Cybersecurity and Compliance Glossary.
Plain-language explanations of the terms that matter most for businesses operating in Saudi Arabia, the UAE, Bahrain, and the wider GCC. No jargon used to explain jargon, just clear, honest definitions written for business owners and leaders, not security engineers.
Business Continuity Plan (BCP)
A documented plan describing how an organisation will continue operating its essential functions during and after a significant disruption, covering scenarios such as cyberattacks, natural disasters, and key staff unavailability. It defines which functions are most critical, the minimum acceptable level of operation, and who is responsible for what during an incident.
Breach (Data Breach)
A data breach occurs when personal data is accidentally or unlawfully accessed, disclosed, altered, lost, or destroyed by someone not authorised to do so. Not every security incident constitutes a reportable breach; whether notification is required depends on the nature of the data and the likely harm to affected individuals.
CIS Controls
A prioritised set of cybersecurity best practices published by the Center for Internet Security, organised into eighteen control groups covering asset inventory, data protection, secure configuration, and access control among others.
DPO / vDPO (Data Protection Officer)
A Data Protection Officer manages an organisation's data privacy compliance programme, including consent, data subject rights, and breach notification. A vDPO (Virtual DPO) delivers this function on an outsourced, part time basis rather than as a full time hire.
UAE FDPL (Federal Data Protection Law)
The United Arab Emirates' federal data protection law, establishing rights over personal data and obligations for organisations processing it. It does not apply within the DIFC or ADGM, which operate under their own separate regimes.
ISO 27001 / ISMS
ISO 27001 is the international standard for Information Security Management Systems (ISMS). Certification means an accredited body has confirmed an organisation's security programme is documented, implemented, and subject to ongoing review.
MFA (Multi-Factor Authentication)
A login method requiring more than one form of verification, typically a password plus a code sent to a phone or generated by an app, before granting access to an account or system.
NCA ECC (Essential Cybersecurity Controls)
A baseline set of cybersecurity controls issued by Saudi Arabia's National Cybersecurity Authority, applicable to government agencies and organisations operating critical national infrastructure, and increasingly referenced by private sector businesses.
PDPL (Personal Data Protection Law)
Saudi Arabia's comprehensive data protection law, enforced by SDAIA, establishing lawful basis requirements, data subject rights, cross-border transfer restrictions, and a seventy-two hour breach notification window.
Phishing
A social engineering attack where a fraudulent message, typically email, tricks a recipient into revealing credentials, transferring funds, or installing malware by impersonating a trusted sender.
Penetration Test (Pentest)
An authorised, simulated attack against your systems performed by a security professional to identify exploitable weaknesses, assessed against a specific point in time.
Risk Register
A documented log of an organisation's identified security risks, including their likelihood, potential impact, assigned owner, and treatment decision, reviewed and updated on a regular cycle.
Ransomware
Malicious software that encrypts an organisation's files or systems, with attackers demanding payment in exchange for restoring access. Modern ransomware attacks frequently also exfiltrate data before encryption, adding a data breach dimension.
SAMA CSF (Cybersecurity Framework)
The Saudi Arabian Monetary Authority's mandatory cybersecurity standard for financial institutions operating in the Kingdom, organised around four maturity levels across leadership, risk, and technology domains.
SDAIA (Saudi Data and AI Authority)
The Saudi government authority responsible for enforcing PDPL, issuing guidance, processing complaints, and approving certain cross-border data transfers.
vCISO (Virtual Chief Information Security Officer)
An outsourced, part time security executive who sets strategy, governs risk, and reports to leadership, providing the judgment of a CISO without the cost of a full time hire.
VMaaS (Vulnerability Management as a Service)
A continuous programme of scanning, prioritising, and remediating security vulnerabilities across an organisation's environment, as opposed to a single point-in-time assessment.
Vulnerability
A weakness in a system, application, or configuration that could be exploited by an attacker to gain unauthorised access or cause harm.
Still Not Sure What Applies to You?
The first conversation is free, it is genuinely useful, and there is no obligation attached to it.
