Start with business services, not a generic control count
A portfolio company should first identify the services, systems and data whose failure would materially affect customers, revenue, operations or regulatory obligations. Cyber assurance then asks whether identity, architecture, resilience, vendors and incident readiness are appropriate to that exposure.
This approach makes cross-portfolio comparison more useful because it connects controls to business materiality rather than rewarding the company with the longest checklist.
Use Saudi frameworks as operating reference points
The National Cybersecurity Authority is Saudi Arabia's national reference for cybersecurity. Its regulatory library includes Essential Cybersecurity Controls, cloud controls, data controls and, in July 2026, a National Framework for Cybersecurity Risk Management.
The investor's role is not to certify compliance. It is to know which frameworks apply to the company, whether material gaps are understood, and whether management has credible ownership and remediation.
Add AI-specific cyber questions
NCA's 2026 consultation on AI Cybersecurity Guidelines organized the topic around governance, cyber defense, resilience and third-party cybersecurity, explicitly including generative and agentic AI.
That maps well to portfolio oversight: which AI systems are material, what data they touch, which model or platform vendors they depend on, what failure modes exist, and how incidents or model changes are monitored.
A useful quarterly portfolio view
- Critical cyber risks open, closing and overdue
- Privileged-access and identity exceptions
- Recovery-test status for material services
- Critical third-party dependencies and unresolved concentration risk
- Material incidents and lessons implemented
- AI systems with unresolved security or governance issues
- Major technology programmes changing the risk profile
Keep the dashboard subordinate to the evidence
Red/amber/green status can help a principal scan a portfolio, but it should never replace the underlying evidence. A red item needs an owner, business consequence, target state and closure evidence.
The board should be able to tell whether exposure is reducing, not just whether more controls have been documented.