Press TechRound interviews Secure.com CEO on the future of AI security
Read

Quarterly SAMA Progress Reports Without The Fire Drill

Stop scrambling before every SAMA CSF reporting cycle. See how GRC AI Teammates turn quarterly evidence-chasing into a continuous, audit-ready process.

Key Takeaways

  • SAMA CSF spans 249 controls across four domains, which means quarterly reporting touches governance, risk, operations, and third party security all at once.
  • The recurring pain isn’t proving compliance, it’s the manual work of triage, evidence-chasing, report follow-through, and console-stitching that happens right before the deadline.
  • Continuous, governed evidence collection replaces the pre-deadline scramble with an always-current audit trail.
  • Attack evidence from real testing gives reporting teams proof that controls work, not just documentation that they exist.
  • Governed AI Teammates operate inside scope, permissions, and approvals your team sets, so authority never leaves human hands.

If you work security or GRC at a bank, insurance company, financing company, credit bureau, or financial market infrastructure provider in Saudi Arabia, you know the rhythm. Every quarter, the SAMA Cyber Security Framework (CSF) reporting cycle comes around, and every quarter it turns into the same scramble: pulling screenshots from five different consoles, chasing control owners for status updates, reconciling last quarter’s spreadsheet with this quarter’s reality, and hoping nothing changed in a system nobody remembered to check.

That scramble isn’t a compliance problem. It’s an operations problem. The controls exist. The evidence exists. It’s just scattered across tools, people, and time, and someone has to manually stitch it back together before the deadline.

SAMA CSF · Quarterly Reporting

What quarterly SAMA reporting actually demands

The Cyber Security Framework organizes its controls across four domains — and reporting against it is never a single-team exercise. It pulls in security operations, GRC, cloud, application security, and vendor management, all on the same cycle.

249controls in scope
4framework domains
Quarterlyreporting cadence
Domain 1

Leadership & Governance

Accountability, oversight, and policy ownership at the top of the organization.

Domain 2

Risk Management & Compliance

How risk is identified, tracked, and reconciled against regulatory obligations.

Domain 3

Operations & Technology

The day-to-day controls running across SOC, cloud, and application environments.

Domain 4

Third Party Cyber Security

Vendor access, due diligence, and ongoing oversight of external relationships.

Evidence for a single report lives across five places

SOC tools Cloud posture tools AppSec tools Spreadsheets & tickets GRC team records

What Quarterly SAMA Reporting Actually Demands

The SAMA Cyber Security Framework organizes its controls across four domains: Cyber Security Leadership and Governance, Cyber Security Risk Management and Compliance, Cyber Security Operations and Technology, and Third Party Cyber Security. Reporting against that framework isn’t a single-team exercise. It pulls in security operations, GRC, cloud and infrastructure, application security, and vendor management, all on the same cycle.

That breadth is exactly why quarterly reporting turns into a fire drill. Evidence for a single report lives in:

  • SOC tools tracking alert triage, investigation, and response
  • Cloud posture tools tracking misconfigurations, drift, and exposure
  • AppSec tools tracking code, dependency, and container findings
  • Spreadsheets and tickets tracking third party and vendor access reviews
  • Whatever the GRC team managed to collect since the last cycle

None of that is inherently hard to produce. It’s hard to produce on time, consistently, and in a form an auditor can trust, especially when it’s assembled under deadline pressure once every three months.

Why The Fire Drill Happens

Why the fire drill happens

None of this reflects an understaffed or under-skilled team — it reflects grunt work that most tools hand back to people instead of finishing.

1

Triage

Figuring out which findings from the quarter actually matter for this report.

2

Evidence-chasing

Emailing control owners, waiting on replies, re-requesting the same screenshots.

3

Report follow-through

Tracking whether flagged gaps actually got remediated before the report ships.

4

Console-stitching

Manually pulling data from disconnected tools into one coherent narrative.

The result: burnout concentrated into predictable, dreaded weeks every quarter — instead of a steady, sustainable cadence.

The operational enemy here has a name: grunt work. Specifically, it’s:

  • Triage – figuring out which findings from the quarter actually matter for this report
  • Evidence-chasing – emailing control owners, waiting on responses, re-requesting screenshots
  • Report follow-through – tracking whether flagged gaps actually got remediated before the report goes out
  • Console-stitching – manually pulling data from disconnected tools into one narrative

None of this reflects an understaffed or under-skilled team. It reflects the fact that security work is growing faster than teams can absorb it, and most tools hand triage, evidence, and follow-through back to people instead of finishing the job. The result is burnout concentrated into predictable, dreaded weeks every quarter, not a steady, sustainable cadence.

What Continuous Evidence Collection Looks Like

The fix isn’t a bigger team scrambling harder before each deadline. It’s shifting evidence collection from a quarterly event to a continuous, governed process, so the report is closer to a summary of what’s already true rather than a reconstruction project.

