Location · Penetration Testing in Al-Zulfi, Saudi Arabia

Penetration testing in Al-Zulfi - for workshops that got connected one machine at a time.

CyberFortify delivers manual, exploit-driven penetration testing to the small manufacturers, metal workshops, fabricators and fittings producers of Al-Zulfi - a town north of Riyadh where production has quietly gone digital without anyone being appointed to own the result. We test what a workshop actually runs: the design PC holding your CAD files, the machine controller on the shop floor, the quoting spreadsheet and the supplier portal.

Aligned with: NCA ECC · PDPL · PCI DSS · ISO 27001 · OWASP · PTES · NIST 800-115
Fixed
Priced before we start
CAD
Design-file focused
100%
Manual testing
Free retest
Serving Al-Zulfi: Metal workshops & fabrication · furniture & fittings production · small manufacturers · machine shops & CNC · agriculture & food processing · contractors & suppliers · regional services · trading & distribution · family businesses Serving Al-Zulfi: Metal workshops & fabrication · furniture & fittings production · small manufacturers · machine shops & CNC · agriculture & food processing · contractors & suppliers · regional services · trading & distribution · family businesses
// Executive summary

Al-Zulfi's economy runs on small production - metal workshops, fabricators, furniture and fittings makers, agricultural suppliers and the service firms around them. Most are half-digitised: a CNC controller with a network port, a design PC full of CAD files, a quotation spreadsheet, a supplier portal login. CyberFortify runs manual network, web, cloud and API penetration tests here, scoped to what a workshop actually owns, aligned to the Saudi PDPL, NCA ECC, PCI DSS and ISO 27001. Fixed price, plain-language reporting, free remediation retest.

// 01 Why Al-Zulfi manufacturers need penetration testing

Walk through a workshop in Al-Zulfi and you can read its digital history off the walls. The oldest machines take instructions from a person. In the middle sits a CNC unit bought five or six years ago, with a network port an installer wired into the nearest switch because that beat carrying files on a stick. In the office there is a design PC holding every drawing the business has ever produced, a spreadsheet that generates every quotation, and a browser bookmarked to two or three supplier portals. Each piece was connected by a different person, on a different day, for a different reason. Nobody was ever handed the job of understanding the whole.

That is not negligence; it is what incremental modernisation looks like without an IT department to route it through. The consequences are still concrete. Your CAD files are the business - the accumulated geometry, tolerances and fixes that let you quote work a newcomer cannot - and they usually sit on one machine with one password, shared to anyone who can reach the network. A shop floor PC driving production has no backup and no vendor support contract, so ransomware on it stops output rather than inconveniencing an office. A bid pack in an unprotected mailbox is a competitor's shortcut to your margin. A penetration test answers the question an owner is entitled to ask plainly: given how this place is actually wired, what could someone reach - and what breaks if they do?

// 02 Compliance and regulatory drivers in Al-Zulfi

Small manufacturers rarely feel regulated until a customer's procurement form arrives. These are the obligations CyberFortify most often maps evidence against for Al-Zulfi businesses - two are commercial rather than legal, and they are the ones that decide contracts.

R.01 · Data protection

Saudi PDPL

The Personal Data Protection Law does not exempt you for being small. Employee files, customer contacts and supplier records all count, and the law expects appropriate technical measures. Independent testing is how a workshop shows that word means something.

R.02 · National

NCA Essential Cybersecurity Controls (ECC)

If you fabricate for government bodies, municipalities or their main contractors, the NCA's ECC reaches you through the supply chain. Its Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing, and primes increasingly pass that down in writing.

R.03 · Payments

PCI DSS v4.0 - Req 11.4

Workshops taking card payments for retail sales or deposits fall inside Requirement 11.4, which mandates penetration testing of the cardholder environment and validation of any segmentation you rely on. Low volume does not remove the obligation.

R.04 · Assurance

ISO 27001 - A.8.29

Control A.8.29 asks for security testing across the lifecycle, and larger buyers now want that evidence before awarding a supply contract. A clean test report is often the cheapest way to clear a procurement gate.

R.05 · Intellectual property

Design-file and drawing confidentiality

Your CAD files, tool paths and bill of materials are the intellectual property nobody registered. No regulator enforces their protection, which is exactly why it goes untested - and why permissions on the design share are among the first things we examine.

R.06 · Continuity

Ransomware recoverability

A backup that has never been restored is not a backup, it is a belief. We test whether yours is reachable from the machines an attacker lands on first, and whether a shop floor PC could be rebuilt in a day rather than a fortnight.

// 03 Penetration testing services for Al-Zulfi

Al-Zulfi engagements usually lead with the internal network, because that is where the design PC, the shared drive and the machine controllers sit together. Web and cloud testing follows for firms running quoting or drawings from a hosted platform.

A.02

Network pen testing

Internal, perimeter and identity testing - flat networks where a shop floor PC can reach the design share, exposed remote access, and vendor support tools left behind after an installation.

A.01

Web application pen testing

Manual testing of your site, ordering pages and any hosted quoting or drawing-management platform against the OWASP Top 10 and the authorisation flaws that expose one customer's documents to another.

A.04

Cloud pen testing

Configuration-aware testing of the cloud mail, file sync and storage where drawings and quotations increasingly live - including the sharing links that were meant to be temporary.

