SAK Get your exposure reportFree report
SAK Services · flagship engagement

A security executive without the executive hire

Gulf organisations facing NCA ECC, SAMA CSF and PDPL obligations rarely need a full-time CISO before they need the compliance. Our vCISO carries the mandate, with accredited partner capacity behind them.

Available now

vCISO — mandate, roadmap and regulator readiness

A named security executive who owns the program, reports to your board in Arabic or English, and is accountable to the regulator's timeline rather than a consulting statement of work.

  • Security strategy mapped to NCA ECC domains and your sector regulator's expectations
  • A risk register your board can read (5×5) and your CFO can price (FAIR)
  • SAMA CSF maturity uplift plan for regulated financial institutions
  • PDPL readiness: lawful basis, cross-border transfer, breach notification, DPO duties
  • Aramco CCC / SACS-002 supplier certification path where it applies
  • Incident response plan written, tested and rehearsed with your executive team
  • Security strategy and a 12-month roadmap costed against Essential Eight maturity targets
  • A risk register your board can read (5×5) and your CFO can price (FAIR)
  • Essential Eight ML1 → ML2 uplift plan with the evidence assessors actually ask for
  • Incident response plan written, tested and rehearsed with your executive team
  • Third-party and supply-chain assessment for your critical vendors
  • Security input to tenders, customer due diligence and cyber insurance renewals
2 daysminimum engagement / month
AR + ENboard reporting
Remotefirst, on-site when it counts

What lands on the board table

  • Quarterly board pack in Arabic and English, generated from live control evidence
  • NCA ECC compliance position by domain, with gaps and owners named
  • SAMA CSF maturity level and the specific evidence holding you at it
  • Third-party and supplier cybersecurity status across the register
  • Top five risks with financial exposure, not a heat map of coloured squares
  • Quarterly board pack generated from live control evidence, not last quarter's memory
  • Essential Eight maturity scorecard, strategy by strategy
  • Notifiable data breach readiness under the Privacy Act, with the 30-day clock mapped
  • SOCI and APRA CPS 230 obligation status where they apply to you
  • Top five risks with dollar exposure, not a heat map of coloured squares
Book a vCISO discovery call

Arabic and English reporting · partner-delivered execution · data residency options in KSA

Scope

The eight domains a SAK vCISO owns

Not a menu to pick from — all eight are in scope from day one. What changes between tiers is depth and cadence, not coverage.

Domain 01

Security strategy & roadmap

Current state assessed in the first fortnight, a target state defined against the framework that actually binds you, and a costed 12-month roadmap with sequencing, owners and dependencies — re-baselined quarterly, not written once and filed.

Roadmap tracked in GRCorb
Domain 02

Governance

The full branded policy set — information security, acceptable use, access control, cryptography, supplier security, secure development, continuity, incident response — plus the machinery around it: roles, a steering group with a standing agenda, an exception register with expiry dates, and an annual management review.

Satisfies ISO 27001 clause 9.3
Domain 03

Risk management

A register your board can read (5×5, plain language) and your CFO can price (FAIR quantification on the top risks, in dollars). A written risk appetite statement, so "acceptable" stops being a matter of opinion. Treatment plans with named owners and due dates.

ISO 31000 · FAIR
Domain 04

Compliance & certification

Framework selection and scoping, gap assessment, and an evidence program configured once and then collecting continuously — rather than assembled in a panic before an audit. Your assessor works inside the platform. Covers NCA ECC, SAMA CSF, PDPL, Aramco CCC (SACS-002), NDMO data standards, ISO/IEC 27001:2022 and PCI DSS v4.0.1.

Gulf frameworks mapped natively in GRCorb · Arabic reporting
Domain 05

Third-party & supply chain risk

A vendor register tiered by the access each supplier actually has. Security requirements written into contracts and renewal checklists. Assessments proportionate to tier — not a 300-question spreadsheet for the company that supplies your coffee.

Monitored by SAK Vendor
Domain 06

Technical standards & oversight

Identity and MFA, privileged access, patching SLAs by severity, logging and retention, backup and restore testing, cloud baselines, endpoint hardening, secure development. The vCISO sets the standard and verifies it is met; your team does the hands-on work.

Each becomes a control with evidence attached
Domain 07

Incident readiness & response

An incident response plan written for your organisation, playbooks for the scenarios that actually apply to you, an annual tabletop with your executive team, and a breach-notification decision tree mapped to your obligations. When something happens, the vCISO leads the executive response.

