The challenge
The NCA Essential Cybersecurity Controls (ECC) require periodic penetration testing of externally facing systems, and the Critical Systems Cybersecurity Controls (CSCC) extend that to critical systems. The SAMA Cyber Security Framework (CSF) expects testing before go-live and after material change.
Automated scanning finds old versions; it does not find broken business logic or a chain of small flaws that together give full access. That is what a human tester finds.
We deliver testing with a written scope and clear rules of engagement, and a verifiable result: exploitation evidence, severity ratings, remediation steps and a retest to confirm closure.
How we work
- 1
Scoping and rules of engagement
We define targets and approach (black, grey or white box), test windows, contacts and exclusions, and record them in a signed document.
- 2
Execution
Reconnaissance, manual and automated vulnerability discovery, then controlled exploitation to prove impact, following OWASP, PTES and other recognised methodologies, with immediate notice of any critical finding.
- 3
Reporting and retest
An executive and a technical report with exploitation evidence and remediation steps, a walkthrough with your teams, and a retest of remediated findings.
What is included
Web applications and APIs
Testing against OWASP Top 10 and ASVS, including authentication, authorisation, business logic and REST/GraphQL APIs.
Mobile applications
iOS and Android testing against OWASP MASVS: local storage, communications, cryptography and tamper resistance.
External and internal networks
Perimeter, VPN and remote-access testing, then simulation of an attacker inside the network: lateral movement, privilege escalation and Active Directory weaknesses.
Wireless networks
Assessment of encryption, authentication and isolation between guest and internal networks.
Social engineering
Targeted phishing, vishing and physical tests, and an email security assessment (mail gateway and domain spoofing protections), within an agreed scope to measure the human and technical response.
Cloud infrastructure
Testing of configuration, identities and exposed services in AWS, Azure and Google Cloud within provider policies.
Source code review
Tool-assisted manual review of sensitive components: authentication, sessions, input handling and cryptography.
Audit-ready reporting
Reports mapped to ECC, CSCC and SAMA CSF controls, with CVSS scoring and reproducible evidence.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- NCA CSCC
- SAMA CSF
- ISO 27001
- MITRE ATT&CK
Frequently asked questions
How does penetration testing differ from vulnerability scanning?
Scanning is automated and lists potential weaknesses. Penetration testing is human-led and proves what can actually be exploited and with what impact. You need both; recurring scanning is part of our vulnerability management service.
Will testing affect production systems?
Test windows and exclusions are agreed in advance, and denial-of-service techniques are avoided unless explicitly requested. Any critical finding is reported immediately, before the report.
How often should we test?
Regulatory frameworks tie frequency to system criticality and the rate of change. Common practice is at least annually and after every material change or new launch.
Is a retest included?
Yes, one retest of remediated findings within an agreed period, with the report updated to reflect closure status.
What affects the cost and duration of a penetration test?
Mainly the number and type of targets (web applications, APIs, mobile apps, IP ranges, internal network segments) and, for applications, the number of user roles and the size of the functionality. The testing approach (black, grey or white box), any social engineering or source code review, and whether testing must run outside business hours also shape the effort. We set this out in a written proposal once the scope is agreed.
What do we need to provide before testing starts?
Written authorisation from someone entitled to approve testing of the systems in scope and, where systems are hosted or managed by a third party or cloud provider, confirmation that its terms permit the test. We also need the confirmed target list, test accounts for each user role, the agreed test windows, and technical and escalation contacts. All of this is recorded in the signed rules of engagement before any testing begins.
Which Saudi regulations require penetration testing?
The NCA Essential Cybersecurity Controls (ECC) require periodic penetration testing whose scope covers all services provided externally over the internet and their technical components, including infrastructure, websites, web and mobile applications, email and remote access. The SAMA Cyber Security Framework (CSF) expects customer- and internet-facing services of the financial institutions it regulates to be reviewed and penetration tested annually. Which requirements bind you depends on your sector and whether you fall within the ECC's scope.
Related services
Assess & test
Vulnerability management
Recurring scanning, prioritisation and remediation tracking through to closure.
Assess & test
Red team
A realistic adversary simulation that measures your ability to detect and respond.
Assess & test
Cloud security assessment
Review of cloud configuration, identity and data against recommended practice.
Govern & comply
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

