We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Dubai · Cybersecurity, compliance and GRC for businesses that cannot afford a bad week

You built it in Dubai. Let us make sure one email cannot take it away.

A clinic in Jumeirah, a design studio in Al Quoz, a trading house in Deira and a software supplier to a Dubai government entity all face the same attacker and answer to different rulebooks. We are a Dubai mainland company with a US practice. We assess the business in plain language, map what applies to you, DHA, DESC, DIFC, VARA or the PDPL, and keep the picture current with a read-only compliance agent. You or your IT partner fix; we show you where.

A Dubai mainland company with a US practiceEngineer on site for practicesStaff training includedRead-only by design

Serving DIFC, Business Bay, JLT and Dubai Internet City, Dubai Healthcare City, Jumeirah and Al Barsha, Deira and Bur Dubai, Al Quoz, Jebel Ali and Dubai South. Remote first, on site when it matters.

A Dubai story

The Tuesday the appointment book went blank

The owner of a fourteen-chair dental and physiotherapy clinic in Jumeirah, DHA-licensed, connected to NABIDH

It is a Tuesday in October and the clinic opens at eight. Reception logs in and the practice system asks for a password nobody set. The appointment book is blank. Twelve patients are due before noon and the X-ray software will not open. The dentist is already gowned for the first patient.

The owner finds the note on the server: pay within seventy-two hours or the patient files go online. Eleven years of records. Emirates ID copies, insurance claims, the photographs before and after. NABIDH is untouched; the clinic’s own copy is not.

The IT company that installed the system answers on the third call. The backup runs to a drive inside the server cabinet, and it is encrypted too. Nobody has ever tried restoring it. At eleven the insurer asks for the claims batch that was due on Monday.

On Saturday the receptionist clicked an email that looked like a licence renewal reminder.

What changes the ending

  1. 1An isolated backup with a tested restore, so Tuesday is a restore and not a negotiation (CIS Control 11).
  2. 2Multi-factor authentication on email and the practice system, and admin rights taken off the reception PC (CIS Controls 5 and 6).
  3. 3Staff trained monthly and scored, with the report button beside the inbox; one report on Saturday ends the story (CIS Control 14).
Show me how this runs for my business
You built this in a city that rewards the people who show up every day. So here is the question I ask every owner in Dubai: what price are you willing to pay to let ten years of building go away because someone overseas tricked one person on your team into clicking a link? Put a number on it. Then compare it with the cost of the three fixes above.

Sam Khan, founder. CISA, CRISC.

Dubai, by the numbers

What the Council, the regulators and the researchers counted, not what a vendor guessed.

600,000

attacks a day countered nationally in 2026, up from about 200,000 a day the year before

Source: UAE Cyber Security Council via Gulf News, August 2026

nearly 60%

of the daily attacks on the UAE are aimed at Dubai, Abu Dhabi and Sharjah together

Source: UAE Cyber Security Council via Khaleej Times, October 2025

42%

of breaches in the region begin with an unpatched flaw, the most fixable problem in security

Source: Verizon 2026 Data Breach Investigations Report, EMEA

The regulators and their clocks

Federal Personal Data Protection Law, Federal Decree-Law 45 of 2021 (PDPL)

Notify the UAE Data Office on becoming aware of a breach that threatens privacy; the law sets no fixed hour count. The Implementing Regulations had not been issued as of September 2026, so scope and detail are still being clarified.

Regulator: UAE Data Office · our page · official source

Dubai Health Data Law 11 of 2018, the DHA Health Data Protection and Confidentiality Policy (2022) and the DHA Standards for Health Information Consent and Access Control (January 2025)

Every DHA-licensed facility and every health-data processor in Dubai, including NABIDH participants. Facilities inside Dubai Healthcare City answer to the DHCC regulator instead.

Regulator: Dubai Health Authority · our page · official source

Dubai Information Security Regulation (ISR) v3 and the Cloud Service Provider Security Standard

Dubai government entities and any cloud or service provider that hosts or processes their data; certification and data-residency requirements are contract conditions, and suppliers report incidents through their government client.

Regulator: Dubai Electronic Security Center (DESC) · our page · official source

DIFC Data Protection Law No. 5 of 2020 and DFSA Rulebook GEN 5.5

DIFC entities notify the Commissioner of Data Protection as soon as practicable; DFSA-authorised firms also notify the DFSA of a cyber incident within 72 hours.

Regulator: DIFC Commissioner of Data Protection and the DFSA · official source

Federal Law 2 of 2019 on the use of ICT in health fields

Health data stays inside the UAE unless a health-authority decision permits otherwise. It applies to every clinic, laboratory and health-data processor in every emirate.

