The Saudi MSSP market has matured fast. Dozens of providers now claim 24×7 SOC capability, but the quality gap is wide. This is the evaluation framework we use with clients running formal MSSP RFPs.
01
1. NCA MSOC licence
If your scope touches government, CNI, or sensitive sectors, the MSSP must hold a current NCA Managed Security Operations Centre licence. Ask for the licence number and verify with the NCA directly.
02
2. Onshore SOC
Where do analysts physically sit? For regulated workloads, onshore (KSA) analysts are usually mandatory. Confirm physical location and Saudization ratio.
03
3. Analyst tiers and ratios
Ask for the org chart: how many T1, T2, T3 analysts and threat hunters? What is the customer-to-analyst ratio? Industry healthy benchmark is 30 customers per T1 analyst.
04
4. Detection engineering
Generic SIEM rules catch generic threats. A serious MSSP runs a detection engineering function with: a content backlog, MITRE ATT&CK coverage map, and a documented use-case lifecycle.
05
5. Active response capability
"Detection" without "response" is alerting. Confirm what the MSSP can actually do without escalation: host isolation, account disable, firewall rule changes, EDR remediation.
06
6. SLAs that matter
Time to acknowledge (TTA)
Time to triage
Time to contain
Reporting cadence
07
7. Incident response retainer
Major incidents need a dedicated IR team with forensic capability. Is IR included or a separate contract? Are the responders local or fly-in? What is the surge capacity?
08
8. Threat intelligence
Generic feeds are commodity. Look for sector-specific intelligence (banking, energy, government), Arabic-language darkweb monitoring, and regional adversary tracking.
09
9. Tooling stack
Multi-tenant or single-tenant SIEM? Whose EDR? How does data isolation work? Who owns the detection logic if you leave?
10
10. Reporting and regulator readiness
Reports must be defensible to NCA and SAMA reviewers. Ask to see a redacted monthly report and a sample regulator submission.
11
11. Exit and portability
What happens to your detection content, runbooks, and historical data when the contract ends? Insist on portability clauses up front.
12
12. References
Ask for two references in your sector and size band. Speak to them about: false-positive rate, escalation quality, and willingness to push back when you are wrong.
13
Red flags
"24×7" but only one analyst on night shift.
SOC tour declined.
No detection engineering function, only OOTB rules.
Refusal to share MITRE coverage.
SLAs without financial penalty.
Vague pricing tied to undefined "alerts."
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Related Reading
More insights from the Allo Technologies practice
Managed Security Pricing in Saudi Arabia: MDR, SOC, and MSSP Models
What managed security really costs in the Kingdom: broken down by model, scope, and SLA so you can budget without surprises.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners