Cloud security & compliance on AWS — engineered for NCA, SAMA and PDPL.

White Stork designs and secures AWS environments around the controls that matter for NCA ECC and Cloud Cybersecurity Controls, SAMA CSF, and PDPL — including encryption, identity, monitoring, logging, and regional data residency requirements. AWS Advanced Tier Services Partner, backed by ISO 27001-certified practices, with delivery in Arabic and English.

  • AWS Advanced Tier Services Partner
  • ISO 27001 (in certification)
  • Well-Architected — Security pillar
  • In-region data residency
  • NCA · SAMA · PDPL
  • Bilingual
  • Since 2012
How we secure & keep you compliant

Five layers, one team.

Mapped to your requirements, engineered into the build, and monitored continuously — by the same AWS engineering team that runs your cloud.

Mapped to your requirements, not generic “best practice.”

We map your AWS environment to applicable NCA ECC and Cloud Cybersecurity Controls (CCC), SAMA Cyber Security Framework, and PDPL requirements — and produce the technical evidence needed to demonstrate how those controls are implemented.

Capability provenCompliance expressed as concrete AWS configuration, not a policy PDF.

Security engineered into the build (DevSecOps).

IAM least-privilege, encryption at rest and in transit, secrets management, network segmentation, and automated patching — built into the pipeline, not bolted on.

Capability provenSecure-by-default environments, every deploy.

Keep your data in-region.

Deploy workloads in AWS Bahrain, UAE, or Saudi Arabia to support applicable data-residency and sovereignty requirements.

Capability provenResidency answered by architecture, not promises.

Continuous detection & compliance.

AWS-native monitoring — GuardDuty, Security Hub, CloudTrail, Config — for threat detection and audit-ready posture, watched as part of how we run your cloud.

Capability provenOngoing compliance, not a one-off certificate.

Built against recognized standards.

We review environments against the AWS Well-Architected Framework, including the Security pillar, and align our internal security practices with ISO 27001 requirements.

Capability provenSecurity grounded in recognized frameworks, not ad-hoc practice.
What we map to

The frameworks and controls we map to.

F1 · Regulatory & legal

NCA ECC

Saudi Arabia’s Essential Cybersecurity Controls — baseline cybersecurity requirements for organizations within NCA scope.

F2 · Regulatory & legal

NCA CCC

NCA’s Cloud Cybersecurity Controls — cybersecurity requirements specifically addressing cloud environments and services.

F3 · Regulatory & legal

SAMA CSF

The Saudi Central Bank Cyber Security Framework for regulated financial institutions.

F4 · Regulatory & legal

PDPL

Saudi Arabia’s Personal Data Protection Law — requirements for collecting, processing, storing, sharing and transferring personal data.

F5 · Security standard

ISO 27001

The international standard for information security management — our ISO 27001 certification is currently in progress.

F6 · AWS frameworks

AWS Well-Architected

AWS Well-Architected security principles applied to how we design and review cloud environments.

F7 · AWS frameworks

Shared Responsibility

AWS secures the cloud; we engineer, operate and evidence your side of the shared responsibility model.

We map your environment control by control — and provide the evidence to show how each requirement is implemented.

Book a free review
What we do

Security and compliance, end to end.

  1. Cloud compliance assessment & remediation — NCA / SAMA / PDPL

    Your AWS mapped to the controls auditors check, then the gaps closed.

  2. Cloud security architecture & DevSecOps

    Security designed into the build and into the pipeline, not bolted on after.

  3. Data residency & sovereignty on AWS

    Architected to keep data in-region where required, with clear evidence of where it lives.

  4. Identity & access management — IAM

    Least-privilege roles and access your team can actually work with.

  5. Threat detection & monitoring — GuardDuty / Security Hub

    GuardDuty and Security Hub tuned, with actionable alerts routed to the right team.

  6. Continuous compliance / compliance-as-code

    Automated controls and policy-as-code where applicable, so compliance stays visible as the environment changes.

Why White Stork

Compliance fluency built for this region. We work across NCA, SAMA and PDPL requirements and translate them into practical AWS architecture, controls and evidence.

01

Bilingual

Arabic and English documentation, reviews, and audit evidence.

02

Cloud-native security, not a bolt-on

Security is built into how we engineer and run your AWS through DevSecOps — by the same team, not a separate vendor.

03

Aligned to recognized standards

ISO 27001 certification in progress, alongside AWS Well-Architected security practices.

04

Certified and accountable

75+ AWS certifications across our engineering team — and the same team stays accountable after go-live.

How we work

The phases

Every engagement starts with a free review that produces a prioritized gap list — then we remediate, harden, and keep you audit-ready.

5 phases

  1. Free security & compliance review

    Gap assessment against applicable NCA, SAMA and PDPL requirements and AWS Well-Architected security practices — with a prioritized findings list.

    Free
  2. Remediation roadmap

    What to fix, in what order, and why it matters to the auditor.

  3. Secure & harden

    Identity, encryption, segmentation and patching — engineered into AWS.

  4. Detect & monitor

    AWS-native threat detection, monitoring and compliance visibility.

  5. Maintain audit-readiness

    Evidence kept current. Controls reviewed continuously.

Your questions, answered

AWS provides cloud services and regional infrastructure that can support these requirements, but compliance is a shared responsibility. AWS secures the cloud; we handle your side — mapping, configuring and evidencing your environment against applicable NCA ECC/CCC, SAMA CSF and PDPL requirements.

Workloads can be deployed in AWS Bahrain, UAE or Saudi Arabia to support applicable data-residency and sovereignty requirements.

Not inherently. Security depends on how the environment is designed, configured and operated. AWS secures the underlying cloud infrastructure; we secure your workloads with encryption, identity controls, patching, monitoring and DevSecOps.

The National Cybersecurity Authority’s Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) define cybersecurity requirements for organizations and cloud environments within their scope. We map your AWS environment to the applicable controls and provide evidence of how they are implemented.

AWS secures the underlying infrastructure — “security of the cloud.” You are responsible for “security in the cloud”: your data, identities, applications and configuration. We engineer, operate and evidence that side of the shared responsibility model.