A.05

API pen testing

Testing of supplier portal, payment and logistics integrations - the authorisation and data-exposure flaws that sit behind an ordering screen nobody has ever probed.

A.07

Phishing & social engineering

Controlled testing of how a fake supplier invoice or a spoofed drawing request would travel through a small office with short approval chains and no security team.

A.08

Compliance consulting

Turning findings into a short PDPL, NCA and ISO 27001 readiness plan an owner can execute without hiring anyone.

// 04 How we deliver to Al-Zulfi

Al-Zulfi runs on Arabia Standard Time, the same clock as our Gulf base, and sits within a straightforward drive of Riyadh. Most of an engagement runs remotely, which keeps the price proportionate to a workshop's budget; the parts that genuinely need someone on the shop floor are scheduled as a short, planned visit.

What runs remotely

External perimeter, web, cloud, mail and API testing from our secure environment, scheduled around production hours, with read-outs in Arabic or English aimed at the owner rather than a security team that does not exist.

What we do on-site

Internal network and wireless testing at your Al-Zulfi premises - walking the segment between office and shop floor, checking what a machine controller can reach, and confirming whether a backup restore has ever been performed.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote returned within the hour. We work around production - no testing that risks a controller mid-run - and we will say plainly if the scope you asked for exceeds your risk. The free retest means you can prove the fixes held without commissioning a second job.

// 05 Industries we secure in Al-Zulfi

The town's economy is production, land and the services that support both. CyberFortify tests across the sectors that shape its risk:

Metal workshops & fabricationCNC · tool paths · drawings · shop floor PCs
Furniture & fittings productionCAD libraries · cutting lists · showroom systems
Small manufacturers & assemblyBill of materials · quotations · supplier portals
Agriculture & food processingCold storage controls · irrigation · supply records
Contractors & suppliersTender documents · bid packs · client data
Regional services & tradingRetail · card payments · family businesses

// 06 Our methodology

An Al-Zulfi workshop gets the same disciplined process CyberFortify runs for far larger clients - the invoice scales down, the rigour does not. Testing follows the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP. As a CREST Accreditation Pathway firm, we lead with manual testing: a scanner will never notice that a production PC can browse to the design share, but a tester will.

01

Scoping & rules of engagement

In-scope systems, production-safe test windows and escalation contacts agreed in writing, with machine controllers handled by explicit rule rather than assumption.

Fixed quote in 1h
02

Mapping what is connected

We draw the picture nobody currently holds: what the design PC, shop floor machines, mailbox and supplier portal can each reach.

ATT&CK aligned
03

Manual exploitation

Weaknesses are chained under controlled conditions to prove real paths to your drawings and production systems, with false positives removed by hand.

Controlled exploit
04

Reporting & free retest

A report an owner can act on without translation, ordered by production impact and mapped to PDPL, NCA and ISO 27001 - then a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Al-Zulfi

A scan report and a shrug

An automated scan sold as a penetration test - three hundred pages of colour-coded output with no view on which finding could stop your machines - or a proposal built for a bank and priced accordingly.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team in your own time zone that scopes to a workshop, not an enterprise. Real manual exploitation, findings ranked by production impact and design-file exposure, plain-language read-outs in Arabic or English, fixed pricing and a free retest.

Al-Zulfi engagements often pair an internal network test with compliance consulting, so the result is a short plan for protecting drawings and restoring production - not a document filed beside the machine manuals.

// 08 Frequently asked questions

Why would anyone attack a small workshop in Al-Zulfi?

Most of the time nobody chooses you specifically. Ransomware crews buy access in bulk from scanners that sweep the internet for exposed remote desktop, weak passwords and unpatched file sharing, then encrypt whatever they land on. A twelve-person workshop with a design PC and a shared drive is worth encrypting because it will pay to get the drawings back. Targeted theft of a bid or a drawing set happens too, usually through a compromised mailbox rather than anything sophisticated.

Our CNC machine is not connected to the internet. Is it still at risk?

Usually it is more connected than the owner believes. The controller may not reach the internet directly, but it sits on the same flat network as the office PCs, or it accepts tool paths from a USB stick that was last plugged into a machine with no antivirus, or its vendor left a remote support tool installed. We map what the machine can actually reach and what can actually reach it, which is often the first time anyone has drawn that picture.

How do you protect our CAD files and drawings during a test?

We prove access without taking your intellectual property. If we can reach a design share, we evidence it with directory listings, file names and hashes rather than copying drawings out, and anything incidental is destroyed at the end of the engagement under the terms of the signed agreement. Your bill of materials, quotations and tool paths stay where they are.

We have backups. Do we still need a penetration test?

Backups and testing answer different questions, and most small manufacturers have never answered either one properly. A backup that has never been restored is a hypothesis, and if it is a drive left permanently attached to the server, ransomware will encrypt it alongside everything else. We check whether your backup is reachable from the machines an attacker would compromise, and we ask when a restore was last performed end to end.

Which rules apply to a manufacturer in Al-Zulfi?

The Saudi PDPL covers the employee, customer and supplier records you hold regardless of your headcount. If you supply government bodies or work through their portals, the NCA Essential Cybersecurity Controls reach you as a supplier and require periodic vulnerability assessment and penetration testing. If you take card payments, PCI DSS 4.0 Requirement 11.4 applies. Larger customers increasingly ask for ISO 27001 evidence before awarding contracts.

Ready for a pen test in Al-Zulfi?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →