Avenlor
Home / Insights / Compliance
Compliance

Cybersecurity Governance and NCA Compliance

Cybersecurity has become a governance question, not only a technical one. The questions we hear most about board-level oversight and the NCA's Essential Cybersecurity Controls.

Avenlor ConsultingGovernance & Internal Controls6 min read

Cybersecurity used to sit entirely with IT. It no longer does — regulators, insurers, and boards increasingly expect to see the same governance discipline applied to cyber risk that applies to financial or operational risk. Here are the questions we're asked most.

What is the Essential Cybersecurity Controls (ECC) framework?

The ECC is the baseline cybersecurity framework issued by Saudi Arabia's National Cybersecurity Authority (NCA), setting minimum controls across governance, defense, resilience, and third-party cybersecurity that government entities and critical national infrastructure organizations must implement, and that many private-sector companies now adopt as the de facto standard.

Is cybersecurity a board-level responsibility, or an IT matter?

Both, but governance frameworks increasingly treat it as a board-level responsibility — the board sets risk appetite for cyber exposure, ensures adequate resourcing, and receives regular reporting on the organization's security posture, while IT and security teams execute the technical controls that answer to that oversight.

Who should own cybersecurity governance day to day?

A named individual — a Chief Information Security Officer (CISO) or equivalent — with a reporting line that gives them enough independence to escalate a security concern about a business unit's practices, and a mandate that extends to reviewing third-party and vendor access, not only internal systems.

What does the ECC expect in terms of governance structure?

A documented cybersecurity strategy and policy approved by senior leadership, a named accountable owner, a risk assessment process specific to cyber threats, and defined roles and responsibilities — the same governance discipline expected of financial or operational risk, applied to cyber.

How does third-party and vendor risk fit into cybersecurity governance?

Any vendor with access to company systems or data extends the organization's attack surface, so the ECC and similar frameworks expect vendor risk assessments before onboarding, security requirements written into contracts, and periodic review of vendor access — treating third-party cybersecurity as part of the same governance perimeter, not a separate concern.

What should the board actually see on cybersecurity?

A regular, non-technical summary: the organization's risk posture relative to appetite, significant incidents and how they were handled, the status of any regulatory findings, and progress against the security roadmap — not a raw vulnerability scan, which is a technical working document for the security team.

What is an incident response plan, and why does it need board visibility?

It is the documented, tested process for detecting, containing, and recovering from a security incident, with defined roles for who decides what and when. The board needs visibility because a serious incident is a business continuity and reputational event, not only a technical one, and the organization's response in the first hours often determines how much damage it causes.

How often should cybersecurity controls be tested and reviewed?

At minimum annually, through a combination of vulnerability assessments, penetration testing, and a tabletop exercise that rehearses the incident response plan with actual decision-makers — testing that a plan exists is not the same as testing that it works under pressure.

What cybersecurity governance needs to work

  • A documented strategy and policy approved by senior leadership
  • A named, accountable owner with real independence
  • Vendor and third-party access reviewed with the same rigor as internal systems
  • Regular, non-technical reporting to the board on posture and incidents
  • A tested incident response plan with defined decision rights
  • Annual testing — vulnerability assessment, penetration testing, and a tabletop exercise

The organizations that handle a security incident well are rarely the ones with the most sophisticated tools — they're the ones that treated cyber risk as a governance question long before the incident happened, with clear ownership and a board that was already paying attention.

Need cybersecurity governance that satisfies the board and the regulator?

We design cybersecurity governance frameworks — policy, oversight structure, and board reporting — aligned to the ECC and built to work under pressure.

Discuss your mandate →

Read next

Building an Enterprise Risk Management Framework → PDPL Compliance in Saudi Arabia: A Governance Approach →

This article is general guidance on governance practice and does not constitute legal, audit, or regulatory advice. Requirements depend on your circumstances and the applicable regulations at the time; obtain professional advice for your specific engagement.