Al-Zulfi's economy runs on small production - metal workshops, fabricators, furniture and fittings makers, agricultural suppliers and the service firms around them. Most are half-digitised: a CNC controller with a network port, a design PC full of CAD files, a quotation spreadsheet, a supplier portal login. CyberFortify runs manual network, web, cloud and API penetration tests here, scoped to what a workshop actually owns, aligned to the Saudi PDPL, NCA ECC, PCI DSS and ISO 27001. Fixed price, plain-language reporting, free remediation retest.
// 01 Why Al-Zulfi manufacturers need penetration testing
Walk through a workshop in Al-Zulfi and you can read its digital history off the walls. The oldest machines take instructions from a person. In the middle sits a CNC unit bought five or six years ago, with a network port an installer wired into the nearest switch because that beat carrying files on a stick. In the office there is a design PC holding every drawing the business has ever produced, a spreadsheet that generates every quotation, and a browser bookmarked to two or three supplier portals. Each piece was connected by a different person, on a different day, for a different reason. Nobody was ever handed the job of understanding the whole.
That is not negligence; it is what incremental modernisation looks like without an IT department to route it through. The consequences are still concrete. Your CAD files are the business - the accumulated geometry, tolerances and fixes that let you quote work a newcomer cannot - and they usually sit on one machine with one password, shared to anyone who can reach the network. A shop floor PC driving production has no backup and no vendor support contract, so ransomware on it stops output rather than inconveniencing an office. A bid pack in an unprotected mailbox is a competitor's shortcut to your margin. A penetration test answers the question an owner is entitled to ask plainly: given how this place is actually wired, what could someone reach - and what breaks if they do?
// 02 Compliance and regulatory drivers in Al-Zulfi
Small manufacturers rarely feel regulated until a customer's procurement form arrives. These are the obligations CyberFortify most often maps evidence against for Al-Zulfi businesses - two are commercial rather than legal, and they are the ones that decide contracts.
Saudi PDPL
The Personal Data Protection Law does not exempt you for being small. Employee files, customer contacts and supplier records all count, and the law expects appropriate technical measures. Independent testing is how a workshop shows that word means something.
NCA Essential Cybersecurity Controls (ECC)
If you fabricate for government bodies, municipalities or their main contractors, the NCA's ECC reaches you through the supply chain. Its Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing, and primes increasingly pass that down in writing.
PCI DSS v4.0 - Req 11.4
Workshops taking card payments for retail sales or deposits fall inside Requirement 11.4, which mandates penetration testing of the cardholder environment and validation of any segmentation you rely on. Low volume does not remove the obligation.
ISO 27001 - A.8.29
Control A.8.29 asks for security testing across the lifecycle, and larger buyers now want that evidence before awarding a supply contract. A clean test report is often the cheapest way to clear a procurement gate.
Design-file and drawing confidentiality
Your CAD files, tool paths and bill of materials are the intellectual property nobody registered. No regulator enforces their protection, which is exactly why it goes untested - and why permissions on the design share are among the first things we examine.
Ransomware recoverability
A backup that has never been restored is not a backup, it is a belief. We test whether yours is reachable from the machines an attacker lands on first, and whether a shop floor PC could be rebuilt in a day rather than a fortnight.
// 03 Penetration testing services for Al-Zulfi
Al-Zulfi engagements usually lead with the internal network, because that is where the design PC, the shared drive and the machine controllers sit together. Web and cloud testing follows for firms running quoting or drawings from a hosted platform.
Network pen testing
Internal, perimeter and identity testing - flat networks where a shop floor PC can reach the design share, exposed remote access, and vendor support tools left behind after an installation.
Web application pen testing
Manual testing of your site, ordering pages and any hosted quoting or drawing-management platform against the OWASP Top 10 and the authorisation flaws that expose one customer's documents to another.
Cloud pen testing
Configuration-aware testing of the cloud mail, file sync and storage where drawings and quotations increasingly live - including the sharing links that were meant to be temporary.
API pen testing
Testing of supplier portal, payment and logistics integrations - the authorisation and data-exposure flaws that sit behind an ordering screen nobody has ever probed.
Phishing & social engineering
Controlled testing of how a fake supplier invoice or a spoofed drawing request would travel through a small office with short approval chains and no security team.
Compliance consulting
Turning findings into a short PDPL, NCA and ISO 27001 readiness plan an owner can execute without hiring anyone.
