Gulf
IT Audit and Cyber Security Assurance in Dubai and the UAE
A market with several overlapping regulatory regimes — federal, emirate-level and free zone — where the first useful question is usually not "are we compliant" but "which of these actually binds us".
Establish what applies before assessing anything
Organisations operating in the Emirates are frequently subject to more obligations than they assume, and occasionally to fewer. Federal information assurance standards apply to entities in defined critical sectors. Dubai government entities and organisations working with them face the emirate's own information security regulation. The financial free zones operate independent regimes with their own data protection law. Federal data protection legislation sits alongside all of it.
A common and expensive mistake is assuming a free zone licence exempts an entity from federal obligations. Sometimes it does. Often it does not, and where the entity serves federal government clients or operates in a critical sector, the exemption assumption fails on contact with the first serious due diligence exercise.
We determine applicability formally before scoping the assessment, and where the answer turns on a legal question we say so and recommend you take advice. We are IT auditors, not lawyers, and the boundary matters.
What we are most often asked to do in this market
- Applicability determination across the federal, emirate and free zone regimes that may bind an entity — often the most valuable few days of the whole engagement.
- ISO 27001:2022 gap assessment and internal audit, usually driven by enterprise customers rather than by a regulator.
- Consolidated multi-framework assessment — one control set, one evidence exercise, separate reports per framework.
- Penetration testing and cloud security review, frequently for organisations whose estate is entirely in AWS or Azure and has never been independently assessed.
- Data protection assessment and data flow mapping, including the cross-border transfers hidden inside SaaS platforms and offshore support arrangements.
- Virtual CISO for regional entities carrying group security obligations without local security leadership.
Overlapping regimes, one evidence exercise
Assess once, report several times
Where more than one framework applies, running sequential assessments means asking the same people the same questions three times and paying for it three times. It also produces inconsistent answers, because the third interview is conducted by tired people.
We build a consolidated control set covering every applicable framework, collect evidence once, then report separately in each framework's own structure. On multi-framework engagements this is reliably the largest saving available, and it substantially reduces the load on your internal teams — which is usually the constraint that matters more than fee.
The regional pattern worth knowing
A large share of UAE entities are regional offices or subsidiaries carrying a group security policy written elsewhere, for a different regulatory environment. The policy is formally adopted, nobody locally can explain how it maps to UAE obligations, and the gap only surfaces when a customer or authority asks.
Assessing against the group policy alone will not find this. We assess against the obligations that apply here, then show where the group framework already satisfies them and where it does not — which is usually a much shorter list of genuine gaps than an organisation fears.
Cloud, and where the obligations actually sit
Most organisations we assess in the Emirates run predominantly on cloud infrastructure, and a good proportion have never had it independently reviewed. The provider secures the infrastructure; everything above it is yours, and the boundary moves depending on whether you are consuming IaaS, PaaS or SaaS.
Data and access remain your responsibility in every model without exception, and that is where nearly every finding lands — storage left publicly readable, over-permissioned identities, keys committed to source control, audit logging never enabled across all accounts and regions. None of these are provider failures, and none are covered by the provider's own certifications, which is the assumption we most often have to correct.
Cross-border data transfer is the second issue, and it is usually invisible until mapped: a SaaS platform hosted outside the region, a support function with offshore access, a backup replicated to a foreign availability zone. Data flow mapping surfaces these, and the results are routinely a surprise to the people who commissioned the work.
How engagements are delivered here
We work remotely and onsite across the Emirates. Documentation review and analysis are performed remotely; walkthroughs, observation and closing meetings onsite. For entities with operations in both the UAE and Saudi Arabia we scope the two together where the frameworks overlap, which is more often than most organisations expect.
Related services
Related regulatory frameworks
Tell us what you are actually being asked for
Describe the situation rather than the service. Working out the right scope is part of what we do, and it costs nothing to ask.
Request a proposal