Is NCA ECC applicable to my organisation?
NCA ECC applicability depends on your organisation's sector, regulatory status and relationship to critical national infrastructure. It is mandatory for entities within its defined scope, including government entities and applicable private-sector entities that own, operate or host critical national infrastructure — and beyond that scope it has become the de facto cybersecurity baseline in the Kingdom. We help organisations determine the requirements applicable to their environment and translate them into governance, controls and implementation priorities.
Who needs SAMA CSF compliance?
All SAMA-regulated financial institutions — banks, insurers, financing companies, payment providers and other licensed entities. SAMA supervises against the Cyber Security Framework through maturity assessments and inspections, and expects institutions to demonstrate a defined maturity level with evidence.
What does AI governance and security advisory cover?
Everything an organisation needs to adopt AI without losing control of it: an AI use-case inventory with risk tiering, governance and approval structures, security controls across the model and data lifecycle, PDPL impact analysis for AI workloads, and policies for staff and vendor AI use — aligned to SDAIA's AI Ethics Principles and emerging regulatory guidance.
Do you resell security products?
No. Our advisory is vendor-independent — we hold no reseller agreements, so architecture and tooling recommendations are driven by risk reduction and your regulatory obligations, not by margin on a product.