Financial Services
Five regulators. One program.
A financial firm in the Emirates can answer to the Central Bank, the SCA, the DFSA, the FSRA and VARA, each with its own cyber rulebook and its own clock. We map them into one control set so evidence is produced once and satisfies every regulator that applies to you.
We are the GRC and compliance experts who pull it all together and make security look easy, so you can focus on actual security.
average cost of a financial-sector breach in the Middle East, the region’s costliest sector
Source: IBM Cost of a Data Breach 2026
incident notification window for ADGM firms under the FSRA framework live since January 2026
Source: FSRA Cyber Risk Management Framework
the Cybersecurity Council disclosed AI-powered attacks aimed at the financial sector, detected and stopped
Source: UAE Cybersecurity Council, via Khaleej Times
Why it feels harder than it should
Several rulebooks, one business.
The Emirates built financial regulation deliberately: federal authorities for the mainland, free zones with their own courts and regulators built to international standards, and a dedicated authority for virtual assets. Each rulebook is serious and each is different. DIFC firms review their cyber incident response plan at least annually and notify within 72 hours. ADGM firms operate a board-approved cyber framework with 24-hour notification, live since January 2026. VARA licensees undergo independent security audits and penetration tests. Onshore, the Central Bank and SCA set their own expectations, including mandated independent IT audits for robo-advisers. Running these in parallel by hand is where compliance teams drown.
What this looks like in practice
Take one concrete case. A payments fintech incorporated in ADGM, serving mainland merchants, that adds a virtual-asset product in Dubai: FSRA cyber framework and data protection renewal in the free zone, Central Bank retail payment rules on the mainland side, VARA technology rulebook for the Dubai virtual-asset entity, and the federal PDPL underneath all of it. Four programs on four clocks, or one AccuSights program mapped to all four.
What actually hits financial firms
Verizon analyzed 1,300 confirmed financial-sector breaches this year: 88% external attackers, 98% financially motivated. In our region the picture sharpens further, and in July 2026 the Cybersecurity Council disclosed AI-powered attacks aimed at the financial sector, detected and stopped. The entry points are unglamorous, which is the good news: they are fixable.
average financial-sector breach cost in the Middle East, the region’s costliest
Source: IBM Cost of a Data Breach 2026
of financial breaches involve the human element
Source: Verizon 2026 DBIR
How they get in
Source: Verizon 2026 DBIR, Financial & Insurance breach entry points
The authorities that reach this sector.
CBUAE
Central Bank of the UAE
Regulates banks, finance companies, exchange houses, payment providers, stored-value facilities, and insurers, with information security and consumer data duties throughout.
DoH
Department of Health, Abu Dhabi
Licenses Abu Dhabi healthcare and mandates ADHICS, the emirate’s healthcare information and cyber security standard, with Malaffi HIE participation.
DHA
Dubai Health Authority
Licenses Dubai healthcare, runs the NABIDH health information exchange, and sets standards including ST-14 for telehealth and health data.
SCA
Securities & Commodities Authority
Regulates onshore capital markets: brokers, fund and asset managers, advisers, listed companies, onshore virtual-asset providers, and robo-advisers, whose rules mandate independent IT audits.
VARA
Virtual Assets Regulatory Authority (Dubai)
Regulates Dubai virtual-asset service providers. Its Technology & Information Rulebook requires independent security audits, penetration tests, tested incident response, and key-management controls.
DFSA
Dubai Financial Services Authority (DIFC)
Regulates financial firms in the DIFC free zone. Its GEN 5.5 rules require a written cyber risk framework, an incident response plan reviewed at least annually, and 72-hour incident notification.
DIFC DP
DIFC Commissioner of Data Protection
Administers the DIFC Data Protection Law (DPL 2020), including annual registration renewal for every DIFC entity that processes personal data.
FSRA
Financial Services Regulatory Authority (ADGM)
Regulates ADGM financial firms. Its Cyber Risk Management Framework, live since 31 January 2026, requires a board-approved program reviewed annually and 24-hour incident notification.
ADGM DP
ADGM Office of Data Protection
Administers ADGM Data Protection Regulations 2021, including annual renewal for registered establishments.
Your regulators, sector by sector
Find yourself in the list.
We cover every name on it.
Banks and digital banks
- Focus
- Board-level cyber governance, security operations, encryption, outsourcing and cloud rules, consumer data protection, business continuity.
