العربية

Service · Board simulation

The board's first decision is due before the forensics are.

Technical exercises rehearse containment. Boards do not contain anything. They decide what to tell a regulator on a clock they did not set, whether to keep trading, what to say publicly, and who speaks — usually with partial information and a legal team still reading the contract. That is the exercise nobody runs.

Why the clock is the scenario

In this region the regulatory deadline usually arrives before technical certainty does. Bahrain's central bank rules put the CBB on a phone call within one hour of an incident. Oman's data protection law runs a 72-hour breach notification. Qatar and Saudi Arabia each have their own reporting expectations attached to their assurance regimes, and a group operating across three Gulf states is on three different clocks simultaneously, in three languages, with three sets of consequences for getting it wrong.

A board that has never rehearsed this defaults to waiting for facts. That is the single most expensive instinct in the room, and it is entirely reasonable — which is why it has to be surfaced in an exercise rather than in an incident.

So the scenario is built backwards from your actual obligations. Not a generic ransomware tabletop with the country name changed: your regulators, your reporting windows, your contractual notification terms, and the specific question of who is authorised to speak when the chief executive is on a plane.

How it runs

Half a day, with the board and the executives who would actually be in the room. No technical prerequisites and no preparation asked of participants.

01

Pre-work, done by us

We establish which reporting obligations genuinely apply to you, the windows attached to each, and what your existing incident plan says — so the exercise tests the plan you have rather than one we imagined.

Your obligationsYour plan
02

The exercise

Three to four injects across a compressed timeline, run in English or Arabic or both as the board needs. Decisions are recorded as they are made, including the ones that get deferred — the deferrals are usually the finding.

Half dayEN / AR
03

The pressure points

Regulatory notification under uncertainty, public and customer communication, whether to keep operating, third-party and supply-chain notification, and the authority question: who decides, and what happens when that person is unreachable.

NotifyTradeSpeak
04

Board pack

What was decided, what could not be decided and why, the gaps in delegated authority the exercise exposed, and a short list of things to change — written for the minutes, not for the security team.

For the minutes

The clocks we build scenarios around

Which of these apply is established in the pre-work. Most groups are surprised by at least one.

Bahrain

CBB Rulebook cyber security modules

e.g. Volume 4, Module RM-9

The most prescriptive mandated-assessor rule verified anywhere in the GCC, and the tightest reporting clock: the CBB notified within one hour by phone. It also requires a qualified CISO with authority to implement the strategy, and penetration testing by internal and external independent parties with the external party changed at least every two years.

The board questionWho makes a regulatory phone call inside sixty minutes, on what authority, with what almost certainly incomplete information — and what do they say if asked whether customer data is affected?
Oman

Personal Data Protection Law

RD 6/2022MD 34/2024

Breach notification within 72 hours, enforceable since February 2026, alongside a 45-day window for data subject requests. The DPO mandate is unconditional, so there is a named officer whose statutory duties run alongside the board's commercial judgement — and may not align with it.

The board questionIf the data protection officer's statutory view and the board's commercial view diverge in hour four, whose position goes to the regulator?
Kuwait and Qatar

Resilience and assurance regimes

CBK CORF v1.0NIA v2.1

Kuwait's framework, in force since December 2025, is explicitly about operational resilience rather than controls alone — continuity of service delivery is the assessed outcome. Qatar's assurance regime attaches to a certification the NCSA can act on, which makes an incident a certification event as well as a security one.

The board questionAt what point does a continuing outage become a reportable resilience failure rather than an incident being managed — and who is watching for that threshold while everyone else watches the technical response?

What this exercise is not

It is not a technical tabletop, not a penetration test, and not an assessment of your security controls — if you want those, they are separate engagements and two of them are gated to licensed firms in some of these markets. It is also not a pass or fail. Boards that make poor decisions in a simulation have had a good day; the finding is worth more than the reassurance. We do not publish or share what happens in the room, and the board pack is yours.

Start with a scoping call

Tell us the sector, the countries you operate in, and who would actually be in the room. The scenario is built from your obligations, so the pre-work starts there.