Location · Penetration Testing in Umluj, Saudi Arabia

Penetration testing in Umluj where the booking record is a safety record.

CyberFortify delivers manual, exploit-driven penetration testing to the dive centres, boat and charter operators, coastal resorts and marine businesses of Umluj - a Red Sea town on the Tabuk coast whose reefs and islands have turned it into a fast-growing marine tourism destination. Here the systems that sell a trip also record who went into the water. We test them against the NCA controls, PCI DSS and the Saudi PDPL.

Aligned with: NCA ECC · PCI DSS · PDPL · ISO 27001 · OWASP · PTES · NIST 800-115
Manifest
Integrity testing
PDPL
Health-data handling
100%
Manual testing
Free retest
Serving Umluj: Dive centres & instructors · boat & charter operators · liveaboards · coastal resorts & camps · marine tour agencies · fisheries & seafood trade · marine conservation & permitting · coastal development · retail & hospitality · clinics & public services Serving Umluj: Dive centres & instructors · boat & charter operators · liveaboards · coastal resorts & camps · marine tour agencies · fisheries & seafood trade · marine conservation & permitting · coastal development · retail & hospitality · clinics & public services
// Executive summary

In Umluj, safety data and operational data are the same data. Dive manifests, passenger counts, medical declarations, emergency contacts, permits and vessel schedules live inside the booking software that runs a marine tourism business. CyberFortify runs manual web, API, cloud and network penetration tests here, aligned to NCA ECC, the Saudi PDPL and PCI DSS 4.0. Fixed price, free remediation retest.

// 01 Why Umluj businesses need penetration testing

Ask a dive centre what its most important database is and the honest answer is not the one holding card numbers. It is the one that says how many people boarded, who they are, what they declared on their medical form, who to call if something goes wrong, and whether everyone who went in came back. That register used to be a clipboard. On this stretch of the Tabuk coast it is a booking platform, a tablet at the jetty and a cloud tenant elsewhere - and the software that takes a deposit is what a skipper reads a roll call from.

That changes what a security failure means. In most industries a compromised record costs money or reputation. Here, a quietly edited manifest, a passenger count that disagrees between the office copy and the boat copy, or a system unreachable at the moment you need to check a name means an operator cannot account for people. Ransomware need not steal anything to do that; it only has to make records unavailable on a morning when four boats are out over the reefs. Nor does an attacker need admin rights - a broken authorisation check that lets one account write to another's trip is enough.

Growth sharpens it. New coastal resorts, expanding charter and liveaboard capacity and marine permitting add systems faster than small operators add security staff. A scanner flags an outdated library and says nothing about whether a departed trip's manifest can still be modified. A penetration test asks that directly.

// 02 Compliance and regulatory drivers in Umluj

Marine tourism sits across three obligations at once: payments, personal data that includes health information, and the availability of records carrying a duty of care. These are the requirements we most often map evidence against here.

R.01 · Data protection

Saudi PDPL - health declarations

Fitness-to-dive forms, disclosed conditions and medication notes are health data, treated by the PDPL as sensitive personal data requiring stronger safeguards than an ordinary booking field. We test how declarations travel, rest and are reached.

R.02 · Payments

PCI DSS v4.0 - Req 11.4

Operators taking deposits and card payments must penetration-test the cardholder environment and evidence segmentation under Requirement 11.4.5, including the hosted checkout paths small operators rely on.

R.03 · Integrity

Manifest & passenger-count integrity

A manifest is only trustworthy if it cannot be altered outside a controlled process. We test whether trip records, headcounts and check-in state can be modified, back-dated or deleted without authorisation or an audit trail.

R.04 · Availability

Safety records must be reachable

A record you cannot read during an incident is a record you do not have. We hunt the weaknesses - abusable endpoints, fragile integrations, resource exhaustion - that could put emergency contacts and roll calls out of reach.

R.05 · National

NCA Essential Cybersecurity Controls (ECC)

Provincial bodies, marine authorities, permitting systems and the suppliers serving Umluj's coastal development fall under the NCA ECC, whose Cybersecurity Defence domain requires periodic vulnerability assessment and penetration testing.

R.06 · Governance

ISO 27001

Resort groups and larger marine operators certifying to ISO 27001:2022 use independent testing to satisfy control A.8.29, and to answer partner and insurer due diligence.

// 03 Penetration testing services for Umluj

Which service leads depends on what carries your records. Dive and boat operators start with web and API, where the manifest lives; resorts lead with cloud and network; anyone taking cards adds a payment-path focus.

A.01

Web application pen testing

Manual testing of booking portals, trip check-in screens and declaration forms against the OWASP Top 10, plus the record-level authorisation logic behind them.

A.05

API pen testing

Broken object-level authorisation and data exposure in the APIs that sync vessel schedules, availability and passenger data with agents and resort partners.

A.04

Cloud pen testing

Configuration-aware testing of the cloud tenants and storage buckets holding manifests, declarations and permit documents - identity, key handling and exposure.

