top of page
ONE ASSESSMENT. EVERY FRAMEWORK YOU REPORT AGAINST.
The problem

A GCC financial institution with regional operations may be reporting against the SAMA Cyber Security Framework, NCA ECC-2:2024, the UAE Information Assurance Standard v2, ISO/IEC 27001:2022 and an internal NIST CSF 2.0 baseline — simultaneously.

 

In most organisations these are five separate exercises, run by different teams, on different cycles, producing different answers to the same underlying questions. The evidence is gathered repeatedly. The gaps are inconsistently rated. And the board receives five maturity scores that cannot be reconciled.

 

The overlap between these frameworks is substantial. The structures differ, the language differs, and the emphasis differs — but the underlying control expectations converge heavily. That overlap is exploitable, and almost nobody exploits it.

 

There is a second problem. Maturity scores do not tell a board anything actionable. "We are at Level 2.7 against a target of Level 3" is a statement about a document, not about risk. It cannot be compared against any other investment the board is considering.

OUR APPROACH

  1. Gather evidence once. A single structured evidence set, mapped to multiple frameworks through the PRAECEPTA crosswalk.

  2. Assess against outcomes, not checkboxes. We use the outcome-based logic of the NCSC Cyber Assessment Framework as our internal assessment engine — it produces materially better findings than checklist scoring — and report against whichever framework you are accountable to.

  3. Report per framework, natively. SAMA in SAMA's language and maturity model. NCA in ECC-2 structure. Each output stands alone and is defensible to its own regulator.

  4. Quantify the gaps financially. Using Open FAIR methodology, material gaps are expressed as probable annualised loss ranges rather than severity labels.

  5. Prioritise by risk reduction per dirham. Once gaps carry financial values, sequencing becomes an investment decision rather than a negotiation.

  6. Report to the board in terms it can act on. Monetary exposure, the reduction each investment buys, and the residual position. Not a heat map.

ENGAGEMENTS

01. Multi-Framework Gap Assessment

Typical duration: 15-25 days

Single assessment producing native outputs across multiple frameworks

02. Regulatory Change Impact Assessment

Typical duration: 5-10 days

Impact of a new or amended regulation on your architecture and control estate

03. Cyber Risk Quantification

Typical duration: 10-18 days

Open FAIR analysis of priority risk scenarios

04. Board Cyber Governance Uplift

Typical duration: 8-15 days

Board education, reporting pack design, risk appetite articulation

05. Cyber Resilience Assessment

Typical duration: 12-20 days

Outcome-based resilience review of essential functions

06. Third-Party Risk Architecture

Typical duration: 12-20 days

Vendor tiering model, assurance framework, SBOM strategy

FRAMEWORKS APPLIED

NCA ECC-2:2024 · NCA CSCC · SAMA CSF · UAE Information Assurance Standard v2· CBUAE guidance · QCB · CBB · NIST CSF 2.0 · ISO/IEC 27001:2022 · NCSC CAF v4.0 · Open FAIR · NIST SP 800-161r1 · DORA and NIS2 for EU-exposed entities

bottom of page