Back to blog
Advisory

vCISO Services Saudi Arabia - Scope, Deliverables and the First 90 Days

Explore vCISO services Saudi Arabia, including scope, deliverables, engagement models, governance and first 90-day priorities with guidance from Cyberactics.

Cyberactics Security Team7 Sep 202625 min read
On this page(11)

A Saudi organization decides it needs stronger cybersecurity leadership. The immediate question sounds simple: should it engage a virtual Chief Information Security Officer, or vCISO?

The harder question comes next: what exactly should that person deliver?

A proposal promising "strategic cybersecurity guidance" leaves considerable room for interpretation. One provider may deliver a risk assessment and quarterly presentation. Another may actively maintain the security roadmap, chair governance meetings, challenge vendors, track remediation, prepare executive reporting, and coordinate with the organization's IT team and security operations provider.

For buyers evaluating vCISO services in Saudi Arabia, those differences matter more than the job title. The engagement needs defined outputs, decision rights, reporting lines, working relationships, and measurable priorities.

Saudi regulatory context makes the distinction even more important. An external adviser can provide valuable expertise, but organizations should not assume that buying CISO as a Service transfers regulatory accountability or satisfies a requirement for an internal cybersecurity role. The National Cybersecurity Authority's Essential Cybersecurity Controls (ECC 2-2024) and the Saudi Central Bank Cyber Security Framework contain specific governance and personnel provisions for organizations within their respective scopes.

The right starting point, therefore, is not "How many vCISO hours can we buy?" It is "What cybersecurity leadership outcomes do we need, and who will remain accountable for them?"

What a Saudi vCISO Engagement Should Deliver Beyond Advice

A useful vCISO engagement turns cybersecurity from a collection of technical activities into a managed business-risk program. That requires translating between executive priorities and technical requirements.

Executives need answers to questions such as: Which cyber risks could seriously disrupt revenue, operations, or customer commitments? Where are we accepting more risk than we realize? What should we fund this year? Are major weaknesses actually being fixed?

Technical teams need something more specific: priorities, policies, risk decisions, control requirements, escalation paths, ownership, deadlines, and management backing.

The vCISO sits between those conversations. A mature engagement may therefore cover:

  • Cybersecurity strategy and an associated implementation roadmap
  • Business and cybersecurity risk identification and prioritization
  • Risk register development and maintenance
  • Policy and governance development
  • Regulatory and contractual requirement mapping
  • Security budget and investment planning
  • Executive and board-level reporting
  • Remediation oversight
  • Third-party and supplier risk governance
  • Security architecture and technology decision support
  • Incident preparedness and management escalation
  • Coordination with internal IT, a managed service provider (MSP), security operations center (SOC), or managed security service provider (MSSP)
  • Metrics showing whether risks and control weaknesses are improving

The exact scope should reflect the organization rather than a generic template. A 150-person professional services company operating mainly in Microsoft 365 has different priorities from an industrial business with operational technology, multiple sites, and critical production systems.

For a broader explanation of the function, see Cyberactics' complete guide to vCISO and security advisory services. Organizations still deciding which leadership model they require can separately consider a vCISO versus an in-house CISO.

The First 90 Days Should Produce Evidence, Not Just Meetings

A vCISO cannot understand an organization on day one. There are systems to discover, business dependencies to understand, existing risks to validate, contracts and policies to read, stakeholders to interview, and regulatory applicability to establish.

That makes the first 90 days particularly important. By the end of that period, management should have a materially clearer view of where the organization stands, which risks require attention, who owns them, and what happens next.

The 30-, 60-, and 90-day sequence below is a practical engagement model, not a regulatory timetable. It should be adjusted to the organization's size, maturity, risk, and urgency.

First 30 Days: Understand the Business Before Prescribing Controls

The first month should be dominated by discovery. A weak approach starts with a preferred security framework and immediately searches for gaps. A stronger vCISO first learns what the business actually needs to protect.

Establish Business Context

The vCISO should understand the organization's operating model, important products and services, major customers, locations, critical processes, technology dependencies, and planned changes.

