Skip to content

Policy and capability

Vision 2030 and the DDoS Layer: Why Traffic That Leaves Also Takes the Learning With It

Last updated: August 2026 · Localisation, local content and where operational skill accumulates · Reading time ~15 min

Two identical workbenches: the near one deeply worn and surrounded by an accumulation of purpose-built tooling, the far one pristine and bare, with a conduit carrying the work away from it toward somewhere outside the frame.

Traffic scrubbed abroad does not build domestic operational capability; it renews a contract. Every diversion event teaches somebody — and if the inspection point is offshore, the party that learns is a provider in another country. An in-country inline tier keeps the data and the experience in the same place, which is the part of localisation that never appears in a data-flow diagram.

Saudi Arabia’s development programme is explicit about a small number of things: diversifying the economy away from a single revenue source, growing a digital economy, and building local content and local capability rather than importing finished capability indefinitely. Those are declared goals, restated consistently, and nothing in this guide requires reading anything more specific than that into them.

Applied to cybersecurity procurement, they produce a question that a compliance assessment never asks. Not is this control adequate — that is settled elsewhere, and our guide to the national controls covers it — but does the way we deliver this control build the thing the country said it wanted to build, or substitute for it?

For DDoS mitigation the answer turns out to be unusually clear, and it hinges on something that does not appear in any data-flow diagram.

Availability became a public asset

The first move is to notice what a digital-economy goal does to the status of uptime.

When commerce, government service delivery, banking and logistics all migrate to public-facing digital channels, the availability of those channels stops being an operational metric belonging to individual organisations. It becomes a property of the national economy — the same way port throughput or grid reliability is. An extended outage in a payment network or a citizen services portal is not a bad quarter for one operator; it is a period during which a part of the economy that was deliberately digitised does not function.

That reframing is why DDoS deserves attention in a development-policy conversation at all. It is one of the few threat classes whose entire purpose is to remove availability, it requires no compromise of anything, and it is cheap to launch against a target that has become economically important.

The part of localisation that gets discussed

Most localisation discussion concerns data. Where is it stored, where is it processed, under whose jurisdiction, on what legal basis. Applied to DDoS the analysis is well trodden: a scrubbing tier cannot classify traffic without processing source addresses, headers, session identifiers and, for application-layer protection, request bodies — so a tier operating abroad is processing that material abroad, whatever it stores. The GCC residency guide sets that out in full and this guide does not repeat it.

What a scrubbing tier must see to do its job Source IP addresses Request headers & user agent Session cookies / tokens Request bodies (if TLS terminated) Cloud scrubbing Processed abroad crosses the border crosses the border crosses the border crosses the border On-premise mitigation Processed in country stays inside stays inside stays inside stays inside
What a mitigation tier must process to do its job, against where the processing happens.

That analysis is correct and incomplete. It measures what crosses the border. It does not measure what fails to accumulate on this side of it.

The part that does not

Consider what actually happens during a mitigated attack, from the point of view of institutional learning rather than traffic.

Someone watches the traffic arrive. Someone recognises which signature this is, notices which of the protected services started to wobble first, decides whether the threshold that fired was correct, adjusts it, watches the effect, and afterwards writes down what to do differently. That sequence is where operational competence is manufactured. It cannot be acquired from a report, a course, or a certification, because the useful part of it is specific to the estate being defended — your normal, your services, your false positives, your change process.

Now ask where that sequence takes place under each architecture.

If everyday inspection happens in a provider’s scrubbing centres, it takes place in that provider’s operations room, staffed by that provider’s engineers, in another country. Your team receives a notification, a graph and, later, a summary. They have not watched anything. Over five years and several dozen events, the provider’s organisation becomes measurably better at defending traffic like yours, and yours becomes measurably better at reading reports.

If everyday inspection happens on equipment in your own facility, the same sequence takes place in your operations room. The engineer who tuned the threshold is on your payroll, in the country, and remains employable in the country afterwards. The knowledge does not leave when a contract expires, because it was never held by the counterparty.

