Location · Penetration Testing in Saihat, Saudi Arabia

Penetration testing in Saihat - for the firms that hold a workforce's identity data.

CyberFortify delivers manual, exploit-driven penetration testing to Saihat's staffing and manpower agencies, HR and payroll bureaus, transport and catering contractors, training centres and clinics - a coastal Qatif-area city whose businesses mostly serve the Eastern Province workforce rather than the industry it works in. What they hold is people's data: passports, iqama details, salary files, bank accounts. We test the systems that hold it, and map findings to the Saudi PDPL, the NCA controls and PCI DSS.

Aligned with: PDPL · NCA ECC · PCI DSS 4.0 · ISO 27001 · OWASP · PTES · NIST 800-115
Fixed
Scoped to your size
PDPL
Identity-data focused
100%
Manual testing
Free retest
Serving Saihat: Staffing & manpower supply · HR & payroll bureaus · workforce transport · catering & accommodation · training & certification centres · clinics & occupational health · contracting & facilities · retail & local commerce · professional services Serving Saihat: Staffing & manpower supply · HR & payroll bureaus · workforce transport · catering & accommodation · training & certification centres · clinics & occupational health · contracting & facilities · retail & local commerce · professional services
// Executive summary

Saihat serves the Eastern Province workforce rather than its industry - staffing agencies, payroll and HR bureaus, transport, catering, training and clinics. Their crown jewels are identity and payroll records held at scale. CyberFortify runs manual web, network, cloud and API penetration tests for these firms, aligned to the Saudi PDPL, NCA ECC and PCI DSS 4.0. Fixed price, audit-ready reporting, free retest.

// 01 Why Saihat businesses need penetration testing

Trace the people who staff the Eastern Province's plants and sites back to where they are recruited, paid, housed, fed, driven and medically cleared, and much of that line runs through Saihat. Sitting between Dammam and Qatif, the city refines nothing - it administers and looks after the workforce that does. That changes what an attacker is coming for.

A manpower agency's file server is not full of engineering drawings. It is full of people - scanned passports, iqama and residency details, national IDs, onboarding records, medical and visa documents, and the bank details a salary file pays into each month. A transport contractor holds rosters and home addresses; an accommodation provider holds occupancy lists; a training centre holds certifications tied to named individuals. Across a few dozen small firms that is a dense concentration of workforce identity data, held by businesses with two IT-capable staff and a cloud tenant nobody has audited.

Two threats follow. Payroll diversion: take over the mailbox or HR portal of whoever submits the monthly salary file, change bank details before the payroll run, and dozens of workers' wages land in the wrong account - money rarely recovered and always paid twice. And identity theft at volume, where a stolen document archive opens accounts in the names of people with little practical ability to contest it. These risks land on individuals who trusted an agency with their documents. A penetration test establishes whether the systems holding those records hold up against someone actively trying.

// 02 Compliance and regulatory drivers in Saihat

Obligations here arrive through the personal data you hold on other people's behalf, and through the employers who audit you before renewal. These are the requirements we most often map evidence against.

R.01 · Data protection

Saudi PDPL - sensitive data

The PDPL sets heightened duties for sensitive personal data, and a workforce file is thick with it: health and screening records, biometric identifiers, identity documents at scale. "Appropriate technical measures" is not a claim you can make about untested systems.

R.02 · National

NCA Essential Cybersecurity Controls

Agencies and contractors supplying government bodies or critical-sector operators inherit ECC expectations through their contracts. Its Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing - reaching small suppliers, not only operators.

R.03 · Payments

PCI DSS v4.0 - Req 11.4

Training centres taking course fees, clinics taking consultation payments and accommodation providers taking deposits all handle card data. Requirement 11.4 mandates penetration testing of the cardholder environment and evidence that segmentation holds.

R.04 · Assurance

ISO 27001 - A.8.29

Control A.8.29 requires security testing in development and acceptance. For an HR bureau running a self-service portal or bespoke payroll integration, independent testing is the cleanest evidence the control operates rather than merely exists.

R.05 · Financial crime

Payroll-diversion resilience

Wage protection obligations mean a diverted payroll run is your problem regardless of who was tricked. Testing the mailbox, the identity layer and the bank-detail change workflow shows whether one compromised account can move money.

R.06 · Client assurance

Employer & contractor due diligence

The large employers you supply increasingly issue vendor security questionnaires to their labour, transport and catering contractors. An independent test report and retest letter answers those with evidence rather than assertions - and protects the contract.

// 03 Penetration testing services for Saihat

Which service leads depends on where your workforce records live. Agencies and HR bureaus start with the portal and the cloud tenant behind it; transport and catering firms with network and identity; training centres and clinics with the applications holding named individuals' records.

A.01

Web application pen testing

Manual testing of HR self-service portals, onboarding forms and payroll dashboards for the authorisation flaws that let one employee record be read as another.

A.04

Cloud pen testing

Configuration-aware testing of the cloud email, identity and document storage where scanned passports and iqama copies end up - including sharing links nobody revoked.

A.02

Network pen testing

External perimeter, internal and Active Directory testing of office and depot networks, including the remote-access services small firms leave exposed.

A.05

API pen testing

Testing of payroll, banking and government-portal integrations - the interfaces moving salary files and identity data between systems.

A.03

Mobile app pen testing

iOS and Android testing for workforce apps handling rosters, attendance, leave and payslips on personal devices.

A.08

Compliance consulting

Turning findings into a workable PDPL and NCA readiness plan, and into answers for the employer questionnaires in your inbox.

// 04 How we deliver to Saihat

We work from our Gulf base on Arabia Standard Time - Saihat's own clock - so scoping calls, test windows and read-outs land inside your working day. Most testing is delivered remotely, which keeps the cost proportionate; where a tester genuinely needs to be on the network, that is a planned visit to your Saihat premises.

What runs remotely

External perimeter, HR portal, cloud tenant, email, identity and API testing from our secure environment, scheduled around payroll cut-off so we never test the salary run on the day it matters.

What we do on-site

Internal network, wireless and segregation testing at your office, depot or accommodation site where presence is required - a short, scheduled visit.

Every engagement opens with a free 30-minute scoping call and a fixed-price quote inside the hour. If your real exposure is one portal and one mailbox rather than a programme, we will scope it that way.

// 05 Industries we secure in Saihat

The city's economy serves people who work elsewhere. We test across the sectors defining its risk profile:

Staffing & manpower supplyOnboarding records · iqama & passport files · contracts
HR & payroll bureausSalary files · bank details · self-service portals
Workforce transportRosters · addresses · fleet & tracking systems
Catering & accommodationOccupancy lists · card payments · supplier portals
Training & certificationCourse records · named certifications · fee payments
Clinics & occupational healthScreening · medicals · visa health records

// 06 Our methodology

A Saihat engagement runs the same audit-defensible process we run for far larger clients - the rigour does not scale with the invoice. Testing follows the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, application work driven by OWASP, exploitation mapped to MITRE ATT&CK. As a CREST Accreditation Pathway firm we lead with manual testing; automation supports the tester, never substitutes for one. For workforce-data holders the threat model names two endpoints: the document store and the payroll run.

01

Scoping & rules of engagement

Systems, test windows and escalation paths agreed in writing, with payroll and month-end dates deliberately avoided.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped and prioritised around where identity documents rest and how salary payments are authorised.

ATT&CK aligned
03

Manual exploitation

Weaknesses exploited and chained under control - account takeover, cross-record access, unauthorised bank detail change - false positives removed by hand.

Controlled exploit
04

Reporting & free retest

An audit-ready report written for a business without a security team, mapped to PDPL, NCA ECC and ISO 27001, then a free retest.

Audit-ready

// 07 Why CyberFortify for Saihat

An enterprise quote, or a scan

A proposal built for a bank and priced for one, or an automated scan sold as a penetration test - neither tells a fifteen-person agency whether its payroll path can be hijacked.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team on your clock that scopes to your size. Manual exploitation of the portals, mailboxes and payment paths carrying your workforce's data, findings mapped to PDPL, NCA ECC and ISO 27001, Arabic or English read-outs, fixed pricing, free retest.

Saihat engagements often pair a web application test with compliance consulting, so findings become a PDPL plan and a client-questionnaire answer rather than a PDF nobody reopens.

// 08 Frequently asked questions

We are a small manpower agency in Saihat. Do we really need a penetration test?

Ask a different question first: how many people's identity documents are on your systems right now? For most Saihat agencies the answer is several hundred to several thousand - passports, iqama details, national IDs, bank accounts, medical and visa records. That concentration is what makes the test worth doing. We scope it to the systems that actually hold the data, quote a fixed price, and include a free retest.

What is payroll diversion and how would a test catch it?

Payroll diversion is when an attacker changes bank details on the salary file so wages land in an account they control - usually after taking over a payroll administrator's mailbox or the HR portal. We test the whole path: how the mailbox is protected, whether multi-factor authentication can be bypassed, whether a bank detail change can be made without a second approver, and whether the portal lets one account read or edit another's record.

Which rules apply to workforce data held by Saihat businesses?

The Saudi PDPL governs all of it, with heightened duties where records are sensitive - health data from clinics and pre-employment screening, and identity documents held at scale. Firms supplying government bodies or critical-sector operators also fall under the NCA Essential Cybersecurity Controls, which require periodic vulnerability assessment and penetration testing. Anyone taking card payments is covered by PCI DSS 4.0 Requirement 11.4.

Our client is a large employer and has sent us a security questionnaire. Can you help?

Yes - this is one of the most common reasons Saihat firms call us. Large employers increasingly ask their labour supply, transport and catering contractors for evidence of independent testing before renewing a contract. We deliver an audit-ready report with findings mapped to the PDPL, NCA ECC and ISO 27001 A.8.29, plus a retest letter you can attach to the questionnaire response.

How long does an engagement take and what does it cost?

A focused test of an HR portal, the payroll path and the network behind them typically runs a week of testing plus reporting. After a free 30-minute scoping call we return a fixed-price quote, usually within the hour and always within one business day. The price is fixed for the agreed scope, with no hourly surprises, and a free remediation retest is included once fixes ship.

Ready for a pen test in Saihat?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →