Back to Insights
Cyber Governance

Cyber Governance for Saudi Boards: A Director's Guide

What a Saudi board is accountable for under NCA ECC-2:2024 and NCNICC-1:2025, the questions to put to management, and the evidence that answers them.

By Al Rashdan
9 min read
#board cybersecurity governance Saudi Arabia#NCA ECC board requirements#NCNICC-1:2025#cyber risk oversight#director cybersecurity duties

01

What Saudi Directors Must Know in 2026

Most Saudi boards treat cybersecurity as an IT problem. Saudi regulators and global precedent now say it is a board problem. The NCA now has the legal authority to fine organisations up to SAR 25 million and suspend licences. PDPL enforcement is active. And the average data breach in the Middle East costs $8.75 million -- the second highest in the world.

This is not a technical briefing. It is a governance briefing. Here is what every director needs to know.

If you are unsure which NCA framework your organisation actually falls under, start with the framework map: the answer is different for government, critical national infrastructure and ordinary private companies, and boards are frequently briefed on the wrong one.


02

The Three Reasons This Belongs in the Boardroom

Regulatory enforcement has arrived. Saudi Arabia's National Cybersecurity Authority was granted concrete penalty powers in December 2024 under Royal Decree M/117. Fines of up to SAR 25 million, licence suspension and suspension of activity are now available enforcement tools. The Personal Data Protection Law (PDPL) went into full enforcement in September 2024, and SDAIA's enforcement committees have since issued dozens of decisions confirming violations. Compliance is no longer guidance backed by goodwill. It is law backed by royal decree.

Personal liability is no longer theoretical. The US SEC criminally charged SolarWinds' CISO for misrepresenting cybersecurity posture to investors. Uber's former CISO was convicted for concealing a data breach. Saudi regulators are tracking this trajectory. Directors who cannot demonstrate active, documented oversight of cybersecurity risk face increasing personal exposure as enforcement matures.

The ROI on board governance is quantifiable. Organisations using AI-augmented security operations detect and contain breaches 100 days faster than the global average, saving approximately $2.2 million per incident. Boards that treat cyber as a cost centre leave measurable value on the table and create avoidable regulatory liability.


03

Six Concepts Every Director Must Understand

You do not need to become a technical expert. You need to be able to ask informed questions and evaluate the answers you receive. These six concepts form the minimum fluency standard.
01

You do not need to become a technical expert. You need to be able to ask informed questions and evaluate the answers you receive. These six concepts form the minimum fluency standard.

02

1. Risk vs. Threat vs. Vulnerability

A vulnerability is a weakness in your systems or processes. A threat is an actor or event that could exploit that weakness. Risk is the probability of that happening multiplied by the business impact if it does. Risk is expressed in riyals and business outcomes, not technical scores. When your CISO reports "500 critical vulnerabilities," the board's response should be: what is our financial risk exposure, and what is the remediation plan?

03

2. Ransomware

Ransomware attackers encrypt your data and demand payment for the decryption key. Saudi Arabia recorded 88 ransomware incidents in 2024 alone. The average cost of a ransomware breach is $4.91 million. Only 12% of victims achieve full recovery. Modern attacks use "double extortion" -- stealing data before encrypting it and threatening public release. Attackers can move laterally through a network in under 48 hours once they have initial access.

04

3. Third-Party and Supply Chain Risk

The 2021 Saudi Aramco data leak did not come from a direct attack on Aramco. It came from a third-party contractor. The $1.5 billion Bybit cryptocurrency heist in February 2025 exploited a vulnerability in a free third-party tool. Approximately 40% of breaches involve data stored or processed by third parties. Your security posture is only as strong as your weakest vendor.

05

4. Insider Threat

Three types exist: malicious insiders who intentionally steal or sabotage, negligent insiders who accidentally cause breaches, and compromised insiders whose credentials have been stolen and are being used by external attackers. Human error is the cause of 74% of all breaches. Malicious insider incidents cost an average of $4.99 million -- the most expensive attack vector -- and bypass perimeter defenses entirely.

06

5. AI-Powered Threats

AI has fundamentally changed the threat landscape. Phishing attacks linked to generative AI surged 1,265% in 2024. Deepfake fraud incidents rose 3,000%. Criminals used a deepfake video call impersonating a CFO to steal $25 million from a multinational in one incident. Meanwhile, "shadow AI" -- employees using unapproved AI tools in their work -- creates data leakage risks that most IT teams cannot see or control.

07

6. Cyber Resilience vs. Cybersecurity

Cybersecurity is about preventing attacks. Cyber resilience is about ensuring your organisation continues to operate when an attack succeeds. The question the board should be asking is not "Are we protected?" It is: "If our primary systems were encrypted tomorrow morning, how long until critical operations resume, and who makes the decisions?"


04

10 Questions the Board Should Ask the CEO

These questions are designed to be specific and difficult to deflect with vague assurances. They should appear on your board agenda at least once per year, and the most critical ones quarterly. On incident readiness:
1

When was the last full tabletop exercise simulating a ransomware attack -- and did it include the C-suite, legal, communications, and the board?

2

What is our current Mean Time to Detect and Mean Time to Respond? How do these compare to last quarter and to industry benchmarks?

3

What is our current NCA ECC-2:2024 compliance score, what are the top five gaps, and when will they be closed?

4

For SAMA-regulated entities

are we at Level 3 maturity across all domains, and progressing toward Level 4 in critical subdomains?

5

What is our PDPL compliance status -- have we completed data mapping, appointed a DPO, and tested our 72-hour breach notification process?

6

What percentage of our critical vendors have undergone a cybersecurity assessment in the past 12 months? What is the estimated business impact if our top three vendors fail simultaneously?

7

What is our cybersecurity spend as a percentage of IT budget and as a percentage of revenue? What is our current vacancy rate for security roles?

8

Does our cyber policy cover ransomware, third-party vendor failure, and business interruption? What are the specific exclusions?

9

Who is personally accountable for cybersecurity risk at the executive level, and is performance against security objectives linked to compensation?

10

What are the top three emerging threats we are least prepared for -- and what is the plan to address each one?

05

Board-Level KPIs: Seven Metrics That Matter

The board does not need a 50-metric technical dashboard. It needs a small set of business-language indicators that reveal whether the programme is working and improving over time.

Metric

Mean Time to Detect (MTTD)

What Good Looks Like

Under 24 hours

Why It Matters

Global average is 194 days. Every 30 days of undetected breach adds approximately $1.5M in cost.

Metric

Mean Time to Respond (MTTR)

What Good Looks Like

Under 48 hours to contain

Why It Matters

Global average is 64 days. AI-augmented teams reach ~35 days, saving $2.2M per incident.

Metric

Security Training Completion

What Good Looks Like

95%+ of all staff

Why It Matters

Required under NCA ECC. Low rates are a red flag for both regulators and insurers.

Metric

Phishing Simulation Click Rate

What Good Looks Like

Below 5%

Why It Matters

The global average is 15-20%. Ask for the trend, not just the number.

Metric

Critical Vulnerability SLA

What Good Looks Like

95%+ patched within 48 hours

Why It Matters

Unpatched known vulnerabilities were the entry point in the majority of major Saudi incidents in 2024.

Metric

Vendor Assessment Coverage

What Good Looks Like

100% of critical vendors annually

Why It Matters

Any unassessed critical vendor is an unmanaged existential risk. Ask for the list.

Metric

Cyber Spend vs. IT Budget

What Good Looks Like

At or above 13% of IT budget

Why It Matters

Below 10% likely signals underinvestment relative to your regulatory obligations and risk profile.

Reporting cadence: CISO to cyber committee monthly. Full board dashboard quarterly. Independent assessment and tabletop exercise annually. Immediate escalation for any material incident.


06

Your 12-Month Board Oversight Roadmap

Phase I: Foundation (Months 1-4)

The goal is to understand your current position and establish governance structures.

  • Commission an independent baseline assessment against NCA ECC-2:2024, SAMA CSF, and PDPL
  • Assign formal cyber oversight responsibility to a committee (risk committee or dedicated tech/cyber committee)
  • Establish a CISO-to-board reporting line -- the CISO should report to the CEO, not the CIO
  • Adopt NIST CSF 2.0 as the governing framework and set an initial cyber risk appetite statement
  • Approve three foundational policies: information security policy, incident response plan, and data classification policy

Maturity target: NIST CSF Tier 2 (Risk-Informed)

Phase II: Active Oversight (Months 5-8)

The goal is to build real capability and test it.

  • Conduct the first board-level tabletop exercise -- simulate ransomware, practice crisis decision-making
  • Implement financial risk quantification so cyber risk is expressed in SAR, not technical metrics
  • Launch a formal third-party risk programme covering 100% of critical vendors
  • Build a standardised quarterly KPI dashboard with traffic-light status

Maturity target: NIST CSF Tier 3 (Repeatable)

Phase III: Maturation (Months 9-12)

The goal is to embed, measure, and raise the bar.

  • Run a full exercise of PDPL and NCA breach notification procedures -- time the 72-hour clock
  • Commission a second independent assessment to measure maturity improvement against baseline
  • Formally integrate cyber risk into the enterprise risk register alongside financial and operational risk
  • Set Year 2 targets including SAMA CSF Level 4 in critical subdomains and an M&A cyber due diligence process

Maturity target: NIST CSF Tier 3 moving toward Tier 4 (Adaptive)


07

The Saudi Regulatory Framework: What Boards Must Know

01

NCA Essential Cybersecurity Controls (ECC-2:2024)

The NCA framework covers all Saudi government entities, their subsidiaries, and all private sector organisations that own, operate, or host Critical National Infrastructure. The updated 2024 framework specifies 108 main controls and 92 subcontrols across four domains: Governance, Cybersecurity Defence, Resilience, and Third-Party/Cloud Security. You will see "110 controls" quoted in several places online; the NCA's own document says 108, and a board paper citing the wrong figure is an easy thing for an assessor to notice.

Board-level requirements include establishing an independent cybersecurity department (separate from IT), creating a supervisory cybersecurity committee with a board-approved charter, and filling cybersecurity roles with qualified Saudi nationals. This expanded under ECC-2:2024: where ECC-1 required only senior cybersecurity positions to be held by Saudi nationals, ECC-2 extends it across the cybersecurity function. Evidence of nationality alone is not enough, the organisation must also show the person performs the role and holds the qualification or experience for it. That is a workforce planning decision with a board-level budget consequence.

Penalties under Royal Decree M/117 (22 December 2024): warnings, temporary or permanent licence suspension, suspension of activity, and fines of up to SAR 25 million (roughly $6.7 million). A committee determines the penalty based on the nature, recurrence and severity of the violation, and decisions can be appealed to the Administrative Court within 60 days.

02

NCNICC-1:2025 (Non-CNI Private Sector)

For a private company that has not been designated critical national infrastructure, this is usually the applicable framework.

Published in January 2026, NCNICC-1:2025 covers private sector organisations that are not critical national infrastructure. If nobody has designated your company as CNI, ECC is probably not your obligation and this is.

It scales by size. Large entities, meaning more than 250 staff or revenue above SAR 200 million, implement 65 controls. Entities of 6 to 249 staff, or SAR 3 million to 200 million, have 26 mandatory controls concentrated in Cybersecurity Defence. The NCA does not expect a 40-person company to run an internal audit function; it does expect multi-factor authentication, patching and tested backups.

The controls bind entities the NCA notifies, and no compliance deadline has been published. The document sets no penalty schedule of its own; the SAR 25 million ceiling above sits in the NCA’s general powers under Royal Decree M/117. The practical risk is not a missed date, it is discovering the obligation when someone asks for evidence.

The board question: has management confirmed in writing which framework applies to us, and on what basis? Assessing against the wrong control set is an expensive way to discover the answer. Our complete NCA framework map sets out the scope trigger for each.

