Information Security

CBUAE Compliance Requirements for Banks and Licensed Financial Institutions in the UAE

CBUAE Compliance Requirements for Banks and Licensed Financial Institutions in the UAE. (Part 2)

Cybersecurity Testing, Incident Management, Business Continuity, Outsourcing, Data Protection and Internal Controls In Part 1, we explored four key areas of the CBUAE compliance landscape: Operational Risk Management, Operational Resilience, ICT & Cybersecurity Risk Management, and UAE Information Assurance requirements. In Part 2, we continue with seven additional areas that banks and Licensed Financial Institutions […]
Continue Reading
CBUAE Compliance Requirements for Banks and Licensed Financial Institutions in the UAE

CBUAE Compliance Requirements for Banks and Licensed Financial Institutions in the UAE. (Part 1)

Cybersecurity, GRC, Operational Risk and Operational Resilience Requirements Banks and Licensed Financial Institutions (LFIs) operating in the UAE are subject to a comprehensive regulatory framework established by the Central Bank of the UAE (CBUAE). CBUAE requirements address key areas including Governance, Risk and Compliance (GRC), Operational Risk, Operational Resilience, ICT and Cybersecurity, Information Assurance, Internal […]
Continue Reading
ADGM Cyber Risk Management Framework 2026

ADGM Cyber Risk Management Framework 2026: What Financial Institutions Need to Know.

Cyber threats continue to increase across the financial sector as institutions become more dependent on digital platforms, cloud services, third-party technology providers and interconnected systems. To strengthen cyber resilience within Abu Dhabi Global Market (ADGM), the Financial Services Regulatory Authority (FSRA) introduced new Cyber Risk Management Rules for Authorised Persons and Recognised Bodies. The requirements […]
Continue Reading
Regulatory Gap Assessment | Framework & Governance Design | RCSA & KRI Implementation | Critical Operations Mapping | Operational Resilience | BCM & DR | ICT & Cybersecurity Resilience | Third-Party Risk | Regulatory Reporting | Independent Validation & Training.

CBUAE Operational Risk Management Regulation 2026: Are UAE Financial Institutions Ready?

The Central Bank of the UAE (CBUAE) Operational Risk Management Regulation – Circular No. 1/2026 introduces enhanced requirements for Licensed Financial Institutions (LFIs) to establish a comprehensive Operational Risk and Operational Resilience framework. The regulation becomes effective on 14 September 2026. For LFIs, this means moving beyond traditional risk management and ensuring that operational resilience […]
Continue Reading
VAPT Services in UAE: Protect Your Business & Meet Regulatory Requirements.

VAPT Services in UAE: Regulatory Requirements, Compliance & Security Testing

As UAE organizations accelerate digital transformation, cloud adoption, and online services, cybersecurity risks continue to increase. A single vulnerability in a network, application, API, or cloud environment can lead to data breaches, financial loss, operational disruption, and regulatory non-compliance. Vulnerability Assessment and Penetration Testing (VAPT) helps organizations identify and validate security weaknesses before attackers can […]
Continue Reading
DESC ISR compliance, ISO 27001 to DESC ISR mapping, Cybersecurity compliance UAE

DESC ISR: What It Is, Who Must Comply, and How It Maps to ISO 27001

Dubai’s cybersecurity landscape is evolving rapidly, and organizations operating within the emirate’s government ecosystem are expected to keep pace. The Dubai Electronic Security Centre (DESC)  Dubai’s dedicated cybersecurity authority enforces the Information Security Regulation (ISR v3.1), a comprehensive thirteen-domain framework that sets the mandatory baseline for information security governance, risk management, and control implementation across […]
Continue Reading