// 04 How we deliver to Al-Zulfi
Al-Zulfi runs on Arabia Standard Time, the same clock as our Gulf base, and sits within a straightforward drive of Riyadh. Most of an engagement runs remotely, which keeps the price proportionate to a workshop's budget; the parts that genuinely need someone on the shop floor are scheduled as a short, planned visit.
What runs remotely
External perimeter, web, cloud, mail and API testing from our secure environment, scheduled around production hours, with read-outs in Arabic or English aimed at the owner rather than a security team that does not exist.
What we do on-site
Internal network and wireless testing at your Al-Zulfi premises - walking the segment between office and shop floor, checking what a machine controller can reach, and confirming whether a backup restore has ever been performed.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote returned within the hour. We work around production - no testing that risks a controller mid-run - and we will say plainly if the scope you asked for exceeds your risk. The free retest means you can prove the fixes held without commissioning a second job.
// 05 Industries we secure in Al-Zulfi
The town's economy is production, land and the services that support both. CyberFortify tests across the sectors that shape its risk:
// 06 Our methodology
An Al-Zulfi workshop gets the same disciplined process CyberFortify runs for far larger clients - the invoice scales down, the rigour does not. Testing follows the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP. As a CREST Accreditation Pathway firm, we lead with manual testing: a scanner will never notice that a production PC can browse to the design share, but a tester will.
Scoping & rules of engagement
In-scope systems, production-safe test windows and escalation contacts agreed in writing, with machine controllers handled by explicit rule rather than assumption.
Fixed quote in 1hMapping what is connected
We draw the picture nobody currently holds: what the design PC, shop floor machines, mailbox and supplier portal can each reach.
ATT&CK alignedManual exploitation
Weaknesses are chained under controlled conditions to prove real paths to your drawings and production systems, with false positives removed by hand.
Controlled exploitReporting & free retest
A report an owner can act on without translation, ordered by production impact and mapped to PDPL, NCA and ISO 27001 - then a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Al-Zulfi
A scan report and a shrug
An automated scan sold as a penetration test - three hundred pages of colour-coded output with no view on which finding could stop your machines - or a proposal built for a bank and priced accordingly.
CyberFortify in the Gulf
A Gulf-based, CREST-pathway team in your own time zone that scopes to a workshop, not an enterprise. Real manual exploitation, findings ranked by production impact and design-file exposure, plain-language read-outs in Arabic or English, fixed pricing and a free retest.
Al-Zulfi engagements often pair an internal network test with compliance consulting, so the result is a short plan for protecting drawings and restoring production - not a document filed beside the machine manuals.
// 08 Frequently asked questions
Why would anyone attack a small workshop in Al-Zulfi?
Most of the time nobody chooses you specifically. Ransomware crews buy access in bulk from scanners that sweep the internet for exposed remote desktop, weak passwords and unpatched file sharing, then encrypt whatever they land on. A twelve-person workshop with a design PC and a shared drive is worth encrypting because it will pay to get the drawings back. Targeted theft of a bid or a drawing set happens too, usually through a compromised mailbox rather than anything sophisticated.
Our CNC machine is not connected to the internet. Is it still at risk?
Usually it is more connected than the owner believes. The controller may not reach the internet directly, but it sits on the same flat network as the office PCs, or it accepts tool paths from a USB stick that was last plugged into a machine with no antivirus, or its vendor left a remote support tool installed. We map what the machine can actually reach and what can actually reach it, which is often the first time anyone has drawn that picture.
How do you protect our CAD files and drawings during a test?
We prove access without taking your intellectual property. If we can reach a design share, we evidence it with directory listings, file names and hashes rather than copying drawings out, and anything incidental is destroyed at the end of the engagement under the terms of the signed agreement. Your bill of materials, quotations and tool paths stay where they are.
We have backups. Do we still need a penetration test?
Backups and testing answer different questions, and most small manufacturers have never answered either one properly. A backup that has never been restored is a hypothesis, and if it is a drive left permanently attached to the server, ransomware will encrypt it alongside everything else. We check whether your backup is reachable from the machines an attacker would compromise, and we ask when a restore was last performed end to end.
Which rules apply to a manufacturer in Al-Zulfi?
The Saudi PDPL covers the employee, customer and supplier records you hold regardless of your headcount. If you supply government bodies or work through their portals, the NCA Essential Cybersecurity Controls reach you as a supplier and require periodic vulnerability assessment and penetration testing. If you take card payments, PCI DSS 4.0 Requirement 11.4 applies. Larger customers increasingly ask for ISO 27001 evidence before awarding contracts.