Skip to content

Capability: Cybersecurity & Compliance

Compliance that holds. Architecture that earns it.

Assessment, architecture and remediation against the frameworks that govern Saudi institutions — NCA ECC-2:2024, SAMA CSF, CITC and PDPL. We design and prove your controls; your own teams keep running them.

  • NCA ECC-2:2024
  • SAMA CSF
  • PDPL
  • ISO/IEC 27001

What we do

Advisory and engineering in one team — the people who score the gap are the people who close it.

  • Assessment & gap analysis

    Control-by-control assessment against ECC-2:2024, SAMA CSF, PDPL or ISO/IEC 27001 — scored by domain, evidenced, and defensible in front of a regulator.

  • Security architecture & zero trust

    An identity-centred model: segmentation, privileged access, conditional access, encryption and key management designed together rather than bought separately.

  • Remediation & control implementation

    Engineering the controls the assessment found missing: configuration, hardening, tooling deployment, and policy that matches what the system actually does.

  • Governance, risk & audit readiness

    Policy set, risk register, control ownership matrix and an evidence pack indexed to control IDs — ready for internal audit or a regulator's review.

How we engage

Scope, score, remediate, attest.

  1. Phase 01

    Scope & baseline

    Applicable frameworks confirmed, scope boundary agreed, asset and data inventory established.

  2. Phase 02

    Assess & score

    Interviews, configuration review and evidence sampling, producing a maturity score per control domain.

  3. Phase 03

    Remediate

    Prioritised roadmap executed with your teams: architecture changes, configuration, tooling and policy.

  4. Phase 04

    Attest & sustain

    Re-assessment, evidence pack, control ownership handed to named owners inside your organisation.

What you receive

  • Assessment report with maturity scoring per control domain
  • Prioritised remediation roadmap with effort and dependency
  • Policy and standard set mapped to the controls they satisfy
  • Architecture blueprints for identity, network and data protection
  • Evidence pack indexed to control identifiers
  • Board-level summary written for non-technical readers

Frameworks we work against

NCA ECC-2:2024
Full control set, domain by domain, for national and regulated entities.
SAMA CSF
Cyber-security framework assessment and uplift for financial institutions.
PDPL
Personal-data governance, classification, retention and transfer controls.
ISO/IEC 27001 & CITC
Management-system readiness and sector obligations, aligned to the same control evidence.

Global incident response community

Proud member of FIRST.

Our CSIRT, NEXTCOR, is a member of FIRST, the Forum of Incident Response and Security Teams. Membership connects our responders to a trusted global network of incident response teams, so an incident in your estate is handled with the reach of that community and the accountability of a team working in Saudi Arabia.

View our team record on first.org(opens in a new tab)
NEXTCORNext Step Cybersecurity Operations & Response
FIRST member since
Countries of operation
  • Saudi Arabia
  • Tunisia
  • France
  • Libya
  • Mauritania
  • Rwanda

Why Next Step for compliance

  • Assessors and engineers together

    The gap analysis is written by people who can also implement the fix, so the roadmap is buildable rather than aspirational.

  • Scored, not narrated

    You get a number per domain and the evidence behind it — a baseline you can re-measure next quarter.

  • Built for handover

    Controls are handed to named owners with the artefacts they need, so the posture survives our departure.

Know exactly where you stand.

Start with a scoped gap assessment. You get domain-level scoring, a remediation roadmap and a summary your board can read.