Regulator: Ministry of Health and Prevention, with the emirate health authorities · our page · official source

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. Much regulator language is still being clarified, and we say so rather than guess. We help interpret the requirements, scope what applies to you, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify; where a regulator has its own process, that process governs.

It happened here

A Dubai-based cryptocurrency exchange lost roughly USD 1.5 billion in Ether from a cold wallet, the largest crypto theft on record; the FBI attributed it to North Korea within a week.

February 2025 · Reuters

A ransomware group claimed to have stolen patient records from a private hospital in Dubai; the claim was not confirmed by the hospital or the DHA, which is exactly why every clinic should know what its own logs would show.

June 2025 · Bloomberg via Yahoo News

The Cyber Security Council confirmed it repelled a coordinated multi-vector campaign against aviation, energy and education, the third sector-wide campaign disclosed in 2026.

August 2026 · Gulf News

We list public reports to show the pattern, never to shame a victim. Any of them could be any of us.

Who we protect in Dubai

Same controls, told from where it hurts for your business.

Clinics, dental, physiotherapy and imaging

If the practice system is encrypted on a Tuesday morning, how long until we see patients again?

The practice system, the imaging software and the patient archive, mapped to the DHA policies and NABIDH terms, with a backup you have watched restore.

Every DHA-licensed facility falls under the DHA data policies and NABIDH terms; the private-clinic strips of Jumeirah, Al Barsha and Deira are dense with practices that run on one server.

How we work with clinics, dental, physiotherapy and imaging

Free-zone professional services

Our clients send us their most sensitive files. What happens the day one of them asks for our security evidence?

Client files, email and the accounts inbox, the AML and PDPL duties you carry, and the ISO 27001 readiness that tenders in DIFC and JLT now ask for.

DIFC firms answer to the DIFC data-protection regime and, where DFSA-authorised, a 72-hour cyber-incident clock; the mid-market firms of Business Bay and JLT inherit their clients’ questionnaires.

How we work with free-zone professional services

Retail, e-commerce and hospitality

The checkout page, the loyalty database and the guest passports: which one gets us into trouble first?

Card flows under PCI DSS v4, customer and guest data under the PDPL, and the delivery-app and booking integrations that are third-party risk.

Wholesale and retail trade has long been Dubai’s largest licence category, from Deira’s trading houses to the malls and the delivery apps.

How we work with retail, e-commerce and hospitality

Fintech, payments and virtual assets

We hold a licence and a 72-hour clock. Do we know what we would report, and to whom, by hour twelve?

One control set behind CBUAE, DFSA or VARA rules and the PDPL, with the evidence and the incident plan ready before the clock starts.

DIFC, the onshore payment licensees and the VARA-regulated firms sit within a few kilometres of each other and share the same attackers; the region’s largest crypto theft happened here in 2025.

How we work with fintech, payments and virtual assets

Architecture and design studios

If someone encrypts thirty years of drawings, what do we do on day one?

The drawing archive and BIM models, the bids, client data under the PDPL, and the supplier bank-change fraud aimed at the accounts inbox.

Al Quoz, Business Bay and Dubai Design District hold hundreds of studios whose entire value is a file server and whose government projects bring DESC clauses into the contract.

How we work with architecture and design studios

Suppliers to Dubai government

The tender says DESC. What does that mean for a forty-person software company, and by when?

ISR v3 and CSP Security Standard alignment as one control set with ISO 27001 and the PDPL, so the evidence is produced once and the tender answer is a report you already have.

Any vendor hosting or processing Dubai government data faces the DESC standards as a contract condition; Dubai Internet City and Silicon Oasis are full of firms meeting that clause for the first time.

How we work with suppliers to dubai government

Clinics, dental, physiotherapy and imaging practices

An AccuSights engineer can visit the practice in Dubai to scope and verify the critical controls.

Scoping and verification in the practice: what runs where, who can reach the patient archive, whether the backup restores, and which health-authority rules apply. We verify and scope; we do not change your systems. You or your IT partner fix, and the read-only agent shows the controls holding afterwards. Staff trained the same month, no per-module charges.

Book the practice visit

Your staff, trained and scored

It is all right to skip the suspicious email. Next time, press the report button too.

Every plan includes staff awareness and phishing training, scored per person and per team, with no per-module charges. Short monthly sessions tied to what is hitting businesses this month, phishing tests that teach one habit, and a report button beside the inbox. It is all right to skip the suspicious email. Next time, report it too; one report protects the whole company.

  • Short monthly training tied to the threats hitting businesses this month, not a yearly video.
  • Scored per person and per team, so you know who needs a hand, with no per-module charges.
  • Phishing tests that teach the report habit; one report protects the whole company.

Enterprise-grade discipline, engineers who answer the phone, and a team that built this for the institutions that spend the most. We run it for you because we care about what you built.

What we do for a business in Dubai

Assess it, map it to your regulators, keep an eye on it.

Assess

Cybersecurity and Data Protection Assessment

For any business, regulated or not: an architecture studio, a design firm, a retailer, a trading company. Where the money, the records and the files actually live, what would stop the business for a week, and the ten fixes that matter first, mapped to any regulator that applies to you.

Details

Comply

Compliance readiness mapped to your regulators

ADHICS, DHA, MOHAP, DESC, DIFC, ADGM, the UAE IA Standard or the PDPL: one control set, evidence produced once, ready the day a regulator, a client or an insurer asks. The regulator has the final say; we get you ready for it.

Details

Keep an eye on it

The read-only compliance agent

Read-only insight so you prioritize the right things and keep an eye on them. We have no access to your systems and we do not remediate. You or your IT partner fix; we show you where, then we check again, and repeat.

Details

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital group decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it inside those institutions. We now run it for the medium-size supplier, the clinic and the government supplier, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one organization.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a government client or a bank asks for, produced once and kept current by the read-only compliance agent.

A supplier to a government entity or a bank is a link in a chain. A breach there is not a small-business story; it reaches the entity, its customers and the people who depend on it. The same is true, at a smaller scale, for the accounting firm that holds nine hundred client files and the clinic that holds twelve thousand patient records.

Questions owners in Dubai ask

What people search for, answered straight.

What does a cybersecurity company in Dubai actually do for a business of twenty to two hundred people?

Three things, in order. An assessment that shows where the money, the records and the drawings live, what would stop the business for a week, and the ten fixes that matter first. A compliance readiness map to whichever regulators apply to you, DHA, DESC, DIFC, VARA or the PDPL, with evidence produced once. And a read-only compliance agent that keeps the picture current so you can see what changed. We do not take over your systems and we do not remediate; you or your IT partner fix, we show you where, then we check again.

Which rules apply to a clinic in Dubai: DHA, DHCC or the federal law?

A DHA-licensed clinic answers to the Dubai Health Data Law, the DHA data-protection policy and the NABIDH terms. A clinic inside Dubai Healthcare City answers to the DHCC regulator instead. Both sit under Federal Law 2 of 2019, which keeps health data inside the UAE, and the federal PDPL. The assessment maps all of it to one control set; the DHA’s own process governs licensing decisions.

What is DESC ISR compliance and does my company need it?

The Dubai Information Security Regulation v3 and the Cloud Service Provider Security Standard are published by the Dubai Electronic Security Center for Dubai government entities and the providers that host or process their data. If you sell software, cloud or IT services to a Dubai government client, the contract will ask for alignment or certification and for data residency. If you do not, DESC is not your regulator, and we will tell you so in the first call rather than sell you a program you do not need.

Does the UAE PDPL apply to my Dubai business, and what do I do if there is a breach?

The federal PDPL applies to any business that processes personal data of people in the UAE, which is nearly every business with customers and staff. DIFC and ADGM run their own data-protection laws for their entities. On a breach that threatens privacy the law asks you to notify the UAE Data Office; it does not set a fixed hour count, and the Implementing Regulations were still unissued as of September 2026. The practical answer is to have the breach assessment and the notification draft written before you need them, which is part of the assessment.

Do I need ISO 27001 in Dubai?

No law requires it, but tenders and enterprise clients increasingly do, and DESC, DIFC and the PDPL all map cleanly onto it. If your pipeline is asking, we build readiness on the same control set that answers your regulators, so the certificate is a by-product rather than a second project. If nobody is asking, the assessment and the read-only agent give you the security without the audit.

How much does a cybersecurity assessment cost in Dubai?

A fixed fee, scoped in the thirty-minute call from the size of the business and the systems in play, and priced for a business of twenty to two hundred people rather than for a bank. Staff training is included with no per-module charges. You leave the call with the scope and the number whether we work together or not.

Sources: Gulf News: UAE thwarts 416 cyberattacks every second (August 2026) · Khaleej Times: UAE faces 200,000 daily cyberattacks (October 2025) · Verizon 2026 Data Breach Investigations Report · u.ae: data protection laws · Dubai Electronic Security Center: standards and policies · Dubai Health Authority: NABIDH · DIFC: data protection

The regulator has the final say. We help interpret, scope and get you ready; we do not certify.

Never too big or too small

Thirty minutes with an engineer. Bring your questions, leave with a scope and a number.

Book the call and we walk through a business like yours: what applies, what to fix first, and what the read-only agent would show you every week. Or leave your details and an engineer in our Dubai practice replies within one business day, in English or Arabic.