Selected Engagement: Advancing Cybersecurity Maturity for Tabby

About The Customer

Tabby is a leading fintech platform operating in a rapidly growing and highly regulated financial ecosystem.

Facing increasing regulatory expectations and the need to strengthen its cybersecurity maturity in alignment with Saudi Central Bank requirements, the organization initiated a comprehensive cybersecurity maturity assessment aligned with the SAMA Cybersecurity Framework.

The engagement delivered a structured evaluation of cybersecurity capabilities, enabling improved visibility, identification of maturity gaps, and the development of a clear roadmap toward higher maturity levels and regulatory readiness.

Engagement Snapshot

01

Problem Statement

Limited visibility into cybersecurity maturity and gaps against SAMA CSF requirements

02

Proposed Solution

Comprehensive maturity assessment with control-level evaluation, evidence validation, and structured advisory

03

Outcome

Improved cybersecurity maturity visibility, clear remediation roadmap, and enhanced regulatory readiness

The Challenge

  • Aligning cybersecurity practices with SAMA CSF maturity expectations
  • Limited visibility into effectiveness of controls across domains
  • Gaps in documentation, evidence, and governance structures
  • Need to prepare for regulatory assessments and audits
  • Increasing complexity due to rapid growth of the fintech environment

Our Methodology

01

Comprehensive Maturity Assessments

Conducted comprehensive cybersecurity maturity assessments aligned with the SAMA Cybersecurity Framework, evaluating capabilities across governance, risk, and operational domains

02

Control-Level Assessment

Performed detailed control-level assessments to measure effectiveness, consistency, and alignment with regulatory expectations

03

Review & Validation of Evidences

Reviewed and validated supporting evidence to confirm implementation maturity and identify gaps in documentation and control execution

04

Identifying Weaknesses

Identified key weaknesses across processes, controls, and governance structures, highlighting areas requiring formalisation and standardisation

05

Providing Recommendations

Provided targeted, risk-based remediation recommendations to address identified gaps and strengthen overall cybersecurity posture

06

Developing Action Plan

Developed a prioritized and actionable roadmap to guide the organization toward higher maturity levels and sustained regulatory alignment

The Outcome

  • Enhanced visibility into cybersecurity maturity across key domains
  • Identified and prioritized critical gaps impacting regulatory alignment
  • Strengthened governance practices and control implementation
  • Improved readiness for regulatory assessments and audits
  • Enabled structured, risk-based decision-making for cybersecurity improvements

Key Highlights

01

Regulatory Alignment

250+ controls assessed and aligned with SAMA CSF maturity expectations above ML3

02

Control Assurance

End-to-end control-level evaluation supported by 1000+ evidence validation and multiple review cycles

03

Risk Visibility

Comprehensive gap analysis identifying high-impact regulatory and operational risks

04

Targeted Remediation

Structured, risk-based remediation roadmap enabling targeted maturity improvement

05

Governance Strengthening

Enhanced governance and control effectiveness through continuous advisory engagement

What Tabby Says About The Outcome

Through this engagement, Tabby gained a clear and structured understanding of its cybersecurity maturity, enabling focused improvements and stronger alignment with regulatory expectations.
Weam Munshi, CISOCISO
Want to move from cybersecurity complexity to clarity?
ASSESS.ELEVATE.STRENGTHEN.

Want to move from cybersecurity complexity to clarity?

Contact Us