Frequently Asked Questions
Find answers to your questions about cybersecurity and the CISO Consulting platform
Cybersecurity 21
We cover all major Saudi cybersecurity frameworks including NCA Essential Cybersecurity Controls (ECC), SAMA Cybersecurity Framework (CSF), Saudi Personal Data Protection Law (PDPL), and NCA Cloud Computing Regulatory Framework (CCRF).
A Security Operations Centre (SOC) is a centralized team responsible for monitoring, detecting, and responding to cybersecurity threats in real time. Both SAMA CSF and NCA ECC require 24/7 security monitoring for regulated entities. Organizations can establish an in-house SOC, use a Managed SOC (MSOC) provider, or a hybrid model depending on budget, size, and risk profile.
Building a cybersecurity program in KSA involves: (1) Identify applicable frameworks (SAMA CSF, NCA ECC, PDPL based on sector); (2) Conduct a baseline risk assessment and gap analysis; (3) Define governance structure and appoint a CISO or vCISO; (4) Develop policies and procedures aligned to the framework; (5) Implement technical controls (IAM, endpoint security, monitoring); (6) Build or outsource SOC capabilities; (7) Train staff; (8) Conduct annual assessments and report to regulators.
Identity and Access Management (IAM) is one of the most scrutinized control domains during both SAMA and NCA regulatory assessments. Below are the mandatory and recommended controls:
SAMA CSF Requirements (Controls 3.2.x – Access Management):
- Implement a formal access provisioning and de-provisioning process with documented approvals.
- Enforce least-privilege and need-to-know principles across all systems.
- Privileged Access Management (PAM): All privileged accounts (domain admins, DBAs, system admins) must be inventoried, managed via a PAM solution, and subject to enhanced monitoring.
- Multi-Factor Authentication (MFA): SAMA mandates MFA for all remote access, privileged accounts, and customer-facing digital banking services.
- Periodic Access Reviews: Conduct quarterly access reviews for privileged users and semi-annual reviews for standard users. Certify and revoke unnecessary access promptly.
NCA ECC Controls (ECC-2: Protection and Defense):
- ECC Article 2-6 requires organizations to implement role-based access control (RBAC) and ensure separation of duties for sensitive functions.
- Session management controls, automatic timeouts, and logging of all privileged sessions are explicitly required.
Practical Recommendations:
- Deploy a centralized Identity Governance and Administration (IGA) platform to automate access lifecycle management.
- Integrate your IAM solution with your SIEM for real-time anomaly detection on account behavior.
- Ensure service accounts and API credentials are managed with the same rigor as human identities — a common audit gap.
- Document your IAM policy and review it annually or after significant organizational changes.
Strong IAM is foundational to achieving compliance across SAMA CSF, NCA ECC, and ISO 27001 Annex A Control 9.
A well-structured Incident Response Plan (IRP) is not optional for Saudi financial institutions — it is a regulatory requirement with defined timelines and reporting obligations. Here is how to build and operationalize one that satisfies SAMA CSF Domain 3.5 and NCA ECC Control 2-14.
Plan Structure (6 Phases):
- Preparation: Define incident categories (per SAMA's severity classification: Critical, High, Medium, Low), establish an Incident Response Team (IRT) with clear roles, and maintain an updated asset inventory.
- Identification: Deploy SIEM and EDR tools to detect anomalies. Define what constitutes a reportable incident under SAMA and NCA guidelines.
- Containment: Isolate affected systems immediately. Document all actions with timestamps for regulatory evidence.
- Eradication & Recovery: Remove threat vectors, restore from verified clean backups, and validate system integrity before resuming operations.
- Post-Incident Review: Conduct a Root Cause Analysis (RCA) within 15 days of resolution and update the IRP accordingly.
- Reporting: This is the most regulated phase.
Regulatory Reporting Timelines:
- SAMA CSF Control 3.5.4: Critical incidents must be reported to SAMA within 72 hours of detection.
- NCA ECC Control 2-14: Significant cybersecurity incidents must be reported to NCA's National Cybersecurity Operations Center (NCOC) within 24 hours.
- PDPL Article 29: Personal data breaches must be reported to SDAIA within 72 hours.
