Banks and insurers
SAMA-supervised institutions that must evidence DDoS protection testing, incident-response rehearsal, and third-party mitigation under the Cyber Security Framework — with a file, not a slide.
For KSA banks, insurance, fintech, government, and MSSPs
أثبت دفاعاتك قبل أن يصل الفيضان الحقيقي.
Insec-Hydra is the self-hosted command room for authorized DDoS resilience testing. Distributed agents, live operator control, SAMA CSF evidence you can export, and 130+ L4/L7 methods — used only on systems you are written-authorized to test.
Examiners do not want a screenshot of a flooder. They want attributable campaigns, allowlisted targets, and a file they can open. Hydra is built so a CISO, a GRC lead, and an operator share the same record — without a how-to-attack guide, and without sending Kingdom telemetry to a foreign managed service.
Each node is an agent. Together they are the hydra.
Who it is for
The Kingdom’s financial and critical-infrastructure operators are expected to test denial-of-service protection — and to show the work. Insec-Hydra is the assessment platform those teams run in-house, or through a licensed MSSP, under written authorization.
SAMA-supervised institutions that must evidence DDoS protection testing, incident-response rehearsal, and third-party mitigation under the Cyber Security Framework — with a file, not a slide.
Digital banks, processors, and payment schemes that need controlled L7 and L4 assessments against customer channels, without turning the exercise into an unmanaged flood.
Entities under NCA ECC that must demonstrate mandatory DDoS protection testing on public services and critical systems — with a paper trail a reviewer can open.
Licensed providers who run isolated tenants for Kingdom clients, each with its own agents, campaigns, audit log, and billing — never a shared attack service.
What operators actually run
The product is organised the way operators navigate it: Command, Design, Fleet, Intelligence, Reports, and Admin — with safety rails on every campaign. Every action is attributable. Every target is allowlisted.
Operators watch running campaigns from one console: WebSocket metrics, a geographic map, platform health, and kill-all. When a test must stop, it stops from a single control — not a scatter of terminals.
Campaign Studio, Test Designer, Scenario Designer, templates, playbooks, plugins, and ramp tests. Intensity, duration, fleet, and method family are planned before a packet is authorised to leave a node.
Windows and Linux agents register with a one-time token and group into teams. Load originates only from machines you own and have approved — never from unmanaged endpoints.
Resilience grade, campaign comparison, a remediation tracker, SAMA CSF mapping with an evidence ZIP, and governance workflows. The briefing layer: what degraded, what recovered, what still needs a control owner.
Dry-run against tenant CIDR allowlists, blocked-target lists, configurable intensity and duration limits, and a state machine that will not skip from draft to running. Circumventing the rails is a terms breach, not a feature.
Multi-tenant RBAC, users and roles, MFA and OIDC, an audit log, license manager, and MSSP distributor billing. Each tenant keeps its own agents, campaigns, and settings. Client estates are never mixed.
How an authorized campaign runs
A campaign is a controlled object with a lifecycle, not a fire-and-forget script. Every transition is logged against an operator identity. The order is the product.
An operator records the in-scope target, method family, intensity, duration, and agent team. The campaign exists inside the tenant. Nothing is sent.
The platform checks the target against the tenant CIDR allowlist and the blocked-target list. Private ranges are flagged. A failed dry-run cannot be armed.
Only after dry-run succeeds can the campaign be armed. Arming is an explicit authorization step — the last gate before live traffic, visible in the audit log.
Armed campaigns start from Live Command. Metrics stream in; kill-all remains one action away. When the window ends, health checks and the report close the file.
Kingdom of Saudi Arabia
Control assessments persist against SAMA CSF domains P3 governance, P4 defence, P5 resilience, and P6 third parties. NCA ECC mandatory protection testing is recorded the same way: campaign outcomes, not anecdotes. Export the evidence ZIP when the examiner asks.
Read the control mapSelf-hosted control
Foreign managed DDoS-testing services leave the Kingdom’s telemetry, scope, and operator identity in someone else’s cloud. Insec-Hydra runs on compute you control — dedicated Windows or Linux — with agents only on authorized test machines.
What you need to run itTell us the sector, the regulator you report to, whether you will self-host or run through an MSSP tenant, and confirm that written authorization will be in place before any test window.