Cybersecurity & GRC Notes

Live watch list

On the radar this week

RSS
Curated from CISA KEV, BleepingComputer, KrebsOnSecurity, and SANS ISC. Weighted for Saudi enterprise relevance; severity reflects the source advisory. Updated 30 minutes ago.

Blog

banner desk

Eight Ways KSA Cybersecurity Programs Fail

Compliance programs in Saudi organizations rarely fail for lack of budget or intent. They fail in predictable patterns: the same eight, over and over. I have watched most of these from both sides of the

Read Post
banner watch coffee

Where ICS Went When It Left the ECC

If you have been reading the ECC-2:2024 control list looking for the industrial control systems domain, stop looking. It is not there. ECC-1:2018 had five domains. ECC-2 has four: governance, defense, resilience, third party and

Read Post
banner notebook

كيف يبدو تقييم الهيئة الوطنية للأمن السيبراني من مقعد المقيّم

معظم النصائح المكتوبة عن تقييمات الهيئة الوطنية للأمن السيبراني يكتبها من يستعدّ لتقييم. والقليل جداً منها يكتبه من جلس في المقعد المقابل، وقرأ حزمة الأدلة، ووازنها بنص الضابط.

Read Post
banner notebook

What an NCA Assessment Looks Like From the Assessor’s Chair

العربية Most of the advice written about NCA assessments is written by people preparing for one. Very little of it is written by people who have sat in the other chair, read the evidence pack,

Read Post
ecc 2 featured bg

ECC-2, Two Years In: What the First Assessment Cycle Exposed

The NCA published ECC-2 in October 2024, superseding ECC-1:2018. Two years and an assessment cycle in, the change list is settled. The question now is which changes have practical effect.

Read Post