Saihat serves the Eastern Province workforce rather than its industry - staffing agencies, payroll and HR bureaus, transport, catering, training and clinics. Their crown jewels are identity and payroll records held at scale. CyberFortify runs manual web, network, cloud and API penetration tests for these firms, aligned to the Saudi PDPL, NCA ECC and PCI DSS 4.0. Fixed price, audit-ready reporting, free retest.
// 01 Why Saihat businesses need penetration testing
Trace the people who staff the Eastern Province's plants and sites back to where they are recruited, paid, housed, fed, driven and medically cleared, and much of that line runs through Saihat. Sitting between Dammam and Qatif, the city refines nothing - it administers and looks after the workforce that does. That changes what an attacker is coming for.
A manpower agency's file server is not full of engineering drawings. It is full of people - scanned passports, iqama and residency details, national IDs, onboarding records, medical and visa documents, and the bank details a salary file pays into each month. A transport contractor holds rosters and home addresses; an accommodation provider holds occupancy lists; a training centre holds certifications tied to named individuals. Across a few dozen small firms that is a dense concentration of workforce identity data, held by businesses with two IT-capable staff and a cloud tenant nobody has audited.
Two threats follow. Payroll diversion: take over the mailbox or HR portal of whoever submits the monthly salary file, change bank details before the payroll run, and dozens of workers' wages land in the wrong account - money rarely recovered and always paid twice. And identity theft at volume, where a stolen document archive opens accounts in the names of people with little practical ability to contest it. These risks land on individuals who trusted an agency with their documents. A penetration test establishes whether the systems holding those records hold up against someone actively trying.
// 02 Compliance and regulatory drivers in Saihat
Obligations here arrive through the personal data you hold on other people's behalf, and through the employers who audit you before renewal. These are the requirements we most often map evidence against.
Saudi PDPL - sensitive data
The PDPL sets heightened duties for sensitive personal data, and a workforce file is thick with it: health and screening records, biometric identifiers, identity documents at scale. "Appropriate technical measures" is not a claim you can make about untested systems.
NCA Essential Cybersecurity Controls
Agencies and contractors supplying government bodies or critical-sector operators inherit ECC expectations through their contracts. Its Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing - reaching small suppliers, not only operators.
PCI DSS v4.0 - Req 11.4
Training centres taking course fees, clinics taking consultation payments and accommodation providers taking deposits all handle card data. Requirement 11.4 mandates penetration testing of the cardholder environment and evidence that segmentation holds.
ISO 27001 - A.8.29
Control A.8.29 requires security testing in development and acceptance. For an HR bureau running a self-service portal or bespoke payroll integration, independent testing is the cleanest evidence the control operates rather than merely exists.
Payroll-diversion resilience
Wage protection obligations mean a diverted payroll run is your problem regardless of who was tricked. Testing the mailbox, the identity layer and the bank-detail change workflow shows whether one compromised account can move money.
Employer & contractor due diligence
The large employers you supply increasingly issue vendor security questionnaires to their labour, transport and catering contractors. An independent test report and retest letter answers those with evidence rather than assertions - and protects the contract.
// 03 Penetration testing services for Saihat
Which service leads depends on where your workforce records live. Agencies and HR bureaus start with the portal and the cloud tenant behind it; transport and catering firms with network and identity; training centres and clinics with the applications holding named individuals' records.
Web application pen testing
Manual testing of HR self-service portals, onboarding forms and payroll dashboards for the authorisation flaws that let one employee record be read as another.
Cloud pen testing
Configuration-aware testing of the cloud email, identity and document storage where scanned passports and iqama copies end up - including sharing links nobody revoked.
Network pen testing
External perimeter, internal and Active Directory testing of office and depot networks, including the remote-access services small firms leave exposed.
API pen testing
Testing of payroll, banking and government-portal integrations - the interfaces moving salary files and identity data between systems.
Mobile app pen testing
iOS and Android testing for workforce apps handling rosters, attendance, leave and payslips on personal devices.
Compliance consulting
Turning findings into a workable PDPL and NCA readiness plan, and into answers for the employer questionnaires in your inbox.
