The Security Baseline a Mid-Sized Omani Business Actually Needs

Eight controls, done properly, remove most of the risk that actually materialises at a mid-sized company. They are unglamorous, they are mostly configuration rather than purchase, and the reason they are not in place is almost never budget — it is that nobody owns them.
This article gives you the eight, in the order to do them, with what each one stops, roughly what it costs and roughly how long it takes. Then it covers the first hour of an incident, who to notify in Oman, and where that duty overlaps with data protection law.
First, an honest word about the threat picture
We looked for a current, citable figure for attacks on Omani businesses and did not publish one.
The numbers circulating for this region come overwhelmingly from vendors selling security products, they disagree with each other by orders of magnitude, and most are either undated or several years old. OCERT publishes advisories and awareness material rather than a public annual statistical report that can be cited with confidence. Repeating a vendor’s number here would make this article feel authoritative and would not make it true. If you need defensible figures for a board paper, ask OCERT directly rather than sourcing them from marketing material.
What can be said without a statistic is this: Omani law now treats a security incident as a reportable event with deadlines, in more than one instrument. The Personal Data Protection Law’s Executive Regulation gives you 72 hours. The cloud and data centre regulation gives your provider 72 hours to you. And in June 2026 the Cybercrime Law was replaced entirely. Regulators do not build notification machinery for a problem that is not happening.
The other thing that can be said plainly: the incidents that hit companies of this size are rarely sophisticated. They are a stolen password with no second factor, an unpatched system exposed to the internet, a backup nobody had tested, or an accounts payable clerk who received a convincing email about changed bank details. Each of those has a boring control that stops it.
The eight controls, in order
The order is deliberate. It is by how much risk each removes per unit of effort, not by how interesting it is.
1. Multi-factor authentication on email and remote access
Stops: the single most common route in — a working password, stolen or guessed, used from somewhere else. Email first, because email is where password resets for everything else arrive.
Costs: usually nothing beyond licences you already hold. Both major business email platforms include it.
Takes: a day to configure, two to three weeks of patient user support. Budget the support, not the configuration — this is where rollouts stall.
Do it properly: enforce it, do not offer it. An optional second factor protects the people who were never the risk.
2. Backups you have restored from
Stops: ransomware from being an existential event, and it is the only control on this list that also covers deleted files, failed hardware and a bad deployment.
Costs: storage, which is cheap, plus the time to test.
Takes: a day to set up, half a day per quarter to verify.
Do it properly: three points. At least one copy must be offline or immutable, because backups reachable with production credentials get encrypted along with production. You must have performed an actual restore — an untested backup is a belief, not a control. And you must know your restore time, because “we have backups” and “we can be trading again by Thursday” are different statements.
3. Patching, with an owner and a deadline
Stops: attacks against known vulnerabilities, which is most opportunistic attacks. Nobody needs to target you; automated scanning finds the exposure.
Costs: time, and occasionally a maintenance window.
Takes: a half-day to establish, then a recurring slot.
Do it properly: a named owner and a written deadline — for example, internet-facing systems patched within a defined number of days of a critical advisory, everything else on a monthly cycle. Without a name and a date this becomes “when we get to it”, which is never.
4. Remove standing administrative access
Stops: a single compromised account from becoming a company-wide compromise. It is the difference between an incident and a catastrophe.
Costs: nothing.
Takes: an afternoon to audit, longer to argue about.
Do it properly: separate administrative accounts from day-to-day accounts, and review who holds them quarterly. Most companies find at least one administrator who left, one shared account nobody will claim, and one supplier still holding access from a project that finished two years ago.
5. Endpoint protection with central visibility
Stops: commodity malware, and — more importantly — it tells you a machine is compromised while you can still do something about it.
Costs: a per-device subscription.
Takes: a few days to deploy across a small fleet.
Do it properly: the word that matters is visibility. Antivirus that reports only to the machine it is installed on is a control nobody is watching. Somebody must receive the alerts and be expected to act on them.
6. Email authentication and filtering
Stops: two different things. Filtering stops most malicious mail reaching your staff. SPF, DKIM and DMARC stop criminals sending mail that appears to come from your domain — which protects your customers and your reputation, not your inbox.
Costs: filtering is usually bundled; the DNS records are free.
Takes: a day, if whoever manages your DNS is reachable.
Do it properly: DMARC only helps once it is set to reject. Left in monitoring mode indefinitely — which is where most of them sit — it reports the abuse without preventing it.
7. Logging, retained long enough to be useful
Stops: nothing by itself. It determines whether you can answer the question that decides everything after an incident: what did they access, and when.
Costs: storage, plus attention when enabling it.
Takes: a day across your main systems.
Do it properly: enable audit logging on email, your core business systems and your infrastructure, and retain it long enough to investigate something you did not notice immediately. Without logs, a breach notification becomes a guess — and you have to make it inside 72 hours.
8. A joiner, mover and leaver process
Stops: the accumulation of access nobody has revoked. Departed staff, changed roles, finished contractors.
Costs: nothing but discipline.
Takes: an hour to write, permanently to maintain.
Do it properly: a written checklist, owned by whoever owns systems rather than by HR alone, covering every service — including the ones bought on a card by a department, which are always the ones missed.
The one that is not technical
Business email compromise — a convincing message asking for a payment or a change of bank details — bypasses every control above, because nothing is broken. Someone is simply persuaded.
The control is a rule, not a product: no change to payment details is ever actioned on the strength of an email. Verification happens on a known phone number, obtained from your own records rather than from the message. Write it down, tell the finance team it is a rule rather than a suggestion, and make it explicitly acceptable to be slow about it.
The first hour of an incident
Decide this now. Nobody makes good decisions at 2am with a ransom note on screen.
Do not turn the machine off. Isolate it from the network instead — unplug the cable, disable the wireless. Powering down destroys evidence in memory and can make recovery harder.
Write down the time and what you saw. A rough timeline started in the first hour is worth more than a reconstruction attempted a week later.
Assume the account is compromised, not just the device. Reset credentials and revoke active sessions for anyone involved, including tokens on mobile devices.
Tell one named person and let them coordinate. The most damaging first hour is one where five people take five uncoordinated actions and nobody records any of them.
Start the notification clock. If personal data may be involved, the 72 hours began when you became aware, not when you finish investigating. Somebody senior needs to know this in hour one.
Preserve, then remediate. Snapshot before you rebuild if you can. Companies routinely destroy the only evidence of what happened while trying to get back to work — an understandable instinct with an expensive result.
Have the phone numbers written down somewhere that does not require the network to read: your IT provider, your hosting provider, your legal adviser, and the person authorised to make decisions.
Who to notify in Oman
Three separate bodies, three separate reasons. Knowing which one you are dealing with saves an hour you will not have.
OCERT — the Oman National Computer Emergency Readiness Team, under the Ministry of Transport, Communications and Information Technology, is the national incident readiness and response body. It publishes advisories and awareness material and operates digital forensics capability. For most private companies, OCERT is who you contact for technical coordination and reporting of an incident.
The Cyber Defence Centre, established by Royal Decree 64/2020 as a body subordinate to the Internal Security Service, sits at the national defence level. It is not your first call as a mid-sized private business, but it is worth knowing it exists, because it explains why cybersecurity in Oman is treated as a matter of state rather than of IT.
The Ministry, for personal data. A personal data breach is a data protection notification, and it is separate from any technical report. See the next section.
Two related duties are worth having on the same page. If a crime has been committed — and unauthorised access, extortion and fraud are crimes — that is a matter for the Royal Oman Police. And note that the legal ground moved recently: Royal Decree 61/2026 promulgated a new Law on Combating Cybercrime on 1 June 2026, published in the Official Gazette on 7 June 2026 and in force from the following day, repealing the Cybercrime Law of 2011. The substance of the new Law is a question for a qualified adviser, not an article; what matters here is that a fifteen-year-old framework was replaced, so any guidance written before mid-2026 is describing a repealed law.
