Back to Blog
Insights17 min read

Cybersecurity Companies in Riyadh: 7 Firms Compared for 2026

A

Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

Cybersecurity Companies in Riyadh: 7 Firms Compared for 2026

We have probably seen your problem before. Our smallest client had eight employees. Our largest secures the nuclear power plant of the United Arab Emirates. Whatever shape yours is, tell us about it and we will tell you how we would fix it.

Saudi Arabia has the most prescriptive cybersecurity regime in the Gulf, and that is the single most important fact when choosing a provider here. The National Cybersecurity Authority publishes control frameworks that tell you what to implement rather than leaving it to your risk appetite, and compliance is assessed. This guide compares seven firms with a real Saudi presence, and explains which framework is likely to be yours.

Disclosure: this guide is published by Atlant Security, which appears at number 4 of 7 below. We are not a reseller or partner of any firm listed, none paid for placement, and none saw this before publication. Every company here was checked against its own live website on 14 September 2026. Strengths and weaknesses are our editorial judgement; each quoted line is taken verbatim from the firm’s own site.

What changed in this edition: This edition was rebuilt and corrects a significant error. Saher Flow Solutions was listed as an "OT Cybersecurity Specialist" and ranked third. It is not a cybersecurity company: its own homepage describes it as a leading multiphase flow measurement technology business, serving oil and gas. That entry was wrong and has been removed. IBM Saudi Arabia and Wipro Arabia have also been removed: both are multinational offices rather than the Saudi firms someone searching for a Riyadh provider is looking for. Two further candidates were dropped because their sites return no HTTP response.

Start Here: the 30 Second Version

If you read nothing else on this page, read the row that describes you. Every provider is compared in detail further down, but choosing the right category of firm matters far more than choosing between two firms in the same category.

If this is youBuy this firstBecause
A government entity or critical infrastructure operatorA gap assessment against the 114 main ECC controlsMandatory, and the assessment is what tells you the size of the programme.
A SAMA-regulated financial institutionA SAMA CSF maturity gap assessmentYou are measured on maturity level, so the target level has to be agreed before you start.
In scope for both ECC and SAMA CSFOne engagement mapped across both frameworksThey share a large control base. Two projects means paying twice for the same work.
A 100 to 500 person Saudi businessA fixed-price assessment from a mid-tier firmTwo firms below take engagements from $1,000. The national providers will not.
You need an actual break-in attemptOffensive testing from a local firmOne firm below does this. Local delivery matters for data residency.

Atlant Security editorial assessment, September 2026. This is our reading of the market, not a figure taken from any published source.

Does a Riyadh Cybersecurity Company Need to Be in Riyadh?

In Saudi Arabia, yes, more than almost anywhere else covered in this series. Data residency expectations, the practicalities of assessment against national frameworks, and procurement norms all favour providers established inside the Kingdom. For government and semi-government work, local establishment is frequently a precondition rather than a preference.

Language and on-site presence matter more here too. Much of the documentation and many of the assessment conversations happen in Arabic, and a provider whose team works in both languages removes a category of friction that is easy to underestimate from outside the region.

For a purely commercial engagement with no framework driver, a remote specialist is perfectly workable. But in this market that describes a minority of the work, because most Saudi security spending is driven by a control framework somebody will assess you against.

Which Saudi Framework Applies to You?

This determines your budget, your timeline and which firms are even eligible, so settle it first. The National Cybersecurity Authority publishes the Kingdom’s core control frameworks, and unlike risk-based standards they are prescriptive: they state the controls you must implement. If you are a Saudi organisation of any scale, the Essential Cybersecurity Controls are the baseline you will be measured against. We cover what they actually require on our NCA ECC compliance page.

Financial institutions carry an additional obligation from their own regulator, whose cyber security framework is detailed and supervised through inspection rather than self-assessment. Our SAMA Cyber Security Framework page walks through it.

If you supply Saudi Aramco, a third obligation applies and it arrives through your contract rather than through regulation. Aramco operates its own cybersecurity standard for third parties, and certification against it is a precondition for a great many suppliers, including small ones that do not consider themselves technology companies at all. We cover that on our Aramco CCC certification page.

Layered across all of these is the Kingdom’s personal data protection regime, which applies to organisations handling personal data regardless of sector. Because these frameworks are revised and are interpreted through assessment practice, treat the authorities’ own publications as definitive rather than any vendor summary, this one included.

