Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
80 articles in this topic
Lesson 36: Third-Party Risk Management — Securing Your Vendor Ecosystem
Security Leadership Path — Lesson 6 of 10. Build a robust Third-Party Risk Management program that satisfies SAMA CSCC and NCA ECC requirements while protecting your organization from vendor-introduced threats.
Guides & LessonsLesson 34: Building a Cybersecurity Team — Hiring and Development
Security Leadership Path — Lesson 4 of 10. A practical guide to recruiting, structuring, and developing a cybersecurity team that meets SAMA CSCC staffing requirements and protects your organization.
Compliance & RegulationLesson 20: Building an Information Security Governance (GRC) Program from Scratch
Saudi Regulatory Compliance — Lesson 10 of 10. Build a complete GRC program from scratch, aligned with SAMA, NCA, and PDPL requirements for Saudi financial institutions.
Compliance & RegulationLesson 18: Cybersecurity Maturity Assessment — How to Measure Your Current Posture
Path 2: Saudi Regulatory Compliance — Lesson 8 of 10. Learn practical methods to measure your cybersecurity maturity against SAMA CSCC and NCA ECC benchmarks.
Compliance & RegulationLesson 16: ISO 27001:2022 — Key Changes and a Practical Implementation Plan
Saudi Regulatory Compliance Path — Lesson 6 of 10. Master the ISO 27001:2022 transition: new control structure, Annex A changes, and a phased implementation roadmap for Saudi financial institutions.
Guides & LessonsLesson 14: Saudi Personal Data Protection Law (PDPL) — A Practical Guide
Path 2: Saudi Regulatory Compliance — Lesson 4 of 10. Master PDPL requirements, data subject rights, and build a practical compliance roadmap for your financial institution.
Compliance & RegulationLesson 12: SAMA Cyber Security Framework (CSCC) — Structure, Domains, and Requirements
Path 2: Saudi Regulatory Compliance — Lesson 2 of 10. A practical breakdown of the SAMA CSCC framework every compliance officer in Saudi finance needs to master.
Network & InfrastructureCitrix NetScaler Under Active Attack: What Saudi Financial Institutions Must Do Now
Critical Citrix NetScaler vulnerability CVE-2026-3055 is under active exploitation. Response guide for Saudi financial institutions subject to SAMA CSCC compliance.
From reading to doing
How ready are you for ECC-2:2024?
Assess your organisation against the NCA Essential Cybersecurity Controls in minutes. It is free and asks for no personal data.
NCA ECC Compliance
Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Aut...
SAMA CSF Compliance
Assessment and preparation for compliance with the Cybersecurity Framework (CSF) issued by the Saudi Central Bank (SAMA)
ISO 27001 Compliance & Certification
Prepare your organization to achieve ISO 27001 certification — the international standard for Information Security Management Syst...