Practical Tips: Conduct tabletop exercises at least twice a year. Ensure your IRP is tested, board-approved, and reviewed annually. Appoint a dedicated incident response coordinator and maintain a 24/7 escalation matrix to avoid response delays during off-hours incidents.
Both SAMA CSF (Domain 3 — Cyber Resilience) and NCA ECC (Article 3-7) mandate that organizations maintain a documented, tested, and regularly updated Cyber Incident Response Plan (CIRP). Regulators expect much more than a paper policy — they want evidence of operational readiness.
CIRP Structure Requirements: Your plan must define six phases aligned with NIST SP 800-61: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. It must assign specific roles — Incident Commander, Technical Lead, Legal/Compliance Officer, Communications Lead — with named alternates.
SAMA-Specific Obligations: SAMA CSF Control 3.3.3 requires banks to report material cyber incidents to SAMA within 72 hours of detection. Your CIRP must include pre-approved communication templates for regulators, customers, and media.
NCA Reporting: Per NCA ECC Article 3-7, organizations must report significant incidents to the National Cybersecurity Authority. Integrating NCA's reporting portal (CCC Platform) into your CIRP workflow is essential.
Testing Requirements: Conduct at minimum:
- Tabletop exercises quarterly — simulate scenarios like ransomware, insider threat, or data breach
- Functional drills semi-annually — test actual technical response procedures
- Full simulation annually — involves all stakeholders including executive management
Document all exercise outcomes, gaps identified, and remediation actions. SAMA examiners will request this evidence during assessments.
Practical Tip: Map your incident classification levels (P1–P4) to regulatory thresholds so your team automatically knows when regulatory notification obligations are triggered, removing ambiguity during a high-stress incident.
Security awareness training is a mandatory SAMA CSF requirement under Control Domain 3.3.6, and many Saudi banks treat it as a checkbox activity rather than a strategic risk reduction program. Here is how to build it properly:
SAMA CSF Baseline Requirements SAMA CSF Control 3.3.6 mandates that all employees, contractors, and third parties with access to organizational systems receive role-based cybersecurity awareness training. Training must be:
- Delivered at onboarding and at least annually thereafter
- Role-specific (general staff vs. IT vs. privileged users)
- Documented with completion records for audit purposes
Recommended Program Structure
Tier 1 – All Staff: Phishing awareness, social engineering, password hygiene, PDPL obligations for staff handling personal data, and physical security (clean desk, tailgating).
Tier 2 – Technical Staff: Secure coding (OWASP Top 10), cloud security basics, incident reporting procedures, and NCA ECC control awareness.
Tier 3 – Executives and Board: Cyber risk governance, regulatory liability under SAMA and NCA, and crisis communication during cyber incidents.
Phishing Simulation Run quarterly simulated phishing campaigns. Track click rates and report-rates as KPIs. SAMA CSF expects measurable evidence of awareness effectiveness.
Arabic-Language Content Ensure core modules are available in Arabic. Saudi regulators expect culturally relevant materials, not direct translations of Western content.
Metrics and Reporting Report training completion rates, phishing simulation results, and awareness assessment scores to the CISO and Board Audit Committee quarterly. Link these metrics to your cybersecurity risk dashboard per SAMA CSF Control 3.1.2 (Cybersecurity Risk Management).
Aligning your program with NIST SP 800-50 provides a recognized international methodology to complement SAMA requirements.
Security awareness training is far more than an annual checkbox — it is a regulatory requirement with specific expectations under both SAMA CSF and NCA ECC.
Regulatory Foundation SAMA CSF Control Domain 3.2 explicitly requires that all staff receive role-based cybersecurity awareness training at least annually. NCA ECC Article 2-5 further mandates a documented awareness program covering phishing, social engineering, password hygiene, and acceptable use policies.
Program Design Principles
Role-Based Curriculum: Do not deliver generic training. Design separate tracks for: (a) General staff — covering phishing, password management, and data handling; (b) IT and security teams — covering threat response, secure coding, and vulnerability management; (c) Executives and board members — covering cyber risk governance, regulatory obligations, and incident escalation.