03

SAMA Cyber Security Framework

Mandatory for all SAMA-regulated financial institutions. The framework is explicit: "The ultimate responsibility for cybersecurity rests with the board." The board must approve the cybersecurity strategy, establish a cyber committee, ensure CISO independence, and receive regular reporting. A minimum maturity of Level 3 is required across all domains, with Level 4 targeted in areas including threat intelligence, access control, and incident response.

04

Personal Data Protection Law (PDPL)

Fully enforceable since September 2024. Key board obligations include appointing a Data Protection Officer, completing data mapping, establishing consent mechanisms, and maintaining a 72-hour breach notification capability to SDAIA. Fines reach SAR 5 million, doubled for repeat violations. Intentional disclosure of sensitive data carries criminal penalties including up to two years' imprisonment.


08

What Regional Incidents Tell Us

Aramco Shamoon Attack (2012): A single phishing click triggered malware that destroyed 35,000 computers in hours. The company reverted to typewriters and fax machines for two weeks. The attack was timed during Ramadan when staffing was minimal. Board lesson: every employee is a potential entry point, and holiday periods require maintained security operations.

TRISIS/Triton at a Saudi Petrochemical Plant (2017): One of the first cyber attacks designed to disable industrial safety systems -- potentially causing an explosion. It only failed because of a software error. The attack exploited inadequate separation between IT and operational technology networks. Board lesson: cybersecurity failures can have life-safety consequences.

Bybit Heist, Dubai (February 2025): $1.5 billion stolen through a vulnerability in a free third-party tool. North Korea's Lazarus Group laundered over $160 million within 48 hours. Board lesson: third-party risk is not a compliance checkbox. It is a primary attack vector.


09

The Board's Role: Oversight, Not Operations

The board's job is not to manage cybersecurity. It is to ensure that management has the strategy, talent, budget, and accountability structures to do so effectively.

Three things anchor that role:

Governance drives outcomes. Organisations that follow structured board governance principles experience significantly fewer incidents without raising costs. The governance investment pays back in avoided breach costs alone.

The personal liability frontier has arrived. The SolarWinds CISO prosecution and Uber CISO criminal conviction have moved board-level accountability from aspiration to legal reality. Saudi regulators are tracking this trajectory.

Know your actual obligation. A board cannot oversee compliance with a framework that does not apply, or miss one that does. If your organisation is private and not critical national infrastructure, NCNICC-1:2025 is the relevant control set and it has been in force since January 2026.

Maturity is achievable. The 12-month roadmap above takes a board from minimal oversight to active, structured governance. It is not a multi-year transformation. It is a series of decisions and structures that most boards can put in place within one annual planning cycle.


10

How Allo Technologies Can Help

Allo Technologies provides cybersecurity advisory and compliance services for Saudi enterprises. Our board engagement services include:
01

Independent [NCA ECC-2

02

Board-level cybersecurity briefings and education sessions

03

Cyber risk appetite framework development

04

[Incident response](https

//allotechnologies.com/services/cybersecurity) plan design and tabletop exercise facilitation
05

[Third-party risk](https

//allotechnologies.com/tools/third-party-risk) programme design
06

CISO advisory and fractional CISO services

Need Expert Guidance?

Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.

Schedule a Consultation

Allo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.

Frequently asked questions

Find answers to common questions about our services

Share this article

Related Reading

More insights from the Allo Technologies practice

Cyber Governance

Boardroom Cyber Governance: Executive Sponsorship and Board-Level Awareness

Transform cybersecurity from IT concern to boardroom priority. Expert strategies for executive sponsorship, board training, and cyber-aware governance.

Read more

Talk to an Expert

Get personalized guidance from our senior security and compliance practitioners

By submitting, you consent to Allo Technologies using these details to arrange your consultation and follow up about it. Our providers process data outside Saudi Arabia, in Canada and the United States. You can withdraw consent or ask us to delete your data at any time. See our privacy policy.

0%