Banking and financial services · SAMA

IT and cyber security built for SAMA’s expectations.

Managed IT, Microsoft 365 governance and cyber security for banks, insurers, finance companies and other firms that answer to SAMA, from an ISO 27001:2022 certified team with an office in Riyadh.
Built for financial institutions

A financial institution’s IT is more than uptime

The SAMA Cyber Security Framework expects documented, owned and monitored controls, a maturity level of at least 3, and oversight of the third parties you rely on. Your compliance team should not have to chase screenshots.
Cre8 IT runs the technical controls you own and produces the records that show they work: monthly reports on multi-factor authentication, patching and backups, access reviews and incident readiness. You keep governance and accountability. We make the evidence easy to find.

What financial institutions ask us for

What the regulator expects

How we support the SAMA Cyber Security Framework

The framework has four domains. These are the areas a reviewer is likely to test and what we do for each.

Leadership and governance (3.1)

Your board and management own cyber security. We document the technical controls your policies rely on and keep them current.

Risk and compliance (3.2)

A live asset register and inputs from our reports, so your risk register rests on real data.

Operations and technology (3.3)

Multi-factor authentication, Conditional Access, device management, patching, encryption, backup and logging, reported monthly.

Maturity level 3 evidence

Documented, approved, owned and monitored: for each control area we help you show a policy, an owner, a dated record and a review.

Third parties (3.4)

You assess your providers, and we expect to be assessed like any provider: certificate and scope, contract terms and where each service is delivered from.

Incident readiness

A written, exercised incident plan with clear roles. We help you agree who decides, rehearse it and keep the logs you will need.
Summary for orientation, checked against the regulators’ published text on 20 September 2026. Confirm the current wording with the regulator. This is not legal advice.

Where we help on data protection

Data protection

The PDPL and financial data

The Saudi Personal Data Protection Law (PDPL) has been fully enforceable since 14 September 2024 and is overseen by SDAIA. It treats credit data as sensitive data, and a controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it.
Access control, encryption, logging and retention are IT jobs, and we implement them. What personal data you hold, your lawful basis and your notices are legal jobs for your data protection lead or legal adviser.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against the SAMA framework’s domains, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance lead can use.

4. Operate

Helpdesk and regular reviews, with reports written for your management and governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

We have supported businesses since 2012. Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
In Saudi Arabia we support Union Bancaire Privée KSA (UBP Saudi Arabia), which is licensed by the Capital Market Authority. In the UAE we also support a regulated advisory and investment firm, and helped it start small and grow fast.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for financial institutions

Sourced to the regulator’s own text, dated and written by a named specialist.
SAMA

SAMA Cyber Security Framework: what Saudi financial institutions need to evidence

Who the SAMA Cyber Security Framework applies to, its four domains, the maturity level SAMA expects and the IT evidence a member organisation keeps.
3 min read · Reviewed 20 September 2026
Third-party risk

Choosing and overseeing an IT provider in Saudi Arabia: third-party risk

What NCA ECC and the SAMA framework expect of your IT provider contracts, the in-Kingdom rule for remote monitoring centres and the questions to ask.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
FAQ

SAMA and financial services questions

What does IT support for a SAMA-regulated firm include?

Beyond a helpdesk, it includes secure configuration of identity, devices and Microsoft 365, patching and backup, incident readiness and the regular reports that become your evidence. We help you map these to the SAMA framework’s domains.

Can you write our cyber security policies?

We can help draft and maintain the technical standards and supporting procedures. Your policies must be approved and owned by your management and governing body, so we work alongside your compliance team rather than in place of it.

Does using Cre8 IT make us compliant with the SAMA framework?

No provider can. You remain responsible for your obligations. We run and evidence the technical controls, help you prepare for reviews, and expect you to assess us as you would any provider.

Do you have an office in Riyadh?

Yes. Our Riyadh office is at Building 3074, Level 29, Tower B, Olaya Towers, Prince Mohammed Bin Abdulaziz Road.

Who is responsible if our IT provider has an incident?

You remain accountable for your regulatory obligations. That is why contracts should require prompt incident notification and why you should supervise the provider. See our third-party risk guide.

Talk to a specialist about your SAMA obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.