The problem
A mid-size Saudi bank faced an NCA and SAMA compliance audit in 90 days with significant gaps across cybersecurity controls, data classification, and incident response procedures. The penalty for failure was regulatory sanction and potential suspension of digital banking services.
What we did
Conducted an emergency gap assessment against NCA Essential Cybersecurity Controls and SAMA Cybersecurity Framework. Delivered a prioritised 90-day remediation plan. Implemented the critical controls, documented all required policies, and ran a pre-audit readiness review.
The outcome
Full NCA and SAMA compliance achieved before the audit deadline. Zero findings raised during the formal audit. Bank retained its digital banking licence with no regulatory action.



