Skip to main contentSkip to main content
NexITC

PILLAR 02 · 10 PRODUCTIZED SKUS

Evidence-grade cybersecurity. PDPL-through-SAMA-CSF aligned.

NexITC's Cybersecurity practice delivers 10 productized engagements spanning posture assessment, compliance fast-tracking, zero-trust architecture (NIST SP 800-207), GRC platform builds, managed SOC operations, and continuous compliance operations. Coverage is aligned to PDPL, ISR v2, ADHICS v2, NESA, and SAMA CSF, with ISO 27001, NIST CSF, NIST SP 800-207, MITRE ATT&CK, and CIS Controls as technical references. AI safety and red-teaming (A9) and sovereign AI infrastructure (B21) sit at the AI/Cyber intersection. All delivery is UAE-resident from Abu Dhabi.

Section 01

The point of view

Regulatory density is the UAE reality. We build postures that survive inspection, not slide decks that survive a steering committee.

No other market layers regulatory obligation the way the UAE does. A healthcare group in Abu Dhabi answers to ADHICS v2 and PDPL. A Dubai government supplier answers to ISR v2. A bank answers to the Central Bank and, for its Saudi operations, to SAMA CSF. A virtual-asset business answers to VARA. Most enterprises here sit under two or three of these at once, with overlapping and occasionally contradictory control language.

The industry's answer to that density has been the compliance matrix: one spreadsheet, five column headings, a tick in each cell. It passes an internal audit and fails an inspection. Regulators in this region increasingly ask for evidence — logs, tickets, attestation trails, exception registers with owners and dates — not a mapping document. Our engagements are designed around producing that evidence continuously rather than assembling it in the two weeks before an assessor arrives.

A control is only real if it produces an artefact on a schedule, and if a named person owns that artefact.

That is what we mean by evidence-grade. A control is only real if it produces an artefact on a schedule, and if a named person owns the artefact. Our GRC builds (B9), compliance operations retainers (C6), and managed SOC (C7) are all structured to emit that evidence as a by-product of normal operation. The posture scorecard (A4) exists to tell you honestly where you are before anyone sells you a programme.

Finally, operations. A 24x7 SOC that cannot brief a UAE regulator in Arabic is a partial capability. Our managed detection and response runbooks are maintained bilingually, our escalation paths assume TDRA CERT notification timelines, and our incident evidence packs are structured to be handed to counsel without rework. Zero trust (B8) is architecture; the SOC is where the architecture proves itself under load.

Section 02

The regulatory overlay

Cybersecurity is the densest regulatory pillar in the portfolio. Five UAE and GCC frameworks drive the majority of scope — PDPL, ISR v2, ADHICS v2, NESA, and SAMA CSF — with NIST CSF, NIST SP 800-207, ISO 27001/27002, MITRE ATT&CK, and CIS Controls used as the underlying control and technique references.

  • PDPL

    Personal Data Protection Law

    Federal personal-data obligations covering lawful basis, data-subject rights, breach notification, and cross-border transfer. Our engagements deliver data inventories, records of processing, DPIA templates, and retention schedules wired into the GRC platform so evidence is continuous rather than reconstructed.

    Applies to: A3 · A4 · B9 · B10 · B17 · C6

  • ISR V2

    Dubai Information Security Regulation v2

    Applies to Dubai Government entities and their suppliers. We map existing controls to ISR v2 domains, close gaps through B8 zero-trust and B10 identity work, and stand up the evidence cadence and exception register that Dubai Electronic Security Center reviews expect.

    Applies to: A3 · A4 · B8 · B10 · C6

  • ADHICS V2

    Abu Dhabi Healthcare Information and Cyber Security Standard v2

    Mandatory for Abu Dhabi healthcare providers and their processors. Engagements cover control-domain gap assessment, medical-device and clinical-system segmentation, third-party assurance, and the DoH-facing evidence pack maintained continuously under a C6 retainer.

    Applies to: A3 · B8 · B9 · B12 · C6 · C7

  • NESA

    UAE Information Assurance Standards (NESA / UAE IA)

    National-level assurance controls for critical infrastructure and government entities. We prioritise the mandatory control subset, align OT-adjacent scope with IEC 62443 through B12, and structure SOC detections (C7) to the threat scenarios NESA expects entities to demonstrate coverage against.

    Applies to: A4 · B8 · B12 · C7

  • SAMA CSF

    Saudi Central Bank Cyber Security Framework

    Applies to UAE-headquartered financial groups with Saudi operations. We run maturity-level scoring against the framework's four domains, remediate to the target level, and maintain board-reportable maturity evidence through compliance operations rather than annual sprints.

    Applies to: A4 · A10 · B9 · C6

Section 03

The Cybersecurity portfolio

The Cybersecurity pillar spans 10 productized engagements. Three Entry-tier assessments establish posture and compliance baselines. Five Build-tier engagements implement zero trust, identity, GRC, and OT security. Two Run-tier subscriptions sustain managed SOC and compliance operations. No Expand-tier engagement — multi-quarter security transformation is delivered as sequenced Build SKUs under one programme governance wrapper.

Entry

Diagnostics and readiness sprints — 2 to 3 weeks. Includes UAE Agentic AI Mandate and PDPL readiness work.

See all Entry services →

Build

Implementation engagements — 6 to 14 weeks. Platforms, controls, and NexAI Agent Foundry builds.

See all Build services →

Run

Managed subscriptions — ADHICS v2, NESA, and SAMA CSF evidence maintained continuously.

See all Run services →

Healthcare setting illustrating the Cybersecurity flagship engagement
Illustrative — Healthcare

Section 04 · Flagship case study

Zero Trust as four named controls precisely. Not a three-year transformation programme.

Cybersecurity · Healthcare · B9 Zero-Trust Core Build™ · 12 weeks

CONTROLS OPERATIONAL AT AUDIT
4 / 4CONTROLS OPERATIONAL AT AUDIT
SIGN TO AUDIT-READY
12 WEEKSSIGN TO AUDIT-READY
COST BELOW GLOBAL-SI PROPOSALS
~85%COST BELOW GLOBAL-SI PROPOSALS

A UAE healthcare provider approaching an ADHICS v2 audit cycle wanted Zero Trust posture in place — not as a strategic aspiration but as evidence a regulator could inspect. B9 delivered four named controls in twelve weeks with acceptance criteria per control. The audit went ahead with the controls operational. The alternative — a global-SI transformation programme quoted at 18 months — was declined at scoping.

Illustrative composite — a representative pattern drawn from NexITC engagements, not a specific client narrative.

Section 05 · Field notes

From our practice.

Long-form POVs from our Cybersecurity practice lead. Lower cadence, deeper analysis. What we're seeing in UAE enterprise Cybersecurity work.

Browse all Cybersecurity Field Notes →

Section 07 · FAQ

Frequently asked questions.

The questions UAE buyers ask most often about our Cybersecurity engagements — scope boundaries, sequencing, and regulatory fit.

  • It depends on sector and jurisdiction. PDPL applies federally to almost everyone. Dubai Government suppliers add ISR v2. Abu Dhabi healthcare adds ADHICS v2. Critical infrastructure adds NESA. Financial groups with Saudi operations add SAMA CSF. The A4 Security Posture Scorecard establishes which apply and where you stand against each.

Ready to start with Cybersecurity?

Most Cybersecurity engagements begin with a 30-minute architecture clinic. We'll help you pick the right SKU or design a scope if none fits.