Book a 20-min call

TECHNOLOGY SERVICE · 07

Security & Compliance

Assessment, control design and remediation for organisations that answer to a regulator, a government client or a demanding enterprise customer. Practical engineering work rather than a policy pack that nobody implements.

Know which regulator you answer to

In the UAE the applicable regime depends on where you are licensed and what you handle. A mainland company falls under the federal personal data protection law, a DIFC or ADGM entity under that free zone's own data protection regulations, and Dubai government suppliers face additional information security requirements. Financial services and healthcare add their own layers on top.

Scoping starts by establishing which of these actually bind you, confirmed with your legal counsel. Controls built against the wrong regime are expensive and reassure nobody.

  • Applicable obligations identified by entity and data type
  • Data inventory with classification and residency constraints
  • Gap analysis against the standard you are being asked to meet

Controls that survive an audit day

An auditor asks for evidence, not intent. Each control is designed with the artefact it produces: an access review with a dated export, a change record tied to a merge, a backup restore with a test log. Controls that cannot generate evidence automatically tend to decay within two quarters.

Policies are written last, describing what the systems already do, which is why they survive contact with the people expected to follow them.

Fix the findings that would actually be exploited

A scanner will return hundreds of items. Triage matters more than the scan: exposure, exploitability and what sits behind the asset decide the order of work, and we will argue for accepting some findings rather than spending your budget on noise. Every accepted risk is recorded with an owner and a review date.

Third parties are inside your perimeter

Most estates now depend on a dozen suppliers with production access, and a supplier breach is your incident to report. Vendor review criteria, contractual data processing terms and a register of who can reach what are part of the same programme rather than a procurement afterthought.

What you get

  • Scoping note stating which obligations apply and why
  • Data inventory with classification, residency and retention rules
  • Gap analysis against the target standard, with severity ratings
  • Prioritised remediation plan with owners and effort estimates
  • Hardened configuration baselines and pipeline security checks
  • Incident response plan, tested through a tabletop exercise
  • Access review, logging and evidence collection running automatically
  • Vendor risk register and template data processing terms

Typical outcomes

3-4 weeks

Assessment to a prioritised remediation plan

Top 10

Critical findings closed before breadth work starts

24 hours

Target to triage a reported vulnerability

Stack we use

Microsoft Entra IDOktaHashiCorp VaultWazuhSnykOWASP ZAPBurp SuiteTerraform

Questions

No. Certification is issued by an accredited certification body, and we do not act as one. Our role is to build the controls and the evidence trail so the audit is a formality rather than a scramble.

Not universally. The federal personal data protection law permits cross-border transfer under defined conditions, while sector rules in finance, health and government are often stricter. We establish which case you are in before any architecture is fixed.

We run application and infrastructure security testing as part of remediation work. For a formal independent penetration test, an external firm is the right choice, and we will prepare the environment and fix what they find.

Yes, as standard, before any access is granted. Where you have your own templates we work to those, and our engineers sign individual confidentiality undertakings as well.

Next step

Start with a 20-minute call.

Tell us the roles you need filled, the system you need built, or both. You will speak to someone who has done the work, and leave the call with a route forward.