Understanding SAMA's Current Cyber Security Framework

The Saudi Central Bank (SAMA) Cyber Security Framework establishes mandatory security governance for all regulated financial institutions, including banks, insurance companies, and payment processors. Unlike prescriptive checklists, the framework emphasizes outcome-based compliance: institutions must demonstrate that their control environment reduces cyber risk to an acceptable level and aligns with the institution's risk appetite.

SAMA's framework is structured around five core pillars: governance and risk management, security operations, incident response, business continuity, and third-party risk management. Each pillar contains specific control objectives that financial institutions must address, with evidence requirements that regulators assess during on-site examinations.

Governance and Risk Management Evidence

SAMA expects documented cyber governance structures with clear accountability. Security leaders must evidence:

  • Board and executive oversight: Board minutes, cyber risk committee charters, and quarterly risk reports showing senior management awareness and decision-making authority.
  • Risk assessment methodology: A documented, repeatable process for identifying, analyzing, and prioritizing cyber risks. This must align with the institution's overall enterprise risk framework and reference current threat intelligence.
  • Risk appetite statements: Written policies defining acceptable risk levels for critical systems, data classification, and incident thresholds that trigger escalation.
  • Compliance mapping: A control matrix cross-referencing SAMA CSF objectives to your implemented controls, showing coverage and remediation timelines for gaps.

Regulators expect this documentation to be current (updated at least annually) and to reflect the institution's actual operating environment, not theoretical controls.

Security Operations and Technical Evidence

SAMA mandates a Security Operations Center (SOC) or equivalent capability for 24/7 monitoring and threat detection. Evidence includes:

  • Security tool inventories: Documented lists of firewalls, intrusion detection systems, endpoint protection, and SIEM platforms, with configuration baselines and change logs.
  • Monitoring and alerting logs: Samples of alert triage, investigation records, and escalation procedures demonstrating active threat hunting and anomaly detection.
  • Patch management records: Evidence of vulnerability scanning, patch testing cycles, and deployment timelines that meet SAMA's expectations (typically critical patches within 30 days).
  • Access control documentation: Role-based access control (RBAC) matrices, privileged account management (PAM) audit trails, and multi-factor authentication (MFA) enforcement logs.

Incident Response and Business Continuity Readiness

SAMA requires a formal incident response plan with annual testing and documented lessons learned. Evidence must include:

  • Incident response playbooks for ransomware, data exfiltration, and system outages.
  • Tabletop exercise reports and simulated incident logs showing detection, containment, and recovery timelines.
  • Business continuity and disaster recovery (BC/DR) test results with recovery time objectives (RTO) and recovery point objectives (RPO) validated against critical system dependencies.
  • Post-incident review summaries demonstrating root cause analysis and control improvements.

Third-Party Risk Management

SAMA expects institutions to manage cyber risk from vendors, cloud providers, and outsourced service providers. Document:

  • Vendor security assessments (questionnaires, audits, or certifications such as ISO/IEC 27001:2022).
  • Service level agreements (SLAs) with explicit security and incident notification clauses.
  • Periodic re-assessment schedules and evidence of follow-up on identified gaps.

Alignment with Broader Regulatory Expectations

SAMA's framework complements the National Cybersecurity Authority's (NCA) Essential Cybersecurity Controls (ECC) and the Saudi Personal Data Protection Law (PDPL). Security leaders should ensure their evidence demonstrates alignment with all three frameworks to avoid conflicting compliance narratives during regulatory reviews.

Practical Steps for Evidence Gathering

Begin by conducting a gap assessment against the SAMA CSF control objectives. Assign ownership for each control, establish evidence repositories (typically a secure SharePoint or governance platform), and implement a quarterly review cycle to keep documentation current. Engage your internal audit function to validate control effectiveness independently, as regulators value third-party assurance.

SAMA's examination teams focus on the maturity and consistency of your control environment. Institutions that demonstrate a proactive, documented approach to cyber governance—even if they identify and remediate gaps—typically fare better than those with ad-hoc or undocumented processes.