Practice 02 · Enterprise Security

Security delivered where the scrutiny is highest.

Data protection and network security for Saudi government, higher education and enterprise environments.

NDA before scoping

EvidenceVerifiable
03
Saudi public sector engagements
Government · Higher education
IBM
Guardium Data Protection and Optim delivered in production
Database monitoring · Data privacy
ISO
IEC 27001:2022 certified information security
Certificate on request
04
Network and endpoint vendors
Palo Alto · Fortinet · Cisco · Kaspersky

What we deliver

The platform is named because the platform is the point.

Each engagement below is a product we have deployed and support in production, not a capability we intend to build.

01

Database activity monitoring

IBM Guardium Data Protection

Continuous monitoring of privileged access to production databases — who queried what, when, and from where. Policy-based alerting on privilege escalation and bulk extraction, with an audit trail that survives review rather than one assembled after the incident.

02

Data privacy and lifecycle management

IBM Optim

Masking of production data before it reaches test and development environments, plus archiving and retention aligned to the record classes a regulator actually asks about. The copies of your data are where exposure usually starts.

03

Sensitive data discovery and classification

Discovery and classification

Scanning of structured and unstructured estates to find personal and regulated data, then classifying it so controls attach to record classes instead of to servers. This is the inventory every other control on this page depends on.

04

Network security

Palo Alto · Fortinet

Perimeter and segmentation design, next-generation firewall deployment and rule-base rationalisation. Segmentation is scoped so that a compromised endpoint does not reach a database it was never meant to touch.

05

Identity and privileged access management

IAM · PAM

Access governance, role design and vaulting for administrative credentials, with session recording on the accounts that carry the most authority. Shared administrator passwords are the finding that recurs most often in this market.

06

GRC advisory

NCA-ECC · SAMA CSF · PDPL · ISO 27001

Gap assessment against the framework that applies to you, control mapping, and the evidence pack a regulator or auditor will ask for. We run the same controls internally — the ISO/IEC 27001:2022 certificate is ours, not a partner’s.

Selected engagements

Three Saudi public sector engagements.

Described by sector and scope. In public sector security work the engagement can itself be the sensitive fact, so clients are not identified here.

Government ministry

Saudi Arabia

Database security and access controls

Higher education institution

Saudi Arabia

Sensitive data discovery and classification across academic and administrative systems

Government authority

Saudi Arabia

Data protection and access governance

Engagement details available under NDA.

Regulatory position

You cannot protect data you have not found.

PDPL places obligations on personal data wherever it sits — including the database a department stood up years ago and never registered. Discovery and classification are not preliminary steps to a compliance programme; they are the step that makes every later control enforceable.

NCA-ECC then carries explicit controls on database activity monitoring and privileged access management. Read together, the two point at the same architecture: know what you hold, classify it, monitor who reaches it, and keep evidence that the monitoring was real.

That is the order we deliver in, and the order an assessment follows.

PDPL

Saudi Personal Data Protection Law

Obligations attach to personal data wherever it sits. Meeting them starts with knowing where it sits.

NCA-ECC

Essential Cybersecurity Controls

Carries explicit controls on database monitoring and privileged access management.

SAMA CSF

Cyber Security Framework

Applies to regulated financial entities and their service providers.

ISO 27001

IEC 27001:2022

Certified in our own operations. Certificate available on request.

Request an assessment.

Tell us the estate, the framework you are being held to, and the deadline. We will tell you honestly whether we are the right team for it.

Request an assessment

NDA before scoping