Rabigh is a planned industrial city, and planned cities share things - power, water, network infrastructure, site services and a common contractor pool. That design efficiency also means your security perimeter is partly defined by organisations you do not control. CyberFortify runs manual network, cloud and API testing plus safe OT-boundary assessment here, aligned to NCA OTCC and ECC, IEC 62443 and the Saudi PDPL. Fixed price, audit-ready reporting, free remediation retest.
// 01 Why Rabigh operators need penetration testing
The economics of an industrial city rest on sharing. Rather than each operator building its own power, water, telecoms and site services, a planned complex like Rabigh provides them in common - which is efficient, and which quietly makes every tenant's security posture partly a function of everyone else's. A shared network segment, a common site-services platform, a contractor with credentials across several tenants: each is a legitimate part of how the city works, and each is a path that does not stop at your fence line. Security models drawn as though the organisation ends at its own perimeter simply do not describe this environment.
Layered onto that is the process risk of integrated refining and petrochemicals. An integrated site is deliberately interconnected - units feed one another, utilities are common, control systems interlock - so the boundary between enterprise IT and operations carries more weight than it would at a standalone plant, and there are more legitimate crossings to examine. Neither problem is one an automated scan can approach: a scanner cannot be aimed safely at process control, and it has no concept of tenancy, so it cannot tell you which findings are yours to fix and which belong to the site operator. That distinction is exactly what a properly scoped manual test delivers.
// 02 Compliance and regulatory drivers in Rabigh
Rabigh's operators carry industrial control obligations plus the complication of proving assurance over infrastructure they share. These are the requirements CyberFortify most often maps evidence against locally.
NCA Operational Technology Cybersecurity Controls (OTCC)
The national baseline for industrial and OT environments - segmentation, secure remote access, hardening and technical assurance over control systems, evidenced without endangering a running unit.
IEC 62443
Zones and conduits are the right vocabulary for a shared site, because they force the question of where one operator's zone ends and another's begins. We test the conduits between them hardest.
Common-infrastructure assurance
Where utilities, networks and site systems are shared, each tenant needs a defensible account of its own boundary. We document exactly what you control and where your dependency on shared services begins.
Multi-tenant contractor access
A contractor working across several tenants is a shared risk nobody owns outright. We test the access such parties hold into your environment, from your side of the boundary.
NCA ECC & critical-sector expectations
Refining, petrochemical and utility operators fall under the ECC and the heightened assurance expected of essential services, including periodic testing of the enterprise estate.
Saudi PDPL & ISO 27001
Operators hold employee, contractor and commercial data under the PDPL, and those pursuing ISO 27001:2022 use independent testing to satisfy A.8.29 and partner assurance.
// 03 Penetration testing services for Rabigh
Rabigh engagements concentrate on boundaries - between IT and OT, and between you and everyone else on site. Which service leads depends on the organisation: process operators prioritise segmentation, tenants lead with network and shared-service exposure, and logistics firms add web and API.
Network pen testing
External perimeter, internal Active Directory, IT/OT segmentation, shared-segment exposure and contractor remote-access testing.
Red teaming
Goal-based simulation asking whether an intrusion via a contractor or shared service would be detected before it reached your operations.
API pen testing
Testing of utility, logistics and inter-organisation integrations - authorisation flaws and over-trusting connections between site parties.
Cloud pen testing
Configuration-aware testing of the analytics, historian and enterprise workloads operators and tenants run in cloud.
Web application pen testing
Manual testing of operations portals, contractor platforms and corporate applications against the OWASP Top 10.
Mobile app pen testing
iOS and Android testing for field, permit-to-work and workforce apps used across the site.
// 04 How we deliver to Rabigh
Rabigh keeps our exact clock - Arabia Standard Time, UTC+3 - so findings are discussed as they land. Enterprise and interface testing runs remotely from our secure environment; anything touching process systems or shared site infrastructure is scheduled with your operations team and, where relevant, coordinated with the site operator.
What runs remotely
External perimeter, web, cloud and API testing delivered from our secure environment during your business hours, with Arabic- or English-language read-outs and immediate escalation of anything critical.
What we do on-site
Internal network, DMZ, wireless, segmentation and OT-boundary review at your Rabigh facility, strictly within your agreed tenancy boundary and coordinated so no live process is disturbed.
Every engagement opens with a free 30-minute scoping call. For industrial sites we fix the safety constraints and the precise tenancy boundary in writing before anything starts - alongside the fixed-price quote and a free remediation retest.
// 05 Industries we secure in Rabigh
The city's economy is integrated processing, shared utilities and the logistics around them. CyberFortify tests across the sectors that define its risk profile:
// 06 Our methodology
Every Rabigh engagement follows the same disciplined, audit-defensible process CyberFortify runs worldwide, with OT safety and tenancy discipline built into each step. IT testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to the relevant MITRE ATT&CK tactics, including ATT&CK for ICS; OT work follows the IEC 62443 zone-and-conduit model and stays non-disruptive. As a CREST Accreditation Pathway firm, we lead with manual testing and never turn automation loose on live control systems.
Scoping & boundary agreement
Targets, tenancy boundary, IT/OT split, shared-service dependencies, permitted techniques and safety constraints fixed in writing before testing begins.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped and prioritised around shared segments, contractor access and the paths toward your process environment.
ATT&CK for ICSControlled exploitation
Weaknesses exploited on the IT side and validated at the OT boundary under agreed conditions, strictly inside your own assets - never a neighbour's.
Process-firstReporting & free retest
Executive summary, CVSS-scored report and OTCC and IEC 62443 mapping - with shared-infrastructure risks separated out for you to escalate to the site operator.
Audit-ready// 07 Why CyberFortify for Rabigh
A vendor with no concept of tenancy
A team that scans an address range without establishing who owns what - unsafe near OT, potentially testing a neighbour's systems, and handing you findings you have no authority to fix.
CyberFortify in the Gulf
A Gulf-based, CREST-pathway team that fixes the boundary before it tests. Real manual exploitation inside your scope, safe OT validation, shared-infrastructure risk clearly separated, findings mapped to NCA OTCC and IEC 62443, fixed pricing and a free remediation retest.
Rabigh engagements typically combine network and segmentation testing with a red team exercise modelling intrusion through a contractor or shared service.
// 08 Frequently asked questions
What is shared-infrastructure risk in an industrial city like Rabigh?
In a planned industrial city, tenants do not each build everything themselves - they draw on common utilities, shared network and telecoms infrastructure, common security and site systems, and a shared contractor pool. That efficiency creates adjacency: a weakness in a shared service, or in a neighbouring tenant using it, can become your exposure. We test what you actually control and map clearly where your boundary with shared infrastructure sits.
Do you test integrated refinery and petrochemical operations in Rabigh?
Yes, using the same safety-first approach we apply to any live process environment: passive analysis and architecture review on the OT side, active testing on the enterprise estate and non-production segments, and rigorous validation of the boundary between them. Integrated refinery-petrochemical sites are unusually interconnected internally, which makes that boundary work more important, not less.
Can you test a single tenant without touching neighbouring operations?
Yes, and scoping this precisely is essential. We establish in writing exactly which assets, address ranges and connections belong to you rather than to the site operator or a neighbouring tenant, and test strictly inside that boundary. Where we identify risk originating in shared infrastructure, we report it to you to escalate rather than testing someone else's systems.
Which regulations apply to penetration testing in Rabigh?
Industrial and OT environments fall under the NCA Operational Technology Cybersecurity Controls and typically work to IEC 62443; critical-sector operators and government suppliers fall under the NCA Essential Cybersecurity Controls; personal data falls under the Saudi PDPL; and card handlers add PCI DSS 4.0.
How fast can we get a quote for a Rabigh engagement?
After a free 30-minute scoping call - which for industrial sites includes agreeing safety constraints and the precise tenancy boundary - we return a fixed-price quote, usually within one hour and always within one business day. Every engagement includes a free remediation retest once fixes ship.