Governance, Risk & Compliance

Vulnerability Assessment

Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate action

We conduct a comprehensive vulnerability assessment using professional scanning tools with manual verification to filter false positives, classify vulnerabilities by CVSS, and provide a practical remediation roadmap.

What's included

  • Select the target framework (NCA ECC-2:2024, SAMA CSF, ISO/IEC 27001:2022 or PDPL) and define the assets, systems and business units in scope
  • Assess each control against the framework requirement and assign a compliance status (Implemented, Partially Implemented, Not Implemented, Not Applicable)
  • Review policies, procedures and operational evidence and interview control owners to confirm controls work in practice, not just on paper
  • Rate every gap by regulatory impact, severity and exploitability to drive remediation priority
  • Produce a gap register and a remediation roadmap with timelines, effort estimates and clear ownership
  • Surface quick wins that can be closed immediately ahead of longer-term projects

Methodology & standards

01

Scope and framework: agree the target framework, asset boundaries and assessment criteria

02

Evidence gathering: review documentation and configurations and run field interviews with the relevant teams

03

Gap analysis and rating: compare each control to the requirement and assign a compliance status and severity

04

Remediation planning: prioritize gaps and propose compensating controls and closure projects

05

Executive readout: present the overall compliance posture and the expected impact of remediation

Deliverables

  • A detailed gap register with the compliance status and supporting evidence for each control
  • A current-state versus target-framework assessment matrix
  • A prioritized remediation roadmap with timelines and resource estimates
  • A quick-wins list that can be closed within weeks
  • An executive summary for the board covering overall compliance percentage and top risks
  • A results presentation and a working session with the teams

Regulatory controls it satisfies

NCA ECC-2:2024
Baseline the current state against the Essential Cybersecurity Controls across four domains and 28 subdomains and rate each control's implementation level
SAMA CSF
Assess current maturity against the six-level maturity model with target maturity level 3 required of financial-sector member organizations
ISO/IEC 27001:2022
Gap analysis against the ISMS clauses and Annex A controls, forming the basis for the Statement of Applicability
PDPL
Optional gap review of personal-data processing obligations where in scope

Typical timeline

A gap assessment typically runs two to four weeks depending on scope size, number of systems and the target framework.

Common questions

How is a gap assessment different from a formal audit?

A gap assessment is an internal advisory exercise that surfaces shortfalls and prioritizes remediation before a formal audit. It does not issue a certificate or a binding compliance verdict; it prepares you to pass one.

Can you assess against more than one framework at once?

Yes. We use a unified control-mapping matrix that measures a single control against several frameworks, for example NCA ECC, SAMA CSF and ISO 27001, to avoid duplicated effort and consolidate remediation.