01
What Saudi Directors Must Know in 2026
Most Saudi boards treat cybersecurity as an IT problem. Saudi regulators and global precedent now say it is a board problem. The NCA now has the legal authority to fine organisations up to SAR 25 million and suspend licences. PDPL enforcement is active. And the average data breach in the Middle East costs $8.75 million -- the second highest in the world.
This is not a technical briefing. It is a governance briefing. Here is what every director needs to know.
If you are unsure which NCA framework your organisation actually falls under, start with the framework map: the answer is different for government, critical national infrastructure and ordinary private companies, and boards are frequently briefed on the wrong one.
02
The Three Reasons This Belongs in the Boardroom
Regulatory enforcement has arrived. Saudi Arabia's National Cybersecurity Authority was granted concrete penalty powers in December 2024 under Royal Decree M/117. Fines of up to SAR 25 million, licence suspension and suspension of activity are now available enforcement tools. The Personal Data Protection Law (PDPL) went into full enforcement in September 2024, and SDAIA's enforcement committees have since issued dozens of decisions confirming violations. Compliance is no longer guidance backed by goodwill. It is law backed by royal decree.
Personal liability is no longer theoretical. The US SEC criminally charged SolarWinds' CISO for misrepresenting cybersecurity posture to investors. Uber's former CISO was convicted for concealing a data breach. Saudi regulators are tracking this trajectory. Directors who cannot demonstrate active, documented oversight of cybersecurity risk face increasing personal exposure as enforcement matures.
The ROI on board governance is quantifiable. Organisations using AI-augmented security operations detect and contain breaches 100 days faster than the global average, saving approximately $2.2 million per incident. Boards that treat cyber as a cost centre leave measurable value on the table and create avoidable regulatory liability.
03
Six Concepts Every Director Must Understand
You do not need to become a technical expert. You need to be able to ask informed questions and evaluate the answers you receive. These six concepts form the minimum fluency standard.
1. Risk vs. Threat vs. Vulnerability
A vulnerability is a weakness in your systems or processes. A threat is an actor or event that could exploit that weakness. Risk is the probability of that happening multiplied by the business impact if it does. Risk is expressed in riyals and business outcomes, not technical scores. When your CISO reports "500 critical vulnerabilities," the board's response should be: what is our financial risk exposure, and what is the remediation plan?
2. Ransomware
Ransomware attackers encrypt your data and demand payment for the decryption key. Saudi Arabia recorded 88 ransomware incidents in 2024 alone. The average cost of a ransomware breach is $4.91 million. Only 12% of victims achieve full recovery. Modern attacks use "double extortion" -- stealing data before encrypting it and threatening public release. Attackers can move laterally through a network in under 48 hours once they have initial access.
3. Third-Party and Supply Chain Risk
The 2021 Saudi Aramco data leak did not come from a direct attack on Aramco. It came from a third-party contractor. The $1.5 billion Bybit cryptocurrency heist in February 2025 exploited a vulnerability in a free third-party tool. Approximately 40% of breaches involve data stored or processed by third parties. Your security posture is only as strong as your weakest vendor.
4. Insider Threat
Three types exist: malicious insiders who intentionally steal or sabotage, negligent insiders who accidentally cause breaches, and compromised insiders whose credentials have been stolen and are being used by external attackers. Human error is the cause of 74% of all breaches. Malicious insider incidents cost an average of $4.99 million -- the most expensive attack vector -- and bypass perimeter defenses entirely.
5. AI-Powered Threats
AI has fundamentally changed the threat landscape. Phishing attacks linked to generative AI surged 1,265% in 2024. Deepfake fraud incidents rose 3,000%. Criminals used a deepfake video call impersonating a CFO to steal $25 million from a multinational in one incident. Meanwhile, "shadow AI" -- employees using unapproved AI tools in their work -- creates data leakage risks that most IT teams cannot see or control.
6. Cyber Resilience vs. Cybersecurity
Cybersecurity is about preventing attacks. Cyber resilience is about ensuring your organisation continues to operate when an attack succeeds. The question the board should be asking is not "Are we protected?" It is: "If our primary systems were encrypted tomorrow morning, how long until critical operations resume, and who makes the decisions?"
04
10 Questions the Board Should Ask the CEO
When was the last full tabletop exercise simulating a ransomware attack -- and did it include the C-suite, legal, communications, and the board?
What is our current Mean Time to Detect and Mean Time to Respond? How do these compare to last quarter and to industry benchmarks?
What is our current NCA ECC-2:2024 compliance score, what are the top five gaps, and when will they be closed?
For SAMA-regulated entities
are we at Level 3 maturity across all domains, and progressing toward Level 4 in critical subdomains?
What is our PDPL compliance status -- have we completed data mapping, appointed a DPO, and tested our 72-hour breach notification process?
What percentage of our critical vendors have undergone a cybersecurity assessment in the past 12 months? What is the estimated business impact if our top three vendors fail simultaneously?
What is our cybersecurity spend as a percentage of IT budget and as a percentage of revenue? What is our current vacancy rate for security roles?
Does our cyber policy cover ransomware, third-party vendor failure, and business interruption? What are the specific exclusions?
