The challenge
The NCA Essential Cybersecurity Controls (ECC) require network isolation, restricted inter-segment access and perimeter protection, and the Critical Systems Cybersecurity Controls (CSCC) require critical systems to sit in dedicated network zones. The SAMA Cyber Security Framework (CSF) expects internal, not just external, traffic to be monitored.
Most networks are flat inside: a strong firewall at the edge, then free movement behind it. That is why an attacker or ransomware moves from one workstation to every server within hours.
We build the network on zero trust: every device is identified before it connects, every zone is isolated, every sensitive workload has its own access policy, and the logs feed the SOC.
How we work
- 1
Assess and design
We map actual traffic flows between systems, define zones and trust levels, and design the segmentation architecture, access policies and logging requirements.
- 2
Phased implementation
We start in monitor-only mode to discover dependencies, then enforce policies zone by zone, with a rollback plan for each phase.
- 3
Operate and review
We hand over documentation, connect devices to the SOC, run or support day-to-day administration, and review rules periodically to remove what is no longer used.
What is included
Next-generation firewalls (NGFW)
Design, deployment and management of firewalls with application and threat inspection and TLS decryption, plus periodic rule reviews.
IDS/IPS and NDR
Intrusion detection and prevention plus network detection and response (NDR) to spot lateral movement and malicious connections inside the network.
Network access control (NAC)
Device and user identification through 802.1X, with automatic classification and placement into the right network, including IoT and xIoT devices.
Micro-segmentation
Workload-level access policies between applications and databases in data centres and cloud, to stop lateral movement.
SD-WAN and secure access
Branch connectivity over software-defined WAN with unified security inspection, and VPN or ZTNA for remote access.
WAF, load balancing and email security
Web application firewalls and load balancers, and email gateways with SPF, DKIM and DMARC plus attachment and link inspection.
Wireless security
Wireless design with enterprise authentication, guest isolation and rogue access point detection.
SOC integration
Forwarding firewall, NAC and NDR logs to SIEM, and building detection use cases for lateral movement.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- NCA CSCC
- SAMA CSF
- CIS Controls
- ISO 27001
Frequently asked questions
Does micro-segmentation require replacing network hardware?
Usually not. Modern solutions work at the workload or hypervisor level, independent of hardware. We confirm this during assessment.
How do you avoid breaking systems when policies are enforced?
We start in monitor-only mode to record every real flow, then enforce gradually with a rollback plan and an observation period per zone.
Which vendors do you work with?
We work with several leading firewall, NAC and segmentation platforms, and choose based on your environment, your team's skills and existing investments.
Do you manage the devices after deployment?
Yes, through managed IT services and the NOC, or we hand over to your team with documentation and training.
What affects the cost and effort of a network security project?
The main drivers are the number of sites, zones and workloads in scope, how many firewalls, switches and access points are involved, and whether existing equipment can be reused. Undocumented traffic flows and legacy applications add discovery time, as does the number of phases you choose. Operation after deployment is scoped and priced separately.
What do you need from us to start?
Current network diagrams, firewall rule exports and an inventory of applications and the servers they run on, with critical systems marked. We also need read access to flow data or logs, contacts in the network and application teams, and your approved change windows.
Which NCA ECC requirements does this work support?
The Networks Security Management subdomain of the NCA Essential Cybersecurity Controls (ECC) sets minimum requirements that include physical or logical segmentation using firewalls and defence in depth, isolating production from development and test networks, intrusion prevention, wireless security, DNS security and protection against DDoS attacks. We document how the design and rule sets address each control that applies to you; whether you comply is decided at assessment.
Related services
Solutions & infrastructure
Identity & access
Unified identity, managed privileged access and MFA with a zero-trust approach.
Solutions & infrastructure
Infrastructure
Data centres, servers, storage and networks built to security standards from day one.
Detect & respond
Network Operations Center (NOC)
Network availability and performance monitoring, handling faults before users notice.
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

