
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Saudi Arabia runs one of the region's most actively enforced cybersecurity frameworks — the National Cybersecurity Authority's Essential Cybersecurity Controls, with SAMA's own Cyber Security Framework layered on top for regulated financial institutions. KazaSec extends the same manual, adversary-emulated testing discipline we built as a proudly Lebanese company across the wider EMEA region, including Riyadh and the wider Kingdom. We're increasingly counted among the leading offensive security providers serving organizations in the region, scoping every engagement against the specific control domains ECC-2:2024 and SAMA CSF actually require — not a generic international template relabeled for the Saudi market.
Riyadh's real business concentration sits increasingly in one place: King Abdullah Financial District (KAFD), the Kingdom's designated home for its most critical financial institutions — the Saudi Exchange (Tadawul), the Capital Market Authority, and major banks including Saudi National Bank, Al Rajhi Bank, and Riyad Bank, alongside more than 140 office tenants and 75-plus regional headquarters for multinational companies. For a KAFD-based bank or asset manager, SAMA's Cyber Security Framework isn't optional — it sits alongside the NCA's Essential Cybersecurity Controls as a real, enforced compliance obligation, not a voluntary best practice. Beyond KAFD, Olaya and the wider business district host a denser mix of corporate offices, professional services firms, and government-adjacent organizations working under the same NCA baseline. Wherever your organization sits in Riyadh, engagements are remote-capable by default, with on-site work scoped only where genuinely needed.
A Riyadh engagement needs to name which framework — or both — it's actually being scoped and reported against. The NCA's Essential Cybersecurity Controls (ECC-2:2024) restructures into 4 domains, 28 subdomains, and 108 main controls, covering governance, cyber defense, cyber resilience, and third-party/cloud security — a genuinely comprehensive baseline most organizations in the Kingdom are expected to meet. For KAFD-based financial institutions specifically, SAMA's Cyber Security Framework adds its own governance and technical-control expectations, aligned with but not identical to the NCA's controls — a testing program built only around one framework's language can still leave real gaps against the other's specific requirements. In practice, that means mapping findings to both the NCA's control domains and SAMA's framework in the same report for a regulated bank, not two disconnected documents. Beyond compliance-driven testing, a Riyadh engagement typically covers the same real categories we test everywhere: external network and perimeter security, web application and API testing, cloud security across AWS, Azure, and Google Cloud, and internal network/Active Directory testing for larger enterprise environments. Our free CVE Lookup and Domain Footprint Analyzer tools are a reasonable starting point for understanding your own exposure before scoping a full engagement.
Yes — we scope and report findings against ECC-2:2024's control domains, though formal ECC compliance certification remains a separate process through your own audit pathway.
Yes. For KAFD-based and other SAMA-regulated financial institutions, we map findings to both the NCA's ECC and SAMA's CSF in the same report, since the two frameworks are aligned but not identical.
Engagements are remote-capable by default, covering most real testing scope. On-site work is scoped specifically where genuinely needed.
Talk to us about scoping an engagement around your specific environment and regulatory context in Riyadh.