شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Detect & respond

Threat intelligence & brand protectionKnow what is said and sold about you beyond your perimeter

We watch the open, deep and dark web for your spoofed domains, leaked data and impersonated executives, and turn what we find into action.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • MITRE ATT&CK
  • NIST CSF

Deliverables

  • Approved monitoring profile (domains, brands, executives)
  • Validated alerts with severity classification
  • Takedown request log with status
  • Indicator feed into your tools
  • Monthly external threat report

The challenge

The NCA Essential Cybersecurity Controls (ECC) require threat intelligence to be managed and used for protection, and the SAMA Cyber Security Framework (CSF) expects financial institutions to monitor threats aimed at their customers and brand.

Most attacks do not start inside your network: a typosquatted domain one letter off your name, a cloned app in the stores, a social account in your CEO's name, or your staff passwords in an old dump. All of it happens outside your firewall.

We monitor that space continuously, validate what we find, and give you block-ready indicators and documented takedown requests instead of raw alerts nobody knows what to do with.

How we work

  1. 1

    Define the monitoring surface

    We collect your domains, brands, app names, executive list and email domains, and set keywords and priority levels.

  2. 2

    Monitor and validate

    Monitoring platforms gather signals from domain registrations, app stores, social media and leak forums; our analysts validate every hit before escalating.

  3. 3

    Act and feed back

    We initiate takedowns, notify you of leaked accounts for password resets, feed indicators into SIEM and firewalls, and deliver periodic reports.

What is included

  • Typosquatting and lookalike domains

    Monitoring of domain registrations similar to your names, newly issued TLS certificates and phishing pages that mimic your login portals.

  • Fake and cloned apps

    Detection of apps impersonating your brand on official and third-party stores, with removal requests.

  • Leaked credentials

    Searches of data dumps and infostealer logs for accounts on your email domains and your customers' accounts.

  • Executive impersonation

    Detection of fake accounts and pages in your leaders' names, and fraud campaigns that use them.

  • Dark web monitoring

    Tracking of markets and forums where data or access relating to your organisation or sector is offered.

  • Takedown management

    Documented takedown requests to registrars, hosting providers, app stores and social platforms, tracked to closure.

  • Actionable indicators

    Indicator export in STIX/TAXII or direct block lists into SIEM, firewalls and email gateways.

  • Sector threat reporting

    Periodic briefs on threat actors and techniques observed against Saudi financial, government and enterprise sectors, mapped to MITRE ATT&CK.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • MITRE ATT&CK
  • NIST CSF

Frequently asked questions

Do you guarantee every fake domain is taken down?

No one can guarantee that, since the decision sits with the registrar or platform. We do ensure every request is documented and followed up, and give you block indicators immediately, even before removal.

How do you handle leaked customer credentials?

We report affected accounts through an agreed secure channel and do not retain passwords. Resetting and informing customers stays within your procedures.

Does the service integrate with our SOC?

Yes. Indicators feed into your SIEM and detection tools, or into our managed SOC if you are one of its clients.

What do we need to get started?

A list of domains, brands, apps and executive names, plus an escalation contact. Nothing needs to be installed on your side.

What affects the cost of threat intelligence and brand protection?

The number of domains, brands, apps and executives you want monitored, and which sources are in scope, from domain registrations and app stores to social media and dark web forums. The expected volume of takedown requests, feeding indicators into your tools and how often you want reports also shape the scope. We set this out in a written proposal once the monitoring profile is approved.

Which Saudi regulations does this service help with?

The NCA Essential Cybersecurity Controls (ECC) require threat intelligence feeds to be collected and handled, and the SAMA Cyber Security Framework (CSF) expects the financial institutions it regulates to run a threat intelligence management process drawing on multiple reliable sources, which SAMA extends through its Financial Sector Cyber Threat Intelligence Principles. Our validated alerts, indicator feeds and periodic reports can serve as evidence for these requirements, but acceptance rests with your auditor or regulator.

How is this different from a managed SOC or MDR?

A managed SOC and MDR watch what happens inside your environment, through logs, endpoints and identities. This service watches what happens outside your perimeter, in domain registrations, app stores, social media and leak forums, where your network tools cannot see. The two complement each other, since takedowns and leaked-credential alerts help deal with a threat before it reaches your network.

  • Detect & respond

    Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

  • Detect & respond

    Managed Detection & Response (MDR)

    Endpoint and identity detection and response run by analysts.

  • Detect & respond

    Incident response

    Contain, investigate and recover from incidents with documented procedures.

  • Govern & comply

    Awareness & training

    Awareness programmes and phishing simulations with measurable results.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.