Najjab MCP Server
# Najjab | نجّاب
**دليل الساعات الأولى من الحادثة السيبرانية في دول الخليج يحدد من يجب إبلاغه ومتى ويربط كل مهلة بمصدرها الرسمي ومعه أدلة الاستجابة ومسودة الإشعار وتمرين المحاكاة وخادم MCP لمساعدي الذكاء الاصطناعي.**
**A guide to the first hours of a cyber incident in the Gulf: who to notify, by when, with the official source of every deadline, plus response playbooks, a notice draft, a tabletop exercise and an MCP server for AI assistants.**
الموقع | Site: **https://najjab.3li.info**
---
## بالعربية
### لماذا نجّاب
في الساعة الأولى من الحادثة يسأل الجميع السؤال نفسه وهو من نبلّغ ومتى. والجواب موزع على قوانين حماية البيانات وأطر البنوك المركزية وضوابط الهيئات الوطنية في ست دول وكل منها يحسب المهلة من لحظة مختلفة. لذا يجمع نجّاب هذه الواجبات في سجل واحد ثمّ يحوّل الحادثة إلى قائمة مرتبة بالأقرب موعداً مع عدّاد حي لكل جهة.
### ماذا يقدّم
- **ساعة الإبلاغ** وفيها تختار الدول التي تعمل فيها والمناطق الحرة المالية والقطاع ونوع الحادثة ودرجة خطورتها ووقت اكتشافها فتظهر كل جهة يجب إبلاغها مع موعدها بتوقيتك وبتوقيت الدولة وعدّاد تنازلي يتغير لونه كلما اقتربت المهلة.
- **أدلة الاستجابة** ولكل من برمجيات الفدية واختراق البريد الإلكتروني للأعمال وتسرّب البيانات وانكشاف مفاتيح الوصول السحابية خطوات تبدأ بالساعة الأولى ثمّ الاحتواء والاستئصال والتعافي والأدلة الواجب حفظها وما بعد الحادثة.
- **ملف التقويم** ويضيف كل مهلة بوقت محدد إلى Outlook أو تقويم Google أو تقويم Apple مع تنبيه قبلها بربع ساعة.
- **مسودة الإشعار** وهي نص بالعربية والإنجليزية يجمع الحقائق التي تطلبها كل جهة أولاً ويُوجَّه تلقائياً إلى الجهات التي تستدعيها الحادثة.
- **تمرين المحاكاة** وفيه سيناريو لكل نوع من الحوادث تُكشف تطوراته بالتتابع مع مؤقت للميسّر وأسئلة للنقاش.
- **سجل الواجبات** ويعرض كل واجب مع نطاقه ومصدره ومستوى التحقق منه ثمّ الجهات التي ما زالت قيد التحقق.
- **خادم MCP** ويجيب مساعدي الذكاء الاصطناعي من البيانات نفسها دون اتصال بالإنترنت ودون أي اعتماديات.
### التغطية
| الدولة | الجهة | الواجب | الإبلاغ الأول | التحقق |
|---|---|---|---|---|
| الكويت | بنك الكويت المركزي | الحوادث السيبرانية | العالية خلال ساعة والمتوسطة خلال 4 ساعات من الاكتشاف | النص الرسمي |
| الكويت | بنك الكويت المركزي | خرق البيانات الشخصية | وفق مهل الإبلاغ عن الحوادث | النص الرسمي |
| الكويت | المركز الوطني للأمن السيبراني | الحوادث السيبرانية | دون تأخير وضمن المهل التي يحددها المركز | النص الرسمي |
| الكويت | الهيئة العامة للاتصالات وتقنية المعلومات | خرق البيانات الشخصية لدى المرخص لهم | خلال 24 ساعة من العلم | مصدر ثانوي |
| السعودية | الهيئة السعودية للبيانات والذكاء الاصطناعي | خرق البيانات الشخصية | خلال 72 ساعة من العلم | مصدر ثانوي |
| السعودية | البنك المركزي السعودي | الحوادث المتوسطة والعالية | فوراً | النص الرسمي |
| السعودية | البنك المركزي السعودي | الحوادث التي تمس العملاء | فوراً ثمّ تقرير مفصل خلال 5 أيام | النص الرسمي |
