For KSA banks, insurance, fintech, government, and MSSPs

Prove your defences before the real flood arrives.

أثبت دفاعاتك قبل أن يصل الفيضان الحقيقي.

Insec-Hydra is the self-hosted command room for authorized DDoS resilience testing. Distributed agents, live operator control, SAMA CSF evidence you can export, and 130+ L4/L7 methods — used only on systems you are written-authorized to test.

Examiners do not want a screenshot of a flooder. They want attributable campaigns, allowlisted targets, and a file they can open. Hydra is built so a CISO, a GRC lead, and an operator share the same record — without a how-to-attack guide, and without sending Kingdom telemetry to a foreign managed service.

Each node is an agent. Together they are the hydra.

SAMA CSF P3–P6 NCA ECC Multi-tenant RBAC 130+ L4/L7 methods Self-hosted

Who it is for

Built for the people who must prove resilience, not merely claim it.

The Kingdom’s financial and critical-infrastructure operators are expected to test denial-of-service protection — and to show the work. Insec-Hydra is the assessment platform those teams run in-house, or through a licensed MSSP, under written authorization.

banks

Banks and insurers

SAMA-supervised institutions that must evidence DDoS protection testing, incident-response rehearsal, and third-party mitigation under the Cyber Security Framework — with a file, not a slide.

fintech

Fintech and payments

Digital banks, processors, and payment schemes that need controlled L7 and L4 assessments against customer channels, without turning the exercise into an unmanaged flood.

gov

Government and CNI

Entities under NCA ECC that must demonstrate mandatory DDoS protection testing on public services and critical systems — with a paper trail a reviewer can open.

mssp

MSSPs and distributors

Licensed providers who run isolated tenants for Kingdom clients, each with its own agents, campaigns, audit log, and billing — never a shared attack service.

What operators actually run

A command room, not a one-shot flooder.

The product is organised the way operators navigate it: Command, Design, Fleet, Intelligence, Reports, and Admin — with safety rails on every campaign. Every action is attributable. Every target is allowlisted.

command

Live command

Operators watch running campaigns from one console: WebSocket metrics, a geographic map, platform health, and kill-all. When a test must stop, it stops from a single control — not a scatter of terminals.

design

Campaign design

Campaign Studio, Test Designer, Scenario Designer, templates, playbooks, plugins, and ramp tests. Intensity, duration, fleet, and method family are planned before a packet is authorised to leave a node.

fleet

Distributed fleet

Windows and Linux agents register with a one-time token and group into teams. Load originates only from machines you own and have approved — never from unmanaged endpoints.

intel

CISO intelligence

Resilience grade, campaign comparison, a remediation tracker, SAMA CSF mapping with an evidence ZIP, and governance workflows. The briefing layer: what degraded, what recovered, what still needs a control owner.

safety

Safety rails

Dry-run against tenant CIDR allowlists, blocked-target lists, configurable intensity and duration limits, and a state machine that will not skip from draft to running. Circumventing the rails is a terms breach, not a feature.

admin

Tenant admin

Multi-tenant RBAC, users and roles, MFA and OIDC, an audit log, license manager, and MSSP distributor billing. Each tenant keeps its own agents, campaigns, and settings. Client estates are never mixed.

How an authorized campaign runs

Draft. Dry-run. Armed. Running.

A campaign is a controlled object with a lifecycle, not a fire-and-forget script. Every transition is logged against an operator identity. The order is the product.

  1. 01

    Draft

    An operator records the in-scope target, method family, intensity, duration, and agent team. The campaign exists inside the tenant. Nothing is sent.

  2. 02

    Dry-run

    The platform checks the target against the tenant CIDR allowlist and the blocked-target list. Private ranges are flagged. A failed dry-run cannot be armed.

  3. 03

    Armed

    Only after dry-run succeeds can the campaign be armed. Arming is an explicit authorization step — the last gate before live traffic, visible in the audit log.

  4. 04

    Running

    Armed campaigns start from Live Command. Metrics stream in; kill-all remains one action away. When the window ends, health checks and the report close the file.

Kingdom of Saudi Arabia

Built for SAMA examinations, not slideware.

Control assessments persist against SAMA CSF domains P3 governance, P4 defence, P5 resilience, and P6 third parties. NCA ECC mandatory protection testing is recorded the same way: campaign outcomes, not anecdotes. Export the evidence ZIP when the examiner asks.

Read the control map

Self-hosted control

Your estate. Your evidence. Your keys.

Foreign managed DDoS-testing services leave the Kingdom’s telemetry, scope, and operator identity in someone else’s cloud. Insec-Hydra runs on compute you control — dedicated Windows or Linux — with agents only on authorized test machines.

What you need to run it

Brief your CISO. Scope a licensed assessment.

Tell us the sector, the regulator you report to, whether you will self-host or run through an MSSP tenant, and confirm that written authorization will be in place before any test window.

Contact Insec