That includes asking what management cannot afford to lose. Which systems are necessary to serve customers? How long could finance, production, logistics, or customer service operate without them? Which information would cause serious commercial, contractual, privacy, or regulatory consequences if disclosed? Which suppliers create operational dependencies?

These discussions put technical findings into business context. An unpatched server is a technical finding. An exploitable server supporting a revenue-critical application with an untested recovery process is a business risk requiring a different level of attention.

Build an Accurate Current-State Picture

Discovery should then establish what already exists.

The vCISO may review asset inventories, cloud environments, Microsoft 365, identity and privileged access, endpoint protection, network architecture, firewalls, remote access, backup arrangements, vulnerability management, security monitoring, previous assessments, incident response arrangements, and third-party connections.

Existing documentation should be tested against operational reality. A policy saying privileged access requires multifactor authentication is useful only if the technical environment actually enforces it where required.

Organizations that need to assemble this information can use the cybersecurity assessment checklist for Saudi Arabia as a practical precursor to the engagement.

Determine Regulatory Applicability

"Saudi company" is not itself a complete compliance scope.

The NCA's ECC 2-2024 applies to Saudi government agencies, including ministries, authorities, establishments and others, and their affiliated companies and entities inside and outside the Kingdom, as well as private-sector entities owning, operating, or hosting Critical National Infrastructure. NCA strongly encourages other entities in the Kingdom to use the controls to implement cybersecurity best practices.

A vCISO should therefore determine actual applicability rather than presenting the ECC as universally mandatory for every Saudi private company.

Sector obligations require the same care. The Saudi Central Bank's Cyber Security Framework applies to financial institutions within its defined scope. Other businesses may face different regulatory, contractual, or industry requirements.

The first month should consequently produce a documented view of applicable requirements, together with any questions that require confirmation by legal, compliance, or the relevant authority.

Expected Outputs Around Day 30

By this point, management should begin receiving concrete artifacts rather than only verbal observations. Depending on scope, these could include a current-state assessment, initial risk inventory, regulatory applicability map, stakeholder and responsibility map, documentation-gap list, and list of urgent issues requiring immediate action.

The vCISO should also identify critical risks that cannot reasonably wait for completion of the 90-day exercise.

Days 31-60: Turn Findings Into Governance and Priorities

Discovery tells leadership what exists. The next stage determines what to do about it.

This is where the vCISO engagement should start creating a repeatable management system for cybersecurity.

Build a Risk Register People Will Actually Use

A cybersecurity risk register should not become an archive of technical vulnerabilities.

Each material risk needs enough context for management to make a decision. Useful records typically identify the affected business process or asset, threat or scenario, existing controls, impact, likelihood, risk level, treatment, owner, target date, and current status.

For example, "legacy VPN" says little to an executive team. A more useful risk scenario explains that a remote-access service supporting employees or suppliers lacks required protections, identifies what an attacker could reach if it were compromised, documents the controls already present, and sets out treatment options.

The vCISO should facilitate and maintain the risk-management process, but business ownership cannot simply be outsourced. Management still needs to accept, avoid, transfer, or reduce business risks through the organization's established authority structure.

Convert Risks Into a Roadmap

The roadmap connects the risk register to execution.

It should distinguish immediate remediation from foundational work and longer-term improvements. A business might need to resolve exposed administrative access immediately, while an identity modernization program or security information and event management (SIEM) redesign could require several months.

Priorities should reflect risk, regulatory requirements, business dependencies, implementation effort, and budget.

This prevents a common failure mode: spending heavily on a new security product while basic problems such as uncontrolled privileged accounts, weak recovery arrangements, or incomplete asset visibility remain unresolved.

Establish Governance

The vCISO should clarify how cybersecurity decisions get made.

Who approves policy? Who can accept risk? Who owns vulnerabilities? Who decides when a supplier's security position is unacceptable? Who receives an incident escalation at 2 a.m.? What reaches executive leadership, and at what threshold?

Governance may involve an executive or cybersecurity committee, regular risk reviews, documented roles and responsibilities, formal exception processes, and an escalation path.

The objective is not to create meetings for their own sake. It is to eliminate ambiguity when decisions matter.