Who is personally accountable for cybersecurity risk at the executive level, and is performance against security objectives linked to compensation?
What are the top three emerging threats we are least prepared for -- and what is the plan to address each one?
05
Board-Level KPIs: Seven Metrics That Matter
| Metric | What Good Looks Like | Why It Matters |
|---|---|---|
| Mean Time to Detect (MTTD) | Under 24 hours | Global average is 194 days. Every 30 days of undetected breach adds approximately $1.5M in cost. |
| Mean Time to Respond (MTTR) | Under 48 hours to contain | Global average is 64 days. AI-augmented teams reach ~35 days, saving $2.2M per incident. |
| Security Training Completion | 95%+ of all staff | Required under NCA ECC. Low rates are a red flag for both regulators and insurers. |
| Phishing Simulation Click Rate | Below 5% | The global average is 15-20%. Ask for the trend, not just the number. |
| Critical Vulnerability SLA | 95%+ patched within 48 hours | Unpatched known vulnerabilities were the entry point in the majority of major Saudi incidents in 2024. |
| Vendor Assessment Coverage | 100% of critical vendors annually | Any unassessed critical vendor is an unmanaged existential risk. Ask for the list. |
| Cyber Spend vs. IT Budget | At or above 13% of IT budget | Below 10% likely signals underinvestment relative to your regulatory obligations and risk profile. |
Metric
Mean Time to Detect (MTTD)
What Good Looks Like
Under 24 hours
Why It Matters
Global average is 194 days. Every 30 days of undetected breach adds approximately $1.5M in cost.
Metric
Mean Time to Respond (MTTR)
What Good Looks Like
Under 48 hours to contain
Why It Matters
Global average is 64 days. AI-augmented teams reach ~35 days, saving $2.2M per incident.
Metric
Security Training Completion
What Good Looks Like
95%+ of all staff
Why It Matters
Required under NCA ECC. Low rates are a red flag for both regulators and insurers.
Metric
Phishing Simulation Click Rate
What Good Looks Like
Below 5%
Why It Matters
The global average is 15-20%. Ask for the trend, not just the number.
Metric
Critical Vulnerability SLA
What Good Looks Like
95%+ patched within 48 hours
Why It Matters
Unpatched known vulnerabilities were the entry point in the majority of major Saudi incidents in 2024.
Metric
Vendor Assessment Coverage
What Good Looks Like
100% of critical vendors annually
Why It Matters
Any unassessed critical vendor is an unmanaged existential risk. Ask for the list.
Metric
Cyber Spend vs. IT Budget
What Good Looks Like
At or above 13% of IT budget
Why It Matters
Below 10% likely signals underinvestment relative to your regulatory obligations and risk profile.
Reporting cadence: CISO to cyber committee monthly. Full board dashboard quarterly. Independent assessment and tabletop exercise annually. Immediate escalation for any material incident.
06
Your 12-Month Board Oversight Roadmap
Phase I: Foundation (Months 1-4)
The goal is to understand your current position and establish governance structures.
- Commission an independent baseline assessment against NCA ECC-2:2024, SAMA CSF, and PDPL
- Assign formal cyber oversight responsibility to a committee (risk committee or dedicated tech/cyber committee)
- Establish a CISO-to-board reporting line -- the CISO should report to the CEO, not the CIO
- Adopt NIST CSF 2.0 as the governing framework and set an initial cyber risk appetite statement
- Approve three foundational policies: information security policy, incident response plan, and data classification policy
Maturity target: NIST CSF Tier 2 (Risk-Informed)
Phase II: Active Oversight (Months 5-8)
The goal is to build real capability and test it.
- Conduct the first board-level tabletop exercise -- simulate ransomware, practice crisis decision-making
- Implement financial risk quantification so cyber risk is expressed in SAR, not technical metrics
- Launch a formal third-party risk programme covering 100% of critical vendors
- Build a standardised quarterly KPI dashboard with traffic-light status
Maturity target: NIST CSF Tier 3 (Repeatable)
Phase III: Maturation (Months 9-12)
The goal is to embed, measure, and raise the bar.
- Run a full exercise of PDPL and NCA breach notification procedures -- time the 72-hour clock
- Commission a second independent assessment to measure maturity improvement against baseline
- Formally integrate cyber risk into the enterprise risk register alongside financial and operational risk
- Set Year 2 targets including SAMA CSF Level 4 in critical subdomains and an M&A cyber due diligence process
Maturity target: NIST CSF Tier 3 moving toward Tier 4 (Adaptive)
07
The Saudi Regulatory Framework: What Boards Must Know
NCA Essential Cybersecurity Controls (ECC-2:2024)
The NCA framework covers all Saudi government entities, their subsidiaries, and all private sector organisations that own, operate, or host Critical National Infrastructure. The updated 2024 framework specifies 108 main controls and 92 subcontrols across four domains: Governance, Cybersecurity Defence, Resilience, and Third-Party/Cloud Security. You will see "110 controls" quoted in several places online; the NCA's own document says 108, and a board paper citing the wrong figure is an easy thing for an assessor to notice.
