← Case Studies

A ministry with 108 controls and no idea which ones it failed

A Saudi government body faced an NCA audit with a hundred-page policy set and no evidence. We spent the first month proving what was actually true rather than writing more policy.

A Saudi government body of roughly 3,000 staff, operating citizen-facing digital services across several regional offices

  • 108NCA controls assessed against evidence, not self-declaration
  • 31%Controls documented as compliant that evidence did not support
  • 14 weeksFrom assessment to audit-ready

The situation

Saudi Arabia's National Cybersecurity Authority restructured its Essential Cybersecurity Controls in the 2024 revision, ECC-2:2024, into four domains, twenty-eight subdomains and 108 main controls with ninety-two subcontrols beneath them. Government organisations and critical national infrastructure operators must comply, and as of 2026 the mandatory scope has widened well beyond government. The NCA enforces through audits, contractual obligations and sector oversight.

Alongside it, the Personal Data Protection Law has been in active enforcement since its grace period ended in September 2024. SDAIA reported issuing forty-eight decisions against organisations in violation over the preceding year.

For a public body this is not an abstract compliance burden. An adverse finding is a matter of public record about an organisation that exists to be trusted with citizens' data.

The problem

The body had a policy set running to more than a hundred pages, approved, version-controlled and mapped to the control framework. It had a compliance dashboard that was almost entirely green. It had an audit coming.

It also had a security director who did not believe the dashboard.

The problem was that compliance had been assessed by asking control owners whether they complied. Nobody had asked for evidence. A control marked green might mean a tested, monitored, operating control, or it might mean a document saying the control should exist, written by somebody who had since left.

Three specific worries sat underneath. Nobody could produce logs proving privileged access was reviewed. The third-party and cloud domain had been marked compliant for vendors whose contracts predated the framework entirely. And the regional offices had never been assessed at all, on the assumption that head office policy applied to them.

What we did

We proposed spending the first month producing no documentation whatsoever. That was not a popular opening position with an audit approaching, and the argument for it was simple: writing more policy against an unknown baseline is how an organisation arrives at an audit confident and wrong.

Instead we assessed all 108 controls against evidence. For each one the question was not "do you comply" but "show me the artefact that proves it, dated within the review period". A control with no artefact was recorded as not evidenced, regardless of what the dashboard said.

About thirty-one per cent of controls marked compliant could not be evidenced. Most were not failures of intent. They were controls that operated informally, by a competent person doing the right thing without recording that they had done it, which is indistinguishable from nothing when an auditor asks.

One exchange shaped the rest of the engagement. A network engineer, asked for evidence of segmentation between the corporate network and the systems running citizen services, drew the actual topology on a whiteboard from memory. It was correct, it was well designed, and it existed nowhere else. That drawing became the template for what "evidenced" had to mean.

We then prioritised by exposure rather than by control number, starting with privileged access, third-party assurance and the unassessed regional offices.

The outcome

Fourteen weeks from the start of the assessment, every control was either evidenced or carried a documented, risk-accepted remediation plan with an owner and a date. That second category matters: an auditor treats a known, owned gap very differently from a surprise.

The regional offices were assessed for the first time and pulled into the same regime.

The lasting change was to how compliance is claimed. Green now requires an artefact. The dashboard got worse before it got better, which is the point: a dashboard that cannot go red is not telling you anything.

We had been marking our own homework for three years. The uncomfortable part was not the gaps. It was discovering how many of the things we believed were in place had never been tested.

Director of Information Security, Saudi government body

We would talk you through this properly

Including what we got wrong and would do differently. The people who delivered it are the people you would meet.

Start a conversation