That’s the job of the GRC AI Teammate: it owns controls, compliance posture, evidence collection, audit readiness, and trust reporting on an ongoing basis. Instead of chasing evidence in the days before a SAMA deadline, the evidence, the audit trail, and the control status are already current when the reporting window opens.

From quarterly scramble to continuous evidence

The fix isn’t a bigger team scrambling harder before each deadline — it’s shifting evidence collection from a quarterly event to a continuous, governed process.

The quarterly scramble

  • Screenshots pulled from five different consoles
  • Chasing control owners for status updates
  • Reconciling last quarter’s spreadsheet with this quarter’s reality
  • Hoping nothing changed in a system nobody remembered to check

With the GRC AI Teammate

  • Controls, posture, and evidence collection run continuously
  • Audit trail is already current when the reporting window opens
  • The report becomes a summary, not a reconstruction project
  • Evidence from SOC, cloud, AppSec & GRC lines up into one narrative
Built on Security OS — the shared foundation providing context, orchestration, governed execution, audit trail, and a feedback loop across every AI Teammate.

Every AI Teammate, including the GRC AI Teammate, runs on Security OS, the shared foundation that provides context, orchestration, governed execution, audit trail, and a feedback loop across every teammate. That’s what allows evidence from SOC, cloud, AppSec, and GRC to line up into one coherent, defensible report instead of five disconnected exports.

How The Attack, Harden, Prove Loop Feeds Reporting

A control that exists on paper isn’t the same as a control that actually holds up against a real attempt to break it. That’s where offense-driven evidence changes what a quarterly report can say.

The loop works like this:

  1. Attack – the Red AI Teammate simulates real adversary behavior, only within approved scope
  2. Validate – confirms what’s actually exploitable, not just theoretically risky
  3. Harden – defensive teammates fix what was found: a config change, a control improvement, a detection rule
  4. Prove – retests, records the before and after, and keeps the approval trail as evidence
  5. Repeat – feeds the results back into what gets prioritized next quarter

As the loop puts it: the teammate that attacks teaches the teammate that defends. For SAMA reporting, that means the evidence behind a control isn’t just “this exists,” it’s “this was tested and it held,” with a recorded, approved trail to back it up.

Governed By Design

Authority stays in human hands

None of this works if it means handing an AI system the keys and hoping for the best. Here’s what keeps every AI Teammate accountable — and what it actually replaces.

How every AI Teammate is governed

  • Operates inside customer-defined scope and permissions
  • Follows the approvals and escalation paths your team sets
  • Leaves a full audit trail behind every action it takes
  • Your team sets the rules. AI Teammates do the work
  • Regulators see an approval trail — not a black box

What this replaces — and what it doesn’t

  • This is augmentation, not headcount replacement
  • A single AI Teammate is complete and valuable from day one
  • No need for the full roster of teammates to see value
  • Delivers continuous, audit-ready evidence for your SAMA cycle
What Secure.com does differently

Governed Defense, Powered by Offense

AI Teammates that attack to expose real gaps, harden defenses, and prove the outcome — inside the scope and approvals your team sets.

01

Copilots stop at advice — Secure.com attacks to expose real gaps

02

Point tools create another queue — Secure.com sits above the stack you already own

03

Autonomous systems obscure accountability — authority stays in human hands

04

Hardens defenses, proves the outcome, and hands your team back hundreds of hours every month

Ready to see it running against your own SAMA reporting cycle?

GRC AI Teammate

FAQs

What is the SAMA Cyber Security Framework (CSF)?
It’s the cybersecurity framework issued by the Saudi Arabian Monetary Authority to help regulated financial institutions identify and address cyber security risk, covering 249 controls across four domains: governance, risk and compliance, operations and technology, and third party security.
Who has to report against SAMA CSF?
Member organizations regulated by SAMA, including banks, insurance and reinsurance companies, financing companies, credit bureaus, and financial market infrastructure providers.
Which AI Teammate handles SAMA compliance reporting?
The GRC AI Teammate owns controls, compliance posture, evidence collection, audit readiness, and trust reporting. It works alongside the SOC, Cloud Security, AppSec, and Red AI Teammates, all running on Security OS, so evidence from across the environment stays current and consistent.
Does this mean the AI Teammate replaces our GRC team?
No. It’s augmentation, not replacement. Your team sets the scope, permissions, and approvals, and reviews and owns the final report. The AI Teammate removes the manual evidence-chasing and console-stitching in between.
Do we need every AI Teammate to see value for SAMA reporting?
No. Each AI Teammate, including the GRC AI Teammate, is designed to be complete and valuable on its own from day one. You don’t need the full roster to get continuous, audit-ready evidence.

Conclusion

Quarterly SAMA reporting doesn’t have to mean a predictable week of dread every three months. The controls, the domains, and the deadline aren’t going away, but the fire drill around them is optional. When evidence collection, audit readiness, and trust reporting run continuously instead of getting reconstructed under deadline pressure, the quarterly report becomes a summary of what your team already knows to be true, backed by a governed, approved trail your team controls from start to finish.