The challenge
The NCA Essential Cybersecurity Controls (ECC) require periodic vulnerability scanning and remediation within timeframes proportionate to severity, and the SAMA Cyber Security Framework (CSF) expects the vulnerability lifecycle to be documented from discovery to closure.
The problem is not scanning but what follows it: thousands of unranked findings, operations teams that do not know where to start, and critical flaws left open for months because nobody chased them.
We run the whole process: the scanning tools, prioritisation by real-world exploitation and asset criticality, remediation tickets, and reports that show management the trend month by month.
How we work
- 1
Inventory and asset classification
We build an inventory of internal and external assets, classify them by business criticality, and identify system owners and permitted scan windows.
- 2
Scan and prioritise
Recurring authenticated scans of networks, servers and applications, then ranking by combining CVSS with real-world exploitation data (KEV, EPSS) and asset criticality.
- 3
Track to closure
Remediation tickets to system owners, follow-up against agreed timeframes, verification rescans, and a monthly report of trends and approved exceptions.
What is included
Infrastructure and network scanning
Authenticated scanning of servers, network devices and endpoints using platforms such as Tenable, Qualys or your existing tooling.
Web application scanning
Recurring dynamic scanning of applications and exposed APIs, complementing manual penetration testing.
External attack surface
Continuous discovery of internet-exposed assets, including subdomains and forgotten services.
Risk-based prioritisation
Combining CVSS with actively exploited lists, exploitation likelihood and asset criticality, so teams start with what matters.
Patch management integration
Linking findings to patching tools (WSUS, SCCM/Intune, third-party patching) and your ticketing system.
Configuration compliance
Configuration checks against CIS Benchmarks for operating systems, databases and network devices.
Exception management
A documented register of temporarily accepted vulnerabilities with justification, compensating controls and review date.
Reporting and metrics
Dashboards showing mean time to remediate, ageing vulnerabilities and compliance with agreed timeframes, by unit and system.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- NCA ECC
- SAMA CSF
- CIS Controls
- ISO 27001
- NIST CSF
Frequently asked questions
Do you apply the patches yourselves?
The core service covers scanning, prioritisation and tracking, with remediation staying with system owners. Patch execution can be added under managed IT services.
How often do you scan?
Frequency is set by asset classification and the frameworks that apply to you, and documented in the approved scan plan.
Can you use the scanning tools we already own?
Yes. We run your existing tools where they cover the scope, and provide a platform only where none exists.
Does this integrate with the SOC?
Yes. Vulnerability data feeds the SOC to prioritise alerts, and indicators seen by the SOC adjust vulnerability ranking.
What affects the cost of managed vulnerability management?
The number of assets in scope (servers, endpoints, network devices, web applications and external IP ranges), how often each class is scanned, and whether scans are authenticated. Whether you already own a scanning platform, integration with your patching and ticketing tools, and the depth of reporting also play a part. We set this out in a written proposal after the asset inventory.
What do we need to provide to start?
Asset lists and IP ranges, service accounts with the permissions needed for authenticated scanning, and the scan windows your operations team approves. We also need system owners for each area, access to your ticketing system, and a list of fragile systems to exclude or scan with care.
Do we still need penetration testing if we have vulnerability management?
Yes. Recurring scanning finds known weaknesses across many assets, while in a penetration test a human tester proves what can actually be exploited, including business-logic flaws and chains of small issues that scanners miss. The NCA Essential Cybersecurity Controls (ECC) give each its own subdomain, and we deliver testing through our Penetration Testing service.
Related services
Assess & test
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Operate & outsource
Managed IT services
IT operations and support with clear service levels and regular reporting.
Solutions & infrastructure
Infrastructure
Data centres, servers, storage and networks built to security standards from day one.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

