Our Riyadh IT consulting covers three primary engagement types: cloud migration strategy, enterprise architecture for new organizations, and technology due diligence. Cloud migration strategy: (1) We start with the NDMO data classification exercise — every dataset the organization holds is classified per NDMO categories (Top Secret, Secret, Confidential, Restricted, Public). This classification determines where data can reside: some classifications permit public cloud, others require government-community cloud or on-premises. (2) Application portfolio assessment: we inventory all applications (typically 50-300 for a Saudi government entity), assess their cloud readiness (6R framework: rehost, replatform, refactor, repurchase, retire, retain), and estimate migration complexity and cost per application. (3) Cloud provider selection: we evaluate options against the organization's specific requirements — AWS (me-south-1 Bahrain region, with Saudi local zone announced), Azure (UAE North, with Saudi region development), Google Cloud (Dammam region launched), Oracle Cloud (Jeddah), STC Cloud (Saudi-hosted, government community cloud), and Alibaba Cloud (partner with STC for Saudi market). Selection is based on data sovereignty requirements, application compatibility, cost modeling, and the organization's existing technology investments (an organization deeply invested in Microsoft 365 and Azure Active Directory has a natural Azure alignment). (4) Migration roadmap: sequenced by risk and dependency — we migrate low-risk, non-critical workloads first to build team capability, then progress to production and citizen-facing systems. For enterprise architecture: new Saudi organizations (mega-projects, government entities created by Royal Decree, newly licensed companies) need greenfield IT design. We architect: network infrastructure (SD-WAN, with Saudi connectivity requirements — STC, Mobily, or Zain backbone), identity and access management (Active Directory/Azure AD, with integration to Nafath for citizen-facing services), productivity platforms (Microsoft 365 or Google Workspace — the Saudi market overwhelmingly uses Microsoft), ERP selection (SAP S/4HANA or Oracle for large organizations, Odoo or custom for smaller entities), and cybersecurity architecture aligned with NCA Essential Cybersecurity Controls (ECC-1:2018) — the mandatory framework for all Saudi organizations.