AMAZ Trading & Contracting — Cyber Division

Defend.
Detect.
Dominate.

Enterprise-grade cybersecurity delivered by certified experts. Protecting organisations across Saudi Arabia and the GCC — from compliance frameworks to offensive security operations.

0+
Companies Served
0+
Global Certifications
0+
Security Services
0+
GCC Markets
NCA-ECC Compliance ISO 27001 Implementation Penetration Testing PDPL Consultation SIEM · NDR · EDR Red Team Operations Phishing Simulation Identity & Access Management NCA-ECC Compliance ISO 27001 Implementation Penetration Testing PDPL Consultation SIEM · NDR · EDR Red Team Operations Phishing Simulation Identity & Access Management
Who We Are

AMAZ Cyber
Division

The dedicated cybersecurity arm of AMAZ Trading & Contracting — serving enterprises, government entities, and critical infrastructure operators across Saudi Arabia and the wider GCC.

Our internationally certified team combines deep technical expertise with regional compliance knowledge to deliver end-to-end security tailored to the Gulf threat landscape.

Offensive & Defensive Capability

OSCP+, OSEP, and CRTP-certified professionals who think like attackers — and defend accordingly.

📋
Regulatory Expertise

NCA-ECC, ISO 27001, ISO 20000, and PDPL specialists ensuring full local and international compliance.

🎓
Security Awareness Culture

LMS platforms and phishing simulations that transform your workforce into a human firewall.

AMAZ Cyber Team
// Certified Security Professionals
Team Certifications
OSCP+Offensive Sec.
OSWPWireless Pro
OSEPExp. Pen Tester
CRTPRed Team Pro
CEHEthical Hacker
PMPProject Mgmt
LA-27001Lead Auditor
LI-27001Lead Implmntr
COBIT2019 Foundation
ISO 20000Svc Mgmt
eJPTJr. Pen Tester
eCPPTPro Pen Tester
Technology Solutions

Security Products

Best-in-class platforms deployed and managed by our expert engineers.

01
🔑
Identity & Access Management
Centralised IAM to enforce least-privilege access, streamline user provisioning, and provide full visibility across your identity estate. Integrate with existing directories and enforce MFA at every authentication layer.
IAMSSOMFADirectory
02
🛡
Privileged Access Management
Secure, monitor, and record every privileged session. Eliminate standing privileges and reduce insider threat with just-in-time access workflows.
PAMPIMSession Rec.
03
📱
Mobile Device Management
Enforce corporate policies and manage your entire mobile fleet — iOS, Android, and Windows endpoints from a single console.
MDMUEMBYOD
04
⚙️
Secure Config & FIM
Continuously audit configurations against CIS benchmarks and detect unauthorised file changes in real time.
FIMSCMCIS
05
🔒
DLP & Data Classification
Identify, label, and protect sensitive data across endpoints, email, and cloud. Prevent exfiltration before it happens.
DLPClassificationCASB
06
🔍
Vulnerability Management
Continuous scanning, risk-based prioritisation, and automated patch orchestration to eliminate your attack surface.
VMPatch MgmtRisk Score
07 — 08
📊
SIEM · NDR · EDR Platforms
Full-spectrum threat detection across logs, network traffic, and endpoints. Centralise events, correlate anomalies at scale, and accelerate incident response with AI-assisted alerting — catching threats that evade signature-based tools entirely.
SIEMSOARXDRNDREDR
09
🎓
Awareness LMS Platform
Branded eLearning platform delivering security awareness modules, compliance training, and phishing simulations with full analytics.
LMSAwarenessAnalytics
Professional Services

What We Deliver

Hands-on implementation, assessment, and advisory services led by certified specialists.

01
NCA-ECC Implementation Services
+
Full compliance with Saudi Arabia's Essential Cybersecurity Controls. We conduct a gap analysis across all 29 domains, build a prioritised roadmap, and guide complete implementation — from policy documentation to technical controls deployment. Includes post-implementation verification and evidence collection for NCA audits.
NCA-ECC · KSA
02
ISO 27001:2022 Implementation Services
+
End-to-end ISMS design and rollout aligned to ISO/IEC 27001:2022. Covers context analysis, risk assessment methodology, Statement of Applicability, policy suite, control implementation, and management review preparation. Delivered by certified Lead Implementers.
ISO 27001 · LI
03
ISO 20000 Service Management Implementation
+
IT Service Management framework implementation aligned to ISO/IEC 20000-1. We assess current ITSM maturity, design service management processes, and prepare your organisation for formal certification — covering incident, change, and release management disciplines.
ISO 20000 · ITSM
04
PDPL Consultation Services
+
Saudi Personal Data Protection Law readiness programme covering data inventory and mapping, privacy impact assessments, data subject rights workflows, consent management, breach notification procedures, and DPO advisory. Certified PDPL practitioners ensure full SDAIA compliance.
PDPL · SDAIA
05
ISO 27001 Internal & External Audit with Certification
+
Full audit lifecycle by certified Lead Auditors. Internal audit for readiness, management review facilitation, liaison with certification bodies, and support through Stage 1 and Stage 2 external audits. Certification fees included. Surveillance audit support available.
ISO 27001 · LA
06
Network Vulnerability Assessment (Internal & External)
+
Comprehensive network scanning, manual verification, and exploitation testing across internal infrastructure and internet-facing assets. Deliverables include an executive summary, technical findings with CVSS ratings, and a phased remediation roadmap. Retest included.
VAPT · Network
07
Web Application Penetration Testing
+
OWASP Top 10 and WSTG-aligned manual penetration testing of internal and external web applications. Covers authentication bypasses, injection flaws, business logic vulnerabilities, API security, and access control weaknesses. Delivered with proof-of-concept report and developer-focused remediation guidance.
WAPT · OWASP
08
Mobile Application Penetration Testing
+
Security assessment of iOS and Android applications covering SAST, dynamic runtime testing, API security review, insecure data storage, and traffic interception. Aligned to OWASP Mobile Top 10 and MASVS framework. Delivered by eCPPT and CRTP-certified analysts.
MAPT · MASVS
09
Phishing Simulation Campaigns
+
Multi-vector phishing and spear-phishing campaigns simulating current threat actor tactics. Real-time dashboard tracks click rates and department-level exposure. Employees who interact with simulations are auto-enrolled in targeted awareness training via the LMS platform.
Social Engineering
10
Cybersecurity Awareness Sessions
+
Instructor-led workshops, executive briefings, and customised eLearning programmes building a security-first culture. Topics include social engineering, safe remote working, password hygiene, incident reporting, and compliance obligations. Available in Arabic and English, on-site or virtual.
Arabic · English
Coverage

Saudi Arabia
& The GCC

Headquartered in the Kingdom, AMAZ Cyber serves enterprises and government bodies across all six Gulf Cooperation Council states.

🇸🇦 Saudi Arabia
🇦🇪 UAE
🇶🇦 Qatar
🇰🇼 Kuwait
🇧🇭 Bahrain
🇴🇲 Oman
Compliance Frameworks
NCA-ECC
Saudi National Cybersecurity Authority Essential Cybersecurity Controls
ISO 27001
International Information Security Management System Standard
ISO 20000
IT Service Management — Certification & Implementation
PDPL
Saudi Personal Data Protection Law Compliance
COBIT 2019
Enterprise IT Governance & Management Framework
SECURE

Ready to Secure
Your Organisation?

Let our experts assess your current posture and build a roadmap that fits your risk appetite.