- July 23, 2026
- admin
If your organisation operates in Saudi Arabia, you already know that the regulatory environment around data has changed dramatically over the past two years. The Kingdom’s Personal Data Protection Law (PDPL) is now in full enforcement. The National Cybersecurity Authority’s (NCA) Essential Cybersecurity Controls (ECC) have also been updated and expanded. Regulators are no longer waiting for organisations to report issues, they are actively identifying compliance failures and taking enforcement action.
In 2025 and 2026, the Saudi Data & AI Authority (SDAIA) issued 48 enforcement decisions confirming violations of the PDPL. These included processing personal data without a valid legal basis, unauthorised disclosure of personal information, and failure to implement appropriate technical and organisational safeguards. These are no longer theoretical risks; enforcement is active, and penalties can be substantial.
In this environment, Data Loss Prevention (DLP) has become a compliance necessity rather than an optional security enhancement. For organisations that must ensure their security infrastructure remains inside Saudi Arabia, Fortinet FortiDLP, deployed on a KSA-hosted cloud, provides a practical solution that supports regulatory requirements while strengthening data protection.
Why Data Residency Is Non-Negotiable in Saudi Arabia
A fundamental principle of Saudi Arabia’s regulatory framework is that sensitive data relating to Saudi citizens, residents, and organisations should generally remain within the Kingdom. The Saudi Central Bank (SAMA) requires banks and financial institutions to store customer information, payment data, and transaction records within Saudi Arabia. Similarly, the NCA’s Essential Cybersecurity Controls require organisations operating critical infrastructure to classify sensitive information, identify where it resides, and implement controls that prevent unauthorised movement.
These requirements also extend to backups and disaster recovery environments. Organisations cannot simply host production systems in Saudi Arabia while replicating backup data overseas. Unless specifically authorised, all copies, replicas, snapshots, and archives containing regulated customer information must remain within Saudi borders.
For cloud-delivered cybersecurity solutions, this creates an important consideration. If a DLP platform processes sensitive information through infrastructure located outside the Kingdom, even temporarily or during analysis, it may introduce unnecessary compliance risk.
Fortinet addresses this requirement through its FortiDLP Advanced with Premium Hosting licence, which enables deployments hosted entirely within Saudi Arabian infrastructure, ensuring that sensitive security data remains inside the Kingdom.
What FortiDLP Actually Does
Before considering its compliance benefits, it is worth understanding why FortiDLP represents a significant evolution beyond traditional Data Loss Prevention platforms.
Legacy DLP solutions were designed around static policies and perimeter-based controls. They frequently generate excessive false positives, provide little business context, and overwhelm security teams with alerts while genuine data leaks continue through legitimate business workflows.
FortiDLP takes a fundamentally different approach. Built as a cloud-native platform, it combines AI-enhanced analytics with real-time, content-aware inspection to understand not only what data moved, but why it moved, how it moved, and whether the activity actually represents a security risk. It also maps detections to the MITRE Engenuity Insider Threat TTP Knowledge Base, helping security teams investigate incidents more effectively.
The Core licence provides comprehensive endpoint Data Loss Prevention capabilities, including monitoring of:
- Clipboard activity
- Web uploads
- Printing
- USB devices
- Cloud storage services
This makes it particularly suitable for organisations focused on regulatory compliance while maintaining minimal operational overhead.
The Advanced licence expands those capabilities with:
- User and Entity Behaviour Analytics (UEBA)
- Insider Risk Management
- FortiAI
- Full SaaS visibility across Microsoft 365, Google Workspace, and Box
For Saudi organisations managing both cloud adoption and increasing regulatory obligations, this combination provides considerably deeper visibility into how sensitive information is accessed, shared, and protected.
How FortiDLP Supports Saudi Compliance Requirements
FortiDLP aligns well with several major Saudi regulatory frameworks.
Personal Data Protection Law (PDPL)
The PDPL requires organisations to implement appropriate technical and organisational safeguards, minimise unnecessary data collection, enforce purpose limitation, and protect personal information throughout its lifecycle.
FortiDLP supports these obligations through:
- Real-time content inspection
- Automatic classification of sensitive information
- Policy-based handling controls
- Continuous monitoring of data movement across users and devices
These capabilities help organisations demonstrate that appropriate technical measures are in place to safeguard regulated information.
National Cybersecurity Authority Essential Cybersecurity Controls (ECC)
The NCA ECC requires organisations to:
- Classify sensitive information
- Maintain visibility into where data resides
- Prevent unauthorised movement of critical information
- Maintain an accurate inventory of systems handling sensitive data
FortiDLP provides continuous visibility across:
- Endpoints
- Cloud storage
- SaaS applications
- User activity
- Data movement
This significantly simplifies the process of maintaining an accurate inventory while providing
evidence that appropriate controls are operating effectively.
Saudi Central Bank (SAMA)
For banks and regulated financial institutions, data residency requirements are particularly strict.
Deploying FortiDLP within Saudi-hosted infrastructure eliminates one of the most significant compliance concerns: the possibility that sensitive customer information could be processed or temporarily stored outside Saudi Arabia during security analysis. FortiDLP also stores forensic artefacts, including clipboard captures, screenshots, and shadow file copies, in customer-managed secure object storage. Combined with role-based access controls (RBAC) and PII pseudonymisation, organisations retain control of sensitive evidence while maintaining strong privacy protections.
These architectural capabilities align with international standards such as:
- ISO 27001
- NIST
- PCI DSS
- HIPAA
- GDPR
- CCPA
At the same time, they support organisations working toward compliance with Saudi-specific regulations including PDPL and the NCA Essential Cybersecurity Controls.
Addressing Insider Risk
Not all data loss originates from external attackers.
Many security incidents result from employees, whether through accidental mistakes, negligent behaviour, or deliberate misuse of sensitive information. Industry research indicates that 77% of organisations experienced insider-related data loss incidents within the past 18 months, while 58% reported six or more separate incidents during the same period. Traditional rule-based DLP systems often struggle to distinguish genuine threats from normal business activity.
FortiDLP addresses this challenge through behavioural analytics. Rather than relying solely on predefined policies, it establishes a baseline of normal user behaviour and identifies meaningful deviations that may indicate elevated risk. This contextual approach enables security teams to focus on incidents that truly warrant investigation while reducing alert fatigue.
Getting Started
For organisations evaluating their Data Loss Prevention strategy, several important questions should be considered:
- Does your current DLP solution provide visibility across endpoints, cloud platforms, and SaaS applications?
- Is your security data processed entirely within Saudi Arabia?
- Can you provide regulators with audit-ready evidence demonstrating that sensitive information is properly classified, monitored, and protected?
- Does your DLP solution support both compliance reporting and proactive insider risk management?
Meeting NCA requirements is about more than avoiding regulatory penalties. Strong cybersecurity governance builds confidence among customers, government agencies, business partners, and international stakeholders.
As Saudi Arabia continues to accelerate its Vision 2030 digital transformation initiatives, cybersecurity compliance has become a fundamental business requirement rather than a competitive advantage.
FortiDLP, deployed on Saudi-hosted infrastructure, provides organisations with a practical path toward meeting these expectations by combining modern Data Loss Prevention capabilities with the data residency assurances demanded by Saudi regulators.
Interested in Learning More?
If your organisation is planning to deploy FortiDLP within a Saudi-hosted environment to support compliance with PDPL, NCA Essential Cybersecurity Controls, or SAMA requirements, our team can help. We work with organisations across the Kingdom to design, implement, and manage compliant data security programmes that strengthen protection while supporting evolving regulatory obligations.
Contact us today to discuss how FortiDLP can help secure your data while keeping it where it belongs, inside the Kingdom.
Insider Risk Is a Business Challenge, Not Just a Technical One
Insider risk can never be completely eliminated. Any organisation that gives people access to sensitive information will face some level of exposure.
However, the organisations that manage insider threats most effectively understand that the challenge extends beyond cybersecurity technology. Success requires a combination of:
- Security awareness
- Governance
- Access management
- Monitoring and detection
- Employee engagement
- Incident response planning
By combining these elements into a comprehensive strategy, businesses can significantly reduce their exposure to insider-driven incidents.
How ProSecure Can Help
As insider threats continue to evolve, organisations need a proactive approach that combines technology, governance, and security culture.
ProSecure Limited provides cybersecurity consulting, security assessments, governance frameworks, security awareness programmes, monitoring solutions, and incident response expertise to help organisations identify, manage, and reduce insider risk across their environments.
Want to assess your organisation’s insider risk exposure and strengthen your security posture? Contact ProSecure Limited today to learn how our cybersecurity experts can help protect your business from threats both outside and inside your organisation.