Board-level requirements include establishing an independent cybersecurity department (separate from IT), creating a supervisory cybersecurity committee with a board-approved charter, and filling cybersecurity roles with qualified Saudi nationals. This expanded under ECC-2:2024: where ECC-1 required only senior cybersecurity positions to be held by Saudi nationals, ECC-2 extends it across the cybersecurity function. Evidence of nationality alone is not enough, the organisation must also show the person performs the role and holds the qualification or experience for it. That is a workforce planning decision with a board-level budget consequence.
Penalties under Royal Decree M/117 (22 December 2024): warnings, temporary or permanent licence suspension, suspension of activity, and fines of up to SAR 25 million (roughly $6.7 million). A committee determines the penalty based on the nature, recurrence and severity of the violation, and decisions can be appealed to the Administrative Court within 60 days.
NCNICC-1:2025 (Non-CNI Private Sector)
For a private company that has not been designated critical national infrastructure, this is usually the applicable framework.
Published in January 2026, NCNICC-1:2025 covers private sector organisations that are not critical national infrastructure. If nobody has designated your company as CNI, ECC is probably not your obligation and this is.
It scales by size. Large entities, meaning more than 250 staff or revenue above SAR 200 million, implement 65 controls. Entities of 6 to 249 staff, or SAR 3 million to 200 million, have 26 mandatory controls concentrated in Cybersecurity Defence. The NCA does not expect a 40-person company to run an internal audit function; it does expect multi-factor authentication, patching and tested backups.
The controls bind entities the NCA notifies, and no compliance deadline has been published. The document sets no penalty schedule of its own; the SAR 25 million ceiling above sits in the NCA’s general powers under Royal Decree M/117. The practical risk is not a missed date, it is discovering the obligation when someone asks for evidence.
The board question: has management confirmed in writing which framework applies to us, and on what basis? Assessing against the wrong control set is an expensive way to discover the answer. Our complete NCA framework map sets out the scope trigger for each.
SAMA Cyber Security Framework
Mandatory for all SAMA-regulated financial institutions. The framework is explicit: "The ultimate responsibility for cybersecurity rests with the board." The board must approve the cybersecurity strategy, establish a cyber committee, ensure CISO independence, and receive regular reporting. A minimum maturity of Level 3 is required across all domains, with Level 4 targeted in areas including threat intelligence, access control, and incident response.
Personal Data Protection Law (PDPL)
Fully enforceable since September 2024. Key board obligations include appointing a Data Protection Officer, completing data mapping, establishing consent mechanisms, and maintaining a 72-hour breach notification capability to SDAIA. Fines reach SAR 5 million, doubled for repeat violations. Intentional disclosure of sensitive data carries criminal penalties including up to two years' imprisonment.
08
What Regional Incidents Tell Us
Aramco Shamoon Attack (2012): A single phishing click triggered malware that destroyed 35,000 computers in hours. The company reverted to typewriters and fax machines for two weeks. The attack was timed during Ramadan when staffing was minimal. Board lesson: every employee is a potential entry point, and holiday periods require maintained security operations.
TRISIS/Triton at a Saudi Petrochemical Plant (2017): One of the first cyber attacks designed to disable industrial safety systems -- potentially causing an explosion. It only failed because of a software error. The attack exploited inadequate separation between IT and operational technology networks. Board lesson: cybersecurity failures can have life-safety consequences.
Bybit Heist, Dubai (February 2025): $1.5 billion stolen through a vulnerability in a free third-party tool. North Korea's Lazarus Group laundered over $160 million within 48 hours. Board lesson: third-party risk is not a compliance checkbox. It is a primary attack vector.
09
The Board's Role: Oversight, Not Operations
The board's job is not to manage cybersecurity. It is to ensure that management has the strategy, talent, budget, and accountability structures to do so effectively.
Three things anchor that role:
Governance drives outcomes. Organisations that follow structured board governance principles experience significantly fewer incidents without raising costs. The governance investment pays back in avoided breach costs alone.
The personal liability frontier has arrived. The SolarWinds CISO prosecution and Uber CISO criminal conviction have moved board-level accountability from aspiration to legal reality. Saudi regulators are tracking this trajectory.
Know your actual obligation. A board cannot oversee compliance with a framework that does not apply, or miss one that does. If your organisation is private and not critical national infrastructure, NCNICC-1:2025 is the relevant control set and it has been in force since January 2026.
Maturity is achievable. The 12-month roadmap above takes a board from minimal oversight to active, structured governance. It is not a multi-year transformation. It is a series of decisions and structures that most boards can put in place within one annual planning cycle.
10
How Allo Technologies Can Help
Independent [NCA ECC-2
Board-level cybersecurity briefings and education sessions
Cyber risk appetite framework development
[Incident response](https
[Third-party risk](https
CISO advisory and fractional CISO services
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Related Reading
More insights from the Allo Technologies practice
Boardroom Cyber Governance: Executive Sponsorship and Board-Level Awareness
Transform cybersecurity from IT concern to boardroom priority. Expert strategies for executive sponsorship, board training, and cyber-aware governance.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners