All services

Managed SOC and MDR for Saudi Organisations

Round-the-clock detection and response, delivered with an NCA-licensed monitoring partner, so the logging and escalation controls in NCNICC-1:2025 and ECC-2:2024 are met with evidence rather than intent.

What the service covers

24x7 Detection

Continuous monitoring of endpoints, identity, network and cloud telemetry. Alerts are triaged by analysts, not forwarded to your inbox as raw noise.

Response, Not Just Alerting

Containment actions including host isolation and account disable, agreed in advance so the response happens at 03:00 without waiting for a decision.

Regulatory Evidence

Log retention, coverage reporting and escalation records in the form an NCA review asks for, mapped to the specific control references.

Licensed Monitoring Path

Monitoring is delivered together with an NCA-licensed MSOC partner, which is what NCNICC and ECC expect where detection is outsourced.

Why organisations move to a managed model

Out-of-Hours Is the Gap

Most Saudi mid-market teams cover business hours competently. Attackers pick weekends and public holidays precisely because that is when nobody is watching.

Hiring a SOC Is Not Realistic

A genuine 24x7 rota needs five to six analysts before you count a lead or an engineer. That is out of reach for most organisations of 50 to 250 staff.

The Control Is Explicit

NCNICC-1:2025 names cybersecurity event logging and monitoring. It is not satisfied by having a SIEM that nobody reads.

Tooling Alone Does Not Detect

An EDR licence produces alerts. Detection is what happens when a person decides which of them matters, and that is the part organisations underestimate.

How onboarding runs

1

Scoping & Log Sources

1 week

Agree what is in scope, which telemetry sources exist, and where the coverage gaps are before anything is deployed.

2

Deployment & Tuning

2–3 weeks

Roll out agents and connectors, then tune. The first fortnight of any deployment is noisy and tuning is what makes the service usable.

3

Response Playbooks

1 week

Define containment actions we are pre-authorised to take, escalation contacts, and out-of-hours decision rights. Agreed before an incident, not during one.

4

Go Live

Ongoing

24x7 monitoring with monthly reporting, coverage metrics, and a quarterly review of detection content against your changing estate.

Find out whether monitoring is your gap

The NCNICC readiness assessment scores your logging and monitoring controls alongside the rest of the mandatory set, and emails you the breakdown.

Related services

Cloud Security

Securing cloud workloads and identity in KSA.

Explore

NCA ECC Compliance

For government and CNI entities.

Explore

Cybersecurity Audit

Assessment and penetration testing.

Explore

Managed SOC and MDR FAQ

Do you hold an NCA MSOC licence?

We deliver monitoring together with an NCA-licensed MSOC partner rather than holding the licence ourselves. This matters because NCNICC-1:2025 and ECC-2:2024 both expect outsourced monitoring and escalation arrangements to involve a licensed provider. We are direct about the structure because it is the first thing a Saudi buyer should check, and any provider who is vague about it is worth a second question.

What is the difference between MDR and a SIEM?

A SIEM is a tool that collects and correlates logs. MDR is a service where analysts watch the output and act on it. Buying a SIEM without the people to run it is the most common way organisations end up with an expensive log archive and no detection capability. If you already own a SIEM, we can often work with it rather than replacing it.

What detection tooling do you use?

AI-driven detection tooling from an established North American security vendor, combined with analyst triage. We deliberately do not build the service around a single product name, because the tooling changes faster than the service does and the value is in the detection content and the response process rather than the logo.

How quickly do you respond?

Response targets are agreed per engagement and written into the service description rather than left implied. Ask any provider for time to acknowledge, time to triage and time to contain as separate numbers, because a single blended response time usually hides the one that matters.

Does this satisfy the NCNICC logging and monitoring control?

It addresses it directly, and produces the evidence a review asks for: log sources in scope, retention configuration, and records of review and escalation. It does not on its own make you NCNICC compliant, since monitoring is one control area among the mandatory set. The readiness assessment shows where the rest stand.

Can you monitor cloud as well as endpoints?

Yes. Cloud control plane and identity telemetry are usually where the earliest signal of a compromise appears, often before anything reaches an endpoint. Cloud coverage is part of scoping rather than an add-on.