THE OMAN PICTURE
Our longest delivery record in any market, and the one where the regulatory picture moved fastest.
Oman has gone from a light regulatory footprint to a national cyber framework, an active central bank regime and a data protection law with executive regulations — inside four years. Organisations that built their control environment before that shift are the ones we are usually asked to help.
What is different here
- A compact market with real supervision. The Central Bank of Oman's expectations of licensed institutions are detailed and examined. The Financial Services Authority applies its own requirements to market and insurance participants.
- The PDPL is now operational, not theoretical. Royal Decree 6 of 2022 and its executive regulations created obligations — permits, consent handling, transfer conditions, breach notification — that many organisations documented but never operationalised.
- National coordination is active. Incident reporting obligations into the national CERT and sector directives from the Cyber Defence Centre are real reporting lines with real clocks.
- Energy and utilities carry an OT perimeter. Distributed physical estates, vendor remote access and IT-OT convergence make the risk picture different from a purely corporate one.
- Teams are small. A Omani security function is frequently three or four people carrying the same obligations as a team of thirty elsewhere. Automation and managed operation are not a luxury here; they are how the obligations get met at all.