We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Abu Dhabi · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

In Abu Dhabi you are a link in someone’s chain. Let us make sure you are not the weak one.

A clinic under ADHICS, an engineering contractor in Mussafah serving an energy operator, a fintech on Al Maryah Island with a 24-hour clock, a supplier to a government entity: Abu Dhabi businesses answer to serious rulebooks and to clients who check. We assess the business in plain language, map what applies, ADHICS, ADGM, the UAE IA Standard or the PDPL, and keep the picture current with a read-only compliance agent. You or your IT partner fix; we show you where.

A Dubai mainland company with a US practiceEngineer on site for practicesStaff training includedRead-only by design

Serving Al Maryah Island (ADGM), Mussafah and ICAD, Masdar City, Khalifa City and Al Reem Island, KEZAD and Khalifa Port, Al Ain, Al Ruwais. Remote first, on site when it matters.

A Abu Dhabi story

The week the progress claim went to the wrong bank

The managing director of a seventy-person engineering services contractor in Mussafah, supplier to an energy operator and to one government entity

It is a Thursday in March and the finance manager is closing the month. A progress claim on a maintenance contract, 1.4 million dirhams, was approved on Monday. The client’s accounts team writes to say the bank details on the invoice changed last week and they paid the new account.

Nobody in the company changed anything. Someone read the finance inbox for six weeks, learned who signs what, and sent one email from a lookalike domain with a new IBAN on the letterhead. The client’s supplier-risk team now wants the incident report, the access logs and the last assessment. There is no last assessment.

By Sunday the ERP is encrypted as well, from the same stolen login. The site engineers keep working from paper. The prequalification for the next tender asks whether the company has had a security incident in the last twelve months.

The finance inbox had one password, no second factor, and the same password as the ERP.

What changes the ending

  1. 1Multi-factor authentication on email and the ERP, separate admin accounts, and a leaver process that runs the same day (CIS Controls 5 and 6).
  2. 2A payment-change rule: any new bank details are confirmed by phone on a known number, and every client is told so in writing (CIS Control 14).
  3. 3Central logs that someone actually reads, and an isolated backup tested by restoring the ERP (CIS Controls 8 and 11).
Show me how this runs for my business
Your clients in Abu Dhabi are energy operators, hospitals and government entities, and they will ask for your evidence sooner or later. So here is the question I ask every owner here: what price are you willing to pay to let ten years of building go away because someone overseas tricked one person on your team into clicking a link? Put a number on it. Then compare it with the cost of the three fixes above.

Sam Khan, founder. CISA, CRISC.

Abu Dhabi, by the numbers

What the Council, the regulators and the researchers counted, not what a vendor guessed.

692

controls in the Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS), 162 primary and 530 secondary, across 11 domains

Source: Department of Health Abu Dhabi, ADHICS FAQ

3,144

health facilities connected to Malaffi, the Abu Dhabi health information exchange, including 100% of hospitals

Source: Malaffi homepage counter, read 2 September 2026

24 hours

the cyber-incident notification window under the ADGM FSRA Cyber Risk Management Framework, in force since 31 January 2026

Source: ADGM FSRA, 2026

The regulators and their clocks

Abu Dhabi Healthcare Information and Cyber Security Standard (ADHICS) v2

Every DoH-licensed facility and payer, in Basic, Transitional and Advanced tiers; hospitals with 21 or more beds and payers meet all three. Incident reporting to the DoH as the standard prescribes, evidence at licence renewal, and Malaffi participation as a DoH duty.

Regulator: Department of Health Abu Dhabi · our page · official source

ADGM Data Protection Regulations 2021 and the FSRA Cyber Risk Management Framework

ADGM entities notify the Office of Data Protection within 72 hours of a personal-data breach and renew annually. FSRA-authorised firms hold a board-approved cyber programme reviewed annually and notify the FSRA of a cyber incident within 24 hours; the framework has been in force since 31 January 2026.

Regulator: ADGM Office of Data Protection and the FSRA · official source

UAE Information Assurance Standard v2, the CIIP Policy and NCAP

The national baseline for government entities and critical operators, flowing by contract to their suppliers. NCAP accreditation of government entities, cybersecurity providers and training organizations is rolling out through 2026; deadlines and assessor lists were not public as of September 2026.

Regulator: UAE Cyber Security Council and TDRA · our page · official source

Federal Personal Data Protection Law, Federal Decree-Law 45 of 2021 (PDPL)

Notify the UAE Data Office on becoming aware of a breach that threatens privacy; the law sets no fixed hour count. The Implementing Regulations had not been issued as of September 2026, so scope and detail are still being clarified.

Regulator: UAE Data Office · our page · official source

Federal Law 2 of 2019 on the use of ICT in health fields

Health data stays inside the UAE unless a health-authority decision permits otherwise. It applies to every clinic, laboratory and health-data processor in every emirate.

Regulator: Ministry of Health and Prevention, with the emirate health authorities · our page · official source

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

It happened here

Passports and identity documents of more than 700 delegates to Abu Dhabi Finance Week were exposed on an unprotected cloud server; organisers said the breach was limited and quickly secured. The lesson is cloud configuration, not the event.

February 2026 · The National

The Cyber Security Council confirmed that 634 UAE public and private entities were targeted through a global cloud credential leak and that the attacks were thwarted; no entity was named.

March 2025 · The National

The Cyber Security Council confirmed it repelled a coordinated campaign against aviation, energy and education; energy is Abu Dhabi’s core sector and no entity was named.

August 2026 · Gulf News

We list public reports to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Abu Dhabi

Same controls, told from where it hurts for your business.

Clinics, dental, physiotherapy and imaging under DoH

ADHICS has 692 controls and our licence renewal is in nine months. Which fifty matter for a clinic our size?

The ADHICS tier that applies to you, mapped once to the practice system, Malaffi connection and the patient archive, with evidence kept current by the read-only agent so renewal is a report, not a project.

All DoH-licensed facilities and payers fall under ADHICS, and 3,144 facilities are connected to Malaffi; the clinic-dense districts of Khalifa City and Al Reem are where the standard meets a single server.

How we work with clinics, dental, physiotherapy and imaging under doh

Suppliers to government entities

Our government client’s contract now cites the UAE IA Standard. What does a sixty-person supplier actually have to show?

Your position against the IA Standard v2 families, the always-applicable controls first, one evidence set that also answers NCAP and any sector rulebook you carry.

Abu Dhabi government entities work under the Abu Dhabi Digital Authority’s standards and the national IA baseline, and both flow by contract to suppliers; NCAP accreditation is rolling out through 2026.

How we work with suppliers to government entities

Energy-sector and defence suppliers

The operator’s supplier-risk team sent a 140-question security questionnaire. Who answers it, and what happens when they audit the answers?

The questionnaire answered from evidence rather than hope: OT and ERP separation, remote access, payment controls and incident readiness, kept current between audits by the read-only agent. CMMC readiness where a US prime is in the chain.

Mussafah, ICAD and Al Ruwais hold the energy operator’s contractor base, and Tawazun-managed defence procurement sets supplier security expectations by contract; a Mussafah supplier is a link in a national chain.

How we work with energy-sector and defence suppliers

Financial firms under ADGM

The FSRA framework gives us 24 hours to notify. Do we know what we would say by hour six?

A board-approved cyber programme that is real, the 24-hour and 72-hour notification playbooks written in advance, and the evidence kept continuous for the annual review.

Al Maryah Island is ADGM: FSRA-authorised firms, fintechs and virtual-asset firms under a framework that has been in force since 31 January 2026.

How we work with financial firms under adgm

Construction and industrial firms

Our ERP, our site tablets and our progress claims all run through one office. What stops one stolen password from stopping the project?

Identity and access on the ERP and email, the payment-change rule, an isolated backup restored on a timer, and the prequalification evidence developers and KEZAD tenants now ask for.

Mussafah and KEZAD are the fabrication and logistics belt, running on on-premise ERP and thin site IT; payment-diversion fraud targets exactly the progress-claim flow.

How we work with construction and industrial firms

Clinics, dental, physiotherapy and imaging practices

An AccuSights engineer can visit the practice in Abu Dhabi to scope and verify the critical controls.

Scoping and verification in the practice: what runs where, who can reach the patient archive, whether the backup restores, and which health-authority rules apply. We verify and scope; we do not change your systems. You or your IT partner fix, and the read-only agent shows the controls holding afterwards. Staff trained the same month, no per-module charges.

Book the practice visit

Your staff, trained and scored

It is all right to skip the suspicious email. Next time, press the report button too.

Every plan includes staff awareness and phishing training, scored per person and per team, with no per-module charges. Short monthly sessions tied to what is hitting businesses this month, phishing tests that teach one habit, and a report button beside the inbox. It is all right to skip the suspicious email. Next time, report it too; one report protects the whole company.

  • Short monthly training tied to the threats hitting businesses this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand, with no per-module charges.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade discipline, engineers who answer the phone, and a team that built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a business in Abu Dhabi

Assess it, map it to your regulators, keep an eye on it.

Assess

Cybersecurity and Data Protection Assessment

For any business, regulated or not: an architecture studio, a design firm, a retailer, a trading company. Where the money, the records and the files actually live, what would stop the business for a week, and the ten fixes that matter first, mapped to any regulator that applies to you.

Details

Comply

Compliance readiness mapped to your regulators

ADHICS, DHA, MOHAP, DESC, DIFC, ADGM, the UAE IA Standard or the PDPL: one control set, evidence produced once, ready the day a regulator, a client or an insurer asks. The regulator has the final say; we get you ready for it.

Details

Keep an eye on it

The read-only compliance agent

Read-only insight so you prioritize the right things and keep an eye on them. We have no access to your systems and we do not remediate. You or your IT partner fix; we show you where, then we check again, and repeat.

Details

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital group decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it inside those institutions. We now run it for the medium-size supplier, the clinic and the government supplier, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one organization.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a government client or a bank asks for, produced once and kept current by the read-only compliance agent.

A supplier to a government entity or a bank is a link in a chain. A breach there is not a small-business story; it reaches the entity, its customers and the people who depend on it. The same is true, at a smaller scale, for the accounting firm that holds nine hundred client files and the clinic that holds twelve thousand patient records.

Questions owners in Abu Dhabi ask

What people search for, answered straight.

What is ADHICS compliance and who must comply?

ADHICS is the Abu Dhabi Healthcare Information and Cyber Security Standard, published by the Department of Health. Version 2 carries 692 controls across 11 domains, applied in Basic, Transitional and Advanced tiers depending on the size and type of facility. Every DoH-licensed facility and payer is in scope, from a two-room dental clinic to a hospital group, and evidence is expected at licence renewal. The DoH’s own process governs; we map you to the tier that applies and keep the evidence current.

What does ADHICS v2 require, and how is it checked?

The standard covers governance, asset management, access control, operations, communications, third parties, incident management and the other domains you would expect, with the primary controls required across tiers and the secondary controls added as the tier rises. The DoH publishes the standard and an implementation guideline; Malaffi participation and incident reporting to the DoH are duties in their own right. Our assessment reads the same documents and turns them into a plain-language gap list for your facility, with the ten fixes that close the most controls first.

What is the ADGM FSRA Cyber Risk Management Framework and when did it start?

The FSRA framework has been in force since 31 January 2026 for FSRA-authorised firms. It asks for a board-approved cyber programme reviewed annually and for cyber-incident notification to the FSRA within 24 hours. Separately, the ADGM Data Protection Regulations 2021 ask for personal-data breach notification to the Office of Data Protection within 72 hours. We write both playbooks with you before you need them and keep the programme evidence continuous with the read-only agent.

Is NESA the same as the UAE IA Standard?

Yes, in practice. The standard people still call NESA is the UAE Information Assurance Standard, now in version 2, published in 2025 by the UAE Cyber Security Council with the TDRA regulation behind it. It is the baseline for government entities and critical operators, and it flows by contract to their suppliers. If a tender or a client cites NESA, the IA Standard v2 families are what you map to.

Do energy-sector and defence suppliers in Abu Dhabi need a cybersecurity certification?

There is no single mandated certificate. The expectations arrive through the operator’s supplier-risk questionnaires, Tawazun contract terms, the UAE IA Standard where the client is government or critical infrastructure, and, for subcontractors of a US prime handling federal contract information, the US CMMC program. ISO 27001 is the certificate most often asked for in prequalification. We build one control set that answers all of them and keep the evidence ready between audits.

Can an engineer come to my clinic in Abu Dhabi?

Yes. An AccuSights engineer can visit the practice in Abu Dhabi to scope and verify the critical controls: what runs where, who can reach the patient archive, whether the backup restores, and which ADHICS tier applies. We verify and scope; we do not change your systems. You or your IT partner make the fixes, and the read-only agent shows the controls holding afterwards.

Sources: Department of Health Abu Dhabi: ADHICS v2 standard · Malaffi · ADGM Office of Data Protection · ADGM FSRA · UAE Cyber Security Council · The National: Abu Dhabi Finance Week data breach (February 2026) · The National: 634 entities targeted (March 2025)

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

Never too big or too small

Thirty minutes with an engineer. Bring your questions, leave with a scope and a number.

Book the call and we walk through a business like yours: what applies, what to fix first, and what the read-only agent would show you every week. Or leave your details and an engineer in our Dubai practice replies within one business day, in English or Arabic.