Training Frequency & Formats Beyond annual mandatory training, implement monthly micro-learning modules (5–10 minutes), quarterly phishing simulations with failure-rate tracking, and real-time teachable moments triggered by security incidents.
Phishing Simulation Program Conduct simulated phishing campaigns at least quarterly. Track click rates, credential submission rates, and report rates. Per SAMA CSF guidelines, persistent high-risk users should receive targeted remediation training within 5 business days of a failed simulation.
Metrics & Reporting Maintain training completion records in your GRC platform. Key metrics to report to senior management include: completion rate (target: 95%+), phishing simulation failure rate (target: below 5%), and number of self-reported phishing emails. These metrics should feed into your quarterly cybersecurity risk dashboard.
Localization Ensure all training content is available in Arabic. Saudi regulators expect culturally appropriate, locally relevant content — not generic translated modules.
Security Awareness Training is not an optional best practice — it is an explicit regulatory obligation. SAMA CSF Control 3.4.1 requires organizations to establish a cybersecurity awareness and training program, while NCA ECC Domain 2-5 mandates ongoing staff education tailored to roles and risk exposure.
Building a compliant and effective SAT program:
1. Governance Foundation: Assign ownership (typically CISO or HR jointly), secure executive sponsorship, and document the program in a formal policy reviewed annually. Board members and senior leadership must be included — SAMA CSF explicitly expects awareness at all organizational levels.
2. Role-Based Training Tracks: Do not deliver generic training to all staff. Segment your audience:
- General staff: Phishing recognition, password hygiene, social engineering, device security
- IT & Security teams: Incident response procedures, secure coding (OWASP Top 10), vulnerability management
- Executives & Board: Cyber risk governance, regulatory obligations, crisis decision-making
3. Training Frequency & Format: SAMA CSF expects at minimum annual training for all staff, with quarterly updates for high-risk roles. Blended learning formats (e-learning modules, live workshops, tabletop simulations) improve retention significantly over passive presentations.
4. Phishing Simulation Testing: Run simulated phishing campaigns at least quarterly. Track click rates, credential submission rates, and reporting rates. Use results to identify vulnerable departments and tailor follow-up training.
5. Metrics & Reporting: Report training completion rates, phishing simulation trends, and awareness assessment scores to the board or audit committee. SAMA examiners will review evidence of program execution during assessments.
6. Regulatory Updates: Incorporate PDPL obligations, SAMA regulatory updates, and NCA threat advisories into annual content refresh cycles to keep material current and locally relevant.
A mature SAT program reduces human-vector incident risk and directly supports your SAMA CSF maturity scoring in Domain 3 (Cybersecurity Resilience).
A comprehensive Incident Response Plan (IRP) should include: (1) Roles and responsibilities (CISO, IR team, legal, communications); (2) Incident classification and severity levels; (3) Detection and reporting procedures; (4) Containment, eradication, and recovery steps; (5) Evidence preservation and forensics guidance; (6) SAMA/NCA regulatory notification requirements; (7) External communication plan; (8) Lessons learned process; (9) Testing schedule.
Security awareness training is explicitly required under SAMA CSF Control 3.2.1 (Cybersecurity Awareness and Training) and NCA ECC Article 2-6 (Human Resources Security). A program that satisfies both frameworks must go beyond annual slideshow training and embed a continuous security culture. Here's how to build one:
1. Conduct a Role-Based Training Needs Analysis: Not all employees face the same threats. Segment training by role: executives need governance and social engineering awareness; IT/security staff need technical deep-dives; general staff need phishing, password hygiene, and data handling modules. SAMA CSF specifically calls out privileged users as requiring enhanced training.
2. Define a Training Calendar: SAMA requires documented evidence of at least annual formal training, but best practice includes quarterly phishing simulations, monthly security newsletters, and mandatory onboarding modules for new hires.
3. Include Regulatory-Specific Content: Your program must cover topics directly mapped to Saudi regulations: PDPL data handling obligations, SAMA incident reporting procedures, NCA ECC acceptable use policies, and social engineering tactics targeting the financial sector (e.g., CEO fraud, vishing).
4. Measure Effectiveness: Track phishing simulation click rates, training completion rates, and pre/post knowledge assessments. SAMA and NCA auditors expect documented metrics showing program effectiveness over time.
5. Localize for Saudi Context: Arabic-language content, culturally relevant scenarios, and references to Saudi regulatory obligations significantly improve engagement and retention. Ensure content reflects local threat actors and fraud schemes common in the MENA region.
Document everything: attendance records, assessment scores, and remediation actions for staff who fail phishing tests. This documentation is essential during SAMA supervisory reviews and NCA compliance audits.
A robust Vulnerability Management Program (VMP) for Saudi banks must be structured to satisfy SAMA CSF Control 3.3.3 (Vulnerability Management) and ISO 27001 Annex A.12.6.1 (Management of Technical Vulnerabilities).
Program Pillars:
1. Asset Discovery & Classification Maintain a continuously updated asset inventory (SAMA CSF 3.1.1). Classify assets by criticality to prioritize remediation efforts — critical financial systems demand a tighter remediation window.
2. Vulnerability Scanning Cadence SAMA CSF requires regular vulnerability assessments. Best practice mandates:
- Weekly authenticated scans for internet-facing systems
- Monthly scans for internal infrastructure
- Real-time scanning integration with SIEM platforms
3. Risk-Based Prioritization Map findings using CVSS scores combined with business context. A CVSS 7.0 vulnerability on a core banking system takes priority over a CVSS 9.0 on an isolated test environment.
4. Remediation SLAs Establish documented SLAs aligned to SAMA CSF Control 3.3.3.5:
- Critical vulnerabilities: Patch within 7 days
- High: 30 days
- Medium: 90 days
- Low: Risk acceptance or 180 days
5. Metrics & Reporting Report monthly to the CISO and quarterly to the Board Risk Committee, covering mean time to remediate (MTTR), open vulnerability aging, and exception trends per ISO 27001 Clause 9.1.
6. Integration with Pen Testing Complement the VMP with annual penetration tests per SAMA CSF 3.3.4 to validate scanner coverage gaps.
A documented, metrics-driven VMP demonstrates regulatory maturity and reduces the attack surface significantly.
A robust vulnerability management program is a core requirement under SAMA CSF Control 4.3.5 and ISO 27001 Annex A Control 8.8. For Saudi fintechs, the following structured approach is recommended:
1. Asset Inventory as the Foundation: You cannot manage vulnerabilities in assets you don't know exist. Maintain a comprehensive, up-to-date asset register covering all hardware, software, APIs, cloud workloads, and mobile applications per SAMA CSF Control 4.1.1.
2. Scanning Cadence: Conduct authenticated vulnerability scans at minimum monthly for internal systems and weekly for internet-facing assets. SAMA CSF expects evidence of regular scanning with documented remediation tracking.
3. Risk-Based Prioritisation: Not every vulnerability requires immediate patching. Use CVSS scores combined with asset criticality and exploitability context. SAMA CSF Control 4.3.5 requires a documented SLA framework — typically Critical (24–48 hours), High (7 days), Medium (30 days), Low (90 days).
4. Patch Management Integration: Link your vulnerability management tool directly to your patch management workflow. ISO 27001 A.8.8 requires timely installation of security patches with exceptions formally risk-accepted and documented.
5. Compensating Controls: Where patching is not immediately feasible (e.g., legacy core banking systems), document compensating controls such as network segmentation, WAF rules, or enhanced monitoring.
6. Metrics & Reporting: Track Mean Time to Remediate (MTTR) by severity level and report monthly to the CISO and Board Risk Committee, fulfilling SAMA CSF governance reporting obligations.
7. Continuous Improvement: Feed lessons from penetration tests and red team exercises back into your vulnerability management process to close structural gaps identified beyond automated scanning.