That is the claim, and it is narrower than the sovereignty rhetoric usually attached to this subject. It is not that foreign providers are untrustworthy. It is that skill accrues to whoever performs the work, and a development goal about building national capability is a statement about where work should be performed.

Local content is not only where the money goes

Procurement frameworks that weight local content usually count spend: what proportion of contract value is delivered by domestic entities. That is a reasonable proxy and it understates this case.

A recurring offshore scrubbing subscription is, in local-content terms, close to a pure import. It is a service fee, delivered by people and facilities elsewhere, renewed annually, with almost no domestic work attached beyond the account relationship.

An appliance deployed in country is not fully domestic either — the hardware and the software are imported, and this guide is not going to pretend otherwise. But look at what surrounds it: physical installation, network integration, policy design, baselining against local traffic, tuning, monitoring, incident response, capacity planning, testing, and the training of people to do all of it. That work is performed locally by definition, because the equipment is local, and it is the kind of work that produces engineers who are still valuable when the equipment is replaced.

Over a five-year horizon the difference is not the invoice. It is whether the country has more people who know how to defend a national-scale service at the end of the period than at the start.

Where the equipment choice actually matters

Two properties distribute the learning differently, and they are worth putting in a tender.

The first is whether the detection logic is trained and executed on the customer’s own infrastructure. Where it is, tuning is your team’s work and the resulting knowledge is a local asset, which is the property that connects an equipment decision to a capability outcome rather than only to a data-residency one. Where classification depends on a manufacturer-operated intelligence service, the most valuable tuning happens inside that service, and the local role narrows toward operating what is supplied. Both are legitimate designs and the second is often more capable out of the box; they simply put the compounding in different places.

The second is whether operations are transferable. A model in which the manufacturer or a partner operates the platform indefinitely produces the same outcome as offshore scrubbing with extra steps — the equipment is in the country and the competence is not. Ask, in writing, on what timescale the customer’s own team can take over operations, what training is included, and who certifies it. Answers vary widely across the market and rarely appear in a datasheet.

Where the capability ends up after five years
ApplianceEveryday inspection offshoreEveryday inspection in country
Who observes the attack in detailThe provider's operations centreYour own operations team
What an incident produces internallyA summary report and an invoice lineA tuned policy, a rehearsed runbook and a trained engineer
Where the skill accumulates over five yearsIn the provider's organisationIn the national labour market
Local content in the purchaseRecurring service fee, largely offshoreHardware, integration, operations, training
Position if the relationship endsCapability leaves with the contractCapability stays; hardware and people remain
What the data-flow diagram showsA cross-border processing hop to justifyNo hop for everyday traffic
What the diagram does not showThat the learning also crossed the borderThat it did not

The last two rows are the argument. Every localisation discussion covers the data; almost none covers the experience, and the experience is the part that compounds.

The limit of the argument

Three honest qualifications.

Capacity is not a policy question. No amount of local capability changes the fact that an attack larger than your circuit has already won before your equipment sees it. Upstream capacity remains necessary, and an organisation with a genuine terabit-scale exposure that refuses cloud capacity on capability grounds has confused a preference with a design.

Speed sometimes beats strategy. An organisation currently defenceless and under attack should buy the fastest adequate answer available, which is frequently an upstream service that can be turned on this week. Capability is built over years and outages happen this afternoon.

Local operation is a commitment, not a purchase. An appliance operated by nobody is worse than a service operated by someone competent. The capability argument only pays if the organisation actually staffs, trains and rehearses — and an organisation unwilling to do that should buy the service and be honest about why.

What to put in the tender

  1. State the proportion of delivered work performed in country, by role.
  2. State the timescale on which the customer’s own team can assume full operation, and what training and certification is included.
  3. State what the customer retains — equipment, configuration, knowledge, records — if the commercial relationship ends.
  4. State whether detection is trained and executed on customer infrastructure or depends on an external service, and how it degrades if that service is unreachable.
  5. Require that the diversion runbook is exercised by the customer’s own staff, not demonstrated by the vendor.