PDPL notification duties · NCA incident reporting
Domain 08

Business enablement

Security questionnaires and RFP responses answered properly and fast. Customer due-diligence calls attended, so sales isn't defending a control set it doesn't understand. Cyber insurance renewals, board and investor reporting, security diligence for funding or acquisitions.

Where the retainer pays for itself
Domain 01

Security strategy & roadmap

Current state assessed in the first fortnight, a target state defined against the framework that actually binds you, and a costed 12-month roadmap with sequencing, owners and dependencies — re-baselined quarterly, not written once and filed.

Roadmap tracked in GRCorb
Domain 02

Governance

The full branded policy set — information security, acceptable use, access control, cryptography, supplier security, secure development, continuity, incident response — plus the machinery around it: roles, a steering group with a standing agenda, an exception register with expiry dates, and an annual management review.

Satisfies ISO 27001 clause 9.3
Domain 03

Risk management

A register your board can read (5×5, plain language) and your CFO can price (FAIR quantification on the top risks, in dollars). A written risk appetite statement, so "acceptable" stops being a matter of opinion. Treatment plans with named owners and due dates.

ISO 31000 · FAIR
Domain 04

Compliance & certification

Framework selection and scoping, gap assessment, and an evidence program configured once and then collecting continuously — rather than assembled in a panic before an audit. Your assessor works inside the platform. Covers Essential Eight (ML1 → ML3), ISO/IEC 27001:2022, SOC 2, the Privacy Act and Notifiable Data Breaches scheme, the SOCI Act risk management program, APRA CPS 234 and CPS 230, and ISM/IRAP where you sell to government.

Australian frameworks mapped natively in GRCorb
Domain 05

Third-party & supply chain risk

A vendor register tiered by the access each supplier actually has. Security requirements written into contracts and renewal checklists. Assessments proportionate to tier — not a 300-question spreadsheet for the company that supplies your coffee.

Monitored by SAK Vendor
Domain 06

Technical standards & oversight

Identity and MFA, privileged access, patching SLAs by severity, logging and retention, backup and restore testing, cloud baselines, endpoint hardening, secure development. The vCISO sets the standard and verifies it is met; your team does the hands-on work.

Each becomes a control with evidence attached
Domain 07

Incident readiness & response

An incident response plan written for your organisation, playbooks for the scenarios that actually apply to you, an annual tabletop with your executive team, and a breach-notification decision tree mapped to your obligations. When something happens, the vCISO leads the executive response.

Privacy Act serious-harm test · 30-day OAIC clock · SOCI reporting
Domain 08

Business enablement

Security questionnaires and RFP responses answered properly and fast. Customer due-diligence calls attended, so sales isn't defending a control set it doesn't understand. Cyber insurance renewals, board and investor reporting, security diligence for funding or acquisitions.

Where the retainer pays for itself
Who you get

One named executive, one standard behind them

You are not buying a personality, and you are not buying a pool. You are assigned one named security executive who works to a method the whole practice shares — so what you get does not depend on which individual you happened to draw.

Assigned, not pooled
You get one named executive for the life of the engagement, introduced by name at proposal stage — before you sign, not after. They chair your leadership meeting and they present to your board.
The minimum bar
Every SAK vCISO holds CISSP or CISM, has held security leadership accountability inside a regulated organisation, and has taken at least one organisation through a certification end to end.
Matched to you
Matched on sector and on the framework that binds you. The vCISO who took a scale-up through Essential Eight is not automatically the right one for a SAMA-regulated bank.
A named second
Every engagement has a named backup who attends the quarterly review and can step in without a handover period. Your program does not depend on one person's calendar, health or notice period.
How we work
Remote-first, in Gulf working hours, with Arabic and English reporting. On-site for the kickoff, the annual tabletop, and board meetings where being in the room matters. Additional on-site days can be added to any tier.
Why the bench is the point
Every SAK vCISO runs the same method: the same discovery on SAK Surface, the same control library in GRCorb, the same risk model, the same board-pack format. Consistency is engineered, not hoped for — which is also why we can scale without the quality drifting.
Assigned, not pooled
You get one named executive for the life of the engagement, introduced by name at proposal stage — before you sign, not after. They chair your leadership meeting and they present to your board.
The minimum bar
Every SAK vCISO holds CISSP or CISM, has held security leadership accountability inside a regulated organisation, and has taken at least one organisation through a certification end to end.
Matched to you
Matched on sector and on the framework that binds you. The vCISO who took a scale-up through Essential Eight is not automatically the right one for an APRA-regulated insurer.
A named second
Every engagement has a named backup who attends the quarterly review and can step in without a handover period. Your program does not depend on one person's calendar, health or notice period.
How we work
Remote-first, in Australian working hours — your vCISO is in your meetings, on your calendar and reachable in your day, not catching up overnight. On-site for the kickoff, the annual tabletop, and board meetings where being in the room matters. Additional on-site days can be added to any tier.
Why the bench is the point
Every SAK vCISO runs the same method: the same discovery on SAK Surface, the same control library in GRCorb, the same risk model, the same board-pack format. Consistency is engineered, not hoped for — which is also why we can scale without the quality drifting.
Boundaries

