates, and vendor coordination on faults.
Security integration
Devices and servers ship logs to the SOC, and discovered vulnerabilities become patch tickets within the same cycle.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- ISO 27001
- ISO 22301
- CIS Controls
Frequently asked questions
Do you replace our internal team?
Not necessarily. Many clients keep a small team for business engagement and projects and outsource daily operations to us. The split is set in the responsibility matrix.
How are service levels defined?
They are set in the contract by incident priority and service type, measured from the ticketing system and shown in the monthly report. We do not publish generic figures because every environment differs.
Is on-site support included?
Yes, depending on scope: remote support as the baseline, with scheduled visits or a resident engineer for sites that need it.
What do we receive each month?
A report on service levels, incidents and requests, patch and backup status, and recommendations, with a review meeting.
How do you control your engineers' access to our systems?
Access is limited to named engineers, protected by MFA and granted on least privilege, with administrative work routed through privileged access management and session recording where your tooling supports it. Access is reviewed periodically and removed when an engineer leaves your account or the contract ends. For organisations within ECC scope, ECC-2:2024 requires contracts for IT outsourcing and managed services to include a cybersecurity risk assessment before signing, the provider's adherence to your cybersecurity requirements and policies, and secure removal of your data at the end of service. SAMA CSF also requires SAMA-regulated organisations to obtain SAMA approval before material outsourcing.
How does the transition from our current provider or in-house team work?
We start with an inventory of assets, services, contracts and credentials, followed by knowledge transfer with the outgoing team, ideally including a short parallel run. Administrative credentials move into a password vault and are changed, and responsibilities pass over in agreed phases with documented acceptance at each step. We need a sponsor on your side and cooperation from the outgoing provider, which is best written into their exit terms.
What affects the cost of managed IT services?
The number of users, devices, servers and sites, the support hours you need, and whether on-site presence is required. Scope matters too: help desk only, or full operation covering infrastructure, patching, backup and Microsoft 365 management. Cost also changes depending on whether tools such as the ticketing and device management platforms are provided by us or already licensed by you.
Related services
Detect & respond
Network Operations Center (NOC)
Network availability and performance monitoring, handling faults before users notice.
Solutions & infrastructure
Infrastructure
Data centres, servers, storage and networks built to security standards from day one.
Assess & test
Vulnerability management
Recurring scanning, prioritisation and remediation tracking through to closure.
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

