Scale Risk
Sign inGet a demo
Scale Risk

AI-driven Enterprise Risk Management for cybersecurity teams. Built for the GCC, trusted globally.

© 2026 Scale Risk

Product

  • Platform overview
  • Framework library
  • How it works
  • Request a demo

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy
  • Terms
ZYSEC AI
All rights reserved.Privacy PolicyTerms of Service
Built for the GCC, trusted globally.
Enterprise GRC Platform · Built for the GCC

Security risk
conquered

Risk, compliance, incidents, and architecture — one platform. Native GCC depth. 12 role views. Zero configuration.

Request a DemoSign in
40+Frameworks
12Role Views
6GCC Countries
2,000+Controls
ISO 27001PCI DSSNIST CSF 2.0SOC 2DORANCA ECCCBUAE ISRSAMA CSFHIPAANIS2GDPRCIS v8PDPLQCERT NCFNCSI NCFCBB v3ISO 27001PCI DSSNIST CSF 2.0SOC 2DORANCA ECCCBUAE ISRSAMA CSFHIPAANIS2GDPRCIS v8PDPLQCERT NCFNCSI NCFCBB v3

Trusted by security teams across regulated industries

Financial Services
Banking & Insurance
Government & Defense
Healthcare
Energy & Utilities
Telecoms
The platform

One platform for every security domain

Risk, GRC, incidents, architecture, vendors, and evidence — one platform. Native Arabic support. Every role covered.

Native GCC Regulatory Coverage

Every major Gulf regulatory framework — CBUAE ISR, NCA ECC, SAMA CSF, ADGM FSRA, VARA CSF — built in and maintained. No manual mapping.

CBUAE ISRNCA ECCSAMA CSFADGM FSRAVARA CSF

AI-Assisted Compliance

AI Suggest surfaces control gaps, drafts policy text, triages incident severity, and recommends treatment plans — all in context.

Risk RegisterIncident TriagePolicy DraftVuln ScannerPlaybooks

12 Distinct Role Views

Each of the 14 security roles sees exactly what they need — no more, no less. CISO gets board-ready posture; analyst gets their queue.

CISOGRC ManagerSOC ManagerAnalyst+8 more
Built for the region

Native GRC for the GCC

CBUAE ISR 4-hour breach reporting, SAMA CSF, PDPL, QCB, NESA — pre-built frameworks with jurisdiction-aware incident workflows.

Regulatory frameworks covered

NCA ECCSaudi Arabia
SAMA CSFSaudi Arabia
CBUAE ISRUAE
NESA IASUAE
ADGM FSRAUAE
VARA CSF v2UAE
QCERT NCFQatar
CBB v3Bahrain
NCSI NCFOman
DHADubai
MOHAPUAE
SCAUAE
Security Domains

Six pillars zero silos

Every domain connects — risks link to incidents, incidents link to controls, controls map to frameworks, frameworks generate evidence.

Risk Management
GRC & Compliance
Incident Response
Security Architecture
Vendor Risk
Evidence Management
How it works

Live in days not months

No consultants. No 6-month implementation. Import your frameworks, map your team, and get signal from day one.

Adopt your frameworks

Select from 40+ pre-built templates — NCA ECC, ISO 27001, PCI DSS, SAMA CSF. Controls import instantly.

Map roles & risk appetite

Assign your 12 security roles. Set risk thresholds. Jurisdictions auto-populate regulatory deadlines.

Risk and evidence flow in

Log risks, declare incidents, upload evidence — all linked across frameworks. Every action audit-logged.

Board-ready reporting

CISO dashboard, executive reports, and compliance scorecards update in real time. No manual assembly.

Customer stories

Trusted by security leaders across the GCC

Security teams in banking, government, and critical infrastructure rely on Scale Risk as their single system of record.

Scale Risk replaced three separate tools we were using for GRC, incident tracking, and evidence management. The CBUAE ISR framework was ready out of the box — nothing else in the market comes close for GCC coverage.
K

Khalid Al-Mansouri

CISO · Regional Banking Group, UAE

The 12-role permission model is exactly what a large security team needs. Our SOC analysts see their queue, our CISO sees the board summary, our GRC team manages controls — all from one platform.
P

Priya Nair

GRC Manager · FinTech Enterprise, Riyadh

Implementation took two days, not six months. We imported ISO 27001 and NCA ECC, assigned roles, and had our first risk register within the week. AI Suggest for control gaps saved my team hours.
O

Omar Al-Rashid

Head of Cybersecurity · Government Authority, KSA

How We Compare

Built different

Most GRC tools retrofit compliance onto generic project management. Scale Risk was built from day one for security teams in regulated industries.

FeatureScale RiskVantaDrataOneTrustArcher
GCC Regulatory Coverage
Built-in Frameworks40+20+15+30+10+
Role-Based Dashboards12 roles3 roles3 roles5 roles4 roles
Incident Breach Workflow
Vendor Risk Management
Multi-Framework Mapping
Evidence Multi-Tagging
OT/ICS Security
RTL / Arabic Support
Compliance Library

40+ compliance frameworks at your fingertips

Every framework ships with pre-mapped controls. Import in one click, or build your own.

ISO 27001:2022Global

International standard for information security management systems (ISMS).

93 controlsv2022
COBIT 2019Global

ISACA COBIT 2019 framework for IT governance and management.

40 controlsv2019
PCI DSS 4.0US

Payment Card Industry Data Security Standard version 4.0.

36 controlsv4.0
DORAEU/UK

Digital Operational Resilience Act — ICT risk management for EU financial entities.

20 controlsv2025
BSI C5EU/UK

BSI Cloud Computing Compliance Criteria Catalogue — German cloud security.

17 controlsv2020
FCA PS21/3EU/UK

FCA Operational Resilience Policy Statement for UK regulated firms.

22 controlsv2022
SAMA CSFGCC

Saudi Arabian Monetary Authority Cybersecurity Framework.

28 controlsv2.0
UAE NESA IASGCC

UAE National Electronic Security Authority Information Assurance Standards.

18 controlsv2023
UAE SCA CybersecurityGCC

UAE Securities & Commodities Authority cybersecurity requirements.

22 controlsv2024
Qatar NIA FrameworkGCC

Qatar National Information Assurance Cybersecurity Framework.

35 controlsv2.0
CBB Vol. 2 InsuranceGCC

Central Bank of Bahrain insurance cybersecurity requirements.

26 controlsv2023
CBK Guidelines (Kenya)Africa

Central Bank of Kenya Cybersecurity Guidelines for financial institutions.

22 controlsv2023
RBI Payment Aggregator FrameworkIndia

RBI cybersecurity guidelines for Payment Aggregators and Gateways.

35 controlsv2023
DPDPA 2023India

India Digital Personal Data Protection Act 2023.

30 controlsv2023
APRA CPS 234APAC

Australian Prudential Regulation Authority Information Security standard.

32 controlsv2019
POPIA (South Africa)Africa

South Africa Protection of Personal Information Act.

30 controlsv2021
ADGM Data Protection Regulations 2021GCC

Abu Dhabi Global Market Data Protection Regulations 2021 for ADGM-registered entities.

22 controlsv2021
Oman PDPLGCC

Oman Personal Data Protection Law — fully effective February 2025. NCSI enforcement.

22 controlsv2022
Bank of Ghana Cybersecurity DirectiveAfrica

Bank of Ghana Cybersecurity Directive for BOG-supervised financial institutions.

24 controlsv2023
Jordan CBJ Cybersecurity InstructionsMENA

Central Bank of Jordan Cybersecurity Instructions for CBJ-licensed financial institutions.

24 controlsv2023
Morocco Bank Al-Maghrib CybersecurityMENA

Bank Al-Maghrib Circular 5/W/2021 on cybersecurity for Moroccan credit institutions.

22 controlsv2021
ISO 27001:2022Global

International standard for information security management systems (ISMS).

93 controlsv2022
COBIT 2019Global

ISACA COBIT 2019 framework for IT governance and management.

40 controlsv2019
PCI DSS 4.0US

Payment Card Industry Data Security Standard version 4.0.

36 controlsv4.0
DORAEU/UK

Digital Operational Resilience Act — ICT risk management for EU financial entities.

20 controlsv2025
BSI C5EU/UK

BSI Cloud Computing Compliance Criteria Catalogue — German cloud security.

17 controlsv2020
FCA PS21/3EU/UK

FCA Operational Resilience Policy Statement for UK regulated firms.

22 controlsv2022
SAMA CSFGCC

Saudi Arabian Monetary Authority Cybersecurity Framework.

28 controlsv2.0
UAE NESA IASGCC

UAE National Electronic Security Authority Information Assurance Standards.

18 controlsv2023
UAE SCA CybersecurityGCC

UAE Securities & Commodities Authority cybersecurity requirements.

22 controlsv2024
Qatar NIA FrameworkGCC

Qatar National Information Assurance Cybersecurity Framework.

35 controlsv2.0
CBB Vol. 2 InsuranceGCC

Central Bank of Bahrain insurance cybersecurity requirements.

26 controlsv2023
CBK Guidelines (Kenya)Africa

Central Bank of Kenya Cybersecurity Guidelines for financial institutions.

22 controlsv2023
RBI Payment Aggregator FrameworkIndia

RBI cybersecurity guidelines for Payment Aggregators and Gateways.

35 controlsv2023
DPDPA 2023India

India Digital Personal Data Protection Act 2023.

30 controlsv2023
APRA CPS 234APAC

Australian Prudential Regulation Authority Information Security standard.

32 controlsv2019
POPIA (South Africa)Africa

South Africa Protection of Personal Information Act.

30 controlsv2021
ADGM Data Protection Regulations 2021GCC

Abu Dhabi Global Market Data Protection Regulations 2021 for ADGM-registered entities.

22 controlsv2021
Oman PDPLGCC

Oman Personal Data Protection Law — fully effective February 2025. NCSI enforcement.

22 controlsv2022
Bank of Ghana Cybersecurity DirectiveAfrica

Bank of Ghana Cybersecurity Directive for BOG-supervised financial institutions.

24 controlsv2023
Jordan CBJ Cybersecurity InstructionsMENA

Central Bank of Jordan Cybersecurity Instructions for CBJ-licensed financial institutions.

24 controlsv2023
Morocco Bank Al-Maghrib CybersecurityMENA

Bank Al-Maghrib Circular 5/W/2021 on cybersecurity for Moroccan credit institutions.

22 controlsv2021
NIST CSF 2.0Global

NIST Cybersecurity Framework 2.0 — six functions: Govern, Identify, Protect, Detect, Respond, Recover.

20 controlsv2.0
IEC 62443Global

Industrial Automation and Control Systems cybersecurity standard for OT/ICS environments.

20 controlsv2024
SOC 2 Trust Services CriteriaUS

AICPA SOC 2 Trust Services Criteria for service organisations.

20 controlsv2017
GDPREU/UK

General Data Protection Regulation — EU data protection and privacy.

18 controlsv2018
BSI IT-GrundschutzEU/UK

BSI baseline protection methodology for comprehensive information security.

18 controlsv2023
NCA ECCGCC

Saudi National Cybersecurity Authority Essential Cybersecurity Controls.

22 controlsv2024
CBUAE Cyber Risk ManagementGCC

Central Bank of the UAE Cyber Risk Management Guidelines.

20 controlsv2023
VARA CSF v2.0GCC

Dubai Virtual Assets Regulatory Authority Cyber Security Framework.

32 controlsv2025
DHA CybersecurityGCC

Dubai Health Authority cybersecurity requirements for healthcare.

20 controlsv2024
QCERT NCFGCC

Qatar CERT National Cybersecurity Framework for critical infrastructure.

28 controlsv2023
NCSI NCF (Oman)GCC

Oman NCSI National Cybersecurity Framework for critical infrastructure.

25 controlsv2021
CBU Cybersecurity (Uzbekistan)APAC

Central Bank of Uzbekistan cybersecurity requirements for banks.

20 controlsv2022
IRDAI Cyber Security 2023India

IRDAI Information and Cyber Security Guidelines for Indian insurance entities.

40 controlsv2023
SEBI CSCRF 2023India

SEBI Cybersecurity and Cyber Resilience Framework for regulated entities.

30 controlsv2023
ASD Essential EightAPAC

Australian Signals Directorate Essential Eight Maturity Model.

40 controlsv2023
UAE Federal PDPLGCC

UAE Federal Decree-Law No. 45/2021 on Personal Data Protection. TDRA/UAEDAPT enforcement.

25 controlsv2021
EU AI ActEU/UK

EU Regulation 2024/1689 — comprehensive AI regulation with extraterritorial scope affecting EU persons.

35 controlsv2024
Kuwait PDPLGCC

Kuwait Personal Data Protection Law. CITRA enforcement. 72-hour breach notification.

22 controlsv2023
South Africa FSCA CybersecurityAfrica

FSCA Cybersecurity guidance for South African financial institutions. Complements POPIA.

22 controlsv2024
Egypt CBE Cybersecurity FrameworkMENA

Central Bank of Egypt Cybersecurity Framework for CBE-regulated financial institutions.

26 controlsv2023
NIST CSF 2.0Global

NIST Cybersecurity Framework 2.0 — six functions: Govern, Identify, Protect, Detect, Respond, Recover.

20 controlsv2.0
IEC 62443Global

Industrial Automation and Control Systems cybersecurity standard for OT/ICS environments.

20 controlsv2024
SOC 2 Trust Services CriteriaUS

AICPA SOC 2 Trust Services Criteria for service organisations.

20 controlsv2017
GDPREU/UK

General Data Protection Regulation — EU data protection and privacy.

18 controlsv2018
BSI IT-GrundschutzEU/UK

BSI baseline protection methodology for comprehensive information security.

18 controlsv2023
NCA ECCGCC

Saudi National Cybersecurity Authority Essential Cybersecurity Controls.

22 controlsv2024
CBUAE Cyber Risk ManagementGCC

Central Bank of the UAE Cyber Risk Management Guidelines.

20 controlsv2023
VARA CSF v2.0GCC

Dubai Virtual Assets Regulatory Authority Cyber Security Framework.

32 controlsv2025
DHA CybersecurityGCC

Dubai Health Authority cybersecurity requirements for healthcare.

20 controlsv2024
QCERT NCFGCC

Qatar CERT National Cybersecurity Framework for critical infrastructure.

28 controlsv2023
NCSI NCF (Oman)GCC

Oman NCSI National Cybersecurity Framework for critical infrastructure.

25 controlsv2021
CBU Cybersecurity (Uzbekistan)APAC

Central Bank of Uzbekistan cybersecurity requirements for banks.

20 controlsv2022
IRDAI Cyber Security 2023India

IRDAI Information and Cyber Security Guidelines for Indian insurance entities.

40 controlsv2023
SEBI CSCRF 2023India

SEBI Cybersecurity and Cyber Resilience Framework for regulated entities.

30 controlsv2023
ASD Essential EightAPAC

Australian Signals Directorate Essential Eight Maturity Model.

40 controlsv2023
UAE Federal PDPLGCC

UAE Federal Decree-Law No. 45/2021 on Personal Data Protection. TDRA/UAEDAPT enforcement.

25 controlsv2021
EU AI ActEU/UK

EU Regulation 2024/1689 — comprehensive AI regulation with extraterritorial scope affecting EU persons.

35 controlsv2024
Kuwait PDPLGCC

Kuwait Personal Data Protection Law. CITRA enforcement. 72-hour breach notification.

22 controlsv2023
South Africa FSCA CybersecurityAfrica

FSCA Cybersecurity guidance for South African financial institutions. Complements POPIA.

22 controlsv2024
Egypt CBE Cybersecurity FrameworkMENA

Central Bank of Egypt Cybersecurity Framework for CBE-regulated financial institutions.

26 controlsv2023
CIS Controls v8Global

Center for Internet Security Critical Security Controls version 8.

40 controlsv8.0
SWIFT CSP 2024Global

SWIFT Customer Security Programme mandatory and advisory controls.

43 controlsv2024
HIPAAUS

Health Insurance Portability and Accountability Act — PHI privacy and security.

20 controlsv2013
NIS2 DirectiveEU/UK

Network and Information Security Directive 2 — EU cybersecurity requirements.

20 controlsv2023
FCA SYSCEU/UK

FCA Senior Management Arrangements, Systems and Controls — UK FCA sourcebook.

36 controlsv2024
NCA CSCCGCC

Saudi NCA Critical Systems Cybersecurity Controls for OT systems.

20 controlsv2024
CBUAE ISR 2021GCC

Central Bank of the UAE Information Security Regulation — 14-domain framework.

60 controlsv2021
ADGM FSRA CRMFGCC

Abu Dhabi Global Market Cyber Risk Management Framework.

28 controlsv2023
MOHAP Health Data ProtectionGCC

UAE Ministry of Health cybersecurity and health data protection standards.

18 controlsv2024
CBB Cyber Risk Module v3GCC

Central Bank of Bahrain Cyber Risk Module for financial institutions.

30 controlsvv3
NCEMA Cybersecurity FrameworkGCC

UAE National Cybersecurity Authority CSF — mandated for UAE federal entities and critical infrastructure operators.

32 controlsv2024
RBI Cyber Security FrameworkIndia

Reserve Bank of India Cyber Security Framework for banks and NBFCs.

18 controlsv2023
CERT-In Directions 2022India

Indian CERT incident reporting and cybersecurity obligations.

25 controlsv2022
MAS TRM 2021APAC

Monetary Authority of Singapore Technology Risk Management Guidelines.

45 controlsv2021
PDPA (Singapore)APAC

Singapore Personal Data Protection Act for organisations.

28 controlsv2021
DIFC Regulation 10 (AI) + DPLGCC

DIFC Regulation 10 on AI — first binding AI regulation in MEASA. Combined with DIFC Data Protection Law.

28 controlsv2023
Qatar QCB AI GuidelineGCC

Qatar Central Bank AI Governance Guidelines — binding for Qatar financial sector. Rollout 2024–2027.

24 controlsv2024
Nigeria CBN Cybersecurity FrameworkAfrica

Central Bank of Nigeria Cybersecurity Framework — mandatory for CBN-regulated financial institutions.

28 controlsv2023
Pakistan SBP Cybersecurity FrameworkMENA

State Bank of Pakistan Cybersecurity Framework for SBP-regulated financial institutions.

26 controlsv2023
Turkey BDDK Cybersecurity RegulationMENA

Turkey BDDK Cybersecurity Regulation with KVKK overlap for Turkish financial institutions.

28 controlsv2023
CIS Controls v8Global

Center for Internet Security Critical Security Controls version 8.

40 controlsv8.0
SWIFT CSP 2024Global

SWIFT Customer Security Programme mandatory and advisory controls.

43 controlsv2024
HIPAAUS

Health Insurance Portability and Accountability Act — PHI privacy and security.

20 controlsv2013
NIS2 DirectiveEU/UK

Network and Information Security Directive 2 — EU cybersecurity requirements.

20 controlsv2023
FCA SYSCEU/UK

FCA Senior Management Arrangements, Systems and Controls — UK FCA sourcebook.

36 controlsv2024
NCA CSCCGCC

Saudi NCA Critical Systems Cybersecurity Controls for OT systems.

20 controlsv2024
CBUAE ISR 2021GCC

Central Bank of the UAE Information Security Regulation — 14-domain framework.

60 controlsv2021
ADGM FSRA CRMFGCC

Abu Dhabi Global Market Cyber Risk Management Framework.

28 controlsv2023
MOHAP Health Data ProtectionGCC

UAE Ministry of Health cybersecurity and health data protection standards.

18 controlsv2024
CBB Cyber Risk Module v3GCC

Central Bank of Bahrain Cyber Risk Module for financial institutions.

30 controlsvv3
NCEMA Cybersecurity FrameworkGCC

UAE National Cybersecurity Authority CSF — mandated for UAE federal entities and critical infrastructure operators.

32 controlsv2024
RBI Cyber Security FrameworkIndia

Reserve Bank of India Cyber Security Framework for banks and NBFCs.

18 controlsv2023
CERT-In Directions 2022India

Indian CERT incident reporting and cybersecurity obligations.

25 controlsv2022
MAS TRM 2021APAC

Monetary Authority of Singapore Technology Risk Management Guidelines.

45 controlsv2021
PDPA (Singapore)APAC

Singapore Personal Data Protection Act for organisations.

28 controlsv2021
DIFC Regulation 10 (AI) + DPLGCC

DIFC Regulation 10 on AI — first binding AI regulation in MEASA. Combined with DIFC Data Protection Law.

28 controlsv2023
Qatar QCB AI GuidelineGCC

Qatar Central Bank AI Governance Guidelines — binding for Qatar financial sector. Rollout 2024–2027.

24 controlsv2024
Nigeria CBN Cybersecurity FrameworkAfrica

Central Bank of Nigeria Cybersecurity Framework — mandatory for CBN-regulated financial institutions.

28 controlsv2023
Pakistan SBP Cybersecurity FrameworkMENA

State Bank of Pakistan Cybersecurity Framework for SBP-regulated financial institutions.

26 controlsv2023
Turkey BDDK Cybersecurity RegulationMENA

Turkey BDDK Cybersecurity Regulation with KVKK overlap for Turkish financial institutions.

28 controlsv2023
Designed for every person on the team

Every role gets its own view out of the box

Every role sees exactly the signal they need. No shared generic dashboards. Each view is purpose-built for its owner.

CISO
CISO

Board-ready posture, every morning

Board-ready posture, every morning

CBUAE ISR deadline countdown, risk score trend, open P1 incidents, and investment decision quadrant — one view, zero configuration. Designed for executive-level decisions, not data wrangling.

GRC Manager
GRC Manager

Framework gaps, deadlines, evidence

Framework gaps, deadlines, evidence

59 CBUAE ISR controls tracked. Cross-framework mappings pre-built. Self-assessment queue with AI Suggest. Evidence packages export-ready for external auditors.

Security Analyst
Security Analyst

Your queue, nothing else

Your queue, nothing else

Assigned vulnerabilities with CVSS scores and SLA countdowns. Incident tasks linked to playbook steps. High-signal view — no noise, no context switching.

SOC Manager
SOC Manager

Incidents end-to-end

Incidents end-to-end

P1 declaration triggers CBUAE 4-hour breach notification automatically. Playbook activation in 30 seconds. MTTD and MTTR tracked per incident.

Risk beyond spreadsheets

One platform for the entire security programme.

Request a DemoSign in