شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Assess & test

Penetration testingFind the exploitable gaps before someone else does

We test your applications and networks the way an adversary would, and hand you a report the developer, the auditor and management can each act on.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • ISO 27001
  • MITRE ATT&CK

Deliverables

  • Signed scope and rules-of-engagement document
  • Executive summary report
  • Technical report with exploitation evidence and remediation steps
  • Findings matrix mapped to ECC and SAMA CSF controls
  • Retest report and closure letter

The challenge

The NCA Essential Cybersecurity Controls (ECC) require periodic penetration testing of externally facing systems, and the Critical Systems Cybersecurity Controls (CSCC) extend that to critical systems. The SAMA Cyber Security Framework (CSF) expects testing before go-live and after material change.

Automated scanning finds old versions; it does not find broken business logic or a chain of small flaws that together give full access. That is what a human tester finds.

We deliver testing with a written scope and clear rules of engagement, and a verifiable result: exploitation evidence, severity ratings, remediation steps and a retest to confirm closure.

How we work

  1. 1

    Scoping and rules of engagement

    We define targets and approach (black, grey or white box), test windows, contacts and exclusions, and record them in a signed document.

  2. 2

    Execution

    Reconnaissance, manual and automated vulnerability discovery, then controlled exploitation to prove impact, following OWASP, PTES and other recognised methodologies, with immediate notice of any critical finding.

  3. 3

    Reporting and retest

    An executive and a technical report with exploitation evidence and remediation steps, a walkthrough with your teams, and a retest of remediated findings.

What is included

  • Web applications and APIs

    Testing against OWASP Top 10 and ASVS, including authentication, authorisation, business logic and REST/GraphQL APIs.

  • Mobile applications

    iOS and Android testing against OWASP MASVS: local storage, communications, cryptography and tamper resistance.

  • External and internal networks

    Perimeter, VPN and remote-access testing, then simulation of an attacker inside the network: lateral movement, privilege escalation and Active Directory weaknesses.

  • Wireless networks

    Assessment of encryption, authentication and isolation between guest and internal networks.

  • Social engineering

    Targeted phishing, vishing and physical tests, and an email security assessment (mail gateway and domain spoofing protections), within an agreed scope to measure the human and technical response.

  • Cloud infrastructure

    Testing of configuration, identities and exposed services in AWS, Azure and Google Cloud within provider policies.

  • Source code review

    Tool-assisted manual review of sensitive components: authentication, sessions, input handling and cryptography.

  • Audit-ready reporting

    Reports mapped to ECC, CSCC and SAMA CSF controls, with CVSS scoring and reproducible evidence.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • ISO 27001
  • MITRE ATT&CK

Frequently asked questions

How does penetration testing differ from vulnerability scanning?

Scanning is automated and lists potential weaknesses. Penetration testing is human-led and proves what can actually be exploited and with what impact. You need both; recurring scanning is part of our vulnerability management service.

Will testing affect production systems?

Test windows and exclusions are agreed in advance, and denial-of-service techniques are avoided unless explicitly requested. Any critical finding is reported immediately, before the report.

How often should we test?

Regulatory frameworks tie frequency to system criticality and the rate of change. Common practice is at least annually and after every material change or new launch.

Is a retest included?

Yes, one retest of remediated findings within an agreed period, with the report updated to reflect closure status.

What affects the cost and duration of a penetration test?

Mainly the number and type of targets (web applications, APIs, mobile apps, IP ranges, internal network segments) and, for applications, the number of user roles and the size of the functionality. The testing approach (black, grey or white box), any social engineering or source code review, and whether testing must run outside business hours also shape the effort. We set this out in a written proposal once the scope is agreed.

What do we need to provide before testing starts?

Written authorisation from someone entitled to approve testing of the systems in scope and, where systems are hosted or managed by a third party or cloud provider, confirmation that its terms permit the test. We also need the confirmed target list, test accounts for each user role, the agreed test windows, and technical and escalation contacts. All of this is recorded in the signed rules of engagement before any testing begins.

Which Saudi regulations require penetration testing?

The NCA Essential Cybersecurity Controls (ECC) require periodic penetration testing whose scope covers all services provided externally over the internet and their technical components, including infrastructure, websites, web and mobile applications, email and remote access. The SAMA Cyber Security Framework (CSF) expects customer- and internet-facing services of the financial institutions it regulates to be reviewed and penetration tested annually. Which requirements bind you depends on your sector and whether you fall within the ECC's scope.

  • Assess & test

    Vulnerability management

    Recurring scanning, prioritisation and remediation tracking through to closure.

  • Assess & test

    Red team

    A realistic adversary simulation that measures your ability to detect and respond.

  • Assess & test

    Cloud security assessment

    Review of cloud configuration, identity and data against recommended practice.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.