The practical consequence for a buyer is unusual: in Saudi Arabia, the question "what should we do about security" often has a published answer already. That makes the useful first engagement a gap assessment against the specific framework that binds you, rather than a general exploration of your risks.

Work out which one you are

Which rulebook binds you in Saudi Arabia?

The Kingdom runs a national baseline plus a separate mandatory framework for regulated financial institutions. They share a lot of controls and are frequently bought as two projects when they should be one.

Government, critical infrastructure, essential services or a government vendor

The NCA Essential Cybersecurity Controls: 114 main controls and 897 sub-controls across 5 domains (governance, defence, resilience, third-party and cloud, and industrial control systems)

Enforced by the National Cybersecurity Authority

A bank, insurer, financing company, credit bureau or market infrastructure provider

The SAMA Cyber Security Framework and its maturity model

Enforced by the Saudi Central Bank

You run SCADA, OT or industrial environments

The industrial control systems domain of the ECC, on top of everything else

Enforced by the National Cybersecurity Authority

The three most common situations. The full table below adds a fourth and gives the sourcing for each row.

Your situationWhat appliesWho enforces itWhat it changes when you buy
Government, critical infrastructure, essential services or a government vendorThe NCA Essential Cybersecurity Controls: 114 main controls and 897 sub-controls across 5 domains (governance, defence, resilience, third-party and cloud, and industrial control systems)The National Cybersecurity AuthorityMandatory. Non-compliance risks penalties and lost government contracts. See NCA ECC compliance.
A bank, insurer, financing company, credit bureau or market infrastructure providerThe SAMA Cyber Security Framework and its maturity modelThe Saudi Central BankMandatory and sector-specific, assessed on maturity level rather than pass or fail. See SAMA CSF compliance.
You run SCADA, OT or industrial environmentsThe industrial control systems domain of the ECC, on top of everything elseThe National Cybersecurity AuthorityA different engineering discipline from office security. Scope it separately.
You hold personal data in the KingdomSaudi personal data protection lawThe national data authorityApplies more broadly than the sector frameworks above.

Control counts, domains and scope are as published on Atlant Security’s own compliance pages, linked from each row. Confirm your own position with counsel. This is not legal advice.

Cybersecurity Companies in Riyadh: Side-by-Side Comparison

All 7 firms below have a real presence in the Riyadh area. The table is sorted in the same order as the reviews that follow.

ProviderBasedTeam sizeHourly rateBest for
sirar by stcRiyadh, Saudi Arabia500+Not publishedLarge Saudi enterprises and government entities wanting a national provider
RewterzRiyadh, Saudi Arabia250-999$50-$99Saudi organisations that need a monitored SOC without building one
Security PactRiyadh, Saudi Arabia2-9Not publishedSaudi businesses wanting a small senior consultancy rather than an account manager
Atlant SecurityRemote, serving 14 countriesSmall senior teamFixed price, not hourlyCompanies that need someone to decide what to do and then implement it
Advance DatasecRiyadh, Saudi Arabia10-49$100-$149Saudi mid-market companies wanting security work at an accessible entry point
ITButler e ServicesRiyadh, Saudi Arabia50-249$100-$149Saudi organisations buying a structured security programme rather than a project
Saudi PenTesting CompanyAl Khobar, Saudi Arabia2-9Not publishedSaudi organisations that need an actual break-in attempt, performed locally

Team size, hourly rate and minimum engagement are as published by each firm on the Clutch directory, checked 14 September 2026. They are the firms’ own figures, not our measurements. “Best for” is Atlant Security’s editorial assessment.

What kind of firm each one actually is

The table above compares them on price and location. This one compares them on what they are, which is the comparison that decides whether the engagement works. Most bad purchases in this market are the right firm in the wrong category.

ProviderWhat kind of firm it isWhat the engagement ends withThe limitation this guide flags
sirar by stcFull-service national providerAn enterprise relationship across several towersEnterprise and government oriented; small businesses are not the target
RewterzManaged security (MSSP)A monitored service, and an alert somebody acts onConfirm analyst location and data handling against Saudi residency requirements
Security PactConsultancyA prioritised plan, and with some firms the fixes as wellAt 2-9 people, capacity and cover need a written answer
Atlant SecurityConsultancyA prioritised plan, and with some firms the fixes as wellNo help desk, so day-to-day IT support still needs a local provider
Advance DatasecConsultancyA prioritised plan, and with some firms the fixes as wellSmaller team, so several concurrent workstreams will stretch it
ITButler e ServicesConsultancyA prioritised plan, and with some firms the fixes as well$50,000 minimum rules out smaller or exploratory engagements
Saudi PenTesting CompanyOffensive testingA report describing how they got inVery small team, so lead times may be long

Category is our reading of each firm’s own published description, quoted in its entry below. The limitation column is taken verbatim from the same entry. Checked against each firm’s live site in September 2026.

Read the Atlant Security row the same way you read the others. We are a consultancy. There is no help desk, no monitoring platform and nothing to resell, and that is a limitation as much as a position. If what you need is somebody to answer the phone when a laptop dies, buy from one of the managed providers on this page instead. We are here because deciding what to fix and in what order is a separate purchase from keeping the estate running.

The 7 Best Cybersecurity Companies in Riyadh for 2026

Ordered by fit for a Saudi buyer. The first is the national provider; the rest range from a regional SOC operator to small local specialists.

1. sirar by stc

Riyadh, Saudi Arabia · Website: sirar.com.sa

sirar by stc homepage, a cybersecurity provider serving Riyadh
sirar by stc homepage, captured September 2026.

Best for: Large Saudi enterprises and government entities wanting a national provider

sirar is the cybersecurity arm of stc, the Saudi telecommunications group, and it is the closest thing the Kingdom has to a national security champion. Backing of that kind matters in Saudi Arabia in a way it does not everywhere: data residency, local delivery and the ability to serve government and semi-government entities are structural advantages, not marketing. For a large Saudi organisation that needs a provider able to operate inside the Kingdom’s requirements without exception, this is the default shortlist entry.

sirar by stc | cybersecurity in excellence you can trust

How sirar by stc describes itself on sirar.com.sa, September 2026

Strengths

  • Backed by stc, with national scale and local delivery inside the Kingdom
  • Structured for government and large enterprise data residency requirements
  • Managed detection, consulting and compliance under one provider

Watch out for

  • Enterprise and government oriented; small businesses are not the target
  • No published pricing, and procurement is formal and lengthy

Team size: 500+ · Rate: Not published · Minimum engagement: Enterprise engagement

2. Rewterz

Riyadh, Saudi Arabia · Website: rewterz.com

Rewterz homepage, a cybersecurity provider serving Riyadh
Rewterz homepage, captured September 2026.

Best for: Saudi organisations that need a monitored SOC without building one

Rewterz runs managed detection and response across the Gulf with a substantial team and a published rate band well below what the national providers command. For a Saudi company that has bought tooling and discovered nobody is reading the output, this is the tier that solves the actual problem. The $5,000 minimum keeps it serious without demanding an enterprise commitment. Ask specifically where the analysts watching your environment are located, since that can matter for Saudi data requirements.

AI Powered SOC MSSP | Autonomous Security Ops

How Rewterz describes itself on rewterz.com, September 2026

Strengths

  • Genuine managed SOC capability at a mid-market rate
  • Substantial regional team rather than a two-person operation

Watch out for

  • Confirm analyst location and data handling against Saudi residency requirements
  • MSSP led, so strategic advisory is not the core offering

Team size: 250-999 · Rate: $50-$99 · Minimum engagement: $5,000+

3. Security Pact

Riyadh, Saudi Arabia · Website: securitypact.net

Security Pact homepage, a cybersecurity provider serving Riyadh
Security Pact homepage, captured September 2026.

Best for: Saudi businesses wanting a small senior consultancy rather than an account manager

Security Pact is a small Riyadh consultancy in the 2 to 9 employee band. At that size the proposition is direct access to the people doing the work, which for advisory and assessment engagements is frequently better value than a larger firm where the senior name on the proposal appears once at kickoff. The trade-offs are the usual ones for a team this size and should be settled in writing: capacity, cover, and what happens if your engagement coincides with somebody’s leave.

Top Cyber Security Company in Saudi Arabia

How Security Pact describes itself on securitypact.net, September 2026

Strengths

  • Small enough that the person who scopes the work does the work
  • Riyadh based, so on-site presence is straightforward

Watch out for

  • At 2-9 people, capacity and cover need a written answer
  • Neither rate nor minimum engagement is published

Team size: 2-9 · Rate: Not published · Minimum engagement: Not published

4. Atlant Security

Remote, serving 14 countries · Website: atlantsecurity.com

Atlant Security homepage, a cybersecurity provider serving Riyadh
Atlant Security homepage, captured September 2026.

Best for: Companies that need someone to decide what to do and then implement it

Atlant Security is a consultancy rather than a managed services provider or a product vendor, and the distinction is the reason it is on this list at all. There is no help desk, no monitoring platform and nothing to resell. What it does is the part most local providers leave to you: an audit that produces a prioritised remediation plan with named owners and effort estimates, and the same engineers then implementing the fixes. The firm has run 200+ security assessments across 14 countries since 2013, works to fixed prices rather than hourly billing, and is vendor-independent, so the recommendation carries no resale commission. For a company that does not yet know whether it needs an MSP, a penetration test or a compliance programme, that ordering is the useful thing to buy first.

Strengths

  • Fixed price, so scope and invoice are agreed before work starts
  • Implements the fixes rather than stopping at a findings report
  • Vendor-independent, with no product resale margin behind the advice

Watch out for

  • No help desk, so day-to-day IT support still needs a local provider
  • No 24/7 monitoring platform of its own; continuous detection goes to a partner
  • Remote-first, so regular on-site presence is not the model

Team size: Small senior team · Rate: Fixed price, not hourly · Minimum engagement: $8,000+

5. Advance Datasec

Riyadh, Saudi Arabia · Website: advance-datasec.com

Advance Datasec homepage, a cybersecurity provider serving Riyadh
Advance Datasec homepage, captured September 2026.

Best for: Saudi mid-market companies wanting security work at an accessible entry point

Advance Datasec is a Riyadh security firm publishing a mid-range rate with a $1,000 minimum engagement, which puts it within reach of companies that would never clear procurement at a national provider. For a Saudi business with a hundred to five hundred staff that needs an assessment against the Kingdom’s control frameworks and some help acting on it, this is the right tier to be shopping in. Confirm which specific frameworks the team has delivered against before signing.

Advance Datasec Cyber Security Company in Saudi Arabia

How Advance Datasec describes itself on advance-datasec.com, September 2026

Strengths

  • Low entry point with a published mid-market rate
  • Riyadh based and sized for the Saudi mid-market

Watch out for

  • Smaller team, so several concurrent workstreams will stretch it
  • Ask for specific framework experience rather than a general claim

Team size: 10-49 · Rate: $100-$149 · Minimum engagement: $1,000+

6. ITButler e Services

Riyadh, Saudi Arabia · Website: itbutler.sa

ITButler e Services homepage, a cybersecurity provider serving Riyadh
ITButler e Services homepage, captured September 2026.

Best for: Saudi organisations buying a structured security programme rather than a project

ITButler runs a security services practice out of Riyadh with a team in the 50 to 249 band. Its $50,000 minimum engagement is the highest in this group and tells you plainly what kind of work it takes on: multi-month programmes rather than a one-off assessment. That is the right shape for an organisation building a compliance programme from a standing start against the Kingdom’s control frameworks, and the wrong shape for a company that wants a penetration test.

ITButler: Cybersecurity Service Provider

How ITButler e Services describes itself on itbutler.sa, September 2026

Strengths

  • Sized and structured for multi-month security programmes
  • Riyadh based with a substantial local team

Watch out for

  • $50,000 minimum rules out smaller or exploratory engagements
  • Not the route to a single bounded piece of testing work

Team size: 50-249 · Rate: $100-$149 · Minimum engagement: $50,000+

7. Saudi PenTesting Company

Al Khobar, Saudi Arabia · Website: pentesting.sa

Saudi PenTesting Company homepage, a cybersecurity provider serving Riyadh
Saudi PenTesting Company homepage, captured September 2026.

Best for: Saudi organisations that need an actual break-in attempt, performed locally

This is a small Eastern Province firm doing the thing most providers on this page do not: offensive testing. The distinction matters because a vulnerability scan and a penetration test are different products frequently sold under the same word. A scan lists what a tool noticed. A test produces a narrative of how someone chained three unremarkable weaknesses into administrative control. If a regulator, a customer or an insurer has asked you for a penetration test, this is the category, and being Saudi based simplifies data handling.

Saudi PenTesting Company

How Saudi PenTesting Company describes itself on pentesting.sa, September 2026

Strengths

  • Genuine offensive testing specialism, uncommon among local providers
  • Saudi based, which simplifies data handling and on-site work

Watch out for

  • Very small team, so lead times may be long
  • Testing only; nobody will remediate the findings for you

Team size: 2-9 · Rate: Not published · Minimum engagement: Not published

How to Choose a Cybersecurity Company in Riyadh

The providers below fall into several quite different categories, which makes the selection process matter more than the shortlist. Work through these five steps in order.

  1. Work out which of the things below you are buying

    A managed provider keeps your estate running day to day. A testing firm tries to break in and reports how it went. A consultancy decides what you should do and in what order. A product vendor sells you a platform somebody then has to operate. The table above says which is which.

  2. Ask who fixes the problem after it is found

    A scan, an audit and a penetration test all end with a document. Somebody then has to change firewall rules, rebuild permissions, roll out multi-factor authentication and argue with a vendor about a legacy application. Ask in writing whether remediation is included, excluded, or billed separately.

  3. Get the scope and the price in writing before anyone starts

    A proposal that prices security services without listing what is monitored, tested or documented is not a proposal you can hold anyone to. Ask for a fixed or capped price and an explicit list of exclusions. The price transparency panel further down shows how many of these firms publish anything at all.

  4. Map ECC and SAMA CSF together, once

    If you are a Saudi financial institution you are very likely in scope for both, and they draw on the same underlying control practices. Implementing each shared control once and evidencing it against both frameworks is the single largest cost saving available in this market. A provider who proposes them as two sequential programmes is selling you the same work twice.

  5. Ask what you keep if you leave after twelve months

    Documentation, configurations, log history, tenancy ownership. If the answer is that you keep nothing, you are not buying a security programme, you are renting one, and the renewal conversation will reflect that.

Good signs

  • They name the engineer who will do the work, and you can check that person exists
  • They tell you what is out of scope before you ask
  • They are willing to quote a fixed price for a bounded piece of work
  • They ask about your customers and your parent company, not just your firewall
  • They can say plainly which parts of the job they would subcontract

Walk away if

  • Security is one of a dozen services listed and nobody on the team does it full time
  • The proposal prices security services as a single line with no itemised scope
  • The recommendation happens to be the product they resell
  • They will not put the remediation position in writing
  • They propose ECC and SAMA CSF as two separate programmes

Five questions worth putting in the RFP

Ask thisWhy it mattersWhat a good answer sounds like
What proportion of your revenue is security work?A directory search returns many firms listing cybersecurity among a dozen services.A number, followed by the names of the people who do it full time.
Who specifically will be assigned, and what is their background?Small teams sell with a senior and deliver with a junior. It is the most common complaint.A name, a history you can verify, and a willingness to put it in the contract.
What does your managed security tier actually monitor, and during which hours?MSSP is a marketing term as often as it is an operating model.Named data sources, named hours, and who reads an alert at 03:00.
Is remediation included, excluded, or billed separately?This is where the budget you did not plan for appears.One of the three words, in writing, before you sign.
What happens contractually if we are breached during the engagement?It reveals how much of the risk the provider is genuinely taking on.A clear, unembarrassed answer. Whether they have thought about it matters most.

Atlant Security editorial, September 2026. These are the questions we would ask, based on what goes wrong in engagements we are called in to rescue.

What Cybersecurity Costs in Riyadh

The Saudi market splits like the Emirati one. The national provider does not publish pricing and runs formal procurement. The commercial firms publish hourly bands from roughly $50 to $149, with minimum engagements ranging from $1,000 for a small assessment to $50,000 for a structured multi-month programme.

That spread of minimums is the most useful column in the comparison table above. It tells you what kind of work each firm actually wants, more reliably than any marketing copy does. A $50,000 floor means programmes. A $1,000 floor means they will take a bounded first job. Matching that to what you need saves a great deal of wasted procurement effort.

Where a named NCA framework drives the work, budget for evidence and documentation to exceed the technical remediation, frequently by a wide margin. Demonstrating a control to an assessor is more laborious than implementing it. A fixed-price independent audit generally runs $8,000 to $35,000 and is the sensible way to establish your actual gap before committing to a programme.

The practical problem with buying here

Price transparency among these providers

What each firm publishes about what it charges, before you have spoken to anyone.

ProviderHourly rate
published
Minimum engagement
published
Fixed price
offered
sirar by stc
Rewterz
Security Pact
Atlant Security
Advance Datasec
ITButler e Services
Saudi PenTesting Company

3 of the 7 publish an hourly rate. 4 publish a minimum engagement. Expect to ask, and expect to get the answer in writing before anyone starts.

Rates and minimums as published by each firm on the Clutch directory, checked 14 September 2026. A cross means the figure is not published. It is not a finding that the firm refuses to quote.

What you are buyingPriceWhere this number comes from
Hourly rate, published bands$100-$149 · $50-$99Published by 3 of the 7 firms above on the Clutch directory.
Minimum engagement, published$1,000+ to $50,000+Published by 4 of the 7 firms above.
Fixed-price independent security auditUS$8,000 to US$35,000Atlant Security estimate, based on our own engagements. Not a published figure.
Penetration test, bounded scopeUS$8,000 to US$20,000Atlant Security estimate. Varies more with scope than with provider.
Managed detection and response, per yearFrom US$30,000Atlant Security estimate. The variable is who reads the alerts, not the platform licence.
Gap assessment against NCA ECC complianceQuoted per organisationScope depends on which framework applies. See our NCA ECC compliance page.

Rows marked as published are the firms’ own figures, checked 14 September 2026. Rows marked as an estimate are Atlant Security’s, are labelled as such, and should be treated as a planning range rather than a quotation.

Frequently Asked Questions: Cybersecurity Companies in Riyadh

Is Saher Flow Solutions a cybersecurity company?

No. Its own homepage describes it as a leading multiphase flow measurement technology company, serving the oil and gas industry. A previous version of this article listed it third as an "OT Cybersecurity Specialist", which was incorrect. It has been removed.

Which cybersecurity companies are actually based in Saudi Arabia?

sirar by stc is the national provider, headquartered in Riyadh and part of the stc group. Rewterz, Security Pact, Advance Datasec and ITButler e Services are all Riyadh based, and Saudi PenTesting Company is in Al Khobar. Atlant Security works remotely with clients across 14 countries.

What is the NCA ECC and does it apply to us?

The Essential Cybersecurity Controls are the National Cybersecurity Authority’s baseline control framework, and they are prescriptive rather than risk-based. They are mandatory for government entities, critical national infrastructure operators, essential service providers, and government contractors and vendors, with additional frameworks layered on for critical systems and cloud. Confirm your specific obligations against the authority’s current publications.

We supply Aramco. What do we need?

Aramco operates its own cybersecurity standard for third parties and certification against it is commonly a contractual precondition for suppliers. It reaches many small suppliers who do not regard themselves as technology companies. Check your contract and start early, because the evidence work takes months.

What does a cybersecurity company cost in Riyadh?

The commercial firms publish hourly bands of roughly $50 to $149, with minimum engagements from $1,000 to $50,000 depending on whether you are buying a bounded assessment or a multi-month programme. The national provider does not publish pricing. A fixed-price independent audit generally runs $8,000 to $35,000.

Do we need a Saudi-registered provider?

For government and semi-government work, usually yes, and often as a precondition. For commercial work driven by an NCA framework, a local provider materially reduces friction around data handling and assessment. For work with no framework driver, a remote specialist is fine.

We are a Saudi bank. Do we face NCA ECC as well as SAMA CSF?

Frequently both. SAMA CSF is the mandatory sector framework for institutions the Saudi Central Bank regulates, and many of those institutions are also in scope for the national ECC baseline. The two share many controls because both draw on the same underlying practices, so they should be mapped in a single engagement rather than assessed and remediated twice.

How large is the NCA ECC framework?

It sets 114 main controls and 897 sub-controls organised across 5 domains: Cybersecurity Governance, Cybersecurity Defence, Cybersecurity Resilience, Third-Party and Cloud Computing Cybersecurity, and Industrial Control Systems Cybersecurity. Compliance means implementing and evidencing those controls, which is a programme rather than a project. Our NCA ECC page sets out how we scope it.

Not sure which of these you actually need?

That is the question a fixed-price security audit answers. We assess what you have, tell you what to fix and in what order, and give you a plan you can hand to any provider on this page, including one of our competitors. 200+ assessments across 14 countries since 2013, fixed price agreed before we start.

See what a fixed-price audit covers

Related reading: the 15 largest computer security companies compared, our fixed-price IT security audit, and virtual CISO services.

Looking wider than this list? cybersecuritycompanies.io is a free directory of cybersecurity companies worldwide, filterable by category, location and credentials.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

Connect on LinkedIn