Rules for Regulating Cybersecurity Violations and Investigations Thereof

Article 1: Definitions

  • The following words and phrases - wherever they appear in these rules - shall have the meanings set forth opposite each of them, unless the context requires otherwise:

    • Regulatory Enablers: Regulatory Enablers of the National Cybersecurity Authority, issued by Royal Decree No. (M/117) dated 21/6/1446 AH.
    • Rules: Rules for Regulating Cybersecurity Violations and Investigations.
    • Authority: National Cybersecurity Authority.
    • Council: Board of Directors of the Authority.
    • Governor: Governor of the Authority.
    • Violations: Violations stipulated in item (First) of the Regulatory Enablers.
    • Inspector: The person authorized to conduct inspections, record violations, and investigate them in accordance with paragraph (1) of item (Second) of the Regulatory Enablers.

Article 2: Scope

These rules apply to all persons - natural and legal - subject to the provisions of the regulatory instruments.

Article 3: Appointment of the Inspector

Inspectors shall be appointed by a decision of the Governor in accordance with paragraph (1) of item (Second) of the enabling provisions, and the Authority shall grant the inspector a document proving his official status to carry out the assigned duties.

Article 4: Inspector's Authorities

  • Inspectors - collectively or individually - shall undertake the tasks of monitoring and inspecting places and activities related to cybersecurity; to detect violations and investigate them, and they have the following powers in this regard:

    • 1- Entering places and accessing networks, information technology systems, operational technology systems, and their components including devices, equipment, and software, and reviewing the data and documents contained therein; including backups, other sites, inspecting, examining, and seizing them.
    • 2- Searching for and collecting necessary evidence and information related to the violation, examining any documents, data, information, or records, and taking copies thereof. They are authorized to notarize by any legal means the evidence or indications that come under their observation.
    • 3- Taking custody of any documents, records, information technology systems, operational technology systems, devices, equipment, software, data, or the like, which were used in the violation or are suspected to have been used during the commission of the violation, and seizing and documenting them in the inspection report.
    • 4- Taking any other measures that the inspector deems important within the limits of the powers granted to him by law.

Article 5: Responsibilities of the Inspector

  • The inspector, when performing the tasks assigned to him, shall do the following:

    • 1- Prove his official status, as referred to in Article (Three) of the rules.
    • 2- Comply with the provisions of the regulatory authorizations, these rules, and what is issued by the Authority in this regard.
    • 3- Maintain confidentiality while performing his duties, including the confidentiality of documents, information, data, evidence, written and oral statements, and others that he accesses by virtue of his work, and he is not permitted - even after the completion of his assignment - to disclose them to any other party except with the written approval of the Authority.
    • 4- Prepare an inspection report and document all procedures that took place during the inspection, according to the form determined by the Authority, and document cases of prevention or obstruction from performing his duties in the report.
    • 5- If the inspector suspects during the performance of his duties the occurrence of a crime related to cybersecurity, he must seize what is related to that and refer it to the Authority for submission to the concerned authorities.

Article 6: Procedures for Handling Urgent and Necessary Cases

  • If any of the violations are committed, the Authority, in urgent and necessary cases to maintain cybersecurity - by a decision issued by the Governor or his deputy - may suspend or stop the operation of any activities related to cybersecurity, networks, information technology systems, or operational technology systems, or their components including devices, equipment, and software, subject to the violation, in accordance with the procedures determined by the Authority.

Article 7: Investigation

  • In the event that the Authority deems it necessary to request a statement, conduct an investigation, or hear testimonies regarding any of the violations, as stipulated in paragraph (4) of item (Second) of the statutory powers; it shall undertake - by all means it deems appropriate - the following:

    • 1- Request written or oral statements from the relevant parties.
    • 2- Summon the person accused of the violation, or anyone related to the violation, for investigation.
    • 3- Prepare an investigation report on the violation, according to the form determined by the Authority, and the Authority may suffice with requesting written statements.
    • 4- Refer the matter to the prosecution department within the Authority; in case evidence or indications supporting the establishment of the violation are found.

Article 8: Obligations of the Relevant Parties

  • All persons - natural and legal - subject to the provisions of the regulatory enablers, and these rules shall comply with the following:

    • 1- Full cooperation with the Authority and its representatives, providing the necessary facilitation, enabling them to perform their duties, and not preventing or obstructing them - in any form whatsoever - from carrying out the tasks assigned to them pursuant to the regulatory enablers and these rules.
    • 2- Providing all required documents as well as information, data, records, and the like within the period and in the manner determined by the Authority. It is prohibited to refuse to provide them, manipulate, destroy, or alter them; in a way that affects the progress of inspection or investigation procedures.
    • 3- Commitment to signing the required minutes; in accordance with these rules.
    • 4- Maintaining the confidentiality of seizure, inspection, and investigation works, and it is prohibited to publish or circulate any information, data, or the like; related to the ongoing inspection and investigation procedures, or the resulting outcomes.
    • 5- Adhering to the deadlines set by the Authority; to perform any of the works stipulated in these rules.

Article 9: General Provisions

  • 1- Any procedure stipulated in these rules may be carried out using electronic and technical means.
  • 2- The Authority may seek assistance from whomever it deems appropriate - including relevant entities - in monitoring, inspection, and violation control.
  • 3- The Authority shall periodically review these rules and propose amendments.
  • 4- The Governor shall issue what is necessary to implement these rules.
  • 5- These rules shall be effective from the date of their publication on the Authority’s website, and all conflicting provisions are hereby repealed.