
Building a SOC in Saudi Arabia: Build, Buy or Co-Manage?
The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

Two penetration tests with the same budget can produce radically different value. One examines the systems attackers would actually target, with enough time and access to go deep. The other skims a list of hosts and reports automated scanner output. The difference is almost always decided before testing starts — in the scope.
In the Kingdom, many tests are driven by regulation: the NCA Essential Cybersecurity Controls include a dedicated penetration-testing requirement, and SAMA-regulated institutions are expected to test regularly under the SAMA Cyber Security Framework. Compliance is a valid driver — but a good scope still answers one practical question: what do we need to know?
The objective determines everything else: which assets, which approach, how much time and what the report must say.
Ambiguity in the asset list is the most common cause of disputes and disappointing results. Specify:
| Approach | What the tester knows | Best for |
|---|---|---|
| Black box | Nothing beyond the target | Simulating an uninformed external attacker |
| Grey box | Credentials for defined roles and basic documentation | Most application and internal tests — the best balance of realism and depth |
| White box | Architecture, source code and configuration | High-assurance reviews of critical systems |
Black-box testing sounds realistic, but it spends much of a fixed budget on discovery that real attackers would complete over weeks. Grey-box testing lets testers spend their time finding and proving vulnerabilities.
Agree the deliverables before testing begins. A useful report contains:
Day rate is the least useful comparison. Ask each provider for the effort in person-days per asset, the methodology they follow — such as the OWASP Web Security Testing Guide, PTES or NIST SP 800-115 — a sample report, the experience and certifications of the named testers, and whether retesting is included. A cheaper quote that allocates half the effort is not cheaper.

The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.