Review Policies Against Reality

Policies should reflect the way the organization operates and the controls it intends to enforce.

Depending on scope and risk, the priority set could address access control, acceptable use, incident response, vulnerability management, backups, third-party access, information handling, cloud use, remote access, and security responsibilities.

A vCISO should also resist producing a large library of documents simply to demonstrate activity. Policies that nobody implements provide little protection.

Days 61-90: Move From Planning to Management

By the third phase, the vCISO should know enough about the environment to begin demonstrating whether the governance model works.

The emphasis now moves toward implementation oversight, measurement, and executive visibility.

Assign and Track Remediation

Every significant roadmap initiative needs an owner.

Some actions may belong to internal IT. Others could require an MSP, MSSP, software vendor, cloud engineer, compliance team, HR, procurement, or business owner.

The vCISO's job is not necessarily to perform each technical change. It is to make sure material security work has a reason, priority, owner, and route to completion.

A useful distinction is between ownership and execution. The IT team might implement a Microsoft Entra Conditional Access policy. The SOC might monitor related identity alerts. The vCISO may define the risk requirement and oversee progress. The authorized risk owner accepts any resulting residual business risk in accordance with the organization's governance process.

Those roles should not be confused.

Establish Useful Metrics

Executive security reporting should answer whether the organization is becoming more resilient, not merely count security activity.

Hundreds of thousands of alerts do not tell a CEO much. More useful measures may include overdue critical remediation, vulnerability trends, privileged-access exceptions, endpoint or logging coverage, backup recovery-test results, high-risk suppliers awaiting treatment, outstanding audit findings, security incidents by materiality, and roadmap milestones.

Metrics also need context. A rising vulnerability count might represent deteriorating security, or it might result from improved asset discovery. A vCISO should explain the difference.

Deliver the First Executive Risk View

By approximately day 90, leadership should be able to answer a practical set of questions:

  • What are our most important cyber risks?
  • Which ones require executive decisions?
  • What has improved since the engagement started?
  • Which weaknesses remain?
  • Where are we accepting risk?
  • What must happen next quarter?
  • What investment is required?

If executives still receive only lengthy technical reports with no clear decisions or ownership, the engagement has not yet closed the gap between cybersecurity operations and business governance.

What Should Happen After the First 90 Days?

A vCISO engagement becomes valuable over time when governance continues rather than stopping after the initial assessment.

Monthly activity might include risk-register updates, roadmap tracking, remediation reviews, security operations discussions, major vulnerability decisions, policy work, supplier reviews, and consultations on technology or business changes.

Quarterly activity can move higher up the management chain. Depending on the organization's governance structure, that could include executive risk reporting, security committee meetings, key performance indicator (KPI) and key risk indicator reviews, budget discussions, compliance status, roadmap reprioritization, and strategic decisions.

Annual planning may involve refreshing the cybersecurity strategy, reviewing budgets, reassessing risks, updating the roadmap, and aligning the program with changes to the organization, threat landscape, and applicable requirements.

The schedule should match business need. A high-change organization introducing new cloud platforms and acquisitions may require much more frequent strategic involvement than a smaller, stable environment.

Retainer, Project and Fractional vCISO Engagement Models

Not every organization needs the same commercial arrangement.

A project engagement works best when the objective has a defined beginning and end. Examples could include developing a cybersecurity strategy, conducting a governance assessment, establishing a risk-management program, or preparing a prioritized improvement roadmap.

A retainer makes more sense when the organization needs continuing access to strategic leadership. The scope can specify meetings, reporting, roadmap oversight, policy activity, advisory availability, and recurring governance responsibilities rather than promising an ambiguous block of "consulting."

A fractional CISO model typically provides deeper recurring involvement while remaining external. The adviser may participate routinely in executive discussions and security governance, coordinate multiple workstreams, and act as a regular security leadership resource.

The terminology is less important than the contract. Two providers can both offer "fractional CISO Saudi Arabia" services while proposing completely different levels of involvement. Buyers should compare deliverables, decision responsibilities, availability, escalation arrangements, on-site requirements, reporting cadence, and exclusions.

Hours matter for capacity planning, but outcomes determine whether the engagement works.

