Omani Fuel Company Selects Falconry360 for BCM

Falconry has been awarded an engagement by one of Oman’s leading fuel marketing companies to expand and operationalize its business continuity programme through a combination of resilience advisory and digital enablement. The programme brings together business continuity governance, business impact analysis, recovery planning, crisis coordination, training and ongoing management visibility. The objective is to move continuity management beyond static documents and create a capability that can be maintained, reviewed and used across departments throughout the year. Falconry is supporting the organization with BCM programme expansion, BIA and recovery analysis, continuity and crisis-management planning, training, testing and handover. Falconry360 provides the automation layer, digitizing key BCM workflows, supporting role-based access, dashboards, reporting and structured data management across the programme. By combining advisory implementation with a connected technology layer, the engagement is designed to strengthen both resilience maturity and the day-to-day manageability of the BCM programme – creating clearer ownership, stronger traceability and better readiness for future exercises and disruptions.
Falconry Supports Oman Investment Data Privacy

Falconry has supported a leading investment organization in Oman with the implementation of personal data protection requirements, helping translate regulatory expectations into a more structured privacy governance approach. Investment organizations handle personal information across employees, investors, counterparties, service providers and corporate functions. Effective privacy compliance therefore requires clear accountability and repeatable practices that can be applied consistently across the organization rather than treated as a one-time legal exercise. The engagement focused on supporting the implementation of privacy governance and operational controls required to manage personal data more consistently. Falconry worked with relevant stakeholders to help structure responsibilities, align internal practices with applicable data protection requirements and create a clearer foundation for ongoing compliance and oversight. The work supports the organization in moving toward a more sustainable privacy operating model, with data protection embedded into governance and business processes as regulatory expectations and organizational activities continue to evolve.
Falconry Supports Saudi ISO 27001 Implementation

Falconry has supported a leading Saudi apparel company with the implementation of an information security management system aligned with ISO/IEC 27001. As organizations expand their digital operations, customer channels, internal systems and third-party dependencies, information security needs to be managed through a clear governance framework rather than isolated technical controls. ISO/IEC 27001 provides a structured basis for connecting security risks, responsibilities, policies and controls within a managed system. Falconry’s engagement supported the organization in establishing the governance and implementation foundation required for an ISO 27001-aligned information security management system. The work focused on translating security requirements into practical organizational responsibilities, documented controls and a repeatable approach to managing information security risk. The programme provides a stronger basis for ongoing security management and assurance, helping the organization maintain visibility over its information security obligations as the business and its technology environment continue to grow.
Falconry Supports Oman BCM & DR Programme

Falconry is supporting a major integrated industrial water-services provider in Oman with the development of its business continuity management and disaster recovery framework. Industrial utility environments depend on the continued availability of critical services, systems, people and third parties. A coordinated BCM and DR approach is therefore essential to ensure that business and technology recovery arrangements support the same operational priorities during disruption. The engagement focuses on establishing a structured continuity and recovery framework that can support governance, critical-service prioritization, recovery planning and coordinated response. By connecting business continuity and disaster recovery requirements, the programme aims to provide clearer alignment between operational dependencies and the technology capabilities required to support them. The work strengthens the organization’s foundation for resilience planning and provides a more consistent basis for future exercises, reviews and continuous improvement across critical services.
Falconry Supports Saudi Enterprise Risk Programme

Falconry is supporting a leading Saudi hospitality and real estate group through a risk management and governance advisory engagement designed to strengthen the organization’s enterprise-level risk capability. As organizations expand across assets, operations and strategic initiatives, risk management needs to provide more than a periodic register. It must support clear ownership, consistent assessment, management reporting and decision-making across the business. The engagement includes baseline review and progressive enhancement of the organization’s risk and governance practices, with Falconry working alongside management to strengthen structure, clarify responsibilities and improve the way risk information is consolidated and used. The programme is being delivered through phased advisory work so that improvements can be embedded progressively rather than treated as a one-time redesign. The engagement reflects Falconry’s approach to enterprise risk: combining practical governance design with implementation support so that risk management becomes a usable management discipline linked to accountability and business decisions.
Designing Falconry360 Use Cases for NCA/SAMA Cyber and GCC PDPL in One Blueprint

KSA’s NCA / SAMA cybersecurity regimes and GCC-wide PDPL data protection laws are now two of the strongest forces shaping governance in the region. For most banks and large institutions, the majority of new governance, risk, and compliance work traces back to one of these two streams: hard cyber controls and evolving data protection requirements. Trying to implement them separately—one project for NCA, one for SAMA, another for PDPL in each country—creates duplication, inconsistency, and unnecessary cost. Falconry360 allows you to design a single implementation blueprint where NCA/SAMA cyber controls and GCC PDPL are modelled once and then reused across entities, regulators, and use cases. Step 1: Start from Shared Libraries, Not Separate Projects The foundation of the blueprint is three shared libraries in Falconry360: Control Library – one canonical cyber and privacy control set that you can map to: NCA ECC, OTCC, CCC, DCC, CSCC, NCNICC‑1 SAMA Cyber Security Framework domains and principles GCC PDPL obligations (KSA PDPL, UAE FDPL/PDPL, Oman, Qatar). Obligations Library – NCA/SAMA clauses and GCC PDPL articles represented as structured obligations with tags for regulator, country, theme, and risk type. Data / Asset / Service Library – shared records of critical systems, business services, data categories, and third parties that are reused by cyber, privacy, and vendor risk. By investing in these libraries first, you avoid building separate “mini frameworks” for each regulation. Step 2: Design Two Primary Use-Case Streams Once libraries exist, you can structure Falconry360 configuration around two major streams, each spanning several layers (ANTICIPATE, COMPLY, WITHSTAND, ASSURE). NCA/SAMA Cyber Governance Stream Core use cases: Cyber Risk Register (ANTICIPATE) Cyber risks aligned to NCA domains (e.g., governance, defence, resilience, third‑party) and SAMA CSF pillars. Linked to assets, services, vendors, and controls from the central library. NCA/SAMA Obligation Mapping (COMPLY) ECC/OTCC/CCC/DCC/CSCC/NCNICC‑1 and SAMA CSF clauses mapped to controls, policies, and evidence. Coverage and gap views per entity (e.g., SAMA‑regulated bank vs non‑CNI private sector). Cyber Incidents and Issues (WITHSTAND/ASSURE) Common incident model that captures NCA/SAMA impact, affected controls, and required reporting. Issues and remediation plans tracked against the same controls and obligations. FalconryX can then: read NCA/SAMA updates, suggest new obligations, propose mappings, and draft impact assessments. GCC PDPL Compliance Stream Core use cases: PDPL Obligations and Data Inventory (COMPLY / ANTICIPATE) Common PDPL themes (lawful basis, consent, rights, retention, security, transfers) mapped once and tagged by country. Data processing inventory linking systems, purposes, and data categories to PDPL obligations. Privacy Controls and Workflows Controls from the central library (access control, encryption, logging, DPIAs, rights handling) linked to PDPL obligations and processing activities. Standard workflows for DPIAs, new products, vendor onboarding, and change management that automatically pull in PDPL requirements. Incidents and Rights Requests Incidents with PDPL impact flags per country and required notification timelines. Rights requests tracked end‑to‑end, linked to systems and obligations. FalconryX can: extract PDPL obligations from new guidance, help draft DPIAs, and generate regulator‑ready breach summaries. Step 3: Reuse the Same Objects Across Both Streams The key to this blueprint is deliberate reuse. A cloud platform might be: A critical system under NCA CSCC/CCC and SAMA CSF. A PDPL‑relevant system processing customer data in KSA and UAE. A vendor might simultaneously be: In scope for NCA OTCC/DCC third‑party cyber controls. A PDPL “processor” handling personal data across multiple GCC markets. By modelling these as single assets and vendors, with multiple tags, you avoid double‑counting and conflicting views. Step 4: Anchor Both Streams in the Five Falconry360 Layers Map the blueprint explicitly to Falconry360’s layers: GOVERN – Policies and charters for NCA/SAMA cyber, PDPL, AI, and vendor governance. ANTICIPATE – Cyber, operational, and privacy risks connected to NCA/SAMA and PDPL obligations. COMPLY – All NCA, SAMA, and PDPL clauses as obligations with mappings to controls and evidence. WITHSTAND – Resilience scenarios where cyber incidents or data breaches impact important business services. ASSURE – Audit and ICFR scopes that include NCA/SAMA and PDPL controls, with shared issues and remediation. This ensures NCA/SAMA and PDPL are not separate “programmes” but part of one governance operating system. Step 5: Deliver a Clear Story to Regulators and Boards With this blueprint, you can explain to stakeholders: To regulators: how NCA, SAMA, and PDPL obligations are captured, mapped, executed, and assured in one model. To boards: how cyber and privacy risks sit on the same map of critical services, systems, and vendors, and how actions are prioritised. Falconry360 provides the structure; FalconryX provides the intelligence layer that keeps it current and reduces manual effort.
