Services الخدمات
Security, held end to end.
Nineteen services across four practices — defence that is managed rather than merely installed, testing that is adversarial rather than automated, people who know what an attack looks like, and governance that stands up to the regulator you actually answer to.
Managed Security ServicesMSSP
خدمات الأمن السيبراني المدارة
-
Microsoft 365 Security
Comprehensive management of the Microsoft 365 environment — identity, mail flow, data protection and device policy held under one hand rather than four.
-
Managed Detection & Response MDR
Proactive threat detection and rapid response. Someone is watching, and someone is authorised to act on what they see.
-
Security Control Management & Monitoring
Continuous management and monitoring of the controls already in place, tuned as the estate changes — so they keep working long after the project that bought them closed.
-
Incident Response Retainer IRR
Standing readiness with agreed response times. Retained before the incident, not negotiated during one — which is what shortens recovery and limits the damage.
-
Endpoint Security
End-to-end managed protection across laptops, servers and mobile devices, from deployment and policy through to triage of what it catches.
Vulnerability Assessment & Penetration TestingVAPT
إختبار الاختراق وتقييم الثغرات
-
Website Penetration Testing
Authorised testing of web applications and the APIs behind them, covering the OWASP Top 10 and the business-logic abuse no scanner knows to look for.
-
Mobile App Penetration Testing
iOS and Android, assessed as a whole: the application, what it stores on the device, and the services it talks to.
-
Network Penetration Testing
External and internal, from what the perimeter exposes to how far an attacker moves once inside it.
-
Vulnerability Assessment
Scheduled, authenticated scanning across the estate, with findings ranked by what is genuinely exploitable in your environment rather than by raw severity alone.
-
Source Code Review
Manual and tool-assisted review of application source, for the classes of flaw that testing from the outside will not reach.
Cybersecurity Awareness
التوعية بالأمن السيبراني
-
Awareness Sessions & Workshops
Interactive training for staff at every level, in Arabic and English — built around the threats your people actually meet, not a generic slide deck.
-
Phishing Simulation
Realistic simulated campaigns that measure readiness honestly and show precisely where the next round of training belongs.
Governance, Risk & ComplianceGRC
الحوكمة والمخاطر والامتثال
-
Gap Assessment
Where you stand today against the framework you are held to, with a prioritised, costed path to close the distance.
-
NCA ECC Compliance
The Essential Cybersecurity Controls of the Saudi National Cybersecurity Authority, from scoping through to evidence.
-
SAMA CSF Compliance
The Saudi Central Bank's Cyber Security Framework, for banks, insurers and the financial entities it supervises.
-
Insurance Authority Compliance
Cybersecurity requirements set by the Saudi Insurance Authority for insurers and insurance service providers.
-
Aramco CCC Compliance
The Cybersecurity Compliance Certificate required of Saudi Aramco contractors and third parties before award.
-
ISO 27001 Compliance
An information security management system built to the standard — scoping, risk treatment, documentation and certification readiness.
-
Virtual CISO vCISO
Strategic security leadership on retainer: direction, board reporting and ownership, without carrying a full-time hire.