Location · Penetration Testing in Dumat al-Jandal, Saudi Arabia

Penetration testing in Dumat al-Jandal for custodians of an irreplaceable record.

CyberFortify delivers manual, exploit-driven penetration testing to the research institutions, conservation programmes and organisations that hold Dumat al-Jandal's excavation and survey data - the archives, registers and 3D records that are the only surviving evidence of ground that has already been dug. We test the systems that keep that data intact, available and confidential, mapping findings to NCA ECC, the NCA Cloud Cybersecurity Controls and the Saudi PDPL.

Aligned with: NCA ECC · NCA CCC · PDPL · ISO 27001 · OWASP · PTES · NIST 800-115
NCA
ECC & Cloud aligned
Archive
Integrity tested
100%
Manual testing
Free retest
Serving Dumat al-Jandal: Archaeological research · conservation programmes · museums & collections · academic field projects · GIS & survey teams · municipal & public bodies · olive agriculture & food processing · local hospitality · professional services Serving Dumat al-Jandal: Archaeological research · conservation programmes · museums & collections · academic field projects · GIS & survey teams · municipal & public bodies · olive agriculture & food processing · local hospitality · professional services
// Executive summary

Dumat al-Jandal's most valuable digital asset is a record that cannot be recreated. Excavation destroys what it studies, so the site archive - context sheets, artefact registers, photogrammetry, 3D scans and GIS plans - carries evidence that no longer exists in the ground. CyberFortify runs manual cloud, web, API and network penetration tests for the organisations holding that data, aligned to NCA ECC, the NCA Cloud Controls and the Saudi PDPL. Fixed price, audit-ready reporting, free remediation retest.

// 01 Why Dumat al-Jandal organisations need penetration testing

Archaeology is the rare discipline that destroys its own primary source. A trench can only be excavated once; the moment a deposit is lifted, the stratigraphy that gave it meaning is gone, and what remains is the record made of it. That record is now almost entirely digital - context sheets typed into a database, photogrammetry and 3D scans of standing fabric, artefact registers keyed to find numbers, geophysical survey grids, and a GIS layer that ties every observation to a coordinate. In Dumat al-Jandal, where excavation and conservation work continues across the fortress, the old quarter and the historic mosque, this season's data is the only version of this season that will ever exist.

That produces a risk profile most IT threat models handle badly. Ransomware on a commercial network is expensive and recoverable; ransomware on a site archive with untested backups is knowledge destroyed. Silent corruption is worse, because a subtly altered artefact register or a mis-georeferenced GIS layer can propagate into publication before anyone notices. The confidentiality problem runs in parallel: precise find locations, geophysical results and unpublished survey data have real value to looters and to competitors racing to publish. Small institutions with modest IT teams carry all of this on shared drives, cloud tenants and collaboration platforms never tested against a determined attacker.

// 02 Compliance and regulatory drivers in Dumat al-Jandal

Research and heritage bodies in Al-Jouf sit inside the Saudi national control set, and their obligations bite hardest around data custody. These are the requirements CyberFortify most often maps evidence against for organisations here.

R.01 · National

NCA Essential Cybersecurity Controls (ECC)

Public bodies and the contractors and suppliers that serve them fall under the ECC, whose Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing. Our reports close those sub-controls with evidence an assessor accepts.

R.02 · Cloud

NCA Cloud Cybersecurity Controls (CCC)

Archives, imagery libraries and GIS platforms increasingly live in cloud tenants. The CCC expect technical assurance over identity, configuration and data protection - which configuration-aware testing evidences directly.

R.03 · Integrity

Research-archive integrity & availability

Irreplaceable data demands more than a backup job that reports success. We test whether an attacker can reach, alter or delete archive storage and snapshots, and we push for a tested restore that proves recovery works before you need it.

R.04 · Confidentiality

Unpublished survey & location data

Precise coordinates, geophysical results and embargoed stratigraphy carry looting and publication risk. We test whether access control genuinely separates sensitive layers, or whether sharing links, metadata and APIs quietly expose them.

R.05 · Data protection

Saudi PDPL

Staff, volunteer, student and visitor records fall under the Personal Data Protection Law, which requires appropriate technical measures. Independent testing evidences that those measures were validated rather than assumed.

R.06 · Governance

ISO 27001 & digital preservation

Institutions certifying to ISO 27001:2022 use independent testing for control A.8.29, and grant funders increasingly ask how a digital preservation commitment is verified. Testing supplies the technical half of that answer.

// 03 Penetration testing services for Dumat al-Jandal

Engagements here concentrate on the systems that store, publish and share research data. Which service leads depends on where your archive lives - cloud tenants for collaborative projects, on-premise servers and field laptops for teams keeping custody in-house.

A.04

Cloud pen testing

AWS, Azure and Google Cloud review focused on archive storage, snapshot and retention settings, identity scope and tenant isolation, aligned to the NCA Cloud Controls.

A.01

Web application pen testing

Manual testing of catalogue, database and image-delivery applications against the OWASP Top 10, including access-control logic around embargoed records.

A.05

API pen testing

GIS, imagery and collaboration APIs tested for broken object-level authorisation, token abuse and endpoints that return location fields they should redact.

A.02

Network pen testing

External perimeter, internal Active Directory and segmentation testing across offices, field bases and the storage that holds the site archive.

A.03

Mobile pen testing

Field-recording and photo-capture apps tested for insecure local storage, weak sync and credentials that survive on a lost or stolen device.

A.07

Red teaming

Goal-based simulation aimed squarely at the archive: could an intruder reach, encrypt or exfiltrate it, and would anyone notice in time?

// 04 How we deliver to Dumat al-Jandal

Al-Jouf runs on Arabia Standard Time, UTC+3 - our own clock - so findings are raised while your team is at their desks. On-site work is scheduled around excavation and conservation seasons so field operations are not disrupted.

What runs remotely

Cloud configuration, web, API and external testing from our secure environment, with Arabic- or English-language read-outs and immediate escalation of anything that threatens archive integrity or exposes location data.

What we do on-site

Internal network, wireless, field-office and assumed-breach testing at your premises in Dumat al-Jandal and across Al-Jouf, plus in-person briefings for directors, archive staff and audit teams.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote returned within the hour. No hourly meters, no scope creep, and a free remediation retest once your team ships the fixes.

// 05 Industries we secure in Dumat al-Jandal

The town's economy mixes research and conservation work with long-established agriculture and the services that support both. We test across all of it:

Archaeological researchField projects · site archives · specialist analysis
Conservation & heritageFabric recording · condition data · intervention logs
Museums & collectionsCatalogues · artefact registers · loan records
Survey & GISPhotogrammetry · 3D scanning · spatial datasets
Agriculture & foodOlive growing · pressing · processing & logistics
Public sector & servicesMunicipal systems · education · local business

// 06 Our methodology

Dumat al-Jandal engagements follow the same disciplined, audit-defensible process CyberFortify runs worldwide, weighted toward the data-custody paths that matter to a research holder. Testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to the relevant MITRE ATT&CK tactics and application work driven by the OWASP methodology. As a CREST Accreditation Pathway firm we lead with manual, human-driven testing - automation supports the tester, it never replaces one.

01

Scoping & rules of engagement

Targets, archive systems, cloud tenants, test windows and escalation paths agreed in writing, with excavation-season constraints built into the schedule.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped around the irreplaceable data - where the archive lives, who can reach it, and which datasets carry confidentiality risk.

ATT&CK aligned
03

Manual exploitation

Findings are chained toward archive storage, backups and location-bearing datasets under controlled conditions, with false positives eliminated by hand.

Controlled exploit
04

Reporting & free retest

Executive summary, CVSS-scored technical report and NCA control mapping, plus recovery recommendations - followed by a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Dumat al-Jandal

A scan-and-report vendor

Tool output rebadged as a pen test, blind to backup and retention weaknesses, indifferent to which datasets must stay confidential, delivered on an offshore clock - and generic enough that an NCA assessor or a funder sends it back.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team in Al-Jouf's own time zone that treats your archive as the crown jewel it is. Real manual exploitation, backup and restore paths tested rather than assumed, findings mapped to NCA ECC and the Cloud Controls, fixed pricing and a free remediation retest.

Engagements here commonly pair cloud testing with a web application assessment, because most site archives are reached through a hosted catalogue sitting on top of cloud storage.

// 08 Frequently asked questions

Why does a research or conservation body in Dumat al-Jandal need penetration testing?

Because excavation is destructive and the record is the evidence. Once a deposit is removed it cannot be dug again, so the context sheets, artefact registers, photogrammetry, 3D scans and GIS site plans become the only surviving account of what was there. A penetration test asks whether an attacker could alter, encrypt or quietly delete that archive, and whether your backups would actually bring it back.

How do you test whether our site archive backups would really restore?

We treat backups as an attack target rather than an assumption. We test whether the credentials used by day-to-day accounts can reach backup storage, whether retention and immutability settings can be changed from a compromised workstation, and whether snapshots can be deleted through the cloud console or API. We then ask your team to perform a tested restore of a real archive volume so recovery is demonstrated, not asserted.

Can testing protect unpublished survey data and precise find locations?

That is one of the main reasons to test. Precise coordinates, geophysical survey results and unpublished stratigraphy have real value to looters and to rival publication, so confidentiality matters as much as availability. We examine who can read location-bearing layers in your GIS, whether embargoed datasets are separated by access control rather than by folder convention, and whether file-sharing links, image metadata or an over-permissive API can expose them.

Which Saudi regulations apply to research organisations working in Al-Jouf?

Public bodies, their contractors and their suppliers fall under the NCA Essential Cybersecurity Controls, whose Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing. Cloud-hosted archives and the platforms that serve them fall under the NCA Cloud Cybersecurity Controls. Personal data about staff, volunteers and study participants is covered by the Saudi PDPL, and organisations certifying to ISO 27001:2022 use independent testing to satisfy control A.8.29.

Do you deliver on-site in Dumat al-Jandal, and how fast is a quote?

Cloud, web, API and external testing runs remotely in Arabia Standard Time, the same zone Al-Jouf works in. Internal network, wireless, field-office and assumed-breach testing is delivered on-site in Dumat al-Jandal and across the province on an agreed schedule. After a free 30-minute scoping call we return a fixed-price quote, usually within the hour and always within one business day, with a free remediation retest included.

Ready for a pen test in Dumat al-Jandal?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →