We turn cybersecurity from a reactive cost into strategic enablement: we assess your current security maturity, identify gaps against SAMA and NCA, and lay out a phased roadmap with clear priorities, budget, and KPIs — so you know what to implement, when, and why.
What's included
- Current-state maturity assessment against a recognized model across governance, defense, and resilience.
- Target operating model design: defining the future security function, its capabilities, structure, and sourcing model (in-house versus managed).
- Gap analysis mapped to the control domains of SAMA CSF and NCA ECC.
- A risk-prioritized initiative portfolio: a backlog of initiatives scored by risk reduction against effort.
- A multi-year roadmap (18 to 36 months) with phases, dependencies, and quick wins.
- Budget model and business case: capex and opex estimates, headcount needs, and a risk-reduction and return narrative for the board.
Methodology & standards
Discovery and current-state assessment: interviews, document review, and maturity scoring against SAMA CSF, NCA ECC, and ISO/IEC 27001.
Define the target state and risk appetite: peer benchmarking and a target maturity per domain.
Gap analysis and identification of the initiatives needed to close them.
Prioritization and sequencing: risk-based scoring and dependency mapping into a phased roadmap.
Budgeting, business case, and a board-ready executive presentation.
Deliverables
- Current-state maturity assessment report with heatmap and scorecard.
- Target operating model blueprint.
- Gap analysis matrix mapped to SAMA CSF and NCA ECC domains.
- Phased multi-year roadmap.
- Multi-year budget and investment model.
- Executive strategy deck for the board.
Regulatory controls it satisfies
Typical timeline
A fixed-duration project, typically four to eight weeks depending on organizational size, number of business units, and the breadth of the current-state assessment.
Common questions
How does this differ from the vCISO service?
The strategy and roadmap is a fixed-scope project that produces the plan; the vCISO service owns and executes that plan over time. Many clients start with the roadmap, then retain a vCISO to drive delivery.
Which maturity model do you use?
We baseline against the SAMA CSF maturity model and the NCA ECC domains, and can align to NIST CSF tiers where a client prefers an internationally recognized scale.
From the same practice