Privileged Access Management (PAM) is a critical control area addressed by both NCA ECC (Control 2-5: Access Management) and SAMA CSF (Control Domain 3.1, specifically Controls 3.1.3 and 3.1.4). Saudi financial institutions must implement a comprehensive PAM framework with the following components: (1) Discovery and inventory of all privileged accounts across on-premises and cloud environments, including service accounts, admin accounts, and shared credentials; (2) Just-in-time (JIT) access provisioning, ensuring elevated privileges are granted only when needed and automatically revoked after task completion; (3) Multi-factor authentication (MFA) enforced for all privileged sessions without exception, per NCA ECC Art. 2-5-3; (4) Session recording and real-time monitoring of all privileged activities, with tamper-proof audit logs retained for a minimum of 12 months as required by SAMA CSF; (5) Separation of duties ensuring no single individual holds excessive administrative rights across critical systems; and (6) Regular access reviews — at least semi-annually — with formal recertification by system owners. For cloud environments, apply cloud-native IAM controls (e.g., AWS IAM, Azure PIM) alongside your enterprise PAM solution. Shared or generic admin accounts must be eliminated; all privileged access must be individually attributed and auditable. PAM solutions such as CyberArk, BeyondTrust, or Delinea are commonly adopted in the Saudi banking sector. Critically, SAMA examiners frequently test whether privileged access logs are actually reviewed — automate alerting on anomalous privileged sessions to demonstrate active monitoring.
An effective Incident Response Plan (IRP) in Saudi Arabia must satisfy dual regulatory obligations — SAMA CSF and NCA ECC — each with distinct notification timelines and requirements. Here's how to build a compliant IRP:
1. Establish an Incident Response Team (IRT): Define clear roles: Incident Commander, Technical Lead, Legal/Compliance Officer, and Communications Lead. Per SAMA CSF Control 3.3.6, the CISO must be notified immediately for critical incidents.
2. Incident Classification Framework: Adopt a severity tiering model (P1–P4) aligned with both SAMA and NCA definitions. Critical incidents include: ransomware attacks, data breaches involving customer PII, and disruption of core banking services.
3. Regulatory Notification Timelines:
- SAMA: Notify SAMA of significant cybersecurity incidents within 72 hours of discovery, with a preliminary report. A detailed incident report must follow within 30 days.
- NCA (ECC Art. 2-9-3): Report incidents affecting critical national infrastructure to NCA's National Cybersecurity Operations Center (NCOC) within 24 hours.
- PDPL: If the incident involves personal data breach, notify SDAIA within 72 hours per PDPL Article 23.
4. Incident Response Phases: Structure your IRP around: Preparation → Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Review. Each phase must have documented runbooks for common attack scenarios (phishing, ransomware, insider threat).
5. Regular Testing & Drills: Conduct tabletop exercises at least annually and full simulation exercises every 18 months. Document results and remediation actions for regulatory evidence.
Pro Tip: Maintain pre-approved communication templates for regulatory notifications to avoid delays during high-stress incident scenarios.
Security awareness training is not merely a best practice — it is a mandatory regulatory requirement for Saudi financial institutions. Human error remains the leading cause of cybersecurity incidents, making a well-structured awareness program one of the most cost-effective security investments.
Regulatory Foundations:
- SAMA CSF Control 3.2.1 requires that all employees, contractors, and third-party users receive role-based security awareness training at least annually, with documented completion records.
- NCA ECC Article 2-6 mandates a formal cybersecurity awareness program covering threats relevant to the institution's operating environment, with evidence of employee acknowledgment.
Program Design Best Practices:
- Role-Based Training: Differentiate content for general staff (phishing, password hygiene), IT teams (secure coding, patch management), and executives (social engineering, governance responsibilities).
- Simulated Phishing Campaigns: Conduct quarterly phishing simulations to measure human risk and target repeat offenders with remedial training. Track click rates and report rates as KPIs.
- Onboarding Integration: Embed mandatory security training into new employee onboarding workflows, with a signed acknowledgment of the Acceptable Use Policy (AUP).
- Incident-Driven Updates: Refresh training content following significant internal incidents or emerging regional threat intelligence (e.g., CERT-SA advisories).
- Measurement and Reporting: Report program metrics — completion rates, phishing simulation results, knowledge assessment scores — to the CISO and board-level risk committee quarterly.
Documentation for Audits:
Maintain training completion records, curriculum materials, and assessment results for a minimum of three years to support SAMA examination requirements. Our platform automates training tracking and generates audit-ready compliance reports aligned to SAMA CSF and NCA ECC control mappings.
