Location · Penetration Testing in Majmaah, Saudi Arabia

Penetration testing in Majmaah where care, teaching and research share one network.

CyberFortify delivers manual, exploit-driven penetration testing to the university, health-sciences and regional-services organisations of Majmaah - a city in northern Riyadh Province where clinicians, students and researchers work from overlapping systems and, often, the same patient records. We test whether those access boundaries hold, and map every finding to the Saudi PDPL and the NCA controls.

Aligned with: NCA ECC · NCA CCC · PDPL · ISO 27001 A.8.29 · OWASP · PTES · NIST 800-115
PDPL
Special-category data
NCA
ECC & CCC aligned
100%
Manual testing
Free retest
Serving Majmaah: University & health-sciences teaching · teaching-hospital functions · clinical systems · research computing · agriculture & agri-services · regional government services · utilities & municipal systems · retail & local business · public-sector suppliers Serving Majmaah: University & health-sciences teaching · teaching-hospital functions · clinical systems · research computing · agriculture & agri-services · regional government services · utilities & municipal systems · retail & local business · public-sector suppliers
// Executive summary

Majmaah is a university city, and a university that teaches health sciences runs a network with three tenants on it: clinical care, education and research. CyberFortify runs manual web, cloud, API and network penetration tests for organisations here, with a specific focus on whether role-based access actually separates those three. Aligned to NCA ECC, the NCA Cloud Cybersecurity Controls and the Saudi PDPL. Fixed price, audit-ready reporting, free remediation retest.

// 01 Why Majmaah businesses need penetration testing

A teaching hospital is three organisations wearing one building. The clinical service needs the electronic health record to be instantly available to whoever is treating the patient in front of them. The faculty needs students to learn from real cases, which means supervised access to records that belong to people who came for treatment, not for teaching. The research office needs datasets derived from those same records, usually de-identified, usually extracted on a schedule, usually landing somewhere the clinical team never looks. Three legitimate purposes, three different lawful bases, one underlying store of patient data.

That is the security question for Majmaah's health-sciences estate, and it is not a question a vulnerability scanner can answer. A scanner reports missing patches. It cannot tell you whether a student account still opens records six months after the rotation ended, whether a research extract carried the medical record number into a spreadsheet on a shared drive, whether break-glass access is genuinely reviewed or simply available, or whether a shared teaching workstation logged in as a clinician is a door anyone can walk through. Those are authorisation and data-flow failures. They are found by a person who follows the path deliberately, holds a low-privilege account and tries to reach something it should never reach.

Majmaah's wider economy - agriculture, agri-services and regional government functions - carries the ordinary internet-facing exposure every organisation has. But the sensitive data, and the reason careful testing pays for itself here, sits with the systems that serve patients and teach the people who will treat them next.

// 02 Compliance and regulatory drivers in Majmaah

Health data does not become less regulated when it is used for teaching or research. These are the obligations we most often map evidence against for organisations in Majmaah, and the ones auditors ask about first.

R.01 · Special category

Saudi PDPL - health data

Patient data is special-category personal data under the PDPL, carrying heightened duties for lawful basis, minimisation and security of processing. Those duties travel with the data into teaching and research use. Testing evidences that access control, not policy language, is what enforces them.

R.02 · National

NCA Essential Cybersecurity Controls (ECC)

Public-sector and government-linked bodies and their technology suppliers fall under the NCA ECC, whose Cybersecurity Defence domain mandates periodic vulnerability assessment and penetration testing. Our reports close those sub-controls with named findings and retest evidence.

R.03 · Cloud

NCA Cloud Cybersecurity Controls (CCC)

Learning platforms, analytics environments and hosted clinical modules bring the CCC into scope, with expectations on tenant separation, identity and data location. We test the cloud tenancy as configured, not as documented.

R.04 · De-identification

Research extracts & de-identification

A research cohort is only as safe as the extract that produced it. We check which fields actually leave the record system, whether identifiers persist in free text or metadata, whether the re-linking key is reachable from the analysis environment, and whether small cohorts remain re-identifiable.

R.05 · Access separation

Student and clinical access separation

Supervised teaching access should be narrower, shorter-lived and more heavily logged than clinical access. We test whether the roles genuinely differ, whether access expires with the rotation, and whether the audit trail would let you answer "who read this record, and why" months later.

R.06 · Governance

ISO 27001:2022 - A.8.29

Control A.8.29 requires security testing across the development and acceptance lifecycle. Organisations certifying or maintaining certification use independent penetration testing as the technical assurance their auditor expects, alongside SOC 2 evidence where enterprise partners ask for it.

// 03 Penetration testing services for Majmaah

Most Majmaah engagements start with the applications that hold records and the identity layer that decides who may open them. Clinical, teaching and research systems tend to be tested together, because the interesting failures live in the seams between them rather than inside any one platform.

A.01

Web application pen testing

Manual testing of record systems, portals and learning platforms against the OWASP Top 10, weighted toward role-based access and business-logic abuse.

A.05

API pen testing

Broken object-level authorisation, over-broad responses and export endpoints - the flaws that quietly turn one record request into a cohort.

A.04

Cloud pen testing

Identity, storage exposure and tenant isolation across hosted learning, analytics and research environments assessed under the NCA CCC.

A.02

Network pen testing

External perimeter, internal and Active Directory testing, plus segmentation checks between clinical, teaching and research network zones.

A.03

Mobile app pen testing

iOS and Android testing for clinical, campus and results-lookup apps, including local storage of records on shared or personal devices.

A.07

Red teaming

Goal-based simulation that answers a single question: starting from one low-privilege account, how far does an intruder get before anyone notices?

// 04 How we deliver to Majmaah

We have no office in Saudi Arabia and do not pretend otherwise. Work is delivered remotely from our Bahrain base, which shares Majmaah's clock at UTC+3, so findings are raised and discussed inside your working day rather than overnight. On-site engagements are arranged where physical presence genuinely adds something.

What runs remotely

Web, API, cloud and external network testing from our secure environment, with Arabic- or English-language read-outs, a live findings channel and immediate escalation of anything critical.

What we do on-site

Internal network, wireless, shared-workstation and segregation testing where clinical and teaching zones meet, plus in-person briefings for executives, clinical leadership and audit teams.

Scoping is written before anything is touched: test windows, excluded clinical systems, rate limits and a named escalation contact. Every engagement opens with a free 30-minute call and a fixed-price quote returned within the hour, and closes with a free remediation retest.

// 05 Industries we secure in Majmaah

Majmaah's risk profile is shaped by education, health sciences and the services a regional centre provides to the area around it:

Health sciences & teaching hospitalsClinical records · supervised access · care systems
Higher educationLearning platforms · identity · campus networks
Research & dataExtracts · cohorts · analysis environments
Agriculture & agri-servicesSupply chain · logistics · operational systems
Regional government servicesCitizen e-services · municipal · suppliers
Utilities & local businessBilling · retail · payments

// 06 Our methodology

Majmaah engagements run the same disciplined, audit-defensible process CyberFortify uses everywhere, with the threat model pointed at record access rather than the perimeter alone. Testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, exploitation is mapped to the relevant MITRE ATT&CK techniques, and application work follows the OWASP methodology. As a CREST Accreditation Pathway firm we lead with manual testing; automation feeds the tester and never stands in for one.

01

Scoping & rules of engagement

Targets, account tiers to be issued, clinical constraints, test windows and escalation paths agreed in writing before any traffic is sent.

Fixed quote in 1h
02

Threat modelling the boundaries

We map where clinical, teaching and research access meet - shared systems, export paths, extracts, break-glass routes - and prioritise there.

ATT&CK aligned
03

Manual exploitation

Least-privilege accounts are used to reach what they should not, findings are chained and proven under controlled conditions, and false positives are removed by hand.

Controlled exploit
04

Reporting & free retest

Executive summary, CVSS-scored technical detail and PDPL/NCA control mapping, with an audit-trail assessment - then a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Majmaah

A scan-and-report vendor

Tool output rebadged as a pen test. It has no concept of a rotation, a cohort or a supervising clinician, so it cannot see the failures that matter most here - and it arrives on an offshore clock, weeks after you needed it.

CyberFortify in the Gulf

A Bahrain-based, CREST-pathway team in Majmaah's own time zone, testing authorisation as carefully as infrastructure. Findings mapped to PDPL, NCA ECC and the Cloud Cybersecurity Controls, fixed pricing, and a free remediation retest that proves the fix.

Engagements here commonly pair a web application test with an API assessment, because a record system's real exposure usually sits in the interfaces and export endpoints behind the screen rather than in the screen itself. Where certification is the driver, our compliance consulting team sequences the testing around the audit calendar.

// 08 Frequently asked questions

How do you test whether student access to patient records is properly supervised?

We test it as an authorisation problem, not a policy question. From a student-tier account we try to reach records outside the assigned teaching cohort, to hold access after a rotation should have ended, to escalate through a shared teaching workstation or group credential, and to pull data through an export or reporting function the role was never meant to reach. Where supervised access depends on a supervising clinician's approval, we check whether the system enforces that approval or merely expects it.

Can penetration testing tell us whether our research extracts are genuinely de-identified?

We can tell you whether the extract, the pipeline that produced it and the environment holding it behave as de-identified data should: which fields actually leave the electronic health record, whether identifiers survive in free-text notes, filenames or audit columns, whether the linking key back to the source record is reachable from the analysis environment, and whether a small cohort stays re-identifiable from the remaining attributes. Statistical disclosure review is a separate discipline, and we say so rather than overstating what a pentest proves.

Which regulations apply to a teaching hospital in Majmaah?

Health data is special-category personal data under the Saudi PDPL, which raises the standard for lawful basis, access control and security of processing - and it stays health data when used for teaching or research. Public-sector bodies and their suppliers fall under the NCA Essential Cybersecurity Controls, whose Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing. Hosted clinical, learning or analytics platforms add the NCA Cloud Cybersecurity Controls, and ISO 27001:2022 certification uses independent testing as evidence for control A.8.29.

Will testing disrupt clinical care or teaching timetables?

No. Clinical availability is a safety matter, so it is scoped as one before testing starts. We agree test windows, excluded systems, rate limits and a named clinical escalation contact in writing, keep destructive techniques off live care systems, and prefer non-production copies or read-only proof for anything touching an active record. Teaching and research systems tolerate a wider scope, and we use that headroom where it buys real assurance.

How fast can we get a quote for a Majmaah engagement?

A free 30-minute scoping call is usually enough to size the work, and we return a fixed-price quote within the hour and always within one business day. We work remotely in your own time zone with on-site engagements available, and every engagement includes a free remediation retest once fixes ship.

Ready for a pen test in Majmaah?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →