CS—05 · Insurance · Cybersecurity
Hisn — Insurer Security Program
Full NCA ECC and SAMA CSF remediation delivered as an engineering program, with a 24/7 managed SOC operating from our Makkah headquarters.
A top-five Saudi insurer · 18-month program · ongoing SOC
The challenge
A regulator-mandated assessment left the insurer with a long list of open controls across the NCA's Essential Cybersecurity Controls and SAMA's framework, no central log visibility, and a hard deadline.
Internal teams were consumed by daily operations — the remediation needed to run without stopping the business.
What we built
We ran remediation as an engineering program: zero-trust network segmentation, identity consolidation, SIEM deployment with Saudi-hosted log retention, and control-by-control evidence collection.
A 24/7 security operations center went live from the Makkah HQ mid-program — detection engineering tuned to the insurer's estate — and we rehearsed the audit before the auditors arrived.
“They treated our regulator's checklist as an engineering spec, not paperwork. We passed the SAMA review first time, and the SOC has caught things our old tools never saw.”
Next case study
Rihal — Sovereign Cloud Migration
Let's build what's next. لنبنِ المستقبل معاً
The Kingdom's IT market is racing from $20 billion to $45 billion by 2030 — and your digital roadmap decides your share of it. Tell us where your organization is headed; we'll bring an architecture, a plan, and a team that has done it before, within one week of your brief.