Enterprise IT · Saudi Arabia · NCA ECC-2:2024

Enterprise IT in Saudi Arabia, Mapped to NCA, SAMA and PDPL Requirements

PRO TECHnology serves organisations in Saudi Arabia from Dubai, and Saudi enquiries are handled by PRONEXT, PRO TECHnology's company in Riyadh. This page sets the Saudi controls that IT teams are audited against next to the solutions we supply: FileWave device management, Kanguru hardware-encrypted drives with remote management, KanguruClone duplicators for wiping drives, and Disk Archive ALTO for long-term copies.

It is written for IT managers, information security teams and buyers at government entities, banks, universities and companies in Riyadh, Jeddah, Dammam and the rest of the Kingdom. It quotes each control, names what helps meet it, and is plain about the limit: no USB drive or device management platform makes an organisation compliant on its own. Policies, approvals and records do, and the products make them enforceable.

Enterprise IT in Saudi Arabia: device management, encrypted storage, secure erasure and archiving mapped to NCA ECC-2:2024, SAMA and PDPL
The controls on this page come from the regulators' own documents, read on 29 September 2026.
  • ECC-2:2024NCA's current Essential Cybersecurity Controls
  • 2.3.3.2strict restriction on external storage media
  • FIPS 140-3 L3Kanguru Defender 3000, NIST certificate #5364
  • PRONEXTPRO TECHnology's company in Riyadh

Key takeaways

  • NCA's Essential Cybersecurity Controls, ECC-2:2024, apply to government entities in the Kingdom and their affiliated companies. Control 2.3.3.2 asks for strict restriction on the use of external storage media and their security, and 2.14.3.4 for secure destruction and re-use of assets that hold classified information, storage media included.
  • ECC 2.6.3.1 asks for separation and encryption of the entity's data on mobile devices and BYOD, and 2.6.3.3 for its deletion when a device is lost or employment ends. For banks, SAMA's Cyber Security Framework names mobile device management (MDM) in its BYOD control, 3.3.10.
  • The PDPL Implementing Regulation requires a controller destroying personal data to destroy all copies, including backups (Article 8), and to notify the competent authority of a harmful breach within 72 hours (Article 24).
  • Data localisation is no longer in the ECC: NCA deleted the hosting-in-the-Kingdom sub-control in 2024 and directs entities to the National Data Management Office (NDMO) at SDAIA before acting on localisation.
  • PRO TECHnology supplies FileWave, Kanguru and Disk Archive to the Kingdom, with Saudi enquiries handled by PRONEXT in Riyadh. FileWave's own 1 July 2026 announcement covers sales, deployment and local support across the Middle East, including Saudi Arabia.

What PRO TECHnology supplies in Saudi Arabia

Four solutions, each with the role PRO TECHnology can show for the Kingdom. The Enterprise IT team in Dubai scopes the solution with you; PRONEXT, PRO TECHnology's company in Riyadh, handles Saudi enquiries. Each quotation states what is done on site in the Kingdom and what is supported remotely from Dubai.

SolutionWhat it doesPRO TECHnology's role for Saudi customersRead more
FileWave device managementOne console for Mac, Windows, iPad, iPhone, Android and Chromebook: enrolment, settings, software and inventoryFileWave's 1 July 2026 announcement says the expanded partnership extends sales, deployment and local support across the Middle East, including Saudi ArabiaFileWave
Kanguru Defender encrypted drives and KRMCHardware-encrypted USB drives, SSDs and hard drives, and a console to manage them after they are issuedKanguru's EMEA partner directory lists PRO TECHnology for Saudi Arabia; partner since September 2021Kanguru
KanguruClone duplicatorsCopy a master drive to many, or wipe drives in batches before reuse or disposalSupplied through the same Kanguru partnershipDuplicator guide
Disk Archive ALTODisk-based long-term archive that keeps two or more copies; a replica set can be removed to a vaultPartnership with Disk Archive Corporation announced on 9 March 2026 for the Middle East; on-site scope confirmed per projectDisk Archive ALTO

NCA ECC-2:2024: what it asks of devices, media and backups

The Essential Cybersecurity Controls, ECC-2:2024, apply to government entities in the Kingdom and their affiliated companies and entities, inside and outside the Kingdom. Other organisations can use them as a reference. The controls below are the ones that decide how devices, removable media and backups are handled; the wording in the second column is NCA's.