Working With Internal IT, an MSP and a SOC or MSSP

One of the most valuable functions of external cybersecurity leadership is creating alignment between teams that see different pieces of the same risk.

Consider vulnerability management. The SOC or vulnerability platform detects a serious weakness. Internal IT understands the affected server and application. An MSP may control the infrastructure. The application vendor may need to approve or provide an update. A business owner knows whether downtime is acceptable.

Who decides what happens next?

Without governance, the vulnerability can remain trapped between teams, with everybody participating but nobody truly accountable for resolution.

The vCISO can establish prioritization criteria, require an owner and treatment plan, escalate overdue risk, and report unresolved exposure to management. Technical execution remains with the appropriate operational team.

The same model applies to incidents. A SOC might detect and investigate suspicious activity, but an incident can quickly require business decisions about containment, system shutdowns, recovery, legal or regulatory escalation, communications, and customer impact.

Strategy, monitoring, and execution need to connect.

This separation is particularly useful when Cyberactics provides Advisory and vCISO services alongside relevant managed cybersecurity and SOC, Microsoft security, or managed IT capabilities. The engagement scope should still state who advises, who operates controls, who independently reviews them, and who remains accountable inside the customer organization.

NCA ECC Governance Requires Careful Role Definition

Organizations within the scope of Saudi Arabia's ECC need to pay particular attention to how an external vCISO fits into their governance structure.

Under ECC 2-2024, in-scope entities must establish a cybersecurity department that is independent from the Information Technology and Communications Department. The controls also require all cybersecurity positions to be filled by full-time and qualified Saudi cybersecurity professionals.

ECC governance also reaches beyond staffing. It requires a documented, approved, and supported cybersecurity strategy and an action plan to implement that strategy.

External advisory can help an organization build the strategy, assess gaps, structure the action plan and broader roadmap, develop governance material, and support implementation. It should not be presented as substituting for internal positions or accountability required by an applicable control.

That distinction belongs in the provider conversation before the contract is signed.

SAMA Makes the Internal Accountability Point Even Clearer

Organizations subject to the Saudi Central Bank Cyber Security Framework need an equally precise view of CISO as a Service.

The SAMA Cyber Security Framework requires a cybersecurity function that is independent from the IT function and provides for a full-time senior manager for that function, referred to as the CISO. Its governance provisions require the CISO to be a Saudi national, sufficiently qualified, and assigned subject to SAMA's no-objection.

The framework states that ultimate responsibility for cybersecurity rests with the board and assigns defined responsibilities to the cybersecurity committee, CISO, and other stakeholders.

For a Member Organization subject to these requirements, an external adviser may provide specialist advice, additional capacity, assessments, program support, or other agreed services. That does not mean a fractional external provider automatically satisfies the framework's CISO and cybersecurity-function governance requirements.

Organizations should map the proposed engagement against their precise regulatory obligations and seek authoritative interpretation where necessary. SAMA states that it is solely responsible for providing interpretations of the framework's principles, objectives, and control considerations.

What vCISO Services Mean Across the GCC

Saudi Arabia illustrates why regional cybersecurity advisory needs local context.

An organization operating across Riyadh, Abu Dhabi, and Muscat may want one consistent cybersecurity strategy, common risk terminology, and a consolidated executive view. That consistency can simplify governance across the wider Gulf Cooperation Council (GCC) and support organizations managing shared technology across the Middle East and North Africa (MENA).

It does not make regulatory requirements interchangeable.

Requirements applicable to a Saudi entity should not automatically be applied to its UAE or Oman operations as legal obligations. Conversely, requirements affecting a UAE or Omani entity cannot be assumed to be satisfied merely because the group follows a Saudi framework.

A regional vCISO engagement should therefore distinguish group-wide security standards from jurisdiction-specific regulatory obligations. The organization can maintain a common control baseline while mapping each legal entity, business activity, system, and data set to the requirements that actually apply.

That distinction becomes particularly useful as GCC businesses centralize cloud services, Microsoft 365, identity, SOC operations, and shared infrastructure while operating legal entities in several jurisdictions. The vCISO can help maintain the common governance view while ensuring that Saudi Arabia, the UAE, Oman, and other operating locations are treated according to their own applicable requirements rather than as a single regulatory environment.