- Standards
- ISO 27001 in practice; PCI DSS where cards; SWIFT CSP where connected.
- Certification
- SWIFT CSP annual attestation where applicable.
- Rhythm
- Annual audit, annual penetration test, continuity testing.
Payment providers, e-wallets and payment tokens
- Focus
- Incident response plans, access control and audit trails, secure development, real-time monitoring, two-factor authentication, and for stored-value facilities an annual gap assessment with independent technology audit.
- Standards
- ISO 27001 or equivalent expected; PCI DSS for card flows.
- Certification
- Standards-based; independent technology audit for stored-value facilities.
- Rhythm
- Annual assessments; attack-simulation testing above volume thresholds; annual continuity test with board sign-off.
Exchange houses and remittance
- Focus
- AML and IT security together: data integrity, system availability, incident reporting, continuity.
- Standards
- ISO-style controls; PCI or SWIFT where applicable.
- Certification
- Standards-based, with independent AML testing.
- Rhythm
- AML returns and inspections; annual audit.
Insurers, brokers and TPAs
- Focus
- Incident response plans are explicitly required for brokers; consumer data with ten-year retention; for health TPAs, ADHICS Advanced obligations layer on top.
- Standards
- ISO-style controls for large data holders; ADHICS Advanced for health data; PCI where card data.
- Certification
- ADHICS applies to health-data TPAs; otherwise standards-based.
- Rhythm
- Annual external audit of systems and controls; quarterly interim reporting.
Brokers, fund and asset managers, advisers (SCA)
- Focus
- Client-asset safeguarding, trading and portfolio system resilience, outsourcing and vendor risk, data protection, continuity.
- Standards
- International standards expected; ISO and NIST in practice.
- Certification
- Standards-based; robo-advisers require recurring independent IT audits.
- Rhythm
- Quarterly externally-audited interim reporting for brokers; annual accounts; technology control reviews.
Virtual-asset firms (VARA, Dubai)
- Focus
- Technology governance, key management, independent audits and penetration tests, tested incident response, insider and privileged-access controls, vendor risk, transaction monitoring.
- Standards
- Independent security audits and penetration tests required by the Technology & Information Rulebook.
- Certification
- Yes: independent security audit and penetration test.
- Rhythm
- Regular audits and tests; incident notification to VARA.
DIFC financial firms
- Focus
- A written cyber risk framework under GEN 5.5, an incident response plan reviewed at least annually, threat-intelligence participation, 72-hour incident notification, plus annual data protection renewal.
- Standards
- Framework-agnostic: ISO, NIST or CIS accepted.
- Certification
- Data protection registration with annual renewal.
- Rhythm
- Cyber plan review at least annually; DFSA returns; annual DP renewal.
ADGM financial firms
- Focus
- The FSRA Cyber Risk Management Framework, live since 31 January 2026: board-approved, reviewed annually, technology contract rules, 24-hour incident notification, plus annual data protection renewal.
- Standards
- Recognized international standards: ISO, NIST.
- Certification
- Data protection registration with annual renewal.
- Rhythm
- Annual framework review; FSRA returns; annual DP renewal.
These are summary profiles. Behind each one sits a complete obligation map, control set and calendar that AccuSights maintains for clients. Seeing yours is what a demo is for.
One program instead
How we make it one control set.
AccuSights maps your controls once against every rulebook that applies: CBUAE, SCA, DFSA, FSRA, VARA and the PDPL. Evidence is collected once and reused everywhere, renewals and reviews land on one calendar, and our read-only compliance agent keeps continuous watch over your posture across infrastructure and cloud, observing and reporting while you stay in control. Up to 75% less duplicate compliance work, and the time goes back into actual security.
Cross-mapped controls
One control, mapped to every regulator on this page that it satisfies.
Evidence collected once
Reused across every emirate, free zone, and framework that applies to you.
Always audit-ready
A read-only compliance agent keeps the picture current. You keep the keys.
Global breach figures: Verizon 2026 Data Breach Investigations Report, the 19th edition, analyzing more than 22,000 confirmed breaches across 145 countries. Regional figures: EMEA section of the same report, and UAE public statistics as cited.
Book a demo
See your obligations as one program.
Thirty minutes with an engineer who works in UAE regulation. You leave knowing which rules apply to you, where the gaps are, and how one control set covers them.