
Cybersecurity
Five frameworks, one control set: de-duplicating UAE compliance obligations
By Practice Lead — Cybersecurity
11 MIN READ · JUNE 2026
PILLAR 02 · 10 PRODUCTIZED SKUS
NexITC's Cybersecurity practice delivers 10 productized engagements spanning posture assessment, compliance fast-tracking, zero-trust architecture (NIST SP 800-207), GRC platform builds, managed SOC operations, and continuous compliance operations. Coverage is aligned to PDPL, ISR v2, ADHICS v2, NESA, and SAMA CSF, with ISO 27001, NIST CSF, NIST SP 800-207, MITRE ATT&CK, and CIS Controls as technical references. AI safety and red-teaming (A9) and sovereign AI infrastructure (B21) sit at the AI/Cyber intersection. All delivery is UAE-resident from Abu Dhabi.
Section 01
Regulatory density is the UAE reality. We build postures that survive inspection, not slide decks that survive a steering committee.
No other market layers regulatory obligation the way the UAE does. A healthcare group in Abu Dhabi answers to ADHICS v2 and PDPL. A Dubai government supplier answers to ISR v2. A bank answers to the Central Bank and, for its Saudi operations, to SAMA CSF. A virtual-asset business answers to VARA. Most enterprises here sit under two or three of these at once, with overlapping and occasionally contradictory control language.
The industry's answer to that density has been the compliance matrix: one spreadsheet, five column headings, a tick in each cell. It passes an internal audit and fails an inspection. Regulators in this region increasingly ask for evidence — logs, tickets, attestation trails, exception registers with owners and dates — not a mapping document. Our engagements are designed around producing that evidence continuously rather than assembling it in the two weeks before an assessor arrives.
A control is only real if it produces an artefact on a schedule, and if a named person owns that artefact.
That is what we mean by evidence-grade. A control is only real if it produces an artefact on a schedule, and if a named person owns the artefact. Our GRC builds (B9), compliance operations retainers (C6), and managed SOC (C7) are all structured to emit that evidence as a by-product of normal operation. The posture scorecard (A4) exists to tell you honestly where you are before anyone sells you a programme.
Finally, operations. A 24x7 SOC that cannot brief a UAE regulator in Arabic is a partial capability. Our managed detection and response runbooks are maintained bilingually, our escalation paths assume TDRA CERT notification timelines, and our incident evidence packs are structured to be handed to counsel without rework. Zero trust (B8) is architecture; the SOC is where the architecture proves itself under load.
Section 02
Cybersecurity is the densest regulatory pillar in the portfolio. Five UAE and GCC frameworks drive the majority of scope — PDPL, ISR v2, ADHICS v2, NESA, and SAMA CSF — with NIST CSF, NIST SP 800-207, ISO 27001/27002, MITRE ATT&CK, and CIS Controls used as the underlying control and technique references.
PDPL
Federal personal-data obligations covering lawful basis, data-subject rights, breach notification, and cross-border transfer. Our engagements deliver data inventories, records of processing, DPIA templates, and retention schedules wired into the GRC platform so evidence is continuous rather than reconstructed.
ISR V2
Applies to Dubai Government entities and their suppliers. We map existing controls to ISR v2 domains, close gaps through B8 zero-trust and B10 identity work, and stand up the evidence cadence and exception register that Dubai Electronic Security Center reviews expect.
ADHICS V2
Mandatory for Abu Dhabi healthcare providers and their processors. Engagements cover control-domain gap assessment, medical-device and clinical-system segmentation, third-party assurance, and the DoH-facing evidence pack maintained continuously under a C6 retainer.
NESA
National-level assurance controls for critical infrastructure and government entities. We prioritise the mandatory control subset, align OT-adjacent scope with IEC 62443 through B12, and structure SOC detections (C7) to the threat scenarios NESA expects entities to demonstrate coverage against.
SAMA CSF
Applies to UAE-headquartered financial groups with Saudi operations. We run maturity-level scoring against the framework's four domains, remediate to the target level, and maintain board-reportable maturity evidence through compliance operations rather than annual sprints.
Section 03
The Cybersecurity pillar spans 10 productized engagements. Three Entry-tier assessments establish posture and compliance baselines. Five Build-tier engagements implement zero trust, identity, GRC, and OT security. Two Run-tier subscriptions sustain managed SOC and compliance operations. No Expand-tier engagement — multi-quarter security transformation is delivered as sequenced Build SKUs under one programme governance wrapper.
Diagnostics and readiness sprints — 2 to 3 weeks. Includes UAE Agentic AI Mandate and PDPL readiness work.
Implementation engagements — 6 to 14 weeks. Platforms, controls, and NexAI Agent Foundry builds.
Managed subscriptions — ADHICS v2, NESA, and SAMA CSF evidence maintained continuously.

Section 04 · Flagship case study
Cybersecurity · Healthcare · B9 Zero-Trust Core Build™ · 12 weeks
A UAE healthcare provider approaching an ADHICS v2 audit cycle wanted Zero Trust posture in place — not as a strategic aspiration but as evidence a regulator could inspect. B9 delivered four named controls in twelve weeks with acceptance criteria per control. The audit went ahead with the controls operational. The alternative — a global-SI transformation programme quoted at 18 months — was declined at scoping.
Illustrative composite — a representative pattern drawn from NexITC engagements, not a specific client narrative.
Section 05 · Field notes
Long-form POVs from our Cybersecurity practice lead. Lower cadence, deeper analysis. What we're seeing in UAE enterprise Cybersecurity work.

Cybersecurity
By Practice Lead — Cybersecurity
11 MIN READ · JUNE 2026

Cybersecurity
By Practice Lead — Cybersecurity
9 MIN READ · MAY 2026

Cybersecurity
By Practice Lead — Cybersecurity
8 MIN READ · APRIL 2026
Section 07 · FAQ
The questions UAE buyers ask most often about our Cybersecurity engagements — scope boundaries, sequencing, and regulatory fit.
It depends on sector and jurisdiction. PDPL applies federally to almost everyone. Dubai Government suppliers add ISR v2. Abu Dhabi healthcare adds ADHICS v2. Critical infrastructure adds NESA. Financial groups with Saudi operations add SAMA CSF. The A4 Security Posture Scorecard establishes which apply and where you stand against each.
Both. C7 is a managed detection and response subscription with 24x7 monitoring, bilingual runbooks, and TDRA CERT-aligned escalation timelines. C6 is a compliance operations retainer that maintains evidence continuously. Advisory-only engagements sit in the Entry tier.
B8 is scoped as a staged engagement, typically 10 to 14 weeks for the first two stages: identity and device trust, then network and application segmentation. We do not attempt a full estate cut-over in one engagement; the sequencing is defined during the A4 scorecard.
Yes. A3 Compliance Fast-Track is designed for exactly that window — a three-week engagement that assembles the evidence pack, identifies unclosable gaps honestly, and prepares the exception register and remediation plan you will be asked to present.
Yes. A10 Cyber Insurance Readiness Pack maps your current controls to the questions underwriters in this market actually ask, identifies the control gaps that drive premium loading or exclusions, and produces the evidence bundle for submission.
Most Cybersecurity engagements begin with a 30-minute architecture clinic. We'll help you pick the right SKU or design a scope if none fits.