A.03

Mobile app pen testing

iOS and Android testing for the tablet and phone apps crews use at the jetty for check-in, roll call and offline trip records.

A.02

Network pen testing

External perimeter and internal testing for dive centres, marinas and resorts, including whether guest Wi-Fi is genuinely isolated from operations.

A.07

Red teaming

Goal-based adversary simulation asking a specific question: could someone reach and change a trip record without anyone noticing?

// 04 How we deliver to Umluj

Umluj runs on Arabia Standard Time (UTC+3), the same clock as our Gulf base, so there is no overnight lag on questions mid-test. Most of what a marine operator exposes is internet-facing, so the bulk of the work runs remotely with no travel loaded into the quote.

What runs remotely

External perimeter, web, cloud and API testing from our secure environment, scheduled around your sailing days so testing never coincides with boats on the water, with Arabic- or English-language read-outs.

What we do on-site

Internal network, wireless and endpoint testing at dive centres, marina offices and resort properties, plus review of the tablets and jetty-side devices that hold trip data, arranged on a planned visit.

We test defensively and never touch live operational procedure: no interference with a real trip, no changes to a real manifest, rules of engagement agreed in writing first. Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour.

// 05 Industries we secure in Umluj

Umluj's economy is the sea - diving, boating, fishing and the coastal hospitality growing around them. We test across the sectors that define the town's risk profile:

Dive centres & instructorsManifests · medical declarations · certifications
Boat & charter operatorsVessel schedules · passenger counts · check-in
Liveaboards & excursionsMulti-day itineraries · guest records · payments
Coastal resorts & campsBooking engines · PMS · POS · guest data
Marine permits & conservationReef access · permit records · reporting
Fisheries, retail & servicesSeafood trade · shops · clinics · public bodies

// 06 Our methodology

Every Umluj engagement follows the audit-defensible process CyberFortify runs worldwide, grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK tactics and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing - the flaws that matter most here are logic flaws, and no scanner reasons about who should be allowed to edit a trip.

01

Scoping & rules of engagement

Targets, in-scope systems, test windows around your sailing calendar and escalation paths agreed in writing before any testing begins.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped and prioritised around the records that carry duty of care - manifests, counts, declarations, emergency contacts, payments.

ATT&CK aligned
03

Manual exploitation

Confirmed weaknesses exploited and chained under controlled conditions against test data only, with false positives removed by hand.

Controlled exploit
04

Reporting & free retest

Executive summary, CVSS-scored technical detail and PDPL, PCI and NCA control mapping - followed by a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Umluj

A scan-and-report vendor

Automated tool output rebadged as a pen test. It will list a missing header and never once ask whether a guest link leaks a full passenger list, or whether a manifest survives the day it is needed.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team in Umluj's time zone that treats operational records as safety-critical. Manual exploitation of booking and manifest logic, findings mapped to PDPL, PCI DSS and NCA ECC, fixed pricing, free retest.

Umluj engagements usually pair a web application test with an API assessment, because passenger data travels between an operator's own site and the agents selling its trips.

// 08 Frequently asked questions

Why does a dive or boat operator in Umluj need penetration testing?

Because your booking system is also your safety register. The same records that take a payment carry the dive manifest, the passenger count, the medical declaration and the emergency contact. If those records can be altered, deleted or made unavailable by someone outside your business, you lose the ability to account for the people you took out on the water. Testing verifies that only your staff can write to them and that a copy survives an incident.

What exactly do you test on a marine tourism booking platform?

We test authentication and session handling, then the authorisation logic behind every record: whether one operator's account can read or edit another's trip, whether a guest-facing link exposes a full passenger list, whether a manifest can be modified after departure without an audit trail, and whether roll-call and check-in endpoints can be abused. We also test the payment path and any partner or agent API feeding your vessel schedule.

Are medical declarations treated differently under Saudi law?

Yes. Fitness-to-dive forms, medication notes and disclosed conditions are health data, which the Saudi Personal Data Protection Law treats as sensitive personal data warranting stronger safeguards. Collecting them in a web form, emailing them, or storing them in a shared folder alongside ordinary booking data raises the stakes considerably. We test how that data is transmitted, who can reach it, and how long it stays reachable.

Which regulations apply to penetration testing in Umluj?

Card payments bring PCI DSS 4.0 Requirement 11.4; guest, passenger and health data falls under the Saudi PDPL's security-of-processing duties; national and provincial bodies and their suppliers, including those handling marine permits and coastal development systems, fall under the NCA Essential Cybersecurity Controls, which mandate periodic vulnerability assessment and penetration testing. Resort operators pursuing ISO 27001:2022 use testing as evidence for control A.8.29.

We are a small operator with a handful of boats. Is a pentest proportionate?

Scope decides cost, and a small operator's scope is small - typically one booking site, one payment path and a cloud tenant. What is not small is the consequence, because a two-boat business carries the same duty to account for its passengers as a large resort. We scope to what you actually run, quote a fixed price after a free 30-minute call, and include a free retest once you have fixed what we found.

Ready for a pen test in Umluj?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →