Saudi banks and financial companies now run on a wide network of outside partners. Cloud providers, payment processors, technology vendors, and outsourced service firms all play a part in daily operations. This reliance is growing fast: the Kingdom’s cybersecurity market itself is on track to grow from roughly USD 4.55 billion in 2025 to USD 4.98 billion in 2026, and a large share of that spend is going toward securing exactly these outside relationships. These partnerships help institutions move faster and serve customers better. But they also open the door to new cyber, operational, and regulatory risks, and the numbers show that risk is rising quickly. Globally, the share of data breaches that involve a third party has grown from 15% two years ago to 48% today, a 60% jump in the last year alone.
At a Glance
- Third-party assurance is now a required part of the 2026 SAMA CSF supervisory cycle, not an optional add-on.
- SAMA expects institutions to reach at least Maturity Level 3 (“Defined”) across all cybersecurity domains, including third-party governance.
- Banks must show independent evidence that critical vendors maintain proper cybersecurity controls; self-reported questionnaires cannot carry that burden alone.
- Board-level reporting on cyber risk, including third-party risk, is moving from an annual to a semi-annual cadence for Tier-1 institutions.
How Insights Helps Organizations
At Insights Financial & Management Consulting, we help institutions strengthen third-party governance through:
- Third-Party Risk Assessments
- Vendor Assurance Reviews
- Third-Party Risk Framework Design
- SAMA CSF Maturity Assessments
- Cybersecurity Governance Reviews
- Operational Resilience Assessments
- Enterprise Risk Management Integration
Our approach helps financial institutions build practical, risk-based assurance programs that align with SAMA’s evolving expectations while strengthening resilience across the vendor ecosystem.