| السعودية | البنك المركزي السعودي | مقدمو خدمات المدفوعات | فوراً للمتوسطة فأعلى | النص الرسمي |
| السعودية | الهيئة الوطنية للأمن السيبراني | الجهات الحكومية والبنى التحتية الحساسة | بلا مهلة محددة | النص الرسمي |
| الإمارات | مصرف الإمارات العربية المتحدة المركزي | الأحداث التي تمس العمليات الحرجة | خلال 4 ساعات ثمّ تقرير موجز خلال 24 ساعة وإشعار بالحوادث عالية الخطورة خلال 72 ساعة | النص الرسمي |
| الإمارات | مكتب الإمارات للبيانات | خرق البيانات الشخصية | عند العلم والمهلة متروكة للائحة التنفيذية | مصدر ثانوي |
| الإمارات | مفوض حماية البيانات في مركز دبي المالي العالمي | خرق البيانات الشخصية في المركز | في أقرب وقت ممكن عملياً | النص الرسمي |
| الإمارات | مكتب حماية البيانات في سوق أبوظبي العالمي | خرق البيانات الشخصية في السوق | خلال 72 ساعة من العلم متى أمكن | النص الرسمي |
| قطر | الوكالة الوطنية للأمن السيبراني | الحوادث الحرجة | خلال ساعتين من التحديد | النص الرسمي |
| قطر | الوكالة الوطنية للأمن السيبراني | خرق البيانات الشخصية | خلال 72 ساعة | النص الرسمي |
| قطر | مصرف قطر المركزي | خروقات البيانات لدى المؤسسات المالية | وفق إرشادات المصرف مع إبلاغ الوكالة ووزارة الداخلية | النص الرسمي |
| قطر | مكتب حماية البيانات في مركز قطر للمال | خرق البيانات الشخصية لدى الشركات المرخصة في المركز | خلال 72 ساعة من العلم | النص الرسمي |
| البحرين | مصرف البحرين المركزي | حوادث البنوك التي تمس العملاء أو الخدمات الحرجة | اتصال خلال ساعة ثمّ تقرير أولي خلال ساعتين وتقرير كامل خلال 10 أيام | النص الرسمي |
| البحرين | المركز الوطني للأمن السيبراني | حوادث الجهات الحكومية والبنى التحتية الحساسة | بلا مهلة محددة في الخطة الوطنية للاستجابة | النص الرسمي |
| البحرين | هيئة حماية البيانات الشخصية | خرق البيانات الشخصية | خلال 72 ساعة من الاكتشاف | مصدر ثانوي |
| عُمان | وزارة النقل والاتصالات وتقنية المعلومات | خرق البيانات الشخصية | خلال 72 ساعة من العلم | مصدر ثانوي |
| عُمان | مركز الدفاع الإلكتروني | حوادث الجهات الحكومية والبنى التحتية الحساسة | بلا مهلة منشورة | مصدر ثانوي |
وما زالت مهلة الإبلاغ عن الحوادث السيبرانية لدى مصرف قطر المركزي وقواعد البنك المركزي العُماني ومجلس الأمن السيبراني لدولة الإمارات قيد التحقق ولن تدخل السجل قبل قراءتها في مصدر رسمي أو موثوق.
### سياسة التحقق
يحمل كل واجب أحد مستويين فإما **النص الرسمي** أي قُرئ في الوثيقة المنشورة لدى الجهة المصدرة ورابطها مرفق وإما **مصدر ثانوي** أي أكّدته مكاتب محاماة ومراجع موثوقة لتعذّر الوصول الآلي إلى النص الرسمي وأسماؤها مرفقة. ولا يدخل السجل رقم لم يُقرأ في أحد المستويين.
### الاستخدام
افتح الموقع مباشرة ولا يحتاج إلى حساب أو تثبيت. وتُحفظ اختياراتك في متصفحك فقط ويحمل الرابط تفاصيل الحادثة لتشاركه مع فريقك فيرى العدّادات نفسها.
ولتشغيل خادم MCP أضف هذا إلى إعدادات مساعدك ثمّ اسأله عن مهل الإبلاغ لأي حادثة.
```json
{
"mcpServers": {
"najjab": { "command": "npx", "args": ["-y", "github:SiteQ8/Najjab"] }
}
}
```
### تنبيه
نجّاب مرجع عملي لا يغني عن الاستشارة القانونية لذا يبقى النص الرسمي هو المعتمد دائماً.
---
## English
### Why
In the first hour of an incident everyone asks the same question: who do we notify, and by when? The answer is spread across data protection laws, central bank frameworks and national cybersecurity controls in six countries, each counting from a different moment. Najjab gathers those duties into one register and turns an incident into a list ordered by what is due first, with a live countdown for every authority.
### What it does
- **The notification clock.** Pick the countries and financial free zones you operate in, your sector, the type of incident, its severity and when it was discovered. Every authority you must notify appears with its due time in your time zone and the country's, and a countdown that changes colour as the deadline nears.
- **Playbooks.** Ransomware, business email compromise, data breach and exposed cloud access keys, each with how it shows up, the first hour, containment, eradication, recovery, the evidence to keep and what to do after.
- **Calendar file.** Every deadline with a fixed time, as events for Outlook, Google Calendar or Apple Calendar with a reminder 15 minutes before each.
- **Notice draft.** Arabic and English text that gathers the facts every regulator asks for first, addressed to the authorities the incident triggers.
- **Tabletop exercise.** A scenario per incident type with developments revealed one at a time, a facilitator timer and questions for the room.
- **Register.** Every duty with its scope, source and verification level, plus the authorities still being verified.
- **MCP server.** The same data answers AI assistants offline, with no dependencies.
### Coverage
| Country | Authority | Duty | First notice | Verification |
|---|---|---|---|---|
| Kuwait | Central Bank of Kuwait | Cyber incidents (CORF control area 8.2.2) | High within 1 hour, medium within 4 hours of discovery | Official text |
| Kuwait | Central Bank of Kuwait | Personal data breach (CORF control 5.11.2.4) | On the incident reporting timelines | Official text |
| Kuwait | National Cyber Security Center | Cyber incidents (NBCC control RS-1) | Promptly, within the Center's timelines | Official text |
| Kuwait | CITRA | Personal data breach at licensed providers (Resolution 26 of 2024) | Within 24 hours of awareness | Secondary source |
| Saudi Arabia | SDAIA | Personal data breach (PDPL Implementing Regulation, Article 24) | Within 72 hours of awareness | Secondary source |
| Saudi Arabia | SAMA | Medium and high incidents (Cyber Security Framework 3.3.15) | Immediately | Official text |
| Saudi Arabia | SAMA | Incidents affecting customers (IT Governance Framework 3.3.8) | Immediately, detailed report within 5 days | Official text |
| Saudi Arabia | SAMA | Payment service providers (Payments Implementing Regulations, Article 121(2)) | Immediately, medium and higher | Official text |
| Saudi Arabia | NCA | Government and critical national infrastructure (ECC-2:2024, 2-13-3) | No fixed period | Official text |
| UAE | Central Bank of the UAE | Events affecting critical operations (Operational Risk Management Regulation, Articles 15.2 and 15.3) | Within 4 hours, summary report within 24 hours, high-risk incidents within 72 hours | Official text |
| UAE | UAE Data Office | Personal data breach (Decree by Law 45 of 2021, Article 9) | Upon awareness, period left to executive regulations | Secondary source |
| UAE (DIFC) | DIFC Commissioner of Data Protection | Personal data breach (DIFC Law No. 5 of 2020, Articles 41 and 42) | As soon as practicable | Official text |
| UAE (ADGM) | ADGM Office of Data Protection | Personal data breach (Data Protection Regulations 2021, Articles 32 and 33) | Within 72 hours of awareness where feasible | Official text |
| Qatar | NCSA | Critical incidents (NIA Standard v2.1, IM 8) | Within 2 hours of identification | Official text |
| Qatar | NCSA | Personal data breach (PDPPL breach notification guideline) | Within 72 hours | Official text |
| Qatar | Qatar Central Bank | Data breaches at licensed financial institutions (Data Handling and Protection Regulation, Article 16) | Under QCB incident reporting guidelines, also to NCSA and the Ministry of Interior | Official text |
| Qatar (QFC) | QFC Data Protection Office | Personal data breach at QFC firms (Data Protection Regulations 2021, Article 31) | Within 72 hours of awareness | Official text |
| Bahrain | Central Bank of Bahrain | Bank incidents affecting customers or critical services (Rulebook OM-5.5.57 and OM-5.5.58) | Call within 1 hour, Section A within 2 hours, Section B within 10 days | Official text |
| Bahrain | National Cyber Security Center | Incidents at government entities and critical national infrastructure (National Cybersecurity Incident Response Plan) | No fixed period | Official text |
| Bahrain | Personal Data Protection Authority | Personal data breach (Resolution 43 of 2022, Article 4(2)) | Within 72 hours of discovery | Secondary source |
| Oman | Ministry of Transport, Communications and IT | Personal data breach (Ministerial Decision 34 of 2024, Articles 30 and 32) | Within 72 hours of awareness | Secondary source |
| Oman | Cyber Defense Centre | Incidents at government entities and critical infrastructure (Royal Decree 64/2020) | No published period | Secondary source |
Still being verified, and kept out of the register until their rules are read in an official or reliable source: the cyber incident timeline of Qatar Central Bank, the Central Bank of Oman and the UAE Cyber Security Council.
### Verification policy
Every duty carries one of two levels. **Official text** means it was read in the document published by the issuing authority, and the link is included. **Secondary source** means reputable law firms and references confirmed it because the official text could not be retrieved automatically, and they are named. No number enters the register without one of the two.
Severity is graded differently by each authority, so pick the grade your own classification gives. A critical incident takes the highest grade an authority defines, and a duty that only starts at a higher grade is listed as not triggered, with the reason.
### Use it
Open the site. There is no account and nothing to install. Your choices stay in your browser, and the address carries the incident details so your team can open the same link and see the same countdowns.
To run the MCP server, add it to your assistant's configuration:
```json
{
"mcpServers": {
"najjab": { "command": "npx", "args": ["-y", "github:SiteQ8/Najjab"] }
}
}
```
| Tool | What it answers |
|---|---|
| `najjab_overview` | Countries, authorities, verification levels and what is still being verified. Start here. |
| `najjab_list_obligations` | Duties filtered by country, trigger or sector, paged. |
| `najjab_get_obligation` | One duty with every deadline row, its source, link and secondary sources. |
| `najjab_deadlines` | Every duty an incident triggers across the given countries and free zones, soonest first, with due times computed from the discovery time. |
| `najjab_playbook` | The playbook for an incident type. |
| `najjab_tabletop` | A tabletop exercise for an incident type. |
| `najjab_calendar` | An .ics file with one event per timed deadline and a reminder 15 minutes before each. |
| `najjab_draft_notice` | A notice draft in Arabic or English addressed to the triggered authorities. |
Every tool is read-only, answers in Arabic or English, and returns Markdown or JSON.
### Develop
Node 18 or later, no dependencies.
```sh
npm run build # validate data/src and write docs/data/bundle.json
npm test # data, engine, MCP and site tests
npm run preflight # build, guards, MCP selftest and tests together
npm run test:ui # browser check with Playwright, when it is installed
npm run links # every source and document link, 404 fails
```
The data lives in `data/src`: `obligations.json` for the duties, `playbooks.json`, `tabletop.json` and `ui.json`. The tests hold every Arabic text to the house rules: a sentence ends with a single period, clauses join with connectives rather than commas, and every number survives translation.
### Not legal advice
Najjab is a practical reference and not legal advice, so always act on the official text. See [NOTICE.md](NOTICE.md) for sources and provenance.
### License
MIT, see [LICENSE](LICENSE). Fonts are under the SIL Open Font License, see `docs/fonts/OFL.txt`.
TDQS
Scored across 8 tools
Each tool targets a distinct function: orientation (overview), browsing duties (list_obligations vs get_obligation are a clear list/single pair), computing deadlines, response guidance (playbook vs tabletop), calendar export, and notice drafting. The only mild overlap is that deadlines, list_obligations, and calendar all touch notification timing, but their descriptions differentiate incident-computed timing from register browsing and export.
All tools share a consistent najjab_ prefix and snake_case formatting. The suffix style is mixed, though: some are verb_noun (list_obligations, get_obligation, draft_notice) and others are bare nouns (overview, deadlines, playbook, tabletop, calendar), but the convention is readable and predictable overall.
Eight tools is well within the ideal 3-15 range and each one serves a clear, non-redundant purpose in the incident-notification workflow. Nothing feels padded or missing in the count.
The surface covers the full arc: orientation, browse/lookup of duties, deadline computation from an incident, response playbook, tabletop exercise, calendar export, and notice drafting. Minor gaps exist (e.g. no direct lookup or filtering by authority, or a comparison/updates view), but core regulatory and response workflows are covered.