<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Saudi Arabia on Mohammed Fayasuddin</title><link>https://fayasuddin.blog/tags/saudi-arabia/</link><description>Recent content in Saudi Arabia on Mohammed Fayasuddin</description><generator>Hugo -- 0.151.0</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 09:00:00 +0530</lastBuildDate><atom:link href="https://fayasuddin.blog/tags/saudi-arabia/index.xml" rel="self" type="application/rss+xml"/><item><title>NCNICC-1:2025: The First NCA Cybersecurity Controls That Now Bind Private Companies</title><link>https://fayasuddin.blog/posts/ncnicc_2025_nca_private_sector_controls/</link><pubDate>Wed, 19 Aug 2026 09:00:00 +0530</pubDate><guid>https://fayasuddin.blog/posts/ncnicc_2025_nca_private_sector_controls/</guid><description>&lt;p&gt;For years, if you ran a private company in Saudi Arabia, the National Cybersecurity Authority&amp;rsquo;s (NCA) controls were something you admired from a distance. They applied to government entities and critical national infrastructure operators. If you weren&amp;rsquo;t in those categories, you could read the frameworks, nod along, and carry on.&lt;/p&gt;
&lt;p&gt;That era just ended.&lt;/p&gt;
&lt;p&gt;In December 2025, the NCA published &lt;strong&gt;NCNICC-1:2025&lt;/strong&gt;, the Non-Critical National Information Infrastructure Cybersecurity Controls. It took effect in January 2026. And for the first time, a binding NCA framework now applies directly to the general private sector. If you run a private company in the Kingdom, this is now your problem to solve, not someone else&amp;rsquo;s.&lt;/p&gt;</description></item></channel></rss>