Skip to content
Vira.saTechnology

CS—05 · Insurance · Cybersecurity

Hisn — Insurer Security Program

Full NCA ECC and SAMA CSF remediation delivered as an engineering program, with a 24/7 managed SOC operating from our Makkah headquarters.

A top-five Saudi insurer · 18-month program · ongoing SOC

108/108
ECC-2:2024 controls closed before deadline
−87%
Mean time to detect across the estate
0
Critical findings in the year-two external audit

The challenge

A regulator-mandated assessment left the insurer with a long list of open controls across the NCA's Essential Cybersecurity Controls and SAMA's framework, no central log visibility, and a hard deadline.

Internal teams were consumed by daily operations — the remediation needed to run without stopping the business.

What we built

We ran remediation as an engineering program: zero-trust network segmentation, identity consolidation, SIEM deployment with Saudi-hosted log retention, and control-by-control evidence collection.

A 24/7 security operations center went live from the Makkah HQ mid-program — detection engineering tuned to the insurer's estate — and we rehearsed the audit before the auditors arrived.

“They treated our regulator's checklist as an engineering spec, not paperwork. We passed the SAMA review first time, and the SOC has caught things our old tools never saw.”
— Chief Information Security Officer, national insurer · name withheld under NDA

Next case study

Rihal — Sovereign Cloud Migration

Let's build what's next. لنبنِ المستقبل معاً

The Kingdom's IT market is racing from $20 billion to $45 billion by 2030 — and your digital roadmap decides your share of it. Tell us where your organization is headed; we'll bring an architecture, a plan, and a team that has done it before, within one week of your brief.