SAK Technologies & Services Get your exposure reportFree report
Exposure management & continuous assurance

Know your exposure.
Prove your compliance.

SAK answers the only two questions that matter — what an attacker can reach from outside, and what you can evidence to a regulator. SAK Technologies builds the software that answers both. SAK Services does the work in between.

No agent to install · no access required · 6-page report in 5 business days

Your security posture, in one viewExample organisation · simulated data

Simulation with example data — not a customer's results.

50
frameworks mapped
3,595
obligations
6
exposure modules
0
agents to deploy

That is what turns a scan into compliance: an exposure we find is not just a ticket, it is evidence — mapped to the obligations that actually bind you, in whichever regime you answer to.

Mapped natively in GRCorbNCA ECCSAMA CSFPDPLISO 27001:2022PCI DSS v4.0.1GDPREssential EightSOCI Act 2018Privacy Act & NDBAPRA CPS 234APRA CPS 230ISM / IRAPSOC 2SMB1001:2026
One umbrella, two offerings

Everything under SAK works from the same picture of your organisation

Most firms resell someone else's tooling. SAK builds its own — and the consultants who deliver our services work from the same asset graph and evidence store the products fill, so nothing is discovered twice.

The products

SAK Technologies

Our product arm builds two platforms of our own. GRCorb scopes a framework, generates branded policy packs, quantifies risk with FAIR and collects control evidence automatically — and shows you how to build each control. Attack surface monitoring finds everything you expose to the internet and scores it against live threat intelligence.

2platforms we build
50frameworks mapped
0agents to deploy
The services

SAK Services

Every cyber security service we deliver, led by our vCISO engagement — with GRC advisory and certification readiness, VAPT and offensive security, AI governance, awareness training and managed attack surface monitoring alongside. Consultants who work from platform data, not a questionnaire.

Explore SAK Services
6engagements
8domains in scope
90day onboarding
The assurance loop

From static compliance to continuous assurance

A point-in-time audit tells you what was true on one Tuesday in March. This runs every day — and each step hands evidence to the next.

  1. 01

    Discover

    Every internet-facing asset, certificate, subdomain and exposed service — found, not declared.

    Attack surface monitoring
  2. 02

    Assess

    Exposures scored against live threat intelligence and what's actually being exploited.

    Attack surface monitoring
  3. 03

    Evidence

    Findings and configuration state collected as control evidence, mapped to obligations.

    SAK Technologies
  4. 04

    Remediate

    Owners, due dates and build instructions — how to fix the control, not just that it failed.

    SAK Technologies
  5. 05

    Assure

    Controls re-verified continuously. Drift raises an exception the day it happens.

    SAK Technologies
  6. 06

    Report

    Board packs and auditor workspaces generated from the same evidence, not rewritten.

    SAK Technologies
Regulatory coverage

Built for your regulator, not translated for it

Your obligations are mapped natively in GRCorb — NCA ECC, SAMA CSF and PDPL in the Gulf, Essential Eight, the ISM, SOCI and the Privacy Act in Australia, plus ISO 27001, SOC 2 and PCI DSS globally — with the evidence each assessor actually asks for.

Gulf

  • NCA ECC-2:2024All 200 controls & sub-controls
  • SAMA Cyber Security FrameworkAll 247 controls
  • PDPL16 controller obligations
  • Aramco CCC (SACS-002)Via services
  • NDMO data standardsVia services

Australia

  • Essential Eight (ML1–ML3)All 126 controls
  • ISM / IRAPAll 1,150 controls
  • SOCI Act 201814 obligations
  • Privacy Act 1988 & NDBAll 13 APPs + NDB
  • SMB1001:2026All 39 controls
  • APRA CPS 234 / CPS 23024 + 22 requirements

Global

  • ISO/IEC 27001:2022All 93 controls + clauses 4–10
  • SOC 2All 61 criteria
  • PCI DSS v4.0.1All 249 requirements
  • GDPR27 obligations
See what each framework asks for

Every figure is counted from GRCorb's own catalogue. “All” means every item of the published framework is in GRCorb. A plain number is the set of obligations organisations are assessed against, not every clause of the law or standard. Via services — delivered by SAK Services consultants; not yet a GRCorb framework.

Delivery network

Accredited delivery partners

We work with accredited specialist firms — ISO certification bodies, offensive security teams and training providers — who deliver alongside our platforms. That is how a product company ships enterprise engagements without pretending to be a body shop, and it means each engagement is staffed by the firm best suited to it, not the only one we have.

Certification

ISO & compliance audit

ISO 27001, 22301, 9001, 27017/27018, PCI DSS, SOC 1/2/3 and SAMA CSF certification and audit practice.

Feeds GRCorb audit workspace
Offensive

Red team & testing

Black, white and grey box penetration testing, malware analysis, compromise assessment, secure code review.

Feeds SAK Surface
Education

Accredited training

Internationally accredited IT security training and certification courses for client teams, run by partner training faculties.

Records filed as evidence
Start here

Get your free external exposure report

Give us a domain. SAK Surface maps every internet-facing asset, expiring certificate, exposed service and lookalike domain we can see from the outside. You get a six-page report in five business days. No agent, no access, no obligation.

Request the report

English & Arabic reporting · partner-delivered execution