ControlWhat ECC-2:2024 saysWhat helpsWhat stays your responsibility
2.3.3.2Strict restriction on the use of external storage media and their securityHardware-encrypted drives that unlock only with a password, registered and managed centrally with KRMC so a lost drive can be disabled when it next connectsWho may use removable media, approving each drive, blocking unapproved USB devices, keeping the register
2.6.3.1Separation and encryption of the entity's data and information stored on mobile devices and BYODsEnrolling laptops, phones and tablets in device management, so passcode and security settings are applied and devices out of policy are visibleDeciding which devices may hold entity data, and the BYOD agreement with staff
2.6.3.3Deletion of the entity's data on mobile devices and BYOD when a device is lost or employment endsRemote lock and wipe for enrolled mobile devices; for Kanguru drives managed in KRMC, delete-and-disable commands that run when the drive next connectsThe leaver process, and reporting lost devices quickly
2-8-3Cryptography that meets at least NCA's National Cryptographic Standards, at a level set by the sensitivity of the dataAES-256 hardware encryption on Kanguru Defender drives; the Defender 3000 holds FIPS 140-3 Level 3 validationMatching the standard level to your data classification, and key management
2-9-3Backups that cover critical assets, quick recovery after incidents, and periodic testing of recoveryAn offline encrypted copy in a rotation (Kanguru Defender HDD350), and a disk archive whose replica set can be vaulted (ALTO)Backup scope, recovery objectives and the restore tests themselves
2.14.3.4Security of the destruction and re-use of physical assets that hold classified information, including storage mediaKanguruClone duplicators to wipe drives in batches before reuse; the method (clear, purge or destroy) chosen by classificationChoosing the method, witnessing it, and keeping disposal records
A FIPS or AES label on a drive is evidence for one part of a control, not the control itself. Auditors look for the policy, the approvals, the register of issued media and the records of what was wiped.

Banks and financial institutions: SAMA's Cyber Security Framework

Member organisations of the Saudi Central Bank work to its Cyber Security Framework. Three of its controls map directly to device and media handling.

  • 3.3.9 Cryptography: the use of cryptographic solutions should be defined, approved and implemented.
  • 3.3.10 Bring Your Own Device: where personal devices are allowed for business use, the BYOD standard covers, among other things, the use of mobile device management (MDM) and encryption on the personal device. FileWave is the device management platform we supply.
  • 3.3.11 Secure disposal of information assets: sensitive information should be destroyed with techniques that make it non-retrievable, such as secure erase, secure wiping, incineration, double crosscut or shredding. Our secure data erasure guide explains which method fits which drive.

Personal data: what the PDPL asks of storage, backups and breaches

The Personal Data Protection Law is supervised by SDAIA. Its Implementing Regulation turns three duties into IT work:

  • Destruction reaches backups. When personal data has to be destroyed, Article 8 requires the controller to destroy all copies stored in its systems, including backups. Plan backup retention so that a destruction request can be carried out, and know which archive copies hold personal data.
  • Security follows NCA. Article 23 requires controllers to comply with NCA's controls, or with recognised cybersecurity practice where NCA's controls do not bind them.
  • Breaches are reported within 72 hours. Article 24 requires the controller to notify the competent authority within 72 hours of becoming aware of a breach that could harm the data or the people it describes. Encrypted drives reduce what a lost device exposes; they do not change the notification duty.

Cloud services and where data is stored

ECC-2:2024 deleted the sub-control that required hosting and storage inside the Kingdom and moved localisation to the National Data Management Office at SDAIA; NCA tells entities to refer to NDMO before acting on localisation. Check your data classification against NDMO's rules before placing data with any cloud service hosted abroad. Dropbox, for example, stores team files in the United States, with options in Australia, the European Union, Japan and the United Kingdom, and lists no Saudi region.

Where data must stay on premises, the storage layers are the same ones used anywhere: working storage for current projects, an offline encrypted backup copy, and a disk-based archive for data kept for years. Our backup and disaster recovery guide sets out how they fit together.

How a project in the Kingdom starts

  1. Tell us the requirement. The organisation type, the controls you are audited against (ECC-2:2024, SAMA, PDPL), the number of devices or drives, the data volume, and the cities involved.
  2. Scope and demonstration. The Enterprise IT team in Dubai proposes the solution and shows it working, at the Business Bay showroom or remotely.
  3. Quotation. Licences, hardware, deployment and training in one proposal, stating what is done on site in the Kingdom and what is supported remotely.
  4. Deployment and handover. A pilot group first, then the rollout, administrator training, and a named contact for support afterwards.

Enterprise IT in Saudi Arabia: common questions

Who supplies FileWave in Saudi Arabia?

PRO TECHnology. FileWave's own announcement of 1 July 2026 says the expanded partnership extends sales, deployment and local support across the Middle East, including Saudi Arabia and the wider Gulf region. Saudi enquiries are handled by PRONEXT, PRO TECHnology's company in Riyadh.

Who supplies Kanguru encrypted USB drives in Saudi Arabia?

PRO TECHnology, which has been Kanguru's partner in the region since September 2021. Kanguru's EMEA partner directory lists PRO TECHnology for Saudi Arabia, and Saudi enquiries are handled by PRONEXT in Riyadh.

Which encrypted USB drives meet NCA ECC control 2.3.3.2?