What the retainer does not cover

Almost nobody publishes this. We do, because an engagement that starts with an unspoken assumption ends badly — and because the buyer who reads this section carefully is the buyer worth having.

Not includedWhat happens instead
24/7 monitoring and alert triageWe do not offer round-the-clock monitoring. Managed exposure covers continuous external discovery in business hours; where genuine 24/7 operations are required we will say so and help you select a provider.
Hands-on remediation and engineeringThe vCISO sets the standard and verifies it. The work is done by your team, or scoped as a separate SAK engagement.
Being the on-call responder at 3amThe vCISO leads the executive response to an incident — decisions, comms, notification, post-incident review. They are not the person staffing a rota.
Penetration testingA separate engagement, deliberately. A tester should not assess controls they helped design.
Legal advice and regulatory filingsWe prepare the facts and draft the notification content. Your lawyer advises and files.
Statutory roles that require an employeeSome regulator-facing designations must sit with an officer of your entity. The vCISO supports the person holding it; they cannot be it.
Unlimited availabilityDays are fixed per tier. Incident surge time is agreed and billed at the time, not absorbed silently.
Engagement tiers

Three levels, one minimum term

Minimum one quarter, then month to month. Anything shorter doesn't produce something worth paying for — the first ninety days is where the value is created.

EssentialsStandardEmbedded
Days per month248
Typical fit20–80 staff, first framework, insurance or customer pressure80–300 staff, certifying, regulated, or selling to enterpriseRegulated entity, multi-framework, or post-incident rebuild
Leadership meetingMonthlyFortnightlyWeekly
Board reportingQuarterlyQuarterly + on requestQuarterly + committee attendance
Frameworks in scope1Up to 2Unlimited
Incident response leadershipBusiness hoursBusiness hours + escalationBusiness hours + escalation
Platforms includedSAK Surface + GRCorbFull SAK Exposure + GRCorbFull SAK Exposure + GRCorb

Priced as a flat monthly retainer, not a day rate. Arabic and English board reporting. Minimum one quarter, then month to month.

Onboarding

The first 90 days

A vCISO who spends the first month "getting up to speed" has wasted a sixth of the year. SAK Exposure does discovery on day one, so the assessment starts with facts rather than a questionnaire.

  1. Days 1–14

    Discovery

    Stakeholder interviews. A SAK Surface baseline of everything internet-facing, including what nobody remembered owning. Asset and vendor registers built from discovery, not from a questionnaire.

  2. Days 15–30

    Assessment

    Gap assessment against the chosen framework. Risk register v1. Roadmap costed and sequenced. First leadership presentation: here is where you are, here is what it costs to get where you need to be.

  3. Days 31–60

    Foundations

    Branded policy pack issued. Incident response plan written. Quick wins started — MFA coverage, patching SLA, restore testing, privileged account cleanup. Evidence collection configured, so proof starts accumulating.

  4. Days 61–90

    Operating rhythm

    First board pack. Tabletop exercise with the executive team. Tier-1 vendor assessments underway. The roadmap moves from a document to a tracked program.

What we need from you

  • An executive sponsor with authority to decide — without one, a vCISO produces recommendations nobody acts on
  • Read-only access for evidence collection: cloud tenants, identity provider, endpoint console
  • A named technical counterpart who can implement
  • Attendance at the monthly leadership meeting
  • Honesty in discovery — we will find what is there anyway, and finding it early is cheaper

What you have after 90 days

  • A costed roadmap your board has seen and approved
  • A complete, branded policy set with evidence attached to each control
  • A risk register in both board language and dollars
  • An incident response plan that has been rehearsed, not just written
  • Continuous control evidence accumulating without anyone chasing it
  • A named executive accountable for all of it
Next step

A 20-minute call, then a written proposal

We confirm scope and the framework that binds you, then send a written proposal with a fixed monthly retainer — and the executive you would get, introduced by name before you sign.

Book a vCISO discovery call