Cyber threats continue to increase across the financial sector as institutions become more dependent on digital platforms, cloud services, third-party technology providers and interconnected systems.
To strengthen cyber resilience within Abu Dhabi Global Market (ADGM), the Financial Services Regulatory Authority (FSRA) introduced new Cyber Risk Management Rules for Authorised Persons and Recognised Bodies. The requirements came into force on 31 January 2026.
The rules establish baseline cyber-risk expectations and require firms to integrate cyber risk management into their existing risk-management frameworks. They build upon the FSRA’s existing Information Technology Risk Management Guidance and cybercrime governance principles.
What Should Financial Institutions Focus On?
ADGM-regulated firms should ensure their Cyber Risk Management Framework appropriately addresses areas such as cybersecurity governance, cyber risk assessment, information asset protection, third-party technology risk, endpoint and network security, security monitoring, incident management, cyber resilience, employee awareness and security testing.
The framework should be proportionate to the firm’s nature, scale, complexity and cyber-risk exposure. The objective is not simply to maintain cybersecurity policies, but to integrate cyber risk into the institution’s overall governance and risk-management environment.
Cyber Incident Management and Reporting
Cyber incident response is another important regulatory area. ADGM states that Authorised Persons must notify the FSRA of applicable incidents impacting their operations and, under GEN 3.5.18, report a material Cyber Incident no later than 24 hours after becoming aware, or having information reasonably suggesting, that such an incident has occurred.
Institutions should therefore establish clear procedures for incident identification, classification, escalation, regulatory notification, containment, recovery and post-incident review.
Third-Party Cyber Risk
Cloud providers, managed service providers, fintech platforms and other technology vendors can introduce significant cyber risks.
Financial institutions should ensure that third-party cyber risks are properly assessed and managed through appropriate due diligence, contractual security requirements, ongoing monitoring, incident escalation and oversight.
Third-party management is also one of the FSRA’s stated supervisory focus areas for IT and cybersecurity.
How MAST Consulting Can Support
MAST Consulting can support ADGM-regulated financial institutions in assessing and strengthening their Cyber Risk Management Framework.
Our approach includes:
ADGM Cyber Gap Assessment → Cyber Risk Assessment → Governance & Framework Development → Cybersecurity Control Assessment → Third-Party Risk → Incident Response → Cyber Resilience → Security Testing → Remediation → Regulatory Readiness
We help organizations translate FSRA requirements into practical governance, policies, controls, processes and compliance evidence.
Is Your Organization Ready?
With the ADGM Cyber Risk Management Rules now in force, Authorised Persons and Recognised Bodies should review their existing cybersecurity environment and identify any gaps against the FSRA requirements.
Talk to MAST Consulting to conduct an ADGM Cyber Risk Management Gap Assessment and strengthen your regulatory readiness.