Where this meets data protection law
If the incident involved personal data, a second obligation runs in parallel and it is time-bound.
Under the Executive Regulation of the Personal Data Protection Law, issued by Ministerial Decision 34/2024, the controller must notify the competent department of the Ministry within 72 hours of becoming aware of a breach that threatens the rights of data subjects, and must notify the affected individuals within the same period where the breach causes severe damage or high risk.
Three practical consequences of that sentence.
The clock starts at awareness, not at understanding. You will be notifying while you still have unanswered questions. Plan for a notification that describes an incomplete picture honestly, rather than a late one that is complete.
You cannot notify what you cannot see. Control 7 exists because of this paragraph. Without logs, you cannot say which records were accessed, and the safe assumption becomes the widest one.
Your processors are inside your obligation. If the breach happened at a supplier, it is still your notification. This is why the contract terms in where your data is allowed to live require breach notification from your provider on a timeline that leaves you able to meet your own — and why the seven things PDPL changes inside your systems treats the processor register as a security document rather than a paperwork exercise.
There is also a third layer if you buy cloud or data centre services: under the TRA’s regulation, providers owe you breach notification within 72 hours, with a shorter window to the regulator for severe incidents. That is a right you hold, and it is worth confirming it appears in your contract.
Where to start on Monday
Controls 1, 2 and 4 — multi-factor authentication, a tested restore, and an audit of administrative access. Together they take about a week of part-time effort, cost close to nothing, and remove more risk than anything you could buy.
Then write down two things: who owns patching, and who is called first when something happens. A baseline with no owner decays back to nothing within a year, which is the real reason most companies do this twice.
Frequently asked questions
What is the minimum cybersecurity a small business in Oman needs? Multi-factor authentication on email and remote access, backups you have actually restored from with one copy offline or immutable, a patching routine with a named owner, and no standing administrative access. Those four remove most of what actually happens. The remaining four on the list above make you able to detect and investigate rather than only survive.
Do we have to report a cyber incident in Oman? It depends what was affected. If personal data was involved, the Executive Regulation of the Personal Data Protection Law requires notification to the Ministry within 72 hours of becoming aware, and to affected individuals within the same period where the harm is severe. Technical incident reporting and coordination sits with OCERT, criminal matters with the Royal Oman Police, and sector regulators may impose their own duties. Confirm your specific obligations with a qualified adviser before you need to.
How much should we spend on security? The first tranche is almost free, because it is configuration of things you already pay for. Be suspicious of any proposal that leads with a product before the eight controls above are in place — spending on detection while multi-factor authentication is optional is buying an alarm for a building with an open door.
Do we need cyber insurance? It is a legitimate risk transfer, not a substitute for controls, and policies commonly require the basics to be in place as a condition of cover. Read the conditions before you buy, and check what the insurer requires you to do in the first hours — some policies oblige you to use their appointed responder, which is a decision better made before an incident than during one.
Our systems are built and maintained by an outside supplier. Whose responsibility is this? Legally, yours — a processor does not absorb your obligations. Practically, it should be written down: who patches, who holds administrative credentials, who monitors, who is called first, and what their response time is. If those answers are not in a contract, they are not commitments. The same principle applies here as in choosing a software partner: if it matters, it is a clause.
This article summarises published positions as at 21 August 2026 and is not legal or security advice. Laws and obligations in this area changed materially during 2026; confirm your position with a qualified adviser. ZAWAT builds and maintains business systems and does not provide incident response — if you are dealing with a live incident, contact OCERT and a qualified incident response provider.
Sources: OCERT — Oman National CERT · Royal Decree 61/2026 issuing the Cybercrime Law (record) · Muscat Daily — Law on Combating Cybercrime issued, 1 June 2026 · Royal Decree 64/2020 establishing the Cyber Defence Centre (record) · Royal Decree 6/2022 — Personal Data Protection Law · Clyde & Co — Oman issues Executive Regulations to the PDPL
Want the baseline built into your systems rather than bolted on afterwards? ZAWAT builds custom software and provides integration and support with access control, logging and backup treated as part of the build. Book a call.