Security & Governance

Protect the data you have just spent a year making useful

Security and governance built into the data platform rather than bolted on afterwards — mapped to the frameworks your regulator actually audits against.

We design and evidence controls against the standards that matter in our regions

ISO/IEC 27001 SAMA CSF NCA ECC (KSA) UAE IA Standard PCI DSS NIST CSF GDPR PDPA (SG/MY) SBP Guidelines SOC 2
Capabilities

Security services, oriented around data

We are a data firm first. Our security practice exists because the platforms we build hold the most sensitive information our clients own — and because "the consultants left a wide-open S3 bucket" is a story we refuse to be part of.

Security Program Strategy

Current-state maturity assessment against a chosen framework, a prioritised remediation roadmap, and a governance operating model your board can actually approve and fund.

Risk & Compliance

Risk register design, control mapping across overlapping frameworks, third-party and vendor risk assessment, and audit-evidence packs that survive a regulator's questions.

Incident Management

Incident response plans, severity taxonomies, escalation paths and tabletop exercises — plus breach-notification playbooks aligned to each jurisdiction's timelines.

Threat & Vulnerability Management

Vulnerability scanning programmes, patch governance, cloud configuration review and secure-by-default baselines for the data platforms we and others have built.

Identity & Access Governance

Role design, least-privilege modelling, privileged access management, joiner-mover-leaver automation and periodic access recertification for warehouse and BI estates.

Data Governance

Data classification, ownership and stewardship models, business glossary, lineage, retention schedules and data-quality accountability — implemented in tooling, not slideware.

Platform security

Securing the warehouse itself

A cloud data warehouse concentrates risk: one platform ends up holding customer PII, financial records and commercial secrets that were previously scattered across systems with different blast radii. The controls have to match that concentration.

  • Column-level classification tagging propagated automatically through lineage
  • Dynamic data masking and tokenisation for PII, PCI and national ID fields
  • Row-level security enforced in the warehouse, not just in the BI tool
  • Customer-managed encryption keys where the regulator requires them
  • Private connectivity — no public endpoints on production data services
  • Immutable query and access audit logs shipped to a separate security account
customer.national_id masked
card.pan tokenised
branch_txn RLS on
access_audit_log immutable
Residency

Data residency across our regions

Residency requirements differ sharply between the jurisdictions we serve, and getting them wrong is expensive. We architect to the specific rule rather than to a generic "keep it in region" assumption.

In Saudi Arabia and the UAE that usually means in-country cloud regions with documented control over key management. In Pakistan, regulated financial data often stays on-premises or in local hosting with a cloud analytics layer over de-identified extracts. Across Singapore, Malaysia and Australia the constraint is more often cross-border transfer conditions than physical location.

  • Jurisdiction-by-jurisdiction control mapping before architecture is fixed
  • Hybrid patterns where a workload genuinely cannot move to cloud
  • De-identification pipelines that let analytics happen without moving raw PII
  • Documented transfer impact assessments for cross-border flows
KSA · in-country region compliant
UAE · in-country region compliant
PK · hybrid on-prem compliant
APAC · transfer assessed compliant
Engagements

Ways clients typically start

01

Data platform security review

Two weeks. We assess an existing warehouse or lakehouse against a control baseline and hand back a prioritised findings register with remediation effort estimates.

02

Framework readiness assessment

Four to six weeks. Gap analysis against SAMA CSF, NCA ECC, ISO 27001 or PDPA, with an evidence plan and a realistic timeline to audit readiness.

03

Governance implementation

Ongoing. Stand up classification, glossary, lineage and stewardship in tooling such as Collibra, Purview, Alation or the native catalog of your warehouse.

Find out where your data platform is exposed

A short review usually surfaces more than an annual audit does — because we know exactly where data teams cut corners under delivery pressure.