📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🚀

Welcome to CISO Consulting

Explore AI-powered cybersecurity tools, compliance frameworks, and threat intelligence for Saudi Arabia.

Explore →
Search Center
ESC to close
Global general → All MEDIUM 2h Global general → All MEDIUM 4h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 19h Global general → All MEDIUM 20h Global general → All MEDIUM 21h Global general → All MEDIUM 23h Global general → All MEDIUM 1d Global general → All MEDIUM 2h Global general → All MEDIUM 4h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 19h Global general → All MEDIUM 20h Global general → All MEDIUM 21h Global general → All MEDIUM 23h Global general → All MEDIUM 1d Global general → All MEDIUM 2h Global general → All MEDIUM 4h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 17h Global general → All MEDIUM 19h Global general → All MEDIUM 20h Global general → All MEDIUM 21h Global general → All MEDIUM 23h Global general → All MEDIUM 1d
SECURE DOCUMENT VAULT

The deliverable library, released on your clearance

Frameworks, policy suites, assessment workbooks and training programs — every document classified, version-controlled, previewable, and delivered over a signed secure link.

DOCUMENTS
4
TOTAL RELEASES
78
CLASSIFICATIONS
2
BILINGUAL
100%
🗜️ ZIP Registered Free 🗜️
🔒Requires clearance
Tools

NCA ECC 2024 Self Assessment ToolKit

This workbook lets an entity assess and evidence its compliance with the NCA Essential Cybersecurity Controls (ECC-2:2024) and produce a defensible position for regulatory review. The control text is reproduced in full from the NCA's published document. Nothing is summarized or paraphrased. What makes it different from a standard checklist: Scoring you can defend. For the 24 main controls that have subcontrols, the score is not entered — it is the count of subcontrols met divided by those applicable. A control cannot be marked Implemented while its subcontrols remain open. Claimed vs verified compliance, side by side. Verified counts only controls whose evidence has been tested (tier T3 or T4). The gap between the two lines is the honest measure of how much of the position rests on assertion. Two scoring bases. The authoritative figure runs on the 108 main controls; an all-items view over 200 rows tracks progress at finer grain. Lifecycle analysis. Every control is tagged Define, Implement, Specify or Review from its own wording, revealing whether weakness sits in writing requirements, implementing them, meeting minimum content, or reviewing them. No hidden constants. Every weight, threshold and dropdown lives on a visible Config sheet and is referenced by formula. Change the model by editing an input, not a formula. Full traceability. Any dashboard figure resolves down to a domain table, a register row, an evidence ID, and an assessor with a date and method. Contents (13 sheets): Cover · Methodology · Executive Dashboard · Compliance Analytics · Subdomain Heatmap · Control Assessment · Evidence Register · Statement of Applicability · Remediation Plan · Assessment Log · Change Log · Chart Data · Config

PublisherCISO Consulting
Version1.0
ClassificationRegistered
Format · SizeZIP · 225 KB
Last revision2026-09
🛡 Signed link
🗜️ ZIP Registered Free 🗜️
🔒Requires clearance
Templates

