Your technology partner across the Middle East
SupportCloud marketplace Our locations
TECHNOLOGY VENDOR · CYBERSECURITY

CyberArrow AI-powered GRC automation for regional and global compliance.

CyberArrow is a governance, risk and compliance (GRC) automation company headquartered in Dubai, with offices in Riyadh, London, Dublin, Madrid and San Jose. Co-founded by chief executive Amar Basic, it is known for putting compliance on autopilot: continuously monitoring controls, collecting audit evidence through more than 80 integrations and mapping more than 3,000 pre-built risks and mitigations across 100-plus frameworks, for customers that include IKEA, Emirates and Revolut.

Headquarters
Dubai, United Arab Emirates
Category
Cybersecurity
WHO THEY ARE

About CyberArrow.

CyberArrow is a governance, risk and compliance (GRC) automation company headquartered in Dubai, with offices in Riyadh, London, Dublin, Madrid and San Jose. Co-founded by chief executive Amar Basic, it is known for putting compliance on autopilot: continuously monitoring controls, collecting audit evidence through more than 80 integrations and mapping more than 3,000 pre-built risks and mitigations across 100-plus frameworks, for customers that include IKEA, Emirates and Revolut.

Its products, CyberArrow GRC, CyberArrow Awareness and CyberArrow Phishing, are built around the regulations that matter in the Gulf, including NCA ECC, NCA NCNICC-1:2025, SAMA CSF and the Saudi PDPL, alongside ISO 27001, ISO 42001, SOC 2, NIS2, DORA and NIST. Government entities, banks, healthcare providers and technology firms in Saudi Arabia and the wider Middle East use it to replace spreadsheets with a single, audit-ready system.

Industries served

  • Government
  • Banking and financial services
  • Healthcare
  • Technology and SaaS
  • Aviation and retail
LATEST SOLUTIONS

The portfolio, today.

01

CyberArrow GRC

Cloud GRC platform that automates control monitoring, evidence collection, policy management, risk registers and audit workflows across multiple frameworks simultaneously, with real-time dashboards for executives and regulators.

02

Regional Compliance Frameworks

Pre-mapped content for NCA ECC, NCA NCNICC-1:2025, SAMA CSF and the Saudi PDPL, so Gulf organisations can evidence compliance with local mandates alongside ISO 27001, SOC 2 and other global standards.

03

Risk Management and KPI Tracking

Enterprise and IT risk registers with automated assessments, treatment plans, cyber-security KPI monitoring and asset-inventory integrations that keep an organisation's risk posture current between formal audits.

04

AI Governance

Structured AI risk assessments, ISO/IEC 42001 and NIST AI RMF control sets and continuous monitoring that let organisations govern their own AI systems and document accountability for regulators.

05

CyberArrow Awareness and Phishing

Security awareness training with short, story-driven content and phishing simulation, connected to the GRC platform so training completion and human-risk metrics feed directly into compliance reporting.

AI FOCUS

Automating compliance work and governing enterprise AI

CyberArrow describes its platform as AI-powered GRC: algorithms automate risk assessments, map controls across frameworks and collect evidence through integrations, which the company says removes up to 90 percent of the manual work in compliance programmes. It is also an active voice on agentic GRC, in which AI agents continuously monitor controls and initiate governance actions within defined boundaries.

In 2026 the platform added ISO/IEC 42001 and NCA NCNICC-1:2025 support, an AI risk register and audit-trail history for controls, and in September 2026 CyberArrow partnered with KPMG to combine advisory services with its enterprise AI GRC platform. This gives Middle East organisations a practical route to operationalise AI governance across policies, risks, controls and evidence.

  • Automated evidence collection through more than 80 integrations
  • 3,000-plus pre-mapped risks and mitigations across 100-plus frameworks
  • ISO/IEC 42001 and NIST AI RMF control sets for AI governance
  • AI risk assessments and registers with continuous control monitoring
ALJAMMAZ AI LAYER

AI security

Where CyberArrow fits in the four-layer AI stack we bring to partners.

Explore the layer
WHAT'S NEW

Recent announcements.

  1. CyberArrow partners with KPMG on AI governance

    CyberArrow and KPMG combined advisory expertise with CyberArrow's enterprise AI GRC platform to help organisations operationalise AI governance through centralised policy management, AI risk registers, automated workflows, continuous compliance monitoring and audit readiness.

  2. ISO 42001 and NCA NCNICC-1:2025 added to CyberArrow GRC

    A platform update added ISO/IEC 42001 for AI management systems and Saudi Arabia's NCA NCNICC-1:2025 national cybersecurity controls, plus a History tab that gives a complete audit trail of control changes, evidence updates and approvals.

  3. CyberArrow charts its growth from Dubai to global markets

    In a company update published during GITEX Global 2025, CyberArrow described its expansion from Dubai to customers on multiple continents, with multi-framework automation across ISO, SOC, NIST and SOX for finance, government, healthcare and technology clients.

READY WHEN YOU ARE

Build with CyberArrow?

Speak with our team about availability, solution design and partner enablement.