The challenge
The NCA Essential Cybersecurity Controls (ECC) require threat intelligence to be managed and used for protection, and the SAMA Cyber Security Framework (CSF) expects financial institutions to monitor threats aimed at their customers and brand.
Most attacks do not start inside your network: a typosquatted domain one letter off your name, a cloned app in the stores, a social account in your CEO's name, or your staff passwords in an old dump. All of it happens outside your firewall.
We monitor that space continuously, validate what we find, and give you block-ready indicators and documented takedown requests instead of raw alerts nobody knows what to do with.
How we work
- 1
Define the monitoring surface
We collect your domains, brands, app names, executive list and email domains, and set keywords and priority levels.
- 2
Monitor and validate
Monitoring platforms gather signals from domain registrations, app stores, social media and leak forums; our analysts validate every hit before escalating.
- 3
Act and feed back
We initiate takedowns, notify you of leaked accounts for password resets, feed indicators into SIEM and firewalls, and deliver periodic reports.
What is included
Typosquatting and lookalike domains
Monitoring of domain registrations similar to your names, newly issued TLS certificates and phishing pages that mimic your login portals.
Fake and cloned apps
Detection of apps impersonating your brand on official and third-party stores, with removal requests.
Leaked credentials
Searches of data dumps and infostealer logs for accounts on your email domains and your customers' accounts.
Executive impersonation
Detection of fake accounts and pages in your leaders' names, and fraud campaigns that use them.
Dark web monitoring
Tracking of markets and forums where data or access relating to your organisation or sector is offered.
Takedown management
Documented takedown requests to registrars, hosting providers, app stores and social platforms, tracked to closure.
Actionable indicators
Indicator export in STIX/TAXII or direct block lists into SIEM, firewalls and email gateways.
Sector threat reporting
Periodic briefs on threat actors and techniques observed against Saudi financial, government and enterprise sectors, mapped to MITRE ATT&CK.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- MITRE ATT&CK
- NIST CSF
Frequently asked questions
Do you guarantee every fake domain is taken down?
No one can guarantee that, since the decision sits with the registrar or platform. We do ensure every request is documented and followed up, and give you block indicators immediately, even before removal.
How do you handle leaked customer credentials?
We report affected accounts through an agreed secure channel and do not retain passwords. Resetting and informing customers stays within your procedures.
Does the service integrate with our SOC?
Yes. Indicators feed into your SIEM and detection tools, or into our managed SOC if you are one of its clients.
What do we need to get started?
A list of domains, brands, apps and executive names, plus an escalation contact. Nothing needs to be installed on your side.
What affects the cost of threat intelligence and brand protection?
The number of domains, brands, apps and executives you want monitored, and which sources are in scope, from domain registrations and app stores to social media and dark web forums. The expected volume of takedown requests, feeding indicators into your tools and how often you want reports also shape the scope. We set this out in a written proposal once the monitoring profile is approved.
Which Saudi regulations does this service help with?
The NCA Essential Cybersecurity Controls (ECC) require threat intelligence feeds to be collected and handled, and the SAMA Cyber Security Framework (CSF) expects the financial institutions it regulates to run a threat intelligence management process drawing on multiple reliable sources, which SAMA extends through its Financial Sector Cyber Threat Intelligence Principles. Our validated alerts, indicator feeds and periodic reports can serve as evidence for these requirements, but acceptance rests with your auditor or regulator.
How is this different from a managed SOC or MDR?
A managed SOC and MDR watch what happens inside your environment, through logs, endpoints and identities. This service watches what happens outside your perimeter, in domain registrations, app stores, social media and leak forums, where your network tools cannot see. The two complement each other, since takedowns and leaked-credential alerts help deal with a threat before it reaches your network.
Related services
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Detect & respond
Managed Detection & Response (MDR)
Endpoint and identity detection and response run by analysts.
Detect & respond
Incident response
Contain, investigate and recover from incidents with documented procedures.
Govern & comply
Awareness & training
Awareness programmes and phishing simulations with measurable results.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

