Capability: Cybersecurity & Compliance
Compliance that holds. Architecture that earns it.
Assessment, architecture and remediation against the frameworks that govern Saudi institutions — NCA ECC-2:2024, SAMA CSF, CITC and PDPL. We design and prove your controls; your own teams keep running them.
- NCA ECC-2:2024
- SAMA CSF
- PDPL
- ISO/IEC 27001
What we do
Advisory and engineering in one team — the people who score the gap are the people who close it.
Assessment & gap analysis
Control-by-control assessment against ECC-2:2024, SAMA CSF, PDPL or ISO/IEC 27001 — scored by domain, evidenced, and defensible in front of a regulator.
Security architecture & zero trust
An identity-centred model: segmentation, privileged access, conditional access, encryption and key management designed together rather than bought separately.
Remediation & control implementation
Engineering the controls the assessment found missing: configuration, hardening, tooling deployment, and policy that matches what the system actually does.
Governance, risk & audit readiness
Policy set, risk register, control ownership matrix and an evidence pack indexed to control IDs — ready for internal audit or a regulator's review.
How we engage
Scope, score, remediate, attest.
- Phase 01
Scope & baseline
Applicable frameworks confirmed, scope boundary agreed, asset and data inventory established.
- Phase 02
Assess & score
Interviews, configuration review and evidence sampling, producing a maturity score per control domain.
- Phase 03
Remediate
Prioritised roadmap executed with your teams: architecture changes, configuration, tooling and policy.
- Phase 04
Attest & sustain
Re-assessment, evidence pack, control ownership handed to named owners inside your organisation.
Every control has an owner, an artefact and a date.
Findings are closed by engineering, not by exception requests.
Your team can defend the posture without us in the room.
What you receive
- Assessment report with maturity scoring per control domain
- Prioritised remediation roadmap with effort and dependency
- Policy and standard set mapped to the controls they satisfy
- Architecture blueprints for identity, network and data protection
- Evidence pack indexed to control identifiers
- Board-level summary written for non-technical readers
Frameworks we work against
- NCA ECC-2:2024
- Full control set, domain by domain, for national and regulated entities.
- SAMA CSF
- Cyber-security framework assessment and uplift for financial institutions.
- PDPL
- Personal-data governance, classification, retention and transfer controls.
- ISO/IEC 27001 & CITC
- Management-system readiness and sector obligations, aligned to the same control evidence.
Global incident response community
Proud member of FIRST.
Our CSIRT, NEXTCOR, is a member of FIRST, the Forum of Incident Response and Security Teams. Membership connects our responders to a trusted global network of incident response teams, so an incident in your estate is handled with the reach of that community and the accountability of a team working in Saudi Arabia.
View our team record on first.org(opens in a new tab)- FIRST member since
- Countries of operation
- Saudi Arabia
- Tunisia
- France
- Libya
- Mauritania
- Rwanda
Why Next Step for compliance
Assessors and engineers together
The gap analysis is written by people who can also implement the fix, so the roadmap is buildable rather than aspirational.
Scored, not narrated
You get a number per domain and the evidence behind it — a baseline you can re-measure next quarter.
Built for handover
Controls are handed to named owners with the artefacts they need, so the posture survives our departure.
Know exactly where you stand.
Start with a scoped gap assessment. You get domain-level scoring, a remediation roadmap and a summary your board can read.