Saudi Arabia — Cyber Threat Profile

The National Cybersecurity Authority (NCA), whose statute was approved by Royal Order No. 6801 dated 11/02/1439H, is the national and specialised cybersecurity reference for the Kingdom, and the national CERT — Saudi CERT, established in 2019 — sits under it. The NCA published the National Cybersecurity Strategy in December 2020 and maintains the Essential Cybersecurity Controls, updated from ECC-1:2018 to ECC-2:2024 and now comprising 4 main domains, 28 subdomains, 108 main controls and 92 subcontrols, applicable to government agencies and their affiliated entities and to all private-sector entities owning, operating or hosting critical national infrastructure. Enforcement is backed by the Statutory Enablers of the NCA, issued by Royal Decree No. M/117 dated 21/06/1446H, under which a violations committee may impose fines of up to SAR 25 million, while the separate Personal Data Protection Law became fully enforceable on 14 September 2024. On the public record, the August 2012 Shamoon wiper compromised Saudi Aramco and affected some thirty-five thousand computers, an attack US intelligence sources attributed to Iran, and in July 2021 Aramco confirmed the indirect release of a limited amount of company data held by third-party contractors amid a $50 million extortion demand. Capacity is a documented constraint: the NCA reported a domestic cybersecurity market of SAR 15.2 billion in 2024, up 14 percent year on year, served by a workforce that surpassed 21,000 professionals, and ECC-2 additionally requires every cybersecurity position to be filled by full-time, qualified Saudi professionals, which narrows the hiring pool further.

Latest Saudi Arabia coverage

Threat actors targeting Saudi Arabia

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions