Topic

Compliance & Regulation

Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.

80 articles in this topic

Phishing & Fraud

AI-Generated Phishing Is Now the #1 Email Threat of 2026 — A Tactical Response Guide for Saudi Financial CISOs

AI-generated phishing attacks have surged 1,265% since 2023 and now account for 82% of all phishing emails. For Saudi financial institutions under SAMA and NCA oversight, the stakes — and the compliance obligations — have never been higher.

16 Apr 2026 6 min
Compliance & Regulation

Booking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions

Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.

16 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert

ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?

16 Apr 2026 4 min
Vulnerabilities

Critical FortiSandbox Flaws CVE-2026-39808 & CVE-2026-39813: Unauthenticated RCE That Saudi Financial Teams Cannot Afford to Miss

Fortinet disclosed two CVSS 9.1 vulnerabilities in FortiSandbox on April 15, 2026 — CVE-2026-39808 and CVE-2026-39813 — enabling unauthenticated code execution and privilege escalation. Saudi banks relying on FortiSandbox for SAMA CSCC-mandated malware detection must patch now.

16 Apr 2026 5 min
Vulnerabilities

CVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet

A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.

15 Apr 2026 5 min
Breaches & Data Leaks

Booking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees

Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.

14 Apr 2026 5 min
Compliance & Regulation

Microsoft Secure Boot Certificates Expire June 26: The 75-Day Countdown Saudi Bank CISOs Cannot Ignore

Microsoft's 2011-era Secure Boot certificates expire June 26, 2026 — and Windows Server won't update itself. Saudi financial institutions have 75 days to act before losing boot-level protection, BitLocker hardening, and SAMA CSCC compliance posture.

12 Apr 2026 6 min
Malware & Threat Actors

North Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study

North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.

7 Apr 2026 5 min
Breaches & Data Leaks

ShinyHunters Breaches the European Commission: 350GB Exposed and What Saudi Banks Must Learn Now

ShinyHunters breached the European Commission's Europa.eu, exfiltrating 350GB including databases and contracts. Saudi financial institutions must act now on identity controls, data governance, and PDPL breach notification readiness.

6 Apr 2026 4 min
Compliance & Regulation

NCA's Tier 1 MSOC Licenses: What Saudi Banks Must Do Now

NCA has licensed six Tier 1 MSOC providers — SITE, Sirar by STC, Haboob, Cyberani, TCC, and SAMI-AEC. SAMA-regulated institutions must now align SOC operations with the NCA's new mandatory licensing framework.

6 Apr 2026 4 min
Compliance & Regulation

SWIFT CSP 2026: Mandatory Controls Saudi Banks Must Implement Now

SWIFT's 2026 security framework makes Control 2.4 mandatory and expands API connector scope. Saudi banks under SAMA oversight must attest by December 31, 2026 — here's what to prioritize now.

4 Apr 2026 5 min
Compliance & Regulation

Lesson 38: AI in Cybersecurity — Opportunities and Risks for Saudi Financial Institutions

Security Leadership Path — Lesson 8 of 10. Explore how AI enhances threat detection, automates SOC operations, and introduces new risks that Saudi financial institutions must address under SAMA CSCC and NCA ECC.

3 Apr 2026 9 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality