Banking & finance
Central bank supervision, a hard incident-reporting window, and an examiner who will ask for evidence going back years.
Typically: SAMA CSF, ISO 27001, NIST CSF
Insurance & NBFIs
Operational resilience and cyber obligations without the compliance headcount of a large bank.
Typically: ISO 27001, NIST CSF, CIS Controls
Healthcare
Patient information assessed alongside information security, against records that cannot be reconstructed after the fact.
Typically: HIPAA, ISO 27001, NIST CSF
Energy & critical infrastructure
National-security scrutiny, supply-chain obligations, and environments that may never touch the internet.
Typically: NCA ECC, Aramco CCC, NIST CSF
Technology & service providers
Every enterprise deal now arrives with a security questionnaire and a certificate requirement attached.
Typically: SOC 2, ISO 27001, CIS Controls
Government & public sector
Data residency that rules out shared cloud, and procurement that requires the answer in writing.
Typically: NCA ECC, ISO 27001, NIST CSF