forumNew topic

They requested basic cybersecurity controls before signing the contract — what are they and which ones do we actually need to implement?

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#1

We're a 12-person enterprise software integration team in Riyadh. We are on the verge of signing a 450,000 SAR annual maintenance and development contract with a major semi-governmental logistics company. Everything was progressing smoothly until procurement sent over an extensive cybersecurity audit questionnaire.

As a contract prerequisite, they require us to complete a "basic cybersecurity controls" checklist and provide evidence for each item. The questionnaire contains dozens of requirements: multi-factor authentication, network segmentation, data encryption, offline backup policies, access logs, regular employee awareness training, and more.

Our budget and time are limited; we have only 3 weeks left to sign. As a small team, implementing all of these from scratch is virtually impossible. Which of these controls are strict red lines for enterprise buyers, and which can we defer with a reasonable commitment roadmap?

JJale K***Expert
Job title
Software team lead
Sector
Livestock
Organization type
a company within a holding
Joined
Feb 2026
Message
136

Doki · Infrastructure migration · 2023

Most Helpful#2

Short answer: Basic cybersecurity controls are the baseline defense standards enterprise buyers demand to mitigate third-party supply chain risks. Right now you should immediately roll out controls that directly lock down system access—such as authentication isolated backups, and endpoint security—while presenting process- policy-, and audit-heavy items as a formal 60-to-90-day action plan.

In Saudi Arabia, public sector and enterprise organizations enforce national cybersecurity frameworks directly onto vendor requirements. There are 3 technical non-negotiables in these audits: 1) Mandatory multi-factor authentication (MFA) across all remote access points to servers, source code repositories, and corporate email 2) Offline or immutable backup mechanisms protecting client data and codebases against ransomware, 3) Centrally managed, licensed endpoint protection alongside up-to-date OS patching across all team workstations.

In contrast network segmentation, SIEM log aggregation architectures external penetration tests, and formal disaster recovery scenarios cannot be completed in 3 weeks. Never falsely mark these items as "completed." Instead select "partially implemented" or "planned," and add a note: "Will be completed within 90 days of contract commencement with external specialist support." Enterprise risk teams routinely accept this approach.

When submitting the form, include screenshots from admin consoles showing MFA enabled, a baseline password policy document, and signed employee information security acknowledgments as technical evidence to expedite sign-off.

UUfuk S***Veteran
Job title
Network Administrator
Sector
Furniture manufacturing
Organization type
workshop
Joined
Oct 2024
Message
187
#3

we got the exact same questionnaire for a similar logistics project in riyadh. it had 40 items and half of them didn't even make sense for a 10-person team like ours. we provided screenshots of mfa and backups submitted a commitment letter with target dates for the rest, and they approved it don't panic.

BBurak Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
cooperative
Joined
Mar 2022
Message
104
#4

On the technical side, their biggest sticking point is exposed SSH and RDP ports. Cut off direct public IP access to your servers and place them behind at least a basic VPN or IP whitelist. If you demonstrate this step alongside active MFA logs in your report, you'll easily clear the technical auditor.

ZZafer B***Member
Job title
Customer service representative
Sector
Insurance
Organization type
chain store
Joined
Nov 2023
Message
34
#5

Enterprise buyers know you don't run a massive corporate SOC. Their real concern is whether an attacker could use your infrastructure as a stepping stone into their own network. If you document that your internal network and the integration pipeline provided to the client are logically segmented, their perceived risk will drop immediately.

HHalilMember
Job title
Supply chain
Joined
Dec 2023
Message
114
#6

Last year we spent around 18,000 SAR to clear a similar vendor list. 6,000 SAR went toward centralized password and identity manager licenses, and the rest went into an automated, isolated cloud backup architecture. We ticked off 19 of the 28 items right away, and cleared the remaining 9 during the audit 3 months later.

NNeslihan K***Expert
Job title
IT Manager
Sector
Catering
Organization type
chain store
Joined
Jan 2023
Message
40
#7

Unfortunately, most vendor questionnaires are just copy-paste jobs. The procurement person on the other end has no idea about the technical depth of the items; they just care that the boxes are checked and signed off. But if a data breach ever happens, those commitments turn into legal leverage against you, so never mark anything as 'done' if you haven't actually done it.

TTaner V***MemberCommunity member
Joined
Jan 2023
Message
307
#8

Before you start filling out the form ask for a 15-minute call with their info sec officer. Tell them, "We're an SME our core technical controls are in place, but we'd like to roll out the corporate policy items across our project roadmap." Ninety percent of the time they're reasonable about it and approve the timeline.

ÜÜlkü O***MemberCommunity member
Joined
Mar 2024
Message
14
#9

for the employee cybersecurity awareness training item, do we really need to get paid certificates from an accredited provider, or is an internal presentation and a sign-in sheet enough proof?

ZZerrinMember
Job title
Wedding planning
Joined
Apr 2024
Message
84
#10

450,000 SAR is a solid contract don't sweat it at all. Enterprise clients renew this paperwork every year just as a formality. It looks intimidating at first but once you get your fundamentals sorted, the rest is just routine bureaucracy.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#11

Looking at it as a process, the picture changes. If you get three different answers on a topic, the question was asked wrong.

I'm also curious if anyone does it differently.

DDeniz K***ExpertCommunity member
Joined
Nov 2024
Message
154
#12

I have a question, don't want to go off-topic though. Mistakes made on the basic cybersecurity controls side are usually reversible but expensive.

Hasty decisions become decisions you have to fix six months later. Of course, it varies if your situation is different.

MMustafa G***Member
Job title
Co-founder
Sector
Machinery manufacturing
Organization type
boutique agency
Joined
May 2022
Message
155
#13

It's rare to find an explanation this clear.

SSelçukMember
Job title
Sports club
Organization type
boutique agency
Joined
Jun 2024
Message
76
#14

thanks, this was very helpful.

DDamla Ö***MemberCommunity member
Joined
Jan 2022
Message
70
#15

I didn't know that.

NNuri U***VeteranCommunity member
Joined
Feb 2024
Message
325
#16

great work.

NNazlı T***MemberCommunity member
Joined
Apr 2025
Message
217
#17

We need to take it step by step. Start with a small trial; don't commit to everything at once.

Just leaving this note, it might be useful.

YYağmur B***MemberCommunity member
Joined
Jun 2024
Message
51
#18

I partly agree, partly disagree. People defend habits, not processes. Resistance comes from there.

Most incidents start with a leaked password, not a vulnerability. That's all, sorry if I went on too long.

AAleyna K***New member
Job title
Quality control inspector
Sector
Livestock
Organization type
120-person company
Joined
Jun 2026
Message
1
#19

I'm a small business, let me explain from my side. Most time waste accumulates in tasks waiting for approval.

Just because everyone does it doesn't mean it's right. I'm also curious if anyone does it differently.

FFatih P***MemberCommunity member
Joined
Nov 2023
Message
1
#20

It's rare to find an explanation this clear. Your time to detect an issue directly determines its cost.

Reply