01Introduction
Banks, insurers and finance companies regulated in Saudi Arabia must meet the central bank's cybersecurity framework, and they're assessed on how mature their controls are, not just whether they exist. See fintech.
02What is SAMA CSF?
The SAMA Cyber Security Framework is issued by the Saudi Central Bank (SAMA) for its regulated financial institutions. It is organized into four domains: leadership and governance, risk management and compliance, operations and technology, and third-party security.
Institutions are rated on a maturity scale from 0 to 5, with level 3 the expected minimum. The operations and technology domain includes vulnerability management and penetration testing. SAMA also publishes a separate framework for threat-led ethical red teaming of financial entities.
03How SAMA CSF works
Institutions work toward a target maturity level.
- 1.
Self-assess
Rate current maturity for each control against SAMA's scale.
- 2.
Close gaps
Formalize, implement and measure controls to reach at least level 3.
- 3.
Test
Run periodic penetration tests and vulnerability scans on critical systems.
- 4.
Supervisory review
SAMA reviews self-assessments and conducts its own examinations.
04Threats and risks
Financial institutions face a concentrated set of threats.
Fraud and account takeover
Attacks on digital banking and payment flows.
API exposure
Open banking and fintech APIs with access control flaws.
Third-party risk
Outsourced and cloud providers holding customer data.
Supervisory findings
Maturity below level 3 triggers regulatory attention.
05How Parameter helps
Parameter helps show that testing is defined, repeatable and measured, which is what maturity levels reward.
Continuous testing
The pentesting agents test digital banking apps and APIs on every release.
Red team preparation
Red team as a service surfaces attack paths before a formal exercise.
Measured remediation
Findings, fixes and retests give the metrics a higher maturity level needs.

