Security built for detection.
Joushen is a cybersecurity and digital-resilience consultancy. We secure your digital frontier with cutting-edge cybersecurity solutions & services.
We build on the platforms enterprises
already trust.
Compliant is not the same as secure.
We deliver both.
Regulation tells you where the floor is. Attackers tell you the truth.
Leading with perspective
We start with your business and its risk, not with a product catalogue.
Working in the trenches
Our consultants are practitioners. They've built the systems they're asked to break.
Delivering real impact
Measured in closed findings and passed audits, not in slide count.
The right technology, implemented right.
Software doesn't secure anything on its own. We select, deploy, tune and operate it, across nine solution areas.
Privileged Access Management
Vault, rotate, time-box and record every admin session.
Intrusion Detection System
Detection across network, endpoints and cloud. Tuned to fire on what matters.
Threat Intelligence
What's targeting you. Your sector, region, leaked credentials and brand.
Identity Protection
MFA, conditional access and continuous verification.
Brand Protection
Phishing sites, fake apps and typo-squatted domains, taken down.
Email Security
Impersonation and BEC protection, DMARC/SPF/DKIM, detonation.
Cybersecurity Awareness & Training
The platform, plus the Arabic-first programme that runs on it.
Digital Forensics & Incident Response
What got in, how, what it touched. Evidence that survives scrutiny.
Governance Risk & Compliance
Map one control to NCA, SAMA, ISO and PDPL. Evidence once, satisfy four.
Nine disciplines. One partner.
Most organisations end up with six vendors and no single view of their risk. We're built to be the one call.
Identity & Access Management (IAM)
Control who reaches what, and prove it. Built to protect assets and support growth.
IAM · SAVIYNT · ONEIDENTITYOffensive Security
Finding the gaps an attacker would find first.
VAPT · RED TEAM · OSCPGovernance, Risk & Compliance
Manage risk and prove compliance through real governance.
NCA ECC · SAMA CSF · ISO 27001Virtual CISO
Strategic direction, without a full-time hire.
vCISO · BOARD-READYCybersecurity Awareness & Training
People who recognize the threat before it lands.
PHISHING SIM · ARABIC-FIRSTCybersecurity Resilience Program
Resilience built to withstand what's next.
BCP · DR · IR PLAYBOOKSOT/ICS Security
Securing the industrial systems that can't go down.
IEC 62443 · PURDUE MODELOne-Stop-Shop for SMBs
Every security need, one partner, one roof.
MANAGED · FIXED-FEEMicro SaaS
Your path to cybersecurity entrepreneurship.
MENTORSHIP · MICROSAASSecurity, as a service.
Point-in-time engagements leave gaps between them. CyberCitadel is Joushen's productised platform. Continuous, subscription-based, and always on.
Penetration Testing as a Service
- Continuous testing across web, mobile, API, cloud and internal networks
- Findings delivered as they're discovered, not in a PDF three weeks later
- Free retests. We verify your fix and close the finding
- A live portal your engineers and your auditors can both use
Governance, Risk & Compliance as a Service
- Continuous control monitoring against NCA, SAMA, PDPL, ISO 27001
- Evidence gathered and kept audit-ready as you go
- Risk register maintained, not resurrected the month before an audit
- Board-ready reporting on demand
Know exactly where you stand.
Four frameworks govern cybersecurity in the Kingdom. Most organisations are subject to at least two.
The National Cybersecurity Authority's baseline controls, spanning governance, defence, resilience, third-party risk and industrial systems, with evidence of implementation, not intent.
Government entities, critical national infrastructure, and their service providers.
Gap assessment against every control, a prioritised remediation roadmap, hands-on implementation, and the evidence pack your assessor will actually ask for.
Maturity across four domains. Leadership and governance, risk management and compliance, operations and technology, third-party and cloud. Measured on a scale, not a checkbox.
Banks, insurers, finance companies, payment providers and fintechs regulated by SAMA.
Maturity assessment, board-level reporting, control uplift, and readiness for SAMA's review cycle.
Lawful basis for processing, data subject rights, breach notification, cross-border transfer controls, and a named accountable owner.
Every organisation processing the personal data of individuals in Saudi Arabia.
Data discovery and mapping, gap assessment, policy and notice drafting, breach response readiness, and privacy controls that hold up in practice.
Governed, classified, quality-controlled data with clear ownership across its lifecycle.
Government entities and their data.
Data governance operating model, classification scheme, and alignment of your controls to the national standards.
Assess. Harden. Prove. Repeat.
The same four steps, whether we're securing a bank or a substation.
Assess
We establish where you actually stand: your assets, your exposure, your regulatory obligations, and the gap between them. No assumptions, no reused templates.
Harden
We close the gaps in priority order, weighted by real risk to your business rather than by severity score alone. We implement, not just recommend.
Prove
We test the defences we built. If they don't hold, we say so. The output is evidence: for your board, your regulator, and yourself.
Repeat
Your attack surface changes weekly. So does the threat. Security posture is a rate, not a state. We keep it moving in the right direction.
Where the stakes are highest.
Government
National entities under NCA mandate, where a breach is a matter of public trust.
Financial services
Banks, insurers and fintechs under SAMA supervision, where downtime is measured in riyals per second.
Energy & industrial
Operators whose control systems predate the internet and can't simply be patched on a Tuesday.
Vision 2030 giga-projects
Greenfield environments where security can still be designed in rather than bolted on.
SMBs
Growing companies that need real security without building a security department.
Field notes from the front line.
Analysis on Saudi regulation, emerging threats, and what we're seeing in the field.
Let's find out what your attack surface really looks like.
Thirty minutes with a senior consultant. No pitch, no obligation, just a straight answer on where you stand.
NO SALES CALL · A PRACTITIONER, NOT A REP