The control does not name products. It asks for strict restriction on the use of external storage media and their security, which means approved, encrypted and managed drives plus a policy and a register. Among Kanguru drives, the Defender 3000 is the model with an active FIPS 140-3 validation, at Level 3, NIST certificate #5364; FIPS 140-2 certificates became historical in September 2026.

Does NCA ECC require mobile device management?

ECC-2:2024 requires separation and encryption of the entity's data on mobile devices and BYOD (2.6.3.1) and deletion of that data when a device is lost or employment ends (2.6.3.3). A device management platform is the usual way to enforce and evidence both. For banks, SAMA's Cyber Security Framework names mobile device management in its BYOD control, 3.3.10.

Does the PDPL require backups to be deleted too?

Yes, when personal data has to be destroyed. Article 8 of the Implementing Regulation requires the controller to destroy all copies of that personal data stored in its systems, including backups, in line with the relevant regulatory requirements.

How quickly must a personal data breach be reported in Saudi Arabia?

Within 72 hours of the controller becoming aware of it, if the breach could harm the personal data or the people it describes. The notification goes to the competent authority, under Article 24 of the PDPL Implementing Regulation.

Can a Saudi government entity keep data on a cloud service hosted abroad?

That is decided by data classification and localisation rules, which NCA moved out of the ECC in 2024 to the National Data Management Office at SDAIA. Check NDMO's requirements first. Dropbox, for example, lists no Saudi storage region.

How are drives wiped securely before reuse in Saudi Arabia?

ECC 2.14.3.4 covers secure destruction and re-use of storage media, and SAMA 3.3.11 lists secure erase, secure wiping and shredding. KanguruClone duplicators wipe drives in batches; the right method depends on the drive type and the data's classification, as our secure data erasure guide explains.

Do you install and support solutions in Saudi Arabia?

For FileWave, FileWave's announcement covers deployment and local support in Saudi Arabia. For the other solutions, what is done on site in the Kingdom and what is supported remotely from Dubai is agreed for each project and written into the quotation.

How do we start a project from Riyadh, Jeddah or Dammam?

Send the requirement, the controls you are audited against, device or drive numbers and the cities involved to sales@protech.ae or call +971 4 343 5501. Saudi enquiries are handled by PRONEXT, PRO TECHnology's company in Riyadh.

حلول تقنية المعلومات للمؤسسات في المملكة العربية السعودية

تخدم بروتكنولوجي (PRO TECHnology) المؤسسات في المملكة العربية السعودية من دبي، وتتولى شركة PRONEXT التابعة لها في الرياض استفسارات العملاء في المملكة. نوفّر إدارة الأجهزة المحمولة (MDM) عبر FileWave، ووحدات تخزين مشفّرة عتاديًا (فلاش ميموري مشفر وأقراص صلبة مشفرة) من Kanguru مع إدارتها عن بعد، وأجهزة نسخ الهارد ومسحه، وأرشفة البيانات طويلة الأمد عبر Disk Archive ALTO.

تطلب الضوابط الأساسية للأمن السيبراني ECC-2:2024 الصادرة عن الهيئة الوطنية للأمن السيبراني تقييدًا صارمًا لاستخدام وسائط التخزين الخارجية وحمايتها (2.3.3.2)، وفصل بيانات الجهة وتشفيرها على الأجهزة المحمولة والأجهزة الشخصية (2.6.3.1)، وحذفها عند فقدان الجهاز أو انتهاء العمل (2.6.3.3)، والنسخ الاحتياطي واختبار الاستعادة (2-9-3)، وأمن إتلاف الأصول وإعادة استخدامها بما فيها وسائط التخزين (2.14.3.4).

وفي القطاع المالي يذكر الإطار التنظيمي للأمن السيبراني الصادر عن البنك المركزي السعودي استخدام إدارة الأجهزة المحمولة ضمن ضوابط الأجهزة الشخصية (3.3.10)، والمسح الآمن والإتلاف عند التخلص من الأصول (3.3.11). ويشترط نظام حماية البيانات الشخصية ولائحته التنفيذية إتلاف جميع نسخ البيانات الشخصية بما فيها النسخ الاحتياطية عند وجوب إتلافها، وإبلاغ الجهة المختصة عن التسرب خلال 72 ساعة.

لا يجعل أي جهاز المؤسسةَ ممتثلة بمفرده؛ فالسياسات والموافقات والسجلات هي ما يطلبه المدقق، والحلول تجعل تطبيقها ممكنًا. أرسلوا متطلباتكم وعدد الأجهزة والمدن المعنية إلى sales@protech.ae أو اتصلوا على ‎+971 4 343 5501.

Plan an Enterprise IT project in the Kingdom

Tell us the controls you are audited against, your device and drive numbers and the cities involved. Saudi enquiries are handled by PRONEXT in Riyadh, with the Enterprise IT team in Dubai.

PRO TECHnology Co. L.L.C. · Office 204, Aswar Building, Sheikh Zayed Road, Business Bay, Dubai, UAE · +971 4 343 5501 · info@protech.ae