Topic

Compliance & Regulation

Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.

83 articles in this topic

Compliance & Regulation

NCA's Tier 1 MSOC Licenses: What Saudi Banks Must Do Now

NCA has licensed six Tier 1 MSOC providers — SITE, Sirar by STC, Haboob, Cyberani, TCC, and SAMI-AEC. SAMA-regulated institutions must now align SOC operations with the NCA's new mandatory licensing framework.

6 Apr 2026 4 min
Compliance & Regulation

SWIFT CSP 2026: Mandatory Controls Saudi Banks Must Implement Now

SWIFT's 2026 security framework makes Control 2.4 mandatory and expands API connector scope. Saudi banks under SAMA oversight must attest by December 31, 2026 — here's what to prioritize now.

4 Apr 2026 5 min
Compliance & Regulation

Lesson 38: AI in Cybersecurity — Opportunities and Risks for Saudi Financial Institutions

Security Leadership Path — Lesson 8 of 10. Explore how AI enhances threat detection, automates SOC operations, and introduces new risks that Saudi financial institutions must address under SAMA CSCC and NCA ECC.

3 Apr 2026 9 min
Compliance & Regulation

Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem

Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.

3 Apr 2026 8 min
Guides & Lessons

Lesson 34: Building a Cybersecurity Team — Hiring and Development

Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.

1 Apr 2026 8 min
Compliance & Regulation

Lesson 20: Building an Information Security Governance (GRC) Program from Scratch

Saudi Regulatory Compliance — Lesson 10 of 10. Build a complete GRC program from scratch, aligned with SAMA, NCA, and PDPL requirements for Saudi financial institutions.

1 Apr 2026 8 min
Compliance & Regulation

Lesson 18: Cybersecurity Maturity Assessment — How to Measure Your Current Posture

Path 2: Saudi Regulatory Compliance — Lesson 8 of 10. Learn practical methods to measure your cybersecurity maturity against SAMA CSCC and NCA ECC benchmarks.

1 Apr 2026 8 min
Compliance & Regulation

Lesson 16: ISO 27001:2022 — Key Changes and a Practical Implementation Plan

Saudi Regulatory Compliance Path — Lesson 6 of 10. Master the ISO 27001:2022 transition: new control structure, Annex A changes, and a phased implementation roadmap for Saudi financial institutions.

1 Apr 2026 7 min
Guides & Lessons

Lesson 14: Saudi Personal Data Protection Law (PDPL) — A Practical Guide

Path 2: Saudi Regulatory Compliance — Lesson 4 of 10. Master PDPL requirements, data subject rights, and build a practical compliance roadmap for your financial institution.

31 Mar 2026 8 min
Compliance & Regulation

Lesson 12: SAMA Cyber Security Framework (CSCC) — Structure, Domains, and Requirements

Path 2: Saudi Regulatory Compliance — Lesson 2 of 10. A practical breakdown of the SAMA CSCC framework every compliance officer in Saudi finance needs to master.

31 Mar 2026 7 min
Network & Infrastructure

Citrix NetScaler Under Active Attack: What Saudi Financial Institutions Must Do Now

Critical Citrix NetScaler vulnerability CVE-2026-3055 is under active exploitation. Response guide for Saudi financial institutions subject to SAMA CSCC compliance.

31 Mar 2026 3 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality