Gulf News

المملكة: 50 thousand riyals reward and 8 conditions for entitlement.. Approval of rules regulating reporting of cybersecurity violations – Urgent


Adopted National Cybersecurity Authority Rules for regulating reporting violations Cybersecurity, with the aim of enhancing compliance with regulations, encouraging reporting of violations, providing a regulatory framework that guarantees the protection of whistleblowers, and regulates the procedures for receiving and studying reports, and the mechanism for granting rewards, while imposing controls for dealing with malicious reports and maintaining the confidentiality of information.

Under the new rules, the authority receives reports through its website or any other means it determines, provided that they are submitted according to approved forms that include the information of the whistleblower, his identity number, and means of communication with him, in addition to the information of the whistleblower. – If available – an accurate description of the violation, its nature, location, and date of learning of it, attaching the relevant documents or evidence, and an expression of the informant’s desire to obtain the reward or not, along with any additional information that the Authority deems necessary.

The rules permitted receiving anonymous reports, but stipulated that the right of the person submitting them to obtain a financial reward would be forfeited, given that disclosing the identity of the informant is one of the conditions for benefiting from the prescribed incentives.

Careful procedures.

Careful procedures To examine reports

The rules obligate the Authority, upon receiving any report, to record it in a confidential register designated for this purpose, then study its content and verify the accuracy of the attached data, documents and evidence, with the possibility of communicating with the person reporting to request clarifications or additional documents when needed.

The Authority ensures that the violation has not been previously discovered by it, or previously reported by another person, before proceeding with the completion of the procedures for examining the report.

8 Conditions for Eligibility Reward

The rules set eight main conditions for entitlement to a financial reward, the most prominent of which is that the violation is proven definitively, whether by a judicial ruling or the end of the statutory appeal period, and that the report has an effective role in proving the violation.

They stipulate that the whistleblower must be a natural person, and not be an employee of the Authority or their relatives up to the fourth degree or work for the entities contracting with it in main or operational tasks, and that the violation must not have been previously reported or disbursed. A reward for it.

The conditions also included that the discovery of the violation should not result from the job duties of the whistleblower, that he should not disclose any information related to the report, and that the information should have been obtained by legitimate means without penetration or irregular entry into the systems, in addition to that the violation should be one of the violations that results in the imposition of a financial fine to be collected.

A specialized committee to determine entitlement

The rules stipulate the formation of a committee by decision of the Authority’s Governor, which includes three At least members of its employees are responsible for studying the reports referred to it, assessing the extent of whistleblowers’ entitlement to rewards, and determining their value in accordance with the approved controls.

The rules take into account that the members of the committee and its chairman must be experienced in regulatory, financial or accounting aspects, provided that the committee submits its recommendations to the governor for approval, with all its members obligated to maintain the confidentiality of the information and documents they see.

A reward not exceeding 50 thousand riyals

The authority set a ceiling. The financial reward is not more than 50 thousand Saudi riyals, or the equivalent of 1% of the value of the fine imposed, whichever is less.

She explained that the committee takes into account several criteria when determining the value of the reward, including the importance of the information contained in the report, its accuracy and completeness, the extent of its contribution to proving the violation, the seriousness of the violation, the difficulty of discovering it, and the extent of the damages that could have resulted if it had not been reported.

The criteria include the extent to which The availability of information to the public, and the extent of the whistleblower’s cooperation with the Authority when communicating with him, in addition to his role in encouraging other parties to cooperate if they are present.

Complete confidentiality for whistleblowers

The rules confirmed that all information and data submitted to the Authority are considered confidential information, with the Authority’s commitment to maintaining the confidentiality of reports and not disclosing any data related to them, especially the identity of the whistleblower, except within the limits permitted by the system.

The rules also granted the Authority the right not to disclose the procedures it has taken regarding reports or The findings it reached, in order to preserve the confidentiality of the investigations and the integrity of the procedures.

Procedures against malicious reports

On the other hand, the rules stressed that the authority has the right to take whatever legal measures it deems appropriate against anyone proven to have submitted a malicious report, including referring him to the competent authorities to take legal measures against him.

It authorized the implementation of all procedures stipulated in the rules using electronic and technical means, while the governor of the authority is responsible for issuing what is necessary for implementation. Its provisions.

The authority clarified that the implementation of these rules begins from the date of their publication on its website, with the cancellation of all provisions that conflict with them, in a way that strengthens the system for reporting cybersecurity violations, establishes the principles of transparency, and encourages responsible reporting, while providing regular protection for whistleblowers and ensuring the integrity of procedures.

Related Articles

Back to top button