
ONE ASSESSMENT. EVERY FRAMEWORK YOU REPORT AGAINST.
The problem
A GCC financial institution with regional operations may be reporting against the SAMA Cyber Security Framework, NCA ECC-2:2024, the UAE Information Assurance Standard v2, ISO/IEC 27001:2022 and an internal NIST CSF 2.0 baseline — simultaneously.
In most organisations these are five separate exercises, run by different teams, on different cycles, producing different answers to the same underlying questions. The evidence is gathered repeatedly. The gaps are inconsistently rated. And the board receives five maturity scores that cannot be reconciled.
The overlap between these frameworks is substantial. The structures differ, the language differs, and the emphasis differs — but the underlying control expectations converge heavily. That overlap is exploitable, and almost nobody exploits it.
There is a second problem. Maturity scores do not tell a board anything actionable. "We are at Level 2.7 against a target of Level 3" is a statement about a document, not about risk. It cannot be compared against any other investment the board is considering.
OUR APPROACH
-
Gather evidence once. A single structured evidence set, mapped to multiple frameworks through the PRAECEPTA crosswalk.
-
Assess against outcomes, not checkboxes. We use the outcome-based logic of the NCSC Cyber Assessment Framework as our internal assessment engine — it produces materially better findings than checklist scoring — and report against whichever framework you are accountable to.
-
Report per framework, natively. SAMA in SAMA's language and maturity model. NCA in ECC-2 structure. Each output stands alone and is defensible to its own regulator.
-
Quantify the gaps financially. Using Open FAIR methodology, material gaps are expressed as probable annualised loss ranges rather than severity labels.
-
Prioritise by risk reduction per dirham. Once gaps carry financial values, sequencing becomes an investment decision rather than a negotiation.
-
Report to the board in terms it can act on. Monetary exposure, the reduction each investment buys, and the residual position. Not a heat map.
ENGAGEMENTS
01. Multi-Framework Gap Assessment
Typical duration: 15-25 days
Single assessment producing native outputs across multiple frameworks
02. Regulatory Change Impact Assessment
Typical duration: 5-10 days
Impact of a new or amended regulation on your architecture and control estate
03. Cyber Risk Quantification
Typical duration: 10-18 days
Open FAIR analysis of priority risk scenarios
04. Board Cyber Governance Uplift
Typical duration: 8-15 days
Board education, reporting pack design, risk appetite articulation
05. Cyber Resilience Assessment
Typical duration: 12-20 days
Outcome-based resilience review of essential functions
06. Third-Party Risk Architecture
Typical duration: 12-20 days
Vendor tiering model, assurance framework, SBOM strategy
