Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
NCA's Tier 1 MSOC Licenses: What Saudi Banks Must Do Now
NCA has licensed six Tier 1 MSOC providers — SITE, Sirar by STC, Haboob, Cyberani, TCC, and SAMI-AEC. SAMA-regulated institutions must now align SOC operations with the NCA's new mandatory licensing framework.
Compliance & RegulationSWIFT CSP 2026: Mandatory Controls Saudi Banks Must Implement Now
SWIFT's 2026 security framework makes Control 2.4 mandatory and expands API connector scope. Saudi banks under SAMA oversight must attest by December 31, 2026 — here's what to prioritize now.
Compliance & RegulationLesson 38: AI in Cybersecurity — Opportunities and Risks for Saudi Financial Institutions
Security Leadership Path — Lesson 8 of 10. Explore how AI enhances threat detection, automates SOC operations, and introduces new risks that Saudi financial institutions must address under SAMA CSCC and NCA ECC.
Compliance & RegulationLesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem
Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.
Guides & LessonsLesson 34: Building a Cybersecurity Team — Hiring and Development
Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.
Compliance & RegulationLesson 20: Building an Information Security Governance (GRC) Program from Scratch
Saudi Regulatory Compliance — Lesson 10 of 10. Build a complete GRC program from scratch, aligned with SAMA, NCA, and PDPL requirements for Saudi financial institutions.
Compliance & RegulationLesson 18: Cybersecurity Maturity Assessment — How to Measure Your Current Posture
Path 2: Saudi Regulatory Compliance — Lesson 8 of 10. Learn practical methods to measure your cybersecurity maturity against SAMA CSCC and NCA ECC benchmarks.
Compliance & RegulationLesson 16: ISO 27001:2022 — Key Changes and a Practical Implementation Plan
Saudi Regulatory Compliance Path — Lesson 6 of 10. Master the ISO 27001:2022 transition: new control structure, Annex A changes, and a phased implementation roadmap for Saudi financial institutions.
Guides & LessonsLesson 14: Saudi Personal Data Protection Law (PDPL) — A Practical Guide
Path 2: Saudi Regulatory Compliance — Lesson 4 of 10. Master PDPL requirements, data subject rights, and build a practical compliance roadmap for your financial institution.
Compliance & RegulationLesson 12: SAMA Cyber Security Framework (CSCC) — Structure, Domains, and Requirements
Path 2: Saudi Regulatory Compliance — Lesson 2 of 10. A practical breakdown of the SAMA CSCC framework every compliance officer in Saudi finance needs to master.
Network & InfrastructureCitrix NetScaler Under Active Attack: What Saudi Financial Institutions Must Do Now
Critical Citrix NetScaler vulnerability CVE-2026-3055 is under active exploitation. Response guide for Saudi financial institutions subject to SAMA CSCC compliance.