
VAPT in Saudi Arabia: How to Scope a Penetration Test Properly
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.

A security operations centre is not a room full of screens. It is a capability that continuously collects security telemetry, detects threats, investigates alerts, responds to incidents and improves detection over time. Whether that capability sits in-house, with a provider or somewhere between is a business decision — and it should be made on facts, not assumptions.
In the Kingdom, the NCA Essential Cybersecurity Controls require event log management and continuous security monitoring, and SAMA-regulated institutions face equivalent expectations. Whichever model you choose must produce evidence that meets them.
A year has 8,760 hours. A full-time analyst, after annual leave, public holidays, training and sickness, is typically available for around 1,600 to 1,800 hours. Covering a single seat around the clock therefore needs five to six analysts — before you add a team lead, a detection engineer, threat hunting or incident response specialists.
Most in-house SOC business cases underestimate this. A realistic minimum for a credible 24x7 in-house SOC is a team of eight to twelve people, plus the cost of recruiting and retaining them in a competitive market.
| In-house | Managed (MSSP / MDR) | Co-managed | |
|---|---|---|---|
| Control | Full | Shared through contract | High — you keep ownership of decisions |
| Time to capability | 12–24 months | Weeks | Weeks to a few months |
| Business context | Deepest | Must be transferred and maintained | Retained in-house |
| Cost profile | High fixed cost | Predictable subscription | Blended |
| Best for | Large, highly regulated organisations with scale | Organisations without a security team | Organisations with a small team that need 24x7 depth |
Alert counts and dashboards full of green tiles say little about protection. These measures tell leadership whether the investment is working:
Report these monthly and review them quarterly with the provider or team. A SOC whose metrics never change is not improving.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.