SAMA Quantum Computing Readiness Pack

The circular applies to banks, credit information companies, finance companies, payment service companies, and support entities for financing activity licensed by the Saudi Central Bank. It imposes no filing obligation. Compliance is demonstrated through the evidence an institution holds and through the minutes of its committees, which means the exposure arrives at examination rather than at a submission date. That shapes what this pack contains. Every document produces evidence. Every procedure states the artifact that closes it and the acceptance test that proves it. The working model calculates rather than collects, so a change to a weight or an assumption recalculates the whole priority picture instead of requiring the analysis to be redone. The pack was written against the official circular text, not against press reporting of it. The four measures are reproduced as worded, including the points most often lost in summary: the risk category list is expressly non-exhaustive and names human capital within it, Measure 3 carries no date of its own but follows the outputs of Measure 2, and the standing governance item applies where applicable with escalation to the Board or its equivalent. Method is distinguished from obligation throughout. Where a document specifies an exposure test, a weighting model or a target algorithm, it says so and marks it as professional practice, tunable to the institution's own risk posture. Nothing is presented as a regulatory requirement that the circular does not impose. What is inside Twelve documents Quantum Computing Risk and Cryptographic Resilience Policy — board-level policy with a statement-by-statement embedding table showing which form, checklist or pipeline each clause is wired into Cryptographic Asset Inventory and Classification Procedure — nine-step procedure with a full implementation runbook, six discovery techniques sequenced with what each one misses, and cycle acceptance criteria Quantum Risk Assessment Methodology and Report — twelve-week delivery plan, workshop facilitation protocol, a worked scoring example and the scoring errors to correct at calibration Post-Quantum Cryptography Migration Strategy and Roadmap — target cryptographic state, seven phases with gates, and seven documented alternative solutions with their limitations Governance Addendum and Board Reporting Pack — terms of reference amendment clauses, a six-page reporting pack template, escalation protocol and minute wording Third-Party Quantum Readiness Assessment and Contract Clauses — a 24-question vendor attestation, a six-dimension scoring rubric and five contract clauses Compliance Attestation and Evidence Pack — evidence index mapped to each measure, attestation, correspondence template and an 18-question examination readiness checklist Program Delivery Roadmap and Milestone Plan — 23 milestones, critical path with float analysis, quarter-by-quarter plan, resource and budget structure, gate reviews Board Briefing Deck — 15 slides taking a board from the circular to the four decisions it needs to make Cryptographic Standard — approved algorithms, key lengths, protocol versions and modes, minimum requirements by data classification, and a dated deprecation calendar Key Management Standard — four-tier key hierarchy, full lifecycle from ceremony to destruction, separation of duties, and what post-quantum specifically breaks in key handling Program Charter — objectives with measures of achievement, decision rights, seven workstreams, assumptions and constraints, and a definition of done Assurance Test Program — four audit engagements with numbered procedures, sample sizes, a stratified sampling method and the form of the opinion The working model A 15-sheet workbook with 1,545 formulas: requirement traceability, a 24-field cryptographic bill of materials, sensitivity and priority classification, data and services classification, crypto-agility assessment, third-party register, risk register, treatment plans, roadmap, exception register, governance calendar, trend history and a rolled-up dashboard. Every dropdown value, weight, threshold and deadline lives on a single reference sheet as an editable cell. Nothing is hardcoded. Change the threat horizon assumption and every priority tier recalculates. Worked examples are seeded throughout so the model can be checked against a known answer before real data is loaded: eight inventory records spanning core banking, correspondent messaging, payment switching, database encryption, cloud, code signing, backup and branch environments, five third-party records including one non-responsive vendor, eight data and service records, eighteen risks, twenty-two treatment actions and twenty-three milestones. Bilingual, properly English and Arabic are delivered as two separate packages. No file mixes languages, and no workbook sheet does either. The Arabic edition is not a translation laid over an English layout. Page direction, headings, lists, tables, headers and footers all run right to left, and the workbook has Arabic sheet names, Arabic dropdown values and Arabic formula literals, with every calculation verified to produce identical results to the English edition. Each package contains the documents in Word, the same documents in PDF, the workbook and the presentation, in separate folders. Who this is for Chief information security officers, heads of compliance, chief risk officers, internal audit functions and program managers at institutions within the circular's distribution scope. It also suits consultancies and advisory teams delivering readiness work for those institutions. Before you use it This is a professional template set, not a completed compliance position. Content in angle brackets must be completed by the institution. The algorithm selections, weights, thresholds and dates reflect prevailing practice and should be calibrated to your own estate and risk appetite, then approved through your own governance. The pack does not constitute legal advice, and it does not replace reading the circular itself. Author Prepared by AlHasan AlGhamdi, Founder of CISO Consulting, a Saudi cybersecurity governance, risk and compliance consultancy based in Riyadh advising financial institutions across the Kingdom and the wider Gulf.