A robust vulnerability management program is foundational to cybersecurity compliance for Saudi financial institutions. Both SAMA CSF and NCA ECC explicitly require systematic identification, assessment, and remediation of technical vulnerabilities across all in-scope assets.
SAMA CSF Requirements (Control 3.3): SAMA mandates that member organizations establish a formal vulnerability management process covering network infrastructure, applications, endpoints, and cloud environments. This includes regular vulnerability scanning (at minimum quarterly) and risk-based prioritization of findings.
NCA ECC Requirements (ECC-1-4-3): NCA requires that critical vulnerabilities be remediated within defined SLAs — typically critical findings within 15 days, high within 30 days, and medium within 90 days — depending on your sector's risk classification.
Practical Implementation Steps:
- Asset Inventory: Maintain a complete, up-to-date asset inventory as the foundation. You cannot protect what you don't know exists.
- Scanning Cadence: Deploy authenticated scanning tools (e.g., Tenable, Qualys) for weekly internal scans and quarterly external scans at minimum.
- Risk-Based Prioritization: Use CVSS scores combined with asset criticality and exploitability context — not CVSS alone.
- Patch Management Integration: Link your vulnerability management workflow with your patch management process and change control procedures.
- Metrics and Reporting: Track Mean Time to Remediate (MTTR) per severity level and report to CISO and board-level risk committees quarterly.
- Penetration Testing: Complement scanning with annual penetration tests per SAMA CSF Control 3.3.4 and NCA ECC requirements.
- Exception Management: Formally document and risk-accept any vulnerabilities that cannot be patched within SLA, with compensating controls in place.
A well-implemented program reduces your attack surface, demonstrates regulatory maturity, and provides quantifiable risk reduction evidence during audits.
Human error remains the leading cause of cybersecurity incidents globally, and SAMA CSF explicitly addresses this under Domain 3.2 – Human Resource Security (Controls 3.2.4 and 3.2.5). A compliant and effective Security Awareness Training (SAT) program for Saudi banks must go beyond annual tick-box training.
Program Structure:
- Risk-Based Audience Segmentation: Tailor content by role. Frontline staff need phishing recognition and social engineering defense. IT and security teams require technical threat briefings. Executives and board members need cyber-risk governance training, including understanding their accountability under SAMA and NCA regulations.
- Training Frequency & Format: SAMA CSF requires at minimum annual training for all staff, but best practice — and NCA ECC guidance — recommends quarterly micro-learning modules, monthly security tips, and immediate teachable moments following phishing simulations.
- Phishing Simulation Campaigns: Run quarterly simulated phishing exercises across the organization. Track click rates, report rates, and credential submission rates. Use results to identify high-risk individuals requiring targeted remediation training. Per SAMA CSF Control 3.2.5, results should feed into your risk register.
- Arabic-Language Content: Given Saudi Arabia's workforce demographics, ensure training materials are available in Arabic and culturally relevant. Generic English content often underperforms in Gulf organizations.
- Metrics & Reporting: Report SAT effectiveness to the CISO and board annually. Key metrics include phishing simulation failure rates (target below 5%), training completion rates (target 95%+), and security incident tickets attributable to human error (track quarter-over-quarter reduction).
- New Hire Onboarding: All new employees must complete cybersecurity awareness training before accessing production systems — a hard requirement under SAMA CSF 3.2.4.
A well-executed SAT program not only satisfies SAMA examiners but measurably reduces your organization's attack surface.
Implementing robust Role-Based Access Control (RBAC) aligned with the principle of least privilege is a foundational requirement under both SAMA CSF Domain 3.2 (Identity and Access Management) and NCA ECC Control 2-5. For Saudi fintechs, here is a practical compliance roadmap:
Define Roles Before Assigning Access (SAMA CSF 3.2.1): Start by documenting a formal role inventory tied to job functions — not individuals. Map each role to the minimum permissions required for job execution. Common fintech roles include: Payment Operations, KYC Analyst, DevOps Engineer, Finance Controller, and CISO. Avoid broad admin roles shared across teams.