Item five is the cheapest and the most revealing. A capability that only the supplier can exercise is a capability the country does not have.

Sources and further reading

The development programme’s stated objectives are published by the Kingdom and are the right primary source for any policy framing; nothing in this guide depends on a specific target, timeline or figure, and none is asserted here. For the regulatory analysis that sits alongside this policy one, see the national controls guide, the central bank framework guide and the GCC residency guide. For the licence-holder’s version of the same question, see DDoS as a licence obligation.

Frequently asked questions

Is this a regulatory argument or a policy argument?
A policy argument, deliberately. Regulatory obligations around data residency and transfer are covered elsewhere on this site and are a separate analysis with a separate answer. This guide is about something a compliance assessment does not measure: whether the way a control is delivered contributes to national capability or substitutes for it. That question is settled by publicly declared development goals rather than by any rule, which is exactly why it can be argued without citing one.
Doesn't buying a foreign appliance keep the money offshore either way?
It keeps part of it offshore, and the honest position is that no serious network security purchase in any market is fully domestic. But the split is very different. A recurring offshore scrubbing service is almost entirely a service fee, delivered by people and facilities elsewhere. An appliance deployed in country still involves imported hardware and an imported licence, and around it sits integration, operation, tuning, incident response, capacity planning and training — work performed locally, by people who become more valuable for having done it.
What exactly does an operations team learn that a provider's report does not contain?
The parts that are specific to your estate. What your normal looks like in the hour before an attack, which of your services degrade first and why, which thresholds produce false positives against your own application behaviour, how your change process interacts with an incident, and which of your assumptions about your own traffic were wrong. A provider's report describes the attack. The tuning knowledge describes you, and it can only be acquired by watching your own traffic being defended.
Is this an argument against using cloud scrubbing at all?
No. Above your own circuit capacity there is no alternative, and a provider that can absorb a very large flood today is offering something no on-premise design can. The argument is about which tier is the default. A design where the local tier handles everyday traffic and the upstream tier is a rehearsed exception keeps both the capability and the capacity. A design where everything is inspected offshore keeps only the capacity.
How would an organisation actually evidence "local capability" in a procurement?
By making it a scored requirement rather than a sentiment. Ask what proportion of the delivered work is performed in country, whether operations and tuning are transferable to the customer's own team and on what timescale, what training is included and who certifies it, and what the customer retains if the relationship ends. Those are answerable, comparable and verifiable a year later, which a preference for local content expressed as a principle is not.
Does the appliance's own design affect where capability accumulates?
Yes, and in a way that is easy to miss. If the detection logic is trained and executed on the customer's own infrastructure, then tuning it is your team's work and the resulting knowledge is yours. If classification depends on a manufacturer-operated service, the tuning that matters most happens inside that service, and your team's role narrows to operating what it is given. Both are legitimate products; they distribute the learning differently.
What happens to this argument if the organisation is not in a regulated sector?
It gets stronger rather than weaker, because there is no compliance requirement doing the work for you. A regulated entity is often pushed toward in-country processing by rules it has no choice about. An unregulated one is making a free choice, and for that choice the capability argument is the whole case — along with the ordinary commercial one about five year total cost, which our TCO guide covers separately.

Sources

  1. Saudi Vision 2030 — official programme site

    Kingdom of Saudi Arabia · regulator · accessed 2026-08-20

    The primary source for the programme's declared objectives. Nothing in this guide depends on a specific target, timeline or figure, and none is asserted here.

  2. National Cybersecurity Authority — official site

    National Cybersecurity Authority (Saudi Arabia) · regulator · accessed 2026-08-20

    Obtain the current edition of the control set directly from the authority; wording, structure and numbering change between editions. The host did not respond to this publication's network on 20 August 2026 — the address is the authority's own, but it could not be fetched during this revision.

Published: August 2026

This guide is updated as vendors release new models and pricing. How we compare vendors