When a Ramadan Deadline Became a 6TB Leak
In February 2025, the ransomware group DragonForce broke into a prominent Riyadh real estate and construction firm, exfiltrated more than 6TB of internal and client data, and set an extortion deadline for the day before Ramadan began. When it passed unpaid, the group published the full data set. It was the first time DragonForce had hit a large Saudi enterprise, and the timing wasn’t incidental ,construction is one of the Kingdom’s biggest non-oil growth sectors under Vision 2030, and its firms typically run sprawling, interconnected IT environments with dozens of third-party vendors, which makes for a wide attack surface sitting behind a lot of sensitive client and financial data.
That single incident sits inside a much larger pattern. Cyble’s Threat Landscape Report for Saudi Arabia recorded 54 data breach and leak incidents in 2025, .27 initial-access-for-sale listings, and 13 publicly disclosed ransomware attacks, a fragmented but persistent threat environment with no single dominant actor. IT & ITES was the most frequently targeted sector for access sales (26% of listings), often as a stepping stone into client networks; Government & Law Enforcement absorbed the largest share of data breaches (17%); and Construction and general “Organisation” entities tied for the most ransomware hits, each claimed by groups like RALord and Everest.
The Compliance Backdrop That Shapes Every WAF Decision
Saudi Arabia’s digital economy has expanded rapidly under Vision 2030, and much of that growth sits in sectors that carry serious regulatory weight: banking, government digital services, healthcare, and energy. Choosing a WAF here isn’t a purely technical decision it runs through a stack of overlapping national frameworks:
NCA Essential Cybersecurity Controls (ECC-2:2024)
The National Cybersecurity Authority’s 114-control baseline, mandatory for government entities, critical infrastructure operators, and essential service providers, covering application-layer protection, logging, and monitoring. If penalized under this rule the fines are up to SAR 25M and operational suspension .
NCA Cloud Cybersecurity Controls (CCC-2:2024)
An ECC extension specifically for cloud service providers and tenants, updated in 2024 with stricter data-localization requirements.
NCA Data Cybersecurity Controls (DCC-1:2022)
Governs encryption, access control, and secure handling of data across its full lifecycle.
SAMA Cyber Security Framework
Layered on top of ECC for banks and financial institutions, with its own incident-response timelines and data-handling expectations.
Saudi PDPL (Personal Data Protection Law)
Enforced by SDAIA, governing how personal data is collected, processed, and, in many cases, kept in-Kingdom.
A meaningful share of regulated entities particularly in banking and government need contractual and technical assurance that traffic inspection and log storage happen inside Saudi Arabia, not routed through international data centers as a matter of convenience. Under NCA ECC Control 4-2, cloud service agreements must include audit rights, and residency increasingly has to be technically enforced rather than just promised in a contract. That alone rules out providers running a global-only cloud model with no in-country option.
Distributed Denial-of-Service Is Not a Side Issue
It’s tempting to treat DDoS as background noise next to ransomware and data theft, but NETSCOUT’s DDoS Threat Intelligence Report for July–December 2025 shows Saudi Arabia absorbed 333,345 DDoS attacks in the period, averaging 14.89 minutes per attack, with a single incident using as many as 24 distinct attack vectors at once. TCP ACK floods, TCP SYN/ACK amplification, and DNS amplification were the three most common vectors by volume.
Telecom carriers took the brunt of it, wired telecom alone absorbed over 216,000 attacks but natural gas distribution, hit far less often, saw each attack run for an average of 168 minutes, more than ten times the country-wide average. Volume tells you who’s being probed constantly; duration tells you where an attacker actually tried to cause damage.
What to Look For
- Continuously reveals new APIs and shadow endpoints from live traffic, not periodic manual audits.
- Maps its logging and access controls directly to ECC, CCC, and SAMA requirements.
- Enforces data residency technically, not just contractually.
- Treats Layer 7 DDoS as core, not an add-on module.
- Distinguishes human-mimicking bot traffic from real users, given how often credential stuffing shows up regionally.
- Offers Arabic-language, in-region incident response.
Top 5 WAF Solutions for Saudi Arabia (2026)
1. Prophaze
An AI powered WAF that learns application behaviour and discovers unknown APIs at runtime instead of relying on static rule tuning, with API security, bot management, Layer 7 DDoS, and CDN built into the same platform.
What sets it apart for this market is deployment choice: Prophaze ships as a Cloud WAF, a fully On-Premises WAF for customers who need traffic inspection and logs to stay physically inside the Kingdom, a Hybrid WAF that keeps local enforcement while still pulling cloud-assisted threat intelligence, and a Kubernetes-native WAF for containerized environments all compatible with AWS, Azure, GCP, or private-cloud infrastructure, so a bank or government agency isn’t forced to choose one cloud to get compliant coverage.
Global Analyst Recognition track record includes KuppingerCole’s 2022 Leadership Compass debut, three consecutive years on Gartner’s Market Guide Once for API (2024) and then for Cloud WAAP (2025-2026), and a Leader-tier placement in SecureIQLab’s 2026 Cloud WAAP report.
2. Cloudflare
Cloudflare’s WAF protects web applications from common application-layer threats using managed rules, custom rules, and continuously updated threat intelligence. It runs across Cloudflare’s global network and supports controls for organisations that need to manage traffic and security policies at the edge. Cloudflare also operates a data centre in Riyadh.
Consideration: confirm the specific WAF services, data-processing controls, and deployment requirements that apply to your countries environment.
3. Akamai
App & API Protector provides cloud-based WAF protection for websites and applications, inspecting HTTP and HTTPS traffic at the edge and applying adaptive security controls against application threats. Its WAF uses automated updates and machine-learning-based self-tuning to reduce the need for manual policy maintenance.
Consideration: evaluate how much control your security team needs over WAF policies, rules, and tuning, particularly across larger or more distributed application environments.
4. Imperva
Cloud WAF protects web applications against common application-layer attacks, including SQL injection, cross-site scripting, and other OWASP Top 10 threats. It supports automated policy creation, managed security rules, machine-learning-based traffic analysis, and deployment across cloud, hybrid, and on-premises environments.
Consideration: compare its deployment options, policy management, and operational model against your application architecture and security team’s requirements.
5. F5
Distributed Cloud WAF provides layered protection against web application attacks, including injection, cross-site scripting, software vulnerabilities, and other common threats. It combines F5’s WAF engine with signature-based detection, behavioural analysis, threat intelligence, and custom security rules, with centrally managed policies and observability.
Consideration: assess whether its policy controls, deployment model, and integration with your existing F5 environment fit your operational requirements.
Why Prophaze AI Driven WAF Matters for Saudi Enterprises
Most WAF platforms filter traffic. Prophaze is built to understand behaviour and respond before impact occurs. Incoming web, API, and bot traffic is parsed for structure and payload without static signatures, profiled against a continuously updated behavioural baseline, then allowed or blocked automatically including zero-days and business-logic abuse no rule yet exists for.
With Prophaze, Saudi organisations can:
- Detect and block sophisticated threats in real time using AI-powered behavioural analysis, not static rules.
- Choose the WAF deployment that fits the workload - Cloud WAF, On-Premises WAF, Hybrid WAF, or Kubernetes WAF, without switching platforms or vendors as infrastructure changes.
- Run across AWS, Azure, GCP, or private data centers without vendor lock-in, keeping traffic logs and security policies inside the Kingdom where ECC, CCC, and SAMA require it.
- Continuously discover shadow, zombie, and orphaned APIs as e-government and open banking services multiply, with full lifecycle visibility instead of periodic manual audits.
- Absorb Layer 7 DDoS as a built-in capability rather than a bolted-on module, relevant given the volume and duration NETSCOUT recorded across Saudi telecom, energy, and hosting targets.
- Choose self-serve control or hand oversight to Prophaze's team for fully managed protection with in-region support.
What actually matters here is that we don’t make you choose between strong security and staying compliant. Whether it’s running on-premises for a bank bound by SAMA or in the cloud for a ministry working through ECC, the same detection engine is doing the work underneath ,so the deployment model stops being something the security team has to work around, and starts being just a choice your team gets to make.
- Don't Wait for Your Own Countdown
DragonForce gave its Riyadh victim a deadline. Most attackers do. Between a 6TB ransomware leak, over 300,000 DDoS attacks in six months, and a regulatory stack that keeps adding layers, Saudi Arabia’s threat environment has moved past “patch the website” and legacy WAFs were never built to guard what’s actually at risk. Prophaze is AI-native, cloud-native WAF solution designed to protect before that countdown ever starts.
Frequently Asked Questions (FAQ)
1. What does the NCA's ECC framework require for web application security?
ECC-2:2024 requires organizations to protect web applications and APIs against common attack vectors and maintain logging and monitoring capable of supporting incident investigation and regulatory audit, across 114 controls spanning people, process, technology, and strategy.
2. How is data residency actually enforced, versus just promised?
NCA ECC Control 4-2 requires cloud service agreements to include audit rights, and Saudi guidance increasingly expects residency to be technically enforced not simply a contractual promise from a hyperscaler whose support and telemetry may still route outside the Kingdom.
3. How significant is DDoS risk compared to ransomware and data breaches?
Substantial. NETSCOUT recorded over 333,000 DDoS attacks against Saudi targets in the second half of 2025 alone, with telecom carriers absorbing the highest volume and sectors like natural gas distribution facing much longer average attack durations.
4. Which sectors face the most sustained targeting in Saudi Arabia?
IT & ITES leads initial-access sales, Government & Law Enforcement leads data breach volume, and Construction and general enterprise entities lead ransomware claims, per Cyble’s 2025 regional data.
5. Do I need a Saudi-specific vendor, or can a global WAF provider work?
Global providers can work if they offer verifiable in-Kingdom or sovereign deployment options and can map their controls to ECC and SAMA directly,the deciding factor is technical enforcement of residency, not brand size.