Privileged Access Management (PAM): SAMA CSF specifically requires controls around privileged accounts. Deploy a PAM solution to vault, rotate, and audit all privileged credentials. Privileged sessions must be recorded and reviewed periodically. NCA ECC Article 2-5-3 further mandates that privileged access be time-limited and subject to multi-factor authentication (MFA).
Segregation of Duties (SoD): Enforce SoD controls to prevent conflicts of interest — for example, the same user should not be able to both approve and execute financial transactions. This directly addresses SAMA CSF 3.2.3 and supports internal fraud prevention.
Access Reviews: Conduct formal access certification reviews at least quarterly for privileged accounts and bi-annually for all other users. Automate these reviews through your IAM platform where possible.
Joiner-Mover-Leaver Process: Establish an automated provisioning and de-provisioning workflow integrated with your HR system. Dormant accounts must be disabled within 30 days per SAMA guidance.
Audit Logging: All access events — especially for critical financial systems — must be logged and retained for a minimum of one year, with three months readily accessible, per SAMA CSF 3.6 logging requirements.
Human error remains the leading cause of cybersecurity incidents in Saudi financial institutions, making Security Awareness and Training (SAT) a regulatory and operational priority. Both SAMA CSF Control 3.2.2 and NCA ECC Article 2-4 mandate formal, role-based awareness programs that are measurable and regularly updated.
Program Design Essentials:
- Role-Based Curriculum: Develop tailored content for distinct audiences — general staff, IT/security teams, privileged users, executives, and Board members. Generic training fails to address the specific threats each group faces.
- Mandatory Training Frequency: Conduct organization-wide baseline training at onboarding and at minimum annually. High-risk roles (e.g., treasury, privileged access users) should receive quarterly refreshers. NCA ECC Article 2-4.2 explicitly requires documented evidence of training completion.
- Phishing Simulations: Run simulated phishing campaigns at least quarterly to measure click rates, credential submission, and reporting behavior. Track improvement trends over time and remediate repeat offenders with targeted training.
- Threat-Relevant Topics: Include Saudi-specific threat scenarios such as WhatsApp-based social engineering, fake SADAD payment requests, and CEO fraud — threats actively exploited against GCC financial institutions.
- Board & Executive Engagement: SAMA CSF requires cybersecurity awareness at the governance level. Conduct annual tabletop exercises and board briefings covering emerging threats and regulatory updates.
- Measurement & Reporting: Track KPIs including training completion rates, phishing simulation results, and incident tickets attributed to human error. Report these metrics to the CISO and Board Risk Committee quarterly.
- Localization: Provide content in Arabic to maximize comprehension and engagement across the full workforce, not just English-proficient staff.
A well-executed SAT program reduces human-vector incidents significantly and demonstrates to SAMA examiners a mature, proactive security culture.
A robust Cyber Incident Response Plan (CIRP) is mandatory under SAMA CSF (Domain 5 – Cyber Resilience) and NCA ECC (Control 2-12). Regulators expect not just a documented plan, but evidence of regular testing and continuous improvement.
Design requirements:
- SAMA CSF Control 5.3 requires a formal CIRP covering detection, containment, eradication, recovery, and post-incident review phases. The plan must define roles, responsibilities, escalation paths, and communication protocols — including mandatory notification to SAMA within defined timeframes for material incidents.
- NCA ECC Art. 2-12 mandates alignment with the NCA Cybersecurity Incident Management Framework and requires classified incident categorization (P1–P4 severity levels).
- PDPL obligations: Where incidents involve personal data breaches, the PDPL requires notification to the National Data Management Office (NDMO) and affected individuals within defined periods.
Testing requirements:
- Conduct tabletop exercises at least annually involving C-suite and IT leadership.
- Perform live simulation drills (e.g., ransomware scenario) at least once per year.
- Document lessons learned and translate them into CIRP updates within 30 days of each exercise.
Common gaps found during SAMA examinations: Undefined escalation thresholds, missing third-party notification procedures, and untested communication trees. Integrate your CIRP with your GRC platform to automate incident logging, evidence collection, and regulatory reporting workflows.
No matching questions found.
Didn't find what you're looking for?
✉️ Contact Us