Cloud Security for Saudi Organisations
Most cloud incidents are configuration and identity failures, not exotic attacks. This is the work of finding and fixing them, and keeping them fixed as the estate changes.
Where cloud security actually fails
Configuration Drift
A tenancy configured carefully at launch and then changed a hundred times by people in a hurry. Drift, not the original build, is what reviews find.
Identity and Privilege
Over-permissioned roles, service accounts nobody owns, and standing admin access. Identity is the control plane, and it is where compromise escalates.
Shared Responsibility Gaps
The provider secures the platform. Everything you put on it remains yours, and the boundary is where assumptions quietly accumulate.
Data Residency
Where data physically sits, and whether that satisfies the PDPL and any contractual commitments you have made to customers.
What we do
Posture Assessment
Assess the tenancy against the provider's security baseline and the applicable NCA controls, producing a risk-rated finding list rather than a raw scanner dump.
Identity Hardening
MFA coverage, privileged access review, service account ownership, and removal of standing permissions that nobody can justify.
Workload Protection
Endpoint and workload controls extended into cloud, with logging that reaches your monitoring rather than staying in the console.
Ongoing Configuration Review
A recurring check, because a point-in-time assessment describes a tenancy that stopped existing the week after it was written.
How an engagement runs
Inventory & Scope
1 weekEstablish which tenancies, subscriptions and accounts exist. Shadow cloud is common and it is better found now than during a review.
Posture Assessment
2 weeksAssess configuration and identity against the provider baseline, NCA CCC where cloud controls apply, and NCNICC third-party and cloud requirements.
Prioritised Remediation
2–4 weeksFix in risk order, starting with anything internet-facing and anything holding standing privilege.
Keep It Fixed
OngoingRecurring review, plus logging routed to monitoring so a regression is detected rather than discovered at the next assessment.
Start with where you actually stand
The NCNICC readiness assessment covers the third-party and cloud controls alongside the rest of the mandatory set.
Cloud Security FAQ
How is this different from your NCA CCC Cloud Compliance service?
NCA CCC Cloud Compliance is a compliance engagement: assessing against a specific control set and producing the evidence a review expects. Cloud Security is the operational work of finding and fixing weaknesses, whether or not a framework names them. They overlap and are often bought together, but one answers to an auditor and the other answers to an attacker.
Which cloud providers do you work with?
The major hyperscalers and the Saudi regions where they are available. The specific provider matters less than it appears, because the recurring failure modes, configuration drift, over-permissioned identity and unclear shared responsibility, are close to identical across all of them.
Does cloud data have to stay in Saudi Arabia?
It depends on your sector, your data, and your contracts rather than on a single blanket rule. The PDPL restricts transfers of personal data outside the Kingdom and is enforced by SDAIA separately from the NCA frameworks. Some regulated sectors carry stricter residency expectations. This is worth settling early, because it constrains architecture choices that are expensive to reverse.
We only use SaaS, not infrastructure. Does this apply?
Yes, and often more than clients expect. Your SaaS tenancies hold your data and your identity, and their configuration is your responsibility under the shared responsibility model. A misconfigured collaboration platform exposes as much as a misconfigured server, and it is far more likely to be publicly reachable.
Do you fix the findings or just report them?
Both are available. Some clients want the assessment and remediate with their own team, others want us to do the work. We are explicit about which model an engagement is, because a report with no owner for the findings tends to still be open at the next assessment.