Bridgewell Tek symbol
Free Assessment+966 54 859 1369

Compliance · March 15, 2026 · 10 min read

SAMA Cyber Security Framework 2024: What Saudi Banks Need to Know

The SAMA Cyber Security Framework turns cybersecurity from a technical checklist into a governed business capability. Here is how regulated organizations can translate its control objectives into a cloud operating model.

SAMA-regulated institutions operate in an environment where confidentiality, integrity, availability, third-party oversight, and evidence all matter. The SAMA Cyber Security Framework (CSF) provides a structured reference for building that capability. The framework should be read alongside SAMA's supervisory expectations, the organization's risk appetite, and the specific requirements that apply to its license and services.

Governance comes before tooling

A common implementation mistake is to begin by purchasing a security product. The stronger approach begins with accountability. The board and executive management should approve cybersecurity direction, risk appetite, and reporting. A security function should own the control framework, while business and technology owners remain accountable for the risks in their services.

Create a control register that maps each applicable CSF domain and subdomain to an owner, policy, procedure, technical implementation, evidence source, test frequency, and remediation target. This turns an audit request into an operating rhythm. Exceptions should have an owner, expiry date, compensating control, and approval level.

Secure the cloud foundation

Cloud adoption is compatible with regulated workloads when the landing zone is designed deliberately. Separate production, non-production, security, logging, and recovery accounts or subscriptions. Apply organization-wide guardrails for regions, encryption, public exposure, identity providers, and approved services. Prevent teams from creating resources outside the approved baseline without an accountable exception.

Use infrastructure as code and policy-as-code to make the desired state reviewable. The landing zone should provide private connectivity, segmented networks, centralized security logs, managed key services, vulnerability scanning, and a controlled administrative path. Every account should have an owner and a documented purpose.

Identity is the primary control plane

Strong identity controls reduce the blast radius of compromised credentials. Integrate cloud accounts with a central identity provider, require multifactor authentication, and remove standing privileged access wherever possible. Use role-based access, just-in-time elevation, approval workflows, and session logging for administrative actions.

Service identities deserve the same discipline as people. Rotate secrets, prefer workload identity, scope permissions to the smallest useful boundary, and inventory every machine credential. Review access on a schedule and after role changes. A quarterly spreadsheet review is weaker than an automated entitlement report tied to an owner and an approval record.

Detect, investigate, and preserve evidence

Prevention alone is not enough. Centralize identity, network, endpoint, application, database, and cloud control-plane events in a protected logging platform. Establish time synchronization, retention periods, access restrictions, and integrity controls. Define which events generate alerts and which are retained for investigation.

Detection engineering should focus on meaningful scenarios: impossible travel, privilege escalation, disabled logging, unusual data exports, public resource creation, suspicious federation changes, and anomalous access to sensitive systems. Every alert needs a triage owner, severity model, escalation path, and evidence trail.

Resilience and recovery are security outcomes

Availability and recoverability must be tested, not assumed. Classify services by business impact and define recovery time and recovery point objectives. Keep backups isolated from production credentials, encrypt them, restrict deletion, and test restoration. A recovery environment should be protected against the same identity and network failures that affect production.

Run exercises that include ransomware, cloud-region disruption, identity-provider outage, data corruption, and compromised administrator accounts. Measure time to detect, contain, restore, and communicate. Record lessons and track them to closure.

Manage third-party and supply-chain risk

Cloud providers, managed security services, software vendors, and integration partners can materially affect the institution's risk. Classify suppliers by criticality, perform due diligence, define security obligations in contracts, and monitor service performance. Review subcontractors, support access, data locations, breach notification, and exit plans.

For cloud services, document the shared-responsibility boundary. The provider may secure the underlying infrastructure, but the institution still controls identities, configurations, data classification, application logic, and many logging decisions. Make that boundary visible in architecture diagrams and control evidence.

A practical implementation sequence

Start with scope, asset inventory, critical services, and a current-state assessment. Next, remediate identity, public exposure, logging, encryption, and backup gaps. Then establish continuous configuration monitoring and evidence collection. Finally, test incident response and recovery with executives, technology, risk, legal, and key providers.

Use the CSF as a living management system rather than an annual audit project. SAMA readiness improves when controls are embedded in the way teams provision, deploy, monitor, and retire cloud services. The goal is not merely to produce a binder of policies; it is to demonstrate that security decisions are owned, enforced, observed, and improved.

Written by Aslan Ussayev, CTO, Bridgewelltek. This article is educational and does not constitute regulatory or legal advice. Refer to the applicable SAMA Cyber Security Framework and supervisory requirements for authoritative obligations.