Blog / UAE compliance

UAE compliance

Sharjah Factories and the 68-Question Supplier Form: The Old Server, the Flat Network and the March Renewal

Sharjah factory cybersecurity: the supplier questionnaire, the 2014 ERP server and the flat OT network, and the checks to run before a customer asks.

Sam KhanSam Khan The Cyber ExpertFounder and CEO24 September 2026 · 6 min read

The questionnaire arrives on a Thursday

The production manager of a family metal fabrication plant in Sharjah Industrial Area has been there since the second generation ran the place. Eighty-two people. Laser cutters, three press brakes, a paint line, and a customer list built on being the supplier who does not miss a delivery date.

On a Thursday morning the procurement lead at a Jebel Ali logistics contractor sends a PDF. Sixty-eight questions, headed "Supplier Information Security Assessment", to be returned within fifteen working days. Question nine asks whether operational technology is separated from the corporate network. Question twenty-two asks for the patching cycle on anything reachable from the internet. Question forty-one asks for a named contact for security incidents.

He forwards it to the IT contractor, who comes two days a week and looks after the printers and the ERP. The reply is a shrug in written form: "We have antivirus and the firewall from the telco."

The ERP runs on a Windows server bought in 2014 and moved once, into a cupboard behind the QA office. The CNC scheduling PC has one login that everybody uses, because production does not stop for a password. The paint line controller sits on the same flat network as the accounts department's printer.

Nothing is on fire. The contract renewal in March is what is on fire, and question nine is now attached to it.

What the heck does this mean

Operational technology, usually shortened to OT, is the equipment that makes things: controllers, drives, the panel on the paint line, the PC that feeds programs to a CNC machine. It was designed to run for fifteen years without being touched, which is why it is rarely patched and often still speaks to the network in plain text.

A flat network means every device can reach every other device. The accounts PC can reach the paint line controller. That is convenient for the IT contractor and convenient for anyone who gets a foothold in accounts.

Segmentation is putting a wall between the two, so a problem in the office cannot walk onto the shop floor.

A supplier security questionnaire is the customer passing their own obligations down the chain. Their regulator or their insurer asked them; they are asking you.

The UAE Personal Data Protection Law covers the personal data you hold, which for a factory is mostly HR: passports, contracts, insurance files, salaries. The National Cybersecurity Assurance Programme, built on the UAE Information Assurance Standard v2 of 2025, has been rolling out during 2026 with no public register and no published deadlines for a private manufacturer.

The numbers that matter

Ransomware showed up in 61 percent of manufacturing breaches, the highest of any sector, according to the Verizon 2026 Data Breach Investigations Report. A plant that stops is a plant that pays.

The same Verizon 2026 report puts vulnerability exploitation behind 38 percent of manufacturing breaches, which is the polite way of saying the 2014 server in the cupboard is the front door.

Third parties were involved in 48 percent of breaches in the Verizon 2026 report, a rise of 60 percent on the previous year. That is exactly why your customer sent sixty-eight questions instead of trusting you.

What to do this week

  1. Draw the network on one sheet of A3. Every switch, every wireless access point, the telco router, the machines on the shop floor, and every link between the office and the plant. Nobody can answer question nine from memory, and the drawing usually finds two connections nobody knew existed. (CIS 12 Network Infrastructure Management)
  2. Build the asset list from that drawing: every server, PC, controller, tablet and phone that touches the business, with an owner's name and the operating system it runs. Include the machines the vendor installed and still dials into. (CIS 1 Inventory and Control of Enterprise Assets)
  3. Find everything reachable from the internet and patch it first: the router, the firewall, the remote access the ERP vendor uses, the CCTV recorder. The Verizon 2026 report found a median of 43 days to patch a known exploited vulnerability, and attackers are quicker than that. (CIS 7 Continuous Vulnerability Management)
  4. Put one wall between the office network and the shop floor, even a simple one. If the paint line controller and the accounts printer must talk, write down why. If they do not, stop them. (CIS 12 Network Infrastructure Management)
  5. Test a restore, not a backup. Pick the ERP database, restore it to a spare machine, and time it. The answer to "how long would we be down" should be a number somebody has measured, not a hope. (CIS 11 Data Recovery)
  6. Answer the sixty-eight questions truthfully, with a date next to every gap, and name a person for question forty-one. Send it back early. Procurement teams remember the supplier who was clear far longer than they remember the supplier who scored well. (CIS 1 Inventory and Control of Enterprise Assets)

Where AccuSights fits

We assess a plant against the regulators that apply to it, PDPL for the personal data and the UAE Information Assurance Standard controls underneath NCAP, and hand back the questionnaire answers with the evidence behind each one. Our read-only compliance agent gives continuous insight into what is running across your office and plant systems. We have no access and we do not remediate. Your IT partner fixes; we show you where, and in what order. A falcon picks one thing out of the noise and holds it. Start with our Sharjah cybersecurity page.

Questions people ask

Does the UAE PDPL apply to a factory that only holds employee and customer contact data? Yes. The PDPL is about personal data, not about what your company makes. Passport copies in the HR folder, labour contracts, medical insurance files, driver details and the customer contacts in your ERP are all personal data, and the obligation to protect them does not scale down because you make brackets rather than apps. A factory of eighty people usually holds more personal data in HR than it does anywhere else.

Do we have to segment the OT network before we can answer a supplier questionnaire? No, but you do have to answer question nine truthfully. A customer will accept a plan with a date far more often than they will accept a blank. Write down what is flat today, what you will separate first, and when. The answer that ends contracts is the one that turns out to be untrue after an incident, not the one that admits work is in progress.

What does NCAP require of a manufacturer in Sharjah, and by when? The National Cybersecurity Assurance Programme is built on the UAE Information Assurance Standard v2 of 2025 and has been rolling out through 2026. There is no public register and no published deadline for a private manufacturer, so anyone quoting you a date is guessing. Build against the IA Standard controls now and you will be ready when the scope and timing are published.

Your grandfather's machines will outlive the server in the cupboard. Treat the server as the part of the plant that needs the most maintenance, because it is.

Questions people ask

Does the UAE PDPL apply to a factory that only holds employee and customer contact data?

Yes. The PDPL is about personal data, not about what your company makes. Passport copies in the HR folder, labour contracts, medical insurance files, driver details and the customer contacts in your ERP are all personal data, and the obligation to protect them does not scale down because you make brackets rather than apps. A factory of eighty people usually holds more personal data in HR than it does anywhere else.

Do we have to segment the OT network before we can answer a supplier questionnaire?

No, but you do have to answer question nine truthfully. A customer will accept a plan with a date far more often than they will accept a blank. Write down what is flat today, what you will separate first, and when. The answer that ends contracts is the one that turns out to be untrue after an incident, not the one that admits work is in progress.

What does NCAP require of a manufacturer in Sharjah, and by when?

The National Cybersecurity Assurance Programme is built on the UAE Information Assurance Standard v2 of 2025 and has been rolling out through 2026. There is no public register and no published deadline for a private manufacturer, so anyone quoting you a date is guessing. Build against the IA Standard controls now and you will be ready when the scope and timing are published.

Controls this post maps to

CIS 12 Network Infrastructure ManagementCIS 1 Inventory and Control of Enterprise AssetsCIS 7 Continuous Vulnerability Management

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.