We provide specialized security consulting including current security posture assessment, strategy building, appropriate technical solution selection, and planning a cybersecurity roadmap aligned with SAMA and NCA.
What's included
- Full ownership of the cybersecurity program: setting and approving policy, chairing the security steering committee, and holding executive accountability for the security function's performance.
- Board and executive reporting: quarterly board packs, a documented risk-appetite statement, and translation of technical risk into business language the board can act on.
- Definition and tracking of KPIs and KRIs through a recurring metrics dashboard that reflects program maturity.
- Regulator liaison: representing the institution before SAMA and the NCA, and managing self-assessments and responses to supervisory findings.
- Ownership of the security roadmap and budget: a risk-based multi-year plan, spend justification, and disciplined selection of solutions and vendors.
- Leadership during major incidents: acting as the escalation point in a crisis and overseeing response and recovery readiness.
Methodology & standards
Onboarding and baseline: understand the business, inventory obligations against SAMA CSF and NCA ECC, and assess the maturity of the existing program.
Establish governance: build or refresh the policy and standards framework, set risk appetite, and cadence the steering committee and a RACI.
Roadmap and prioritization: a phased, multi-year plan tied to budget and driven by risk reduction.
Run mode: monthly and quarterly program management, KPI/KRI tracking, reporting, and regulatory engagement.
Continuous improvement, maturity uplift, and audit readiness.
Deliverables
- Cybersecurity strategy and multi-year roadmap document.
- Board and executive reporting pack (quarterly).
- Cyber risk register and approved risk-appetite statement.
- KPI and KRI metrics dashboard.
- Policy and standards framework and a cybersecurity governance charter.
- Compliance status and self-assessment against SAMA CSF and NCA ECC.
Regulatory controls it satisfies
Typical timeline
An ongoing retainer, typically a minimum of six to twelve months, with the first governance baseline delivered within the first four to six weeks.
Common questions
Does a vCISO replace an in-house CISO?
It can act as the accountable security leader for organizations that lack the role, or augment an existing team, giving you senior ownership and regulator-facing continuity without the cost of a full-time executive hire.
Can the vCISO represent us before SAMA and the NCA?
Yes. We serve as your cybersecurity point of contact, prepare self-assessments and examination responses, and manage regulatory correspondence alongside your compliance function.
From the same practice