Skip to content

Gulf

IT Audit and Cyber Security Assurance in Riyadh and Saudi Arabia

The Kingdom has the most prescriptive cyber security regulatory environment in the region — and, helpfully, the clearest expectations about what compliance actually has to look like.

Three regimes, and most entities meet more than one

Financial institutions supervised by the Saudi Central Bank are assessed against a maturity-scored cyber security framework with an expected minimum level. Government entities, their contractors and operators of critical national infrastructure fall under the National Cybersecurity Authority's control sets. Personal data processing is governed by the Kingdom's data protection law, administered by SDAIA.

Many organisations sit under two of these and a fair number under all three. The control overlap between them is substantial and almost never exploited — we routinely find entities that have run three separate assessments, generating three sets of evidence from the same underlying controls, at three times the internal cost.

The self-assessment problem

The most common reason an organisation engages us here is that a self-assessed maturity score did not survive supervisory scrutiny.

The pattern is remarkably consistent, and it is rarely dishonesty. Higher maturity levels require, in order: the control is defined, it is implemented consistently across the full scope, it is measured, and it is reviewed and improved. Organisations score the upper levels on the strength of the lower two — a policy exists and a tool is deployed, therefore the control is mature. On assessment, the tool covers sixty percent of the estate, no metric tracks coverage, and no review of the process has ever taken place.

That is defined and partially implemented. Not measured, not reviewed. The gap between a self-assessed four and an evidenced two is where most remediation budget in this market gets allocated.

Why self-assessed scores get revised down

1. Defined A document exists and is approved 2. Implemented Operates across the full scope 3. Measured A metric exists and is acted on 4. Reviewed Assessed, and something changed THE COMMONOVER-SCORE Levels 3 and 4claimed on theevidence of levels1 and 2.

Why an inflated score is worse than a low one

An honest low score with a credible roadmap is a known gap being managed. An inflated score, once found, is a governance failure — because it means management reporting to the board and the supervisor cannot be relied upon. That is a considerably more serious finding than the original control weakness, and it is much harder to close.

Where we revise a score downward we show precisely which maturity criterion is unmet and what artefact would satisfy it. That is more useful to you than the score itself.

What we are most often asked to do in this market

  • SAMA Cyber Security Framework maturity assessment, independently evidenced, reported in the framework's own domain structure so no translation is needed for submission.
  • NCA Essential Cybersecurity Controls assessment, beginning with a formal applicability determination — many private organisations come into scope through a contract term flowed down from a government client rather than by direct notification.
  • Saudi PDPL readiness, including data discovery and cross-border transfer analysis. Transfer is where genuine exposure usually sits, and it is frequently invisible until mapped.
  • ISO 27001:2022 gap assessment, typically alongside the regulatory work rather than instead of it.
  • Cross-framework control mapping so a single evidence exercise serves SAMA, NCA and ISO simultaneously.
  • Penetration testing and cloud security review, including assessment against localisation expectations where they apply.

Evidence standard

The evidence bar in the Kingdom is higher than most organisations expect, and higher than in neighbouring markets. A policy is not implementation. A deployed tool is not a control. A screenshot from one point in time does not demonstrate that a control operated across a period.

We collect evidence to the standard a supervisor would apply, which occasionally means telling a client that something they consider settled will not hold up. Better to hear that from us.

How engagements are delivered here

We work remotely and onsite across the Kingdom. For entities also operating in the UAE, we scope both together where frameworks overlap. Reporting is structured to the framework rather than to our template, so what you receive can go to the supervisor without rework.

Related services

Related regulatory frameworks

Tell us what you are actually being asked for

Describe the situation rather than the service. Working out the right scope is part of what we do, and it costs nothing to ask.

Request a proposal
Top