PublisherAlHasan AlGhamdi
Version1.0
ClassificationRegistered
Format · SizeZIP · 48.1 MB
Last revision2026-09
🛡 Signed link
QuantomComputingSAMA
🗜️ ZIP Registered Free 🗜️
🔒Requires clearance
Tools

Crisis Management Package — Policy to Playbook

This package turns crisis management from a document on a shelf into an operating capability. It runs top to bottom through the governance stack: a Policy that sets mandate and accountability, a Standard that fixes the mandatory controls, a Process that defines flow, RACI, SLAs and KPIs, and a Procedure that walks responders step by step from first alert to stand-down. Around that core sits everything a live response actually consumes. The Plan carries the severity model, activation thresholds and command structure. The Forms pack supplies intake, rapid assessment, activation records, decision logs and closure documentation. The Message Library holds pre-approved holding statements, employee and customer communications, so nobody drafts under pressure. The Quick Reference Cards give each crisis role its first five actions and iron rules on a single page. The Exercise Kit provides a facilitator guide and ready tabletop scenarios to prove the capability works, and the Board Pack turns the aftermath into executive reporting — outcomes against priorities, response performance against SLA, decisions, findings and asks. Every document is fully editable and structured for organizational tailoring: placeholders for entity name, roles, thresholds and contact details, consistent numbering, tables of contents, and a regulatory alignment section ready to map to the frameworks your regulator expects. The Arabic set is a genuine right-to-left build — not a translated layout — so both language versions are presentation-grade for boards, regulators and auditors. What's included (24 files — 12 documents × EN + AR) Crisis Management Guide — reference handbook covering foundations, definitions and the full lifecycle Crisis Management Policy — mandate, scope, policy statements, roles, regulatory alignment Crisis Management Standard — mandatory controls for governance, detection, activation, command, communications Crisis Management Process — swimlane flow, RACI matrix, interfaces, SLAs and KPIs Crisis Management Procedure — step-by-step response from detection through recovery and stand-down Crisis Management Plan — severity model, activation thresholds, command structure, response lifecycle Forms Pack — intake, rapid assessment, severity classification, activation records, logs and closure Message Library — holding statements and employee, customer and stakeholder communications Quick Reference Cards — one-page action cards per crisis role Exercise Kit — facilitator guide, exercise rules, agenda and tabletop scenarios Board Pack — post-crisis executive summary and reporting templates Training Deck — awareness and onboarding presentation for the crisis team Who it's for CISOs, heads of business continuity and resilience, risk and compliance teams, crisis management teams, and internal audit — in financial institutions, government entities and regulated enterprises. Format & specifications 22 editable Microsoft Word documents (.docx) + 2 PowerPoint decks (.pptx) Bilingual: full English and Arabic sets, Arabic built right-to-left Fully editable — no locked content, no protected sections Consistent branding, cover pages and tables of contents throughout Keywords / tags crisis management, incident response, business continuity, resilience, cybersecurity governance, GRC, policy, standard, procedure, playbook, tabletop exercise, board reporting, bilingual, Arabic, Saudi Arabia Call to action Download the package Version line Version 1.0 · © 2026 CISO Consulting · ciso.sa · info@ciso.sa

PublisherAlHasan AlGhamdi
Version1.0
ClassificationRegistered
Format · SizeZIP · 17 MB
Last revision2026-09
🛡 Signed link
🗜️ ZIP Free 🗜️
Training

Financial Security Awareness Package

Financial Security Awareness Package is a professionally designed bilingual Arabic/English awareness campaign created for financial institutions to educate employees about sophisticated social-engineering attacks targeting financial transactions, credentials, and MFA authentication. The package includes A4 posters, digital display screens, and communication graphics, enabling organizations to deliver consistent security messages across physical and digital workplace environments.

PublisherCISO Consulting
Version1.0
ClassificationFree
Format · SizeZIP · 9.7 MB
Last revision2026-08
🛡 Signed link
Financialawareness
⬇ Secure download
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.