PDPL Across the GCC: Automating Data Protection Compliance on Falconry360

Personal Data Protection Laws (PDPL) are rapidly becoming a common thread across the GCC. Saudi Arabia, the UAE, Oman, and Qatar have all moved to establish, update, or strengthen PDPL regimes, each with its own nuances but broadly similar principles around lawful processing, consent, data subject rights, retention, and cross‑border transfers. For regional organisations, the challenge is not just understanding each PDPL in isolation. It is operationalising PDPL at scale across multiple jurisdictions—without building four separate compliance programmes. This is where an automation‑ready platform like Falconry360, supported by FalconryX, becomes a differentiator. The Common DNA of PDPL Regimes in the GCC While there are important differences in detail, GCC PDPLs typically converge on: Lawful basis and consent – clear legal grounds for processing, plus explicit consent where required. Purpose limitation and minimisation – data collected only for specified purposes and kept to what is necessary. Data subject rights – access, rectification, deletion, portability, and objection rights. Retention and deletion – defined retention periods and secure disposal. Cross‑border transfers – rules for sending personal data outside the country. Security and breach notification – appropriate technical and organisational measures plus defined breach reporting timelines. This common DNA makes it possible to design one PDPL control framework and then apply local variations per jurisdiction. Modelling PDPL Obligations Once, Applying Them Many Times In Falconry360, PDPL compliance starts by building a structured, reusable obligations model: Create a PDPL obligations library with core themes (e.g., lawful basis, rights, retention, consent, security, transfers). For each jurisdiction (KSA PDPL, UAE PDPL, Oman, Qatar), map specific articles to these themes and tag them by country. Link obligations to data categories, processing activities, systems, and business units that are in scope. This allows you to answer questions such as: “For customer transaction data in country X, which PDPL obligations apply?” “Which controls and processes support data subject rights across all GCC entities?” Connecting PDPL to Data, Processes, and Controls To turn legal text into execution: Maintain a data inventory: personal data categories, locations, systems, and processing purposes. Link each processing activity to relevant PDPL obligations (by country) and to controls such as access management, encryption, logging, DPIAs, consent capture, and retention jobs. Ensure policies and procedures (e.g., privacy policy, retention policy, incident response) are connected to the same obligations. Falconry360’s single data model lets you reuse the same technical and organisational controls across jurisdictions, while still tagging where local variations exist (for example, different retention periods or notification timelines). Automating PDPL Workflows with FalconryX FalconryX can automate some of the most time‑consuming parts of PDPL compliance: Obligation Extraction and Updates Read PDPL legislation and regulatory guidance to extract new or updated obligations. Suggest mappings to existing obligation themes and controls. Impact Assessment Support Assist in drafting Privacy Impact Assessments (PIAs/DPIAs) by pulling in relevant risks, controls, data flows, and obligations from the platform. Propose standard risk and control language based on similar, previously assessed use cases. Rights and Request Handling Help route and track data subject requests by linking them to data systems, owners, and obligations. Generate draft responses and internal instructions based on defined playbooks. Breach Response Support When incidents are logged, flag whether PDPL obligations are likely triggered and which jurisdictions are impacted. Suggest notification timelines and potential remedial actions based on recorded obligations and policies. One View Across KSA, UAE, Oman, and Qatar For regional leadership, the aim is to see PDPL risk and compliance horizontally, not in silos. Falconry360 enables: A single PDPL dashboard showing status by country, entity, and business unit. Aggregated views of open PDPL-related issues and actions, with drill‑down by obligation or theme. Integrated reporting for boards and regulators that explains how PDPL compliance is structured across GCC, using one model and one set of evidence. This reduces the risk of inconsistent interpretations and makes it easier to demonstrate that PDPL compliance is designed, monitored, and governed centrally, not improvised locally. From Manual PDPL Programmes to Continuous Compliance Most PDPL programmes start manually: gap analyses, document-heavy inventories, and ad hoc trackers. Moving to an automated, platform-led model looks like this: Model common PDPL obligations and controls once, then apply jurisdiction tags. Map data and processing to those obligations in a single inventory. Embed workflows for new projects, product changes, vendor onboarding, and incident handling that automatically pull in PDPL requirements. Use FalconryX to keep obligations, mappings, and documentation up to date as laws and guidance evolve. Over time, PDPL compliance becomes a continuous, data‑driven part of how the organisation operates—rather than a recurring scramble each time a regulator asks, “Show me how you comply.”
NCA and SAMA-Aligned Cyber Governance: Building a Unified Operating Model for KSA

Saudi Arabia has become one of the most structured and demanding cyber regulatory environments in the region. The National Cybersecurity Authority (NCA) has issued a comprehensive suite of mandatory and sector-specific cybersecurity controls, while the Saudi Central Bank (SAMA) enforces its own Cyber Security Framework (SAMA CSF) for regulated financial institutions. For many organisations, 80–90% of the cyber governance and compliance workload is now directly tied to these two pillars. Managing NCA and SAMA requirements through scattered documents and point tools is no longer sufficient. What’s needed is a unified cyber governance operating model that embeds NCA and SAMA expectations into daily risk, compliance, and technology workflows. The NCA and SAMA Cyber Landscape in Brief NCA defines national baselines through: ECC (Essential Cybersecurity Controls – ECC‑1:2018 / ECC‑2:2024) – foundational, mandatory controls for government entities and critical national infrastructure. OTCC (Operational Technology Cybersecurity Controls) – specialised controls for ICS/SCADA and industrial environments. CCC (Cloud Cybersecurity Controls) – standards for cloud service providers and cloud-consuming organisations. DCC (Data Center Cybersecurity Controls) – controls for hosting facilities and data centres. CSCC (Critical Systems Cybersecurity Controls) – measures for systems vital to national security and critical services. NCNICC‑1:2025 – cybersecurity controls tailored for non‑CNI private sector entities, with a strong emphasis on governance, defence, and third‑party risk. In parallel, SAMA CSF provides a structured framework for financial institutions, covering governance, risk management, defence, resilience, and third‑party oversight across all critical systems and services. The combined effect: cyber is no longer just a technical matter—it is a regulated governance discipline. Why a Unified Cyber Governance Operating Model Is Needed Trying to comply with NCA and SAMA using separate spreadsheets, GRC tools, vulnerability platforms, and vendor trackers leads to: Duplicated controls and assessments – the same requirement implemented multiple times with slight variations. Inconsistent mappings – NCA and SAMA clauses linked to different controls in different systems. Limited traceability – difficulty showing regulators how a specific NCA/SAMA requirement is implemented, tested, and monitored across entities and third parties. A unified model should provide: One central control library aligned to NCA ECC, OTCC, CCC, DCC, CSCC, NCNICC‑1 and SAMA CSF. A single view of critical assets, services, and vendors, mapped to those controls. Integrated workflows for risk assessment, implementation, monitoring, incidents, and issues. Structuring NCA and SAMA Controls in Falconry360 In Falconry360, NCA and SAMA expectations can be embedded as part of the COMPLY and ANTICIPATE layers and reused across entities: Control Library Alignment Build a canonical cyber control library mapped to NCA ECC families and SAMA CSF domains. Add specialised control sets for OTCC, CCC, DCC, CSCC and NCNICC‑1 where relevant (e.g., OT environments, cloud, data centres, non‑CNI). Obligation and Clause Mapping Represent each NCA and SAMA requirement as a structured obligation. Map obligations to controls, assets, services, and third parties. Track coverage status and residual gaps. Entity and Sector Views Use tags and filters to distinguish government, CNI, financial institutions, and non‑CNI private sector entities. Provide entity‑specific dashboards showing NCA/SAMA coverage and outstanding actions. This ensures you are not “re‑implementing NCA” for each business unit; you are reusing one model across many contexts. Integrating Risk, Incidents, and Third Parties Cyber governance is not just about controls—it’s about how they relate to risks, events, and vendors. On a unified platform: Cyber risks are classified and assessed using a central taxonomy, with explicit links to NCA/SAMA control requirements. Incidents and breaches are logged with root causes, affected systems, and impacted controls, showing both NCA and SAMA implications. Third‑party assessments are structured around NCA and SAMA expectations (especially ECC, OTCC, CCC, DCC, NCNICC‑1 and SAMA’s third‑party requirements), so vendor posture can be compared consistently. This makes it easier to answer questions such as: “Which NCA/SAMA controls failed in this incident?” or “Which vendors create the highest aggregated compliance exposure?” Using FalconryX to Accelerate NCA/SAMA Alignment FalconryX can significantly reduce manual effort in KSA cyber governance by: Reading NCA and SAMA updates and suggesting new or changed obligations. Proposing control mappings between new clauses and your existing control library. Helping draft impact assessments, risk memos, and regulatory responses grounded in live platform data. Highlighting hotspots where incidents, weak tests, or open issues cluster around critical NCA/SAMA controls. This turns NCA and SAMA cyber compliance from a series of one‑off projects into a continuous, intelligence‑driven process. From Compliance Burden to Strategic Advantage When NCA and SAMA requirements are embedded inside the governance operating system: Compliance becomes demonstrable: you can show, not just claim, how each requirement is implemented and monitored. Cyber risk management becomes more strategic: leadership sees how cyber posture links to critical services and third‑party dependencies. Audit and supervisory interactions become more efficient: evidence, mappings, and history are all in one place. KSA institutions that invest now in NCA/SAMA‑aligned cyber governance as part of a unified operating model will be better positioned to scale, innovate, and respond to future regulatory evolution.
The 2026 CRO, CCO, and CISO: How Integrated Governance and AI Redefine Their Roles

The roles of Chief Risk Officer (CRO), Chief Compliance Officer (CCO), and Chief Information Security Officer (CISO) are converging in important ways. Each owns a piece of the organisation’s defense, yet regulators, boards, and customers increasingly expect a single, coherent view of risk and control. By 2026, integrated governance operating systems and AI‑enabled decision intelligence are reshaping what it means to be effective in these roles. From Siloed Leaders to a Risk and Control “Triad” Historically: The CRO focused on enterprise risk, capital, and risk appetite. The CCO focused on regulatory compliance, policies, and monitoring. The CISO focused on cyber, technology, and information protection. In practice, their worlds now overlap heavily: cyber incidents trigger regulatory issues; compliance failures reflect risk and control weaknesses; operational resilience ties them all together. In an integrated governance model: They operate as a triad, each with distinct accountability but shared data, language, and objectives. They jointly shape risk appetite, control strategy, and resilience priorities. They present unified narratives to boards and regulators, supported by a common platform. How a Governance Operating System Changes Their Daily Work With a platform like Falconry360: The CRO sees a real‑time risk picture that incorporates cyber, privacy, third‑party, conduct, and resilience data—not just financial and operational metrics. The CCO has direct visibility into how obligations are mapped to controls, risks, and evidence, and can track implementation across the business. The CISO can see how cyber risks and incidents affect business services, regulatory exposure, and overall risk appetite. Rather than debating “whose numbers are right,” they discuss what the shared data tells them and what to do about it. The Impact of AI on Their Roles AI, through engines like FalconryX, does more than add convenience; it changes expectations of these leaders. For the CRO: AI‑assisted risk identification and clustering mean the CRO must interpret richer, more dynamic risk insights. The role shifts from risk reporter to strategic navigator, using live intelligence to shape decisions on growth, investment, and resilience. For the CCO: AI‑assisted regulatory mapping and drafting reduce manual burden, allowing more focus on interpretation, prioritisation, and dialogue with regulators. The CCO becomes a designer of regulatory operating models, ensuring obligations are embedded across processes and technology. For the CISO: AI‑enhanced detection, prioritisation, and scenario analysis mean the CISO is expected to connect cyber realities directly to business and regulatory impacts. The role evolves into business-centric security leadership, explaining cyber decisions in terms of services, customers, and risk appetite. All three roles become more forward‑looking and advisory, less consumed by manual reporting. New Expectations from Boards and Regulators With integrated platforms and AI capabilities in place, boards and regulators will increasingly ask: Are CRO, CCO, and CISO aligned in their view of top risks, control weaknesses, and resilience gaps? How quickly can the organisation respond to a new regulatory requirement or emerging threat? How are AI and automation being governed, and what is their role in risk and compliance processes? The bar rises: having tools is not enough—leaders must show how they use integrated data and AI to make better decisions and manage risk more proactively. Skills and Mindsets for the 2026 Triad To thrive in this environment, the 2026 CRO, CCO, and CISO need: Data and digital fluency – understanding how platforms, models, and data flows underpin governance. Cross-functional mindset – comfortable working across risk, compliance, security, operations, finance, and technology. Narrative and influence skills – able to translate complex risk and AI insights into clear stories for boards and regulators. Comfort with continuous change – treating frameworks and models as living systems, not static templates. Integrated governance and AI do not replace these leaders—they amplify their impact. The ones who adapt will find their roles more central than ever to strategy, performance, and trust.
Combined Assurance in Practice: Connecting Risk, Compliance, and Audit Functions

Many organizations recognise the idea of “combined assurance”: risk, compliance, and internal audit should coordinate their efforts so the board receives a coherent view of assurance over key risks. In practice, this often fails because each function runs its own tools, taxonomies, and plans. A governance operating system makes combined assurance a practical reality. Rather than trying to coordinate three separate worlds, it allows them to share the same risk and control landscape while retaining their distinct roles. What Goes Wrong Without Integration Without a shared platform, combined assurance typically faces: Overlap and duplication: multiple functions testing the same controls in slightly different ways. Gaps: important risks or processes that everyone assumes someone else is covering. Conflicting messages: different ratings or opinions about the same risk or control. Boards and executive committees receive multiple reports that are hard to reconcile, weakening confidence in the overall assurance picture. A Shared View, Different Responsibilities In an integrated model: Risk management (first/second line) owns and manages risks and controls as part of daily operations. Compliance ensures obligations are identified, implemented, and monitored. Internal audit provides independent assurance on the design and effectiveness of the governance, risk, and control framework. All three functions work from the same underlying data model: Shared risk taxonomy Shared control library Shared obligations and policies Shared records of incidents, issues, and remediation This doesn’t blur responsibilities; it aligns them. How Combined Assurance Works Day to Day On a platform like Falconry360, combined assurance becomes tangible: Annual and multi‑year assurance plans can be built on the same risk and control data, showing which functions will cover which areas and when. Overlaps and gaps can be identified visually and resolved in planning, rather than discovered later. Assurance results from risk, compliance, and audit activities feed back into a single picture of control effectiveness. Boards can then see, for each key risk or process: Which controls are in place. Which functions have tested them (risk/control testing, compliance monitoring, internal audit, external audit). What the combined results say about residual risk and control strength. The Role of FalconryX Intelligence further strengthens combined assurance by: Highlighting risks and controls with high levels of activity (incidents, issues, test failures) that might merit additional assurance. Suggesting areas where testing is sparse, indicating potential blind spots. Helping draft integrated assurance reports that combine perspectives from risk, compliance, and audit. Combined assurance moves from concept to operating practice—supported by data rather than slides.