Clinics, dental, physiotherapy and imaging
If the practice system is encrypted on a Tuesday morning, how long until we see patients again?
The practice system, the imaging software and the patient archive, mapped to the DHA policies and NABIDH terms, with a backup you have watched restore.
Every DHA-licensed facility falls under the DHA data policies and NABIDH terms; the private-clinic strips of Jumeirah, Al Barsha and Deira are dense with practices that run on one server.
How we work with clinics, dental, physiotherapy and imaging →Free-zone professional services
Our clients send us their most sensitive files. What happens the day one of them asks for our security evidence?
Client files, email and the accounts inbox, the AML and PDPL duties you carry, and the ISO 27001 readiness that tenders in DIFC and JLT now ask for.
DIFC firms answer to the DIFC data-protection regime and, where DFSA-authorised, a 72-hour cyber-incident clock; the mid-market firms of Business Bay and JLT inherit their clients’ questionnaires.
How we work with free-zone professional services →Retail, e-commerce and hospitality
The checkout page, the loyalty database and the guest passports: which one gets us into trouble first?
Card flows under PCI DSS v4, customer and guest data under the PDPL, and the delivery-app and booking integrations that are third-party risk.
Wholesale and retail trade has long been Dubai’s largest licence category, from Deira’s trading houses to the malls and the delivery apps.
How we work with retail, e-commerce and hospitality →Fintech, payments and virtual assets
We hold a licence and a 72-hour clock. Do we know what we would report, and to whom, by hour twelve?
One control set behind CBUAE, DFSA or VARA rules and the PDPL, with the evidence and the incident plan ready before the clock starts.
DIFC, the onshore payment licensees and the VARA-regulated firms sit within a few kilometres of each other and share the same attackers; the region’s largest crypto theft happened here in 2025.
How we work with fintech, payments and virtual assets →Architecture and design studios
If someone encrypts thirty years of drawings, what do we do on day one?
The drawing archive and BIM models, the bids, client data under the PDPL, and the supplier bank-change fraud aimed at the accounts inbox.
Al Quoz, Business Bay and Dubai Design District hold hundreds of studios whose entire value is a file server and whose government projects bring DESC clauses into the contract.
How we work with architecture and design studios →Suppliers to Dubai government
The tender says DESC. What does that mean for a forty-person software company, and by when?
ISR v3 and CSP Security Standard alignment as one control set with ISO 27001 and the PDPL, so the evidence is produced once and the tender answer is a report you already have.
Any vendor hosting or processing Dubai government data faces the DESC standards as a contract condition; Dubai Internet City and Silicon Oasis are full of firms meeting that clause for the first time.
How we work with suppliers to dubai government →Clinics, dental, physiotherapy and imaging practices
An AccuSights engineer can visit the practice in Dubai to scope and verify the critical controls.
Scoping and verification in the practice: what runs where, who can reach the patient archive, whether the backup restores, and which health-authority rules apply. We verify and scope; we do not change your systems. You or your IT partner fix, and the read-only agent shows the controls holding afterwards. Staff trained the same month, no per-module charges.
Book the practice visit