We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO

Blog / UAE compliance

UAE compliance

GISEC Global 2026: Five Conversations a UAE Regulated Business Should Have on the Floor

GISEC Global 2026 runs 16 to 18 September in Dubai. The five conversations a UAE regulated business should have on the floor, and what to bring home.

Sam KhanSam Khan The Cyber ExpertFounder and CEO14 September 2026 · 6 min read

Three days, forty conversations, nothing written down

The IT manager of a 120-person facilities management company in Al Quoz has a GISEC badge and a plan that consists of the word "network". His company services towers across Dubai, holds building access data for a few thousand tenants, and has just been sent a security questionnaire by a client who owns four of those towers. Question 14 asks which national frameworks the company aligns to. He does not know.

He walks the halls for two days. Forty vendors scan his badge. He collects a rollable water bottle, three notebooks and a small mountain of PDFs about platforms that promise to make compliance simple. On the flight of stairs to the metro on Thursday evening he realises he never once said the words "building access data" out loud to anyone.

Back at the office he has 40 sales emails and the same blank on question 14.

The show is not the problem. He went as a shopper. The people who come back with something useful go as investigators, with a one-page brief about their own business and five questions they refuse to leave without answering.

What the heck is on that floor, in plain terms

GISEC Global 2026 runs 16 to 18 September 2026 in Dubai. It is the region's largest cybersecurity gathering, and for a UAE business the useful part is not the product halls. It is that the regulators, the standards bodies and the assessors are all in one building for three days.

A regulator sets the rules for your sector: the Dubai Health Authority for a Dubai clinic, the Department of Health for Abu Dhabi, the Central Bank for a finance house, DESC for a Dubai government supplier, the Data Office for personal data under the PDPL.

An assessor is the independent party who checks your work against a standard.

A provider sells you a product or a service. Not the same thing as an assessor, and worth keeping separate in your head as you walk.

NCAP is the national accreditation programme run by the Cyber Security Council, built on the UAE Information Assurance Standard v2 (2025). There is no public register and no published deadlines yet, so treat any claim of accreditation on a stand as a claim you verify later.

The numbers that matter

Third parties were involved in 48 percent of breaches in the Verizon 2026 Data Breach Investigations Report, up 60 percent on the previous year. Every stand you visit is asking to become one of your third parties. That statistic is the reason the vendor conversation should end with a scope and an evidence sample rather than a signature.

Shadow AI was present in 43 percent of breaches studied in IBM's 2026 Cost of a Data Breach report, and 68 percent of the organizations in it had no AI policy at all. Half the floor this year will be selling AI features. Somebody in your company is already pasting data into a consumer AI chatbot, which is the conversation worth having before you buy anything.

The human element was involved in 62 percent of breaches in the Verizon 2026 report. No product on that floor changes that number by itself. Ask every vendor what their tool does when a trusted employee does the wrong thing on a Tuesday morning, and listen for a real answer.

What to do this week

  1. Write the one-page brief before you go: entity type, licence and free zone, what data you hold, where it is stored, which cloud services touch it, and who your three most important suppliers are. Every good conversation at the show starts from that page. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Visit the regulator stands first, before the product halls, and ask which rulebooks apply to your entity as you described it. Use the UAE regulator directory to plan the route so you are not deciding at a floor map. (CIS 3 Data Protection)
  3. Ask the accreditation question properly. Not "are you accredited" but "which standard, assessed by whom, and can I see the scope". Read the NCAP page beforehand so you know what the programme is built on and what is not published yet. (CIS 15 Service Provider Management)
  4. Take your own supplier questionnaire with you and hand it to the three vendors you are seriously considering. The one who answers it within a week is telling you something the brochure cannot. (CIS 15 Service Provider Management)
  5. Have the AI conversation with your own team, not a stand. Which tools are staff using, with what data, under whose account. The UAE AI Charter of June 2024 sets the direction; your policy is the part only you can write. (CIS 3 Data Protection)
  6. Book the debrief for the Sunday after the show, one hour, with the answers written up while they are fresh. A show with no debrief is a holiday with a lanyard. (CIS 1 Inventory and Control of Enterprise Assets)

Where AccuSights fits

Our assessment maps your business against the regulators that actually apply to you, in the order they matter, so a questionnaire like question 14 has an answer on file. The read-only compliance agent then gives you continuing insight into where your data sits and which controls are missing, so you can prioritise and keep an eye on them. We have no access to your systems and we do not remediate. You or your IT partner fix; we show you where. A falcon over the creek watches everything and singles out the one thing worth moving for.

Questions people ask

Is GISEC worth three days for a company with no security team? One day is worth it if you go with questions instead of a tote bag. The value is not the keynote stage; it is the fifteen minutes you get with a regulator liaison, an assessor and two providers in the same afternoon, which would take six weeks of emails otherwise. Book the meetings before you arrive and leave the rest of the day open.

Can I ask a regulator's stand a direct question about my own business? Yes, and it is the single best use of the floor. Bring one page describing your entity, your licence, where your data sits and who processes it, and ask which rulebooks apply to you. Write down the answer and the name of the person who gave it. That page becomes the first exhibit in your own compliance file.

Should I sign anything at the show? No. Show pricing that expires on Thursday is a sales technique, not a discount. Collect scopes, evidence samples and reference calls, then decide the following week when you can compare them side by side against the obligations you actually carry.

The badge gets you through the door. The one-page brief in your jacket is what decides whether you come home with anything.

Questions people ask

Is GISEC worth three days for a company with no security team?

One day is worth it if you go with questions instead of a tote bag. The value is not the keynote stage; it is the fifteen minutes you get with a regulator liaison, an assessor and two providers in the same afternoon, which would take six weeks of emails otherwise. Book the meetings before you arrive and leave the rest of the day open.

Can I ask a regulator's stand a direct question about my own business?

Yes, and it is the single best use of the floor. Bring one page describing your entity, your licence, where your data sits and who processes it, and ask which rulebooks apply to you. Write down the answer and the name of the person who gave it. That page becomes the first exhibit in your own compliance file.

Should I sign anything at the show?

No. Show pricing that expires on Thursday is a sales technique, not a discount. Collect scopes, evidence samples and reference calls, then decide the following week when you can compare them side by side against the obligations you actually carry.

Controls this post maps to

CIS 15 Service Provider ManagementCIS 1 Inventory and Control of Enterprise AssetsCIS 3 Data Protection

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.