PATTERN 01الأمن السيبرانيCybersecurity

أمن يُبنى، لا يُشترى. Security is built, not bought.

نساعد الجهات على فهم وضعها الأمني الحقيقي، وبناء منظومة مترابطة من الحوكمة والضوابط والمراقبة — تتناسب مع حجم الجهة وطبيعة عملها، لا مع قائمة أدوات جاهزة. We help organisations understand where they genuinely stand, then build a connected system of governance, controls and monitoring — sized to the organisation and how it actually works, not to a vendor's product list.

المجالDiscipline
النمط 01 من ستة تخصصات داخل الأنماط الذكيةPattern 01 of six disciplines inside Smart Patterns
نموذج العملEngagement
استشارة، أو مشروع محدد النطاق، أو دعم مستمرAdvisory, a defined-scope project, or ongoing support
يتكامل معWorks with
التحول الرقمي · الذكاء الاصطناعيDigital Transformation · Artificial Intelligence

كثير من الجهات تمتلك أدوات أمنية جيدة، لكنها تعمل منفصلة: صلاحيات غير مراجَعة، وسجلات لا يقرؤها أحد، وإجراء استجابة موجود على الورق فقط. النتيجة أن الحماية تبدو موجودة بينما الفجوة الحقيقية في الترتيب والتشغيل. Many organisations already own capable security tools — but they run in isolation: access rights that are never reviewed, logs nobody reads, and a response procedure that exists only on paper. Protection looks present, while the real gap sits in arrangement and operation.

نبدأ من صورة واضحة للوضع الحالي: ما الأصول المهمة فعلًا، وأين تمر البيانات، ومن يملك الصلاحية، وما الذي يحدث إذا تعطّل نظام أساسي اليوم. من هذه الصورة نبني خطة مرتبة حسب الأولوية والمخاطر، لا حسب أحدث ما في السوق. We start from a clear picture of the current state: which assets genuinely matter, where data travels, who holds which privileges, and what happens if a core system fails today. From that picture we build a plan ordered by priority and risk — not by whatever is newest on the market.

ما الذي نقدمه عمليًاWhat that means in practice

نعمل مع فريق الجهة لا بدلًا عنه: نوثّق، وندرّب، ونسلّم إجراءات قابلة للتشغيل بعد انتهاء المشروع. الهدف أن تبقى المنظومة قائمة وواضحة حتى بعد خروجنا منها. We work alongside the client's team rather than around it: documenting, training and handing over procedures the organisation can actually run. The aim is a system that stays clear and operable long after we step out of it.

القدراتCapabilities

ست قدرات تعمل كطبقات متتابعة، لا كخدمات منفصلة. Six capabilities working as successive layers — not as separate services.

01

تقييم الوضع الأمنيSecurity assessment

مراجعة منظمة للأصول والأنظمة والصلاحيات والإجراءات، تنتهي بتقرير يوضح الفجوات ويرتّبها حسب الأثر والاحتمالية.A structured review of assets, systems, privileges and procedures, ending in a report that states the gaps and orders them by impact and likelihood.

جرد الأصولAsset inventory تحليل الفجواتGap analysis خارطة أولوياتPrioritised roadmap
02

الحوكمة والالتزامGovernance & compliance

بناء السياسات والأدوار والمسؤوليات ودورات المراجعة، بما يتوافق مع المتطلبات التنظيمية المعمول بها لدى الجهة.Building the policies, roles, responsibilities and review cycles that align with the regulatory requirements applicable to the organisation.

السياسات والإجراءاتPolicies & procedures مصفوفة الأدوارRoles matrix دورات المراجعةReview cycles
03

إدارة المخاطرRisk management

تعريف المخاطر وتقديرها ومتابعتها في سجل حيّ، مع خطط معالجة واضحة ومالك مسؤول لكل خطر.Identifying, rating and tracking risks in a living register, each with a clear treatment plan and a named owner.

سجل المخاطرRisk register خطط المعالجةTreatment plans
04

حماية البنية التحتية والسحابةInfrastructure & cloud protection

تقسيم الشبكة، وضبط الصلاحيات، وتأمين نقاط النهاية والبيئات السحابية، وتوحيد إعدادات الحماية عبر الأنظمة.Network segmentation, privilege control, endpoint and cloud environment hardening, and consistent protection settings across systems.

تقسيم الشبكةSegmentation إدارة الهوية والصلاحياتIdentity & access أمن السحابةCloud security
05

المراقبة والاستجابةMonitoring & response

تفعيل مراقبة تعطي إشارات مفيدة بدل ضجيج التنبيهات، مع إجراء استجابة مكتوب ومجرَّب قبل وقوع الحادث.Monitoring that produces useful signals instead of alert noise, with a response procedure written and rehearsed before an incident occurs.

مراقبة الأحداثEvent monitoring جاهزية الاستجابةResponse readiness استمرارية الأعمالBusiness continuity
06

التوعية وبناء القدراتAwareness & capability building

برامج توعية عملية موجهة للموظفين حسب أدوارهم، لأن أغلب المحاولات الناجحة تبدأ من سلوك بشري لا من ثغرة تقنية.Practical, role-based awareness programmes for staff — because most successful attempts begin with human behaviour rather than a technical flaw.

توعية الموظفينStaff awareness تدريب الفرق التقنيةTechnical team training

تُحدَّد القدرات المطبقة في كل مشروع حسب نطاق العمل المتفق عليه مع الجهة. The capabilities applied in any engagement are defined by the scope agreed with the client.

الحلولSolutions

حلول محددة النطاق، يمكن البدء بواحد منها. Defined pieces of work — you can start with just one.

مراجعة أمنية شاملةFull security review

صورة واضحة عن الوضع الحالي وتقرير بالفجوات وخطة أولويات لأول اثني عشر شهرًا.A clear read on the current state, a gap report and a prioritised plan for the first twelve months.

إطار حوكمة أمن المعلوماتInformation security governance

سياسات وأدوار ودورات مراجعة قابلة للتطبيق داخل الجهة وليست مجرد وثائق.Policies, roles and review cycles the organisation can actually operate — not just documents.

تحصين البنية التحتيةInfrastructure hardening

مراجعة الإعدادات والصلاحيات وتقسيم الشبكة وإغلاق المسارات غير الضرورية.Reviewing configurations and privileges, segmenting the network and closing unnecessary paths.

تفعيل المراقبةMonitoring enablement

ضبط ما يُراقَب وما يُتجاهَل، وتحديد التنبيهات ذات القيمة ومسار التعامل معها.Deciding what gets watched and what gets ignored, which alerts matter and how each is handled.

جاهزية الاستجابة للحوادثIncident response readiness

إجراء مكتوب، وأدوار محددة، وتمرين عملي يختبر الاستجابة قبل الحاجة إليها.A written procedure, assigned roles and a practical exercise that tests the response before it is needed.

برنامج توعية أمنيةSecurity awareness programme

محتوى عربي عملي مبني على سيناريوهات واقعية تخص طبيعة عمل الجهة.Practical Arabic content built on realistic scenarios drawn from how the organisation works.

كيف نعملHow we work

أربع مراحل، ولا مرحلة تبدأ قبل أن تُغلق التي قبلها. Four stages — and none begins before the one before it closes.

01 التقييمAssess

أين نقف اليومWhere we stand today

جمع المعلومات عن الأنظمة والصلاحيات والإجراءات، ومقابلات مع الفرق المعنية، وصولًا إلى صورة واقعية موثّقة.Gathering information on systems, privileges and procedures, with interviews across the relevant teams, until we have a documented and realistic picture.

02 التصميمDesign

ما الذي نريد الوصول إليهWhat we are aiming for

تحديد الوضع المستهدف والضوابط المطلوبة وترتيب التنفيذ حسب الأثر، مع معايير قبول واضحة لكل بند.Defining the target state, the controls required and the order of execution by impact — with clear acceptance criteria for each item.

03 التنفيذImplement

تطبيق مرحلي قابل للمراجعةStaged, reviewable delivery

تنفيذ الضوابط على مراحل، مع توثيق كل تغيير ومراجعته مع فريق الجهة قبل الانتقال للمرحلة التالية.Controls are implemented in stages, with every change documented and reviewed with the client's team before moving on.

04 التشغيلOperate

تسليم قابل للاستمرارA handover that lasts

تدريب الفريق، وتسليم الإجراءات والوثائق، والاتفاق على دورة مراجعة دورية تحافظ على المستوى بعد انتهاء المشروع.Training the team, handing over procedures and documentation, and agreeing a review cycle that keeps the level after the project ends.

لماذا الأنماط الذكيةWhy Smart Patterns

الأمن عندنا جزء من منظومة تنفيذ، لا خدمة معزولة. For us security is part of a delivery system — not an isolated service.

01

مرتبط بالتحول الرقميConnected to transformation

لأننا ننفّذ مشاريع رقمية أيضًا، نفهم أثر كل ضابط أمني على سير العمل قبل فرضه.Because we also deliver digital projects, we understand what each control does to a workflow before imposing it.

02

قابل للتشغيلOperable

لا نسلّم وثائق لا يستطيع أحد تطبيقها؛ نسلّم إجراءات مكتوبة بلغة الفريق الذي سيشغّلها.We don't hand over documents nobody can apply — we hand over procedures written for the team that will run them.

03

محايد تجاه الأدواتTool-neutral

نبدأ من احتياج الجهة، ثم نختار ما يناسبها من أدوات، لا العكس.We start from the organisation's requirement and choose tools to fit it — never the other way round.

القطاعات وحالات الاستخدامSectors & use cases

أينما وُجدت بيانات وأنظمة تشغيل، توجد حاجة لترتيب أمني. Wherever there is data and an operating system behind it, there is a need for security order.

الجهات الحكوميةGovernment entities الشركات الكبرىLarge enterprises المنشآت الصحيةHealthcare التعليمEducation التجزئة والتجارة الإلكترونيةRetail & e-commerce الخدمات اللوجستيةLogistics المقاولات والعقارContracting & real estate
Use case 01

جهة تبدأ برنامجًا أمنيًا من الصفرAn organisation starting a security programme from zero

تحتاج أولًا معرفة ما لديها وما ينقصها، ثم خطة واقعية مرتبة حسب الأولوية بدل شراء أدوات متفرقة.It first needs to know what it has and what is missing — then a realistic, prioritised plan instead of scattered tool purchases.

Use case 02

جهة تستعد لمراجعة تنظيميةAn organisation preparing for a regulatory review

تحتاج توثيقًا مرتبًا وسياسات مطبقة فعلًا وأدلة على التشغيل، لا ملفات معدّة قبل الموعد بأيام.It needs ordered documentation, policies genuinely in force and evidence of operation — not files assembled days before the date.

Use case 03

جهة انتقلت حديثًا إلى السحابةAn organisation recently moved to the cloud

تحتاج مراجعة الإعدادات والصلاحيات، لأن الإعداد الافتراضي غالبًا لا يناسب البيانات الحساسة.It needs its configurations and privileges reviewed, because default settings rarely suit sensitive data.

Use case 04

جهة تريد رفع وعي موظفيهاAn organisation raising staff awareness

تحتاج محتوى عمليًا قصيرًا مرتبطًا بعمل الموظف اليومي، لا محاضرة نظرية سنوية.It needs short, practical content tied to the employee's daily work — not one theoretical session a year.

الخطوة التاليةNext step

لنبدأبصورة واضحةعن وضعك الأمني. Let's start witha clear pictureof where you stand.

تواصل معنا لترتيب جلسة أولية نفهم فيها طبيعة أنظمتك وأولوياتك، ونعود إليك بمقترح نطاق عمل واضح. Get in touch to arrange an initial session. We'll understand your systems and priorities, then come back with a clearly scoped proposal.

تخصصات أخرىOther disciplines

راسلنا على واتسابChat on WhatsApp