Compliance programs in Saudi organizations rarely fail for lack of budget or intent. They fail in predictable patterns: the same eight, over and over. I have watched most of these from both sides of the
Read PostCybersecurity & GRC Notes
Live watch list
On the radar this week
- CRITICAL New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws KSA-ADJACENT BleepingComputer 1d ago
- HIGH Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs KSA-ADJACENT BleepingComputer 20h ago
- CRITICAL September 2026 Microsoft Patch Tuesday KSA-ADJACENT SANS ISC 3d ago
- HIGH ConnectWise ScreenConnect: Improper Privilege Management and Missing Authorization CISA KEV 1d ago
- HIGH JFrog Artifactory: Incorrect Authorization CISA KEV 1d ago
Blog
Where ICS Went When It Left the ECC
Posted by MA August 1, 2025 NCA
If you have been reading the ECC-2:2024 control list looking for the industrial control systems domain, stop looking. It is not there. ECC-1:2018 had five domains. ECC-2 has four: governance, defense, resilience, third party and
Read Postكيف يبدو تقييم الهيئة الوطنية للأمن السيبراني من مقعد المقيّم
Posted by MA July 18, 2025 NCA
معظم النصائح المكتوبة عن تقييمات الهيئة الوطنية للأمن السيبراني يكتبها من يستعدّ لتقييم. والقليل جداً منها يكتبه من جلس في المقعد المقابل، وقرأ حزمة الأدلة، ووازنها بنص الضابط.
Read PostWhat an NCA Assessment Looks Like From the Assessor’s Chair
Posted by MA July 11, 2025 NCA
العربية Most of the advice written about NCA assessments is written by people preparing for one. Very little of it is written by people who have sat in the other chair, read the evidence pack,
Read PostECC-2, Two Years In: What the First Assessment Cycle Exposed
Posted by MA June 13, 2025 NCA
The NCA published ECC-2 in October 2024, superseding ECC-1:2018. Two years and an assessment cycle in, the change list is settled. The question now is which changes have practical effect.
Read Post