// 04 How we deliver to Saihat
We work from our Gulf base on Arabia Standard Time - Saihat's own clock - so scoping calls, test windows and read-outs land inside your working day. Most testing is delivered remotely, which keeps the cost proportionate; where a tester genuinely needs to be on the network, that is a planned visit to your Saihat premises.
What runs remotely
External perimeter, HR portal, cloud tenant, email, identity and API testing from our secure environment, scheduled around payroll cut-off so we never test the salary run on the day it matters.
What we do on-site
Internal network, wireless and segregation testing at your office, depot or accommodation site where presence is required - a short, scheduled visit.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote inside the hour. If your real exposure is one portal and one mailbox rather than a programme, we will scope it that way.
// 05 Industries we secure in Saihat
The city's economy serves people who work elsewhere. We test across the sectors defining its risk profile:
// 06 Our methodology
A Saihat engagement runs the same audit-defensible process we run for far larger clients - the rigour does not scale with the invoice. Testing follows the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, application work driven by OWASP, exploitation mapped to MITRE ATT&CK. As a CREST Accreditation Pathway firm we lead with manual testing; automation supports the tester, never substitutes for one. For workforce-data holders the threat model names two endpoints: the document store and the payroll run.
Scoping & rules of engagement
Systems, test windows and escalation paths agreed in writing, with payroll and month-end dates deliberately avoided.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped and prioritised around where identity documents rest and how salary payments are authorised.
ATT&CK alignedManual exploitation
Weaknesses exploited and chained under control - account takeover, cross-record access, unauthorised bank detail change - false positives removed by hand.
Controlled exploitReporting & free retest
An audit-ready report written for a business without a security team, mapped to PDPL, NCA ECC and ISO 27001, then a free retest.
Audit-ready// 07 Why CyberFortify for Saihat
An enterprise quote, or a scan
A proposal built for a bank and priced for one, or an automated scan sold as a penetration test - neither tells a fifteen-person agency whether its payroll path can be hijacked.
CyberFortify in the Gulf
A Gulf-based, CREST-pathway team on your clock that scopes to your size. Manual exploitation of the portals, mailboxes and payment paths carrying your workforce's data, findings mapped to PDPL, NCA ECC and ISO 27001, Arabic or English read-outs, fixed pricing, free retest.
Saihat engagements often pair a web application test with compliance consulting, so findings become a PDPL plan and a client-questionnaire answer rather than a PDF nobody reopens.
// 08 Frequently asked questions
We are a small manpower agency in Saihat. Do we really need a penetration test?
Ask a different question first: how many people's identity documents are on your systems right now? For most Saihat agencies the answer is several hundred to several thousand - passports, iqama details, national IDs, bank accounts, medical and visa records. That concentration is what makes the test worth doing. We scope it to the systems that actually hold the data, quote a fixed price, and include a free retest.
What is payroll diversion and how would a test catch it?
Payroll diversion is when an attacker changes bank details on the salary file so wages land in an account they control - usually after taking over a payroll administrator's mailbox or the HR portal. We test the whole path: how the mailbox is protected, whether multi-factor authentication can be bypassed, whether a bank detail change can be made without a second approver, and whether the portal lets one account read or edit another's record.
Which rules apply to workforce data held by Saihat businesses?
The Saudi PDPL governs all of it, with heightened duties where records are sensitive - health data from clinics and pre-employment screening, and identity documents held at scale. Firms supplying government bodies or critical-sector operators also fall under the NCA Essential Cybersecurity Controls, which require periodic vulnerability assessment and penetration testing. Anyone taking card payments is covered by PCI DSS 4.0 Requirement 11.4.
Our client is a large employer and has sent us a security questionnaire. Can you help?
Yes - this is one of the most common reasons Saihat firms call us. Large employers increasingly ask their labour supply, transport and catering contractors for evidence of independent testing before renewing a contract. We deliver an audit-ready report with findings mapped to the PDPL, NCA ECC and ISO 27001 A.8.29, plus a retest letter you can attach to the questionnaire response.
How long does an engagement take and what does it cost?
A focused test of an HR portal, the payroll path and the network behind them typically runs a week of testing plus reporting. After a free 30-minute scoping call we return a fixed-price quote, usually within the hour and always within one business day. The price is fixed for the agreed scope, with no hourly surprises, and a free remediation retest is included once fixes ship.