Insights

Field guides for BCM teams in regulated industries.

Written by practitioners for practitioners — clause-level walk-throughs of ISO 22301, the SAMA BCM Framework, BIA methodology and crisis-management playbooks. No fluff, no vendor-neutral hedging; every guide reflects what we've seen work inside KSA and GCC continuity programmes.

Pillar guides

Start with a cornerstone topic.

Pillar10 min read

Business Impact Analysis: A Practitioner's Guide to BIA Methodology

Every credible BCM programme rests on a defensible BIA. This pillar covers the impact matrix, criticality ratings, RTO/RPO/MTPD, dependency mapping, and the cadence that keeps a BIA from going stale.

Read the guide
Pillar10 min read

Crisis Management Playbook: From First Alert to Post-Incident Review

A pillar guide on running a credible crisis-management programme: command structure, activation criteria, communications, the recovery handshake, and the post-incident lifecycle that auditors actually look at.

Read the guide
Pillar11 min read

ISO 22301:2019 Implementation Guide — From Clause 4 to Certificate

A practitioner's walk-through of ISO 22301:2019: every clause explained, the certification path, the gaps auditors find most often, and how to operationalise the standard.

Read the guide
Pillar5 min read

Missed the ISO 27001:2022 Deadline? The Recertification Path After 31 October 2025

The ISO 27001:2013-to-2022 transition window closed on 31 October 2025. A lapsed certificate isn't renewed — you re-enter as a new client and undergo a full initial audit. What that means in practice, and how to rebuild fast in Qatar and KSA.

Read the guide
Pillar8 min read

NCA ECC Business Continuity Requirements: The Resilience Domain in Practice

Saudi Arabia's Essential Cybersecurity Controls put business continuity inside a cybersecurity framework. What the Cybersecurity Resilience domain actually expects, who it applies to, the evidence that satisfies it, and how to run one programme instead of two.

Read the guide
Pillar5 min read

Qatar NIA v2.1: The Annual Re-Certification Reality

Qatar's National Information Assurance Standard is now at v2.1, and certification is an annual discipline — not a one-off. What the current version means, how the v2.0-to-v2.1 re-certification works, and how to make annual NIA compliance sustainable rather than a yearly fire drill.

Read the guide
Pillar10 min read

Qatar PDPPL and Business Continuity: Where Privacy Law Meets Your BCM Programme

PDPPL is a privacy law, not a continuity standard — but the two meet at one critical seam: the personal-data breach. This guide maps exactly where Qatar's PDPPL touches a BCM programme, where it doesn't, and how the incident module becomes the operational home for the 72-hour notification duty.

Read the guide
Pillar9 min read

The SAMA BCM Framework: A Practitioner's Guide for KSA Banks and Fintechs

Every SAMA-licensed entity needs a defensible BCM programme. This guide walks through the five SAMA pillars, the documents auditors sample first, and how SAMA aligns with — and diverges from — ISO 22301.

Read the guide

Pillar · Business Impact Analysis

More on Business Impact Analysis

Read the pillar

Pillar · Crisis Management

More on Crisis Management Playbook

Read the pillar

Pillar · ISO 22301

More on ISO 22301

Read the pillar

Pillar · NCA ECC

More on NCA ECC Business Continuity Requirements

Read the pillar

Pillar · PDPPL

More on Qatar PDPPL and Business Continuity

Read the pillar
Article5 min read

The PDPPL 72-Hour Breach Notification Clock: An Incident-Response Walkthrough

When a personal-data breach hits, the PDPPL 72-hour clock to the NDPO starts at the same moment as your SAMA cyber-incident clock. A practical walkthrough of who decides, what gets evidenced, and how to stop an incident closing with a notification duty still open.

Read article
Article5 min read

Data Residency and PDPPL: Why On-Prem BCM Tooling Matters in Qatar

PDPPL's cloud-privacy regime — reinforced by the NCSA's 2026 Cloud Privacy Assessment Tool — pushes organisations to keep personal data from leaving their control. Here's why per-tenant isolation and on-prem AI inference turn a BCM platform's architecture into a residency feature.

Read article
Article5 min read

Qatar's NCSA Cloud Privacy Assessment Tool: What It Checks and How to Pass It

On 3 April 2026 the NCSA launched a free Cloud Computing Privacy Assessment Tool to help organisations evidence PDPPL compliance in the cloud. Here's what the tool actually assesses — data classification, access, encryption, third-party risk, cross-border transfers, incident response — and how to be ready for each.

Read article
Article4 min read

PDPPL Enforcement Is Real: Penalties, Compliance Orders, and What Triggers Them

Qatar's PDPPL moved from statute to active enforcement in 2024–2025, with public compliance orders against ICT and e-commerce operators and penalties of QAR 1M–5M per violation. What the NDPO has actually done, what it expects, and the breach-response gap that draws the most risk.

Read article

Pillar · SAMA BCM

More on The SAMA BCM Framework

Read the pillar

Latest

Recently published.