REFERENCE  ·  GCC Edition

Cybersecurity and Compliance Glossary.

Plain-language explanations of the terms that matter most for businesses operating in Saudi Arabia, the UAE, Bahrain, and the wider GCC. No jargon used to explain jargon, just clear, honest definitions written for business owners and leaders, not security engineers.

Regulatory Frameworks Services & Roles Threats & Attacks Technical Controls Standards & Certifications
B

Business Continuity Plan (BCP)

Technical ControlsResilience

A documented plan describing how an organisation will continue operating its essential functions during and after a significant disruption, covering scenarios such as cyberattacks, natural disasters, and key staff unavailability. It defines which functions are most critical, the minimum acceptable level of operation, and who is responsible for what during an incident.

Why it matters for GCC businesses: Both SAMA and NCA explicitly require financial institutions and critical sector organisations in Saudi Arabia to maintain tested business continuity plans. An untested or outdated plan is one of the most consistent sources of critical findings across GCC regulatory examinations.

Breach (Data Breach)

Data ProtectionRegulatory

A data breach occurs when personal data is accidentally or unlawfully accessed, disclosed, altered, lost, or destroyed by someone not authorised to do so. Not every security incident constitutes a reportable breach; whether notification is required depends on the nature of the data and the likely harm to affected individuals.

Why it matters for GCC businesses: Saudi PDPL and UAE FDPL both impose a seventy-two hour notification window to the relevant authority. Businesses operating across both jurisdictions need parallel notification procedures ready before an incident happens, not during one.
C

CIS Controls

StandardsTechnical Controls

A prioritised set of cybersecurity best practices published by the Center for Internet Security, organised into eighteen control groups covering asset inventory, data protection, secure configuration, and access control among others.

Why it matters for GCC businesses: CIS Controls are widely used as a practical starting point for businesses that need a structured way to prioritise security investment before pursuing formal certification.
D

DPO / vDPO (Data Protection Officer)

Services & Roles

A Data Protection Officer manages an organisation's data privacy compliance programme, including consent, data subject rights, and breach notification. A vDPO (Virtual DPO) delivers this function on an outsourced, part time basis rather than as a full time hire.

Why it matters for GCC businesses: UAE FDPL explicitly requires certain organisations to appoint a DPO. Saudi PDPL does not name the role directly but creates accountability obligations that make the function essential in practice.
F

UAE FDPL (Federal Data Protection Law)

Regulatory Frameworks

The United Arab Emirates' federal data protection law, establishing rights over personal data and obligations for organisations processing it. It does not apply within the DIFC or ADGM, which operate under their own separate regimes.

Why it matters for GCC businesses: Businesses operating across the UAE mainland and a free zone often need two parallel compliance approaches, not one.
I

ISO 27001 / ISMS

Standards & Certifications

ISO 27001 is the international standard for Information Security Management Systems (ISMS). Certification means an accredited body has confirmed an organisation's security programme is documented, implemented, and subject to ongoing review.

Why it matters for GCC businesses: Increasingly required by enterprise and government clients across financial services, healthcare, and technology procurement as a condition of doing business.
M

MFA (Multi-Factor Authentication)

Technical Controls

A login method requiring more than one form of verification, typically a password plus a code sent to a phone or generated by an app, before granting access to an account or system.

Why it matters for GCC businesses: MFA is one of the single most effective, lowest-cost controls against account compromise, and its absence is among the most common findings in security assessments.
N

NCA ECC (Essential Cybersecurity Controls)

Regulatory Frameworks

A baseline set of cybersecurity controls issued by Saudi Arabia's National Cybersecurity Authority, applicable to government agencies and organisations operating critical national infrastructure, and increasingly referenced by private sector businesses.

Why it matters for GCC businesses: Businesses in regulated or critical sectors in Saudi Arabia are frequently assessed against NCA ECC alongside or instead of ISO 27001.
P

PDPL (Personal Data Protection Law)

Regulatory Frameworks

Saudi Arabia's comprehensive data protection law, enforced by SDAIA, establishing lawful basis requirements, data subject rights, cross-border transfer restrictions, and a seventy-two hour breach notification window.

Why it matters for GCC businesses: PDPL applies to any organisation processing the personal data of individuals in Saudi Arabia, regardless of where that organisation is based.

Phishing

Threats & Attacks

A social engineering attack where a fraudulent message, typically email, tricks a recipient into revealing credentials, transferring funds, or installing malware by impersonating a trusted sender.

Why it matters for GCC businesses: Phishing remains the most common initial entry point for business email compromise and ransomware incidents affecting SMEs in the region.

Penetration Test (Pentest)

Services & Roles

An authorised, simulated attack against your systems performed by a security professional to identify exploitable weaknesses, assessed against a specific point in time.

Why it matters for GCC businesses: Valuable but insufficient alone. Continuous vulnerability management fills the gap between annual or periodic penetration tests.
R

Risk Register

Technical ControlsGovernance

A documented log of an organisation's identified security risks, including their likelihood, potential impact, assigned owner, and treatment decision, reviewed and updated on a regular cycle.

Why it matters for GCC businesses: SAMA auditors specifically assess whether a risk register is current and actively reviewed, not just populated once and forgotten.

Ransomware

Threats & Attacks

Malicious software that encrypts an organisation's files or systems, with attackers demanding payment in exchange for restoring access. Modern ransomware attacks frequently also exfiltrate data before encryption, adding a data breach dimension.

Why it matters for GCC businesses: Recovery costs routinely exceed USD 50,000 even with reliable backups, and paying a ransom does not remove PDPL or UAE FDPL notification obligations if personal data was involved.
S

SAMA CSF (Cybersecurity Framework)

Regulatory Frameworks

The Saudi Arabian Monetary Authority's mandatory cybersecurity standard for financial institutions operating in the Kingdom, organised around four maturity levels across leadership, risk, and technology domains.

Why it matters for GCC businesses: Mandatory, not optional, for banks, insurers, financing companies, and increasingly SAMA-licensed fintechs.

SDAIA (Saudi Data and AI Authority)

Regulatory Frameworks

The Saudi government authority responsible for enforcing PDPL, issuing guidance, processing complaints, and approving certain cross-border data transfers.

Why it matters for GCC businesses: SDAIA is the regulator you notify within seventy-two hours of a qualifying breach under PDPL.
V

vCISO (Virtual Chief Information Security Officer)

Services & Roles

An outsourced, part time security executive who sets strategy, governs risk, and reports to leadership, providing the judgment of a CISO without the cost of a full time hire.

Why it matters for GCC businesses: Most SMEs need CISO-level judgment long before they can justify a six figure full time salary for it.

VMaaS (Vulnerability Management as a Service)

Services & Roles

A continuous programme of scanning, prioritising, and remediating security vulnerabilities across an organisation's environment, as opposed to a single point-in-time assessment.

Why it matters for GCC businesses: New vulnerabilities are disclosed daily; a business scanned once a year has, on average, 364 blind days.

Vulnerability

Technical Controls

A weakness in a system, application, or configuration that could be exploited by an attacker to gain unauthorised access or cause harm.

Why it matters for GCC businesses: The average time between public disclosure of a vulnerability and active exploitation in the wild has dropped to around five days.

Still Not Sure What Applies to You?

The first conversation is free, it is genuinely useful, and there is no obligation attached to it.