When External vCISO Support Does Not Replace Internal Accountability

"Outsourced" can describe delivery. It should not be interpreted automatically as transferred accountability.

This is important even for businesses that are not subject to a regulation requiring a specific internal cybersecurity position.

Executives still decide risk appetite and investment. Business owners understand operational consequences. Authorized risk owners determine whether particular business risks are accepted in accordance with the organization's governance structure. Internal stakeholders authorize material changes and decide how the organization responds during serious disruption.

A provider can improve those decisions with expertise, evidence, and structured governance. It cannot become the organization itself.

The clearest vCISO arrangements therefore document several distinct responsibilities: who identifies risk, who recommends treatment, who approves expenditure, who implements controls, who verifies implementation, who accepts residual risk, who communicates with regulators where applicable, and who makes decisions during incidents.

That responsibility model is as important as the technical scope.

Questions to Ask a Saudi vCISO Provider

Provider evaluation should move quickly beyond "How experienced are your consultants?" Ask prospective providers questions that reveal how the engagement will actually operate:

  • What concrete deliverables should we expect after 30, 60, and 90 days?
  • How will you establish which Saudi regulatory requirements actually apply to us?
  • How do you build and maintain the cybersecurity risk register?
  • Who owns risks and accepts residual risk in your engagement model?
  • How will you convert assessment findings into a prioritized and budgeted roadmap?
  • What will our executives or board receive each month or quarter?
  • How do you measure progress without overwhelming management with technical metrics?
  • How will you work with our IT team, MSP, SOC, MSSP, and other vendors?
  • What is your role during a serious incident?
  • Which activities do you perform directly, and which remain our responsibility?
  • How do you handle conflicts where the provider advising on controls also operates those controls?
  • How is our documentation, risk register, and governance material maintained and handed over if the engagement ends?
  • If ECC, SAMA, or another Saudi framework applies, which responsibilities must remain within our organization?
  • What assumptions or exclusions in your proposal could require additional services later?
  • What access, time, and executive sponsorship do you need from us for the engagement to succeed?

The quality of the answers matters, but so does specificity. A credible provider should be able to explain what it will produce and how it will work with the organization without implying that an external contract makes internal governance obligations disappear.

Buy Cybersecurity Leadership, Not a Job Title

The first 90 days of a Saudi vCISO engagement should leave the organization with something substantially more useful than a security presentation.

Management should understand its major cybersecurity risks. Regulatory applicability should be clearer. Responsibilities should be documented. A working risk register and prioritized roadmap should exist. Technical teams and providers should know what they own. Executives should receive concise information that helps them make decisions.

From there, the vCISO's role is to keep that system moving: challenge priorities, track unresolved risk, guide investment, oversee governance, and connect technical security activity with business resilience.

For some organizations, this external model can provide the level of strategic guidance they currently need. Others, particularly where regulatory requirements or operational complexity demand dedicated internal leadership, will need an in-house CISO with external advisory used as additional capacity. The engagement should be designed around that reality rather than around the word "virtual."

Cyberactics provides Advisory and vCISO services for organizations in Saudi Arabia and across the GCC, alongside cybersecurity assessments, managed cybersecurity and SOC, cloud and Microsoft security, compliance and risk, and managed IT services. Organizations evaluating a vCISO engagement can use that support to define the required scope, first-90-day priorities, governance interfaces, and longer-term cybersecurity roadmap before those responsibilities become another ambiguous line in a services contract.

#vCISO services Saudi Arabia#CISO as a Service Saudi Arabia#fractional CISO Saudi Arabia#NCA ECC 2-2024#SAMA Cyber Security Framework
CY

Cyberactics Security Team

Advisory & vCISO

We help SMBs across Jordan, Saudi Arabia, and the UAE run secure, automated IT - from Zero Trust rollouts to ISO 27001 certification.

Ready to start?

Want the runbook behind this article?

Book a 30-minute call with one of our senior engineers and we'll walk you through the templates we deploy for clients across the MENA region.