Location · Penetration Testing in Duba, Saudi Arabia

Penetration testing in Duba for the systems that move people, not just freight.

CyberFortify delivers manual, exploit-driven penetration testing to Duba's ferry and terminal operators, ticketing platforms, ro-ro cargo handlers and fishing businesses - the northwest Red Sea port where a routine crossing to Egypt turns a modest operator into the custodian of travel documents for thousands of passengers. We test the systems that hold that data and the manifests that account for the people it describes.

Aligned with: NCA ECC · Saudi PDPL · PCI DSS 4.0 · ISO 27001 · OWASP · PTES · NIST 800-115
PDPL
Passenger data first
11.4
PCI DSS for ticketing
Manual
Exploit-driven testing
Free retest
Serving Duba: Ferry & passenger terminal operations · ticketing & check-in platforms · ro-ro & cargo handling · berth & port services · fishing fleet & cold storage · travel agencies · logistics & haulage · hospitality · healthcare · retail & regional commerce Serving Duba: Ferry & passenger terminal operations · ticketing & check-in platforms · ro-ro & cargo handling · berth & port services · fishing fleet & cold storage · travel agencies · logistics & haulage · hospitality · healthcare · retail & regional commerce
// Executive summary

Duba is a small port with a large data responsibility - a Tabuk Province ferry town whose passenger link to Egypt puts travel documents, manifests and ticketing payments through the systems of modestly sized operators. CyberFortify runs manual web, API, cloud and network testing for organisations here, mapped to NCA ECC, the Saudi PDPL, PCI DSS 4.0 and ISO 27001. Fixed price, audit-ready reporting, free remediation retest.

// 01 Why Duba businesses need penetration testing

Count what crosses a ferry desk in a single sailing season. Every traveller hands over a travel document; the number, nationality, date of birth and validity go into a booking record. A card pays for the ticket. A phone number goes on the reservation so the operator can reach the family if departure slips. A name and seat go onto the boarding list, and that list becomes the manifest submitted onward to the authorities who clear the crossing. A town of roughly 55,000 people ends up holding the identity documents of a multiple of that number, refreshed every season, in systems maintained on a regional operator's budget.

That mismatch between the size of the business and the sensitivity of what it holds is the security argument for Duba. Attackers size targets by what the data is worth, and travel document numbers attached to real names and real travel dates are worth a great deal to document-fraud and identity-theft operations. The exposure is rarely dramatic: a booking-lookup endpoint that returns any passenger name record if you guess the reference, a check-in portal whose session never really binds to a booking, an inherited reporting database holding last season's manifests with no owner. Around it sits the ro-ro side of the berth and a fishing fleet with its own cold-storage and traceability records. An automated scan finds none of the authorisation flaws that matter here, because each one needs a human holding two bookings and trying to read across them.

// 02 Compliance and regulatory drivers in Duba

Duba's obligations are shaped by personal data rather than process safety. These are the drivers CyberFortify most often maps evidence against for operators in Tabuk Province.

R.01 · Personal data

Saudi PDPL - travel documents & cross-border transfer

Passport and ID numbers, nationality and dates of birth are personal data under the PDPL, and a crossing moves that data beyond the Kingdom. We test whether it is minimised, access-controlled and protected in transit.

R.02 · Payments

PCI DSS 4.0 Requirement 11.4

Ticketing takes card payments online, at the counter and through agents. Requirement 11.4 obliges annual and post-change testing of the cardholder data environment and its segmentation.

R.03 · Safety record

Manifest integrity as a safety control

The manifest answers who is on board. If boarding records can be altered without authentication or a reconcilable audit trail, the count responders rely on is wrong. We test integrity and logging, not only confidentiality.

R.04 · National

NCA Essential Cybersecurity Controls (ECC)

Government bodies, critical-sector operators and their suppliers fall under the ECC, whose Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing of the enterprise estate.

R.05 · Identity documents

Traveller identity-document protection

Scans of travel documents accumulate in ticketing back-ends, mailboxes and support tickets. We hunt for those copies, test how they are stored and served, and flag retention with no remaining purpose.

R.06 · Governance

ISO 27001 control A.8.29

Operators certifying to ISO 27001:2022 need independent security testing evidence for A.8.29, and increasingly need it to satisfy the partners and agents who connect to their booking systems.

// 03 Penetration testing services for Duba

Duba engagements lead with the booking and boarding stack, because that is where identity data lives. Cargo and fishing operators start with network and cloud instead.

A.01

Web application pen testing

Manual testing of booking, check-in, agent and passenger portals against the OWASP Top 10 - authorisation, session handling and account recovery first.

A.05

API pen testing

Booking-lookup, ticketing inventory, manifest submission and agent integrations tested for broken object-level authorisation and over-trusting partner connections.

A.02

Network pen testing

External perimeter, internal Active Directory, terminal and back-office segmentation, and the remote access vendors keep into port systems.

A.04

Cloud pen testing

Configuration-aware testing of the hosted booking, reporting and storage workloads where passenger records and document scans end up.

A.03

Mobile app pen testing

iOS and Android review of passenger, boarding-scan and crew applications - local storage of tickets and documents is a recurring weak point.

A.07

Red teaming

Goal-based simulation asking a blunt question: could someone reach the passenger database, and would anyone notice before they left with it?

// 04 How we deliver to Duba

Duba runs on Arabia Standard Time, UTC+3 - the same clock as our Gulf base - so findings are raised while your team is at their desks. CyberFortify has no office in Saudi Arabia and does not claim one: engagements here are delivered remotely, with on-site work scheduled when scope requires presence at the terminal or berth.

What runs remotely

External perimeter, booking and check-in web testing, API and cloud assessment, all delivered from our secure environment during Tabuk business hours, with Arabic or English read-outs and immediate escalation of anything critical.

What we do on-site

Internal network, wireless and segmentation testing at your Duba terminal, office or cold-storage facility - scheduled around the sailing timetable so no embarkation or landing is ever disturbed.

Every engagement opens with a free 30-minute scoping call. Targets, permitted techniques, test accounts, data-handling rules for anything resembling passenger data and escalation paths are agreed in writing first - alongside a fixed-price quote and a free retest.

// 05 Industries we secure in Duba

The town's economy is built around the harbour and the crossing. CyberFortify tests across the sectors that define Duba's risk profile:

Ferry & passenger terminalTicketing · check-in & boarding · manifests
Ro-ro & cargo handlingVehicle decks · berth services · documentation
Fishing & seafoodFleet · landing · cold storage & traceability
Travel & agenciesResellers · group bookings · payment handling
Logistics & haulageOnward transport · northwest corridor
Health, hospitality & retailClinics · guesthouses · local commerce

// 06 Our methodology

Duba engagements follow the same disciplined, audit-defensible process CyberFortify runs worldwide, weighted toward the authorisation and data-handling flaws that dominate passenger systems. Testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with web coverage against the OWASP Top 10 and OWASP API Security Top 10, and exploitation mapped to the relevant MITRE ATT&CK techniques. As a CREST Accreditation Pathway firm, we lead with manual testing - the cross-booking checks that catch identity exposure cannot be automated.

01

Scoping & data-handling agreement

Targets, test accounts, sailing-timetable constraints, permitted techniques and rules for handling any real passenger data agreed in writing before testing begins.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped and prioritised around the paths that reach travel documents, ticketing inventory and manifest data.

Data-led
03

Controlled exploitation

Authorisation, session and integrity flaws proven with real exploitation against agreed accounts - demonstrated on test records, never on live travellers.

Evidence-based
04

Reporting & free retest

Executive summary, CVSS-scored technical detail and mapping to NCA ECC, PDPL, PCI DSS 4.0 and ISO 27001 A.8.29, followed by a free remediation retest.

Audit-ready

// 07 Why CyberFortify for Duba

A scan of the booking site

A tool that crawls the public pages, reports a missing header and a TLS nit, and never logs in as two passengers to check whether one can read the other's record - which is where the breach would come from.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team on your timezone that tests booking, boarding and manifest logic by hand, proves the findings that matter with evidence, maps them to NCA ECC and the PDPL, and prices the work fixed with a free retest included.

Duba engagements typically pair a web application test of the booking and check-in stack with an API assessment of the interfaces that carry passenger records onward to agents and authorities.

// 08 Frequently asked questions

Why does a passenger terminal in Duba need penetration testing more than a cargo-only berth?

Because a passenger terminal holds identity data. A cargo berth handles consignments; a ferry terminal handles people, and to move people it collects travel document numbers, nationalities, dates of birth, contact details and payment records for thousands of travellers a season. That is a regulated dataset under the Saudi PDPL, it crosses a border with the sailing, and it attracts fraud and identity-theft operations in a way a container reference number never will.

What does testing a ticketing and check-in platform actually cover?

We test the booking flow end to end: whether one traveller's reference can be used to retrieve another's passenger name record, whether check-in and boarding endpoints enforce authorisation per booking rather than per session, whether ticketing inventory can be manipulated to create or void sailings and seats, and whether the payment path meets PCI DSS 4.0 expectations. Broken object-level authorisation on a booking-lookup API is the single most common finding in this category.

Why do you treat the passenger manifest as a safety control?

Because in an incident the manifest is the answer to the question of who is on board. If records can be silently altered, duplicated or dropped between the boarding system and the operational copy, the count that responders rely on is wrong at the worst possible moment. We test the integrity and audit trail of manifest data - whether changes are authenticated, logged and reconcilable - and treat unlogged modification as high severity even when nothing was exposed.

Which regulations apply to penetration testing in Duba?

Travel documents, contact details and passenger records are personal data under the Saudi PDPL, which also governs transferring that data outside the Kingdom. Government bodies, critical-sector operators and their suppliers fall under the NCA Essential Cybersecurity Controls, whose defence domain requires periodic vulnerability assessment and penetration testing. Anyone taking card payments for tickets adds PCI DSS 4.0 Requirement 11.4, and organisations certifying to ISO 27001:2022 use independent testing as evidence for control A.8.29.

Can you test without disrupting sailings or the fishing fleet's operations?

Yes. Web, API and cloud testing runs remotely against agreed targets, and anything touching live boarding, berth or cold-storage systems is scheduled around the sailing timetable and the landing schedule, with permitted techniques fixed in writing first. We use staging or mirrored environments for destructive test cases and never point automated tooling at systems people are queueing in front of.

Ready for a pen test in Duba?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →