FAQ

Questions regulated firms ask us.

Short, sourced answers on DIFC and ADGM expectations, Microsoft 365, ISO 27001, Cyber Essentials and working with Cre8 IT.
DIFC, ADGM and the regulators

The rules behind the questions

What is the difference between the DFSA and the FSRA?

The DFSA regulates financial services in the Dubai International Financial Centre (DIFC) in Dubai. The FSRA regulates financial services in Abu Dhabi Global Market (ADGM) in Abu Dhabi. Each has its own rulebook, so a firm follows the rules of the regulator that authorises it, and a group with entities in both must meet both.

Which cyber rules apply to DIFC firms and which to ADGM firms?

DIFC firms follow the DFSA Rulebook, mainly GEN 5.5 on cyber risk management and GEN 5.3.21 on outsourcing. ADGM firms follow the FSRA’s Cyber Risk Management Rules in GEN 3.5, in force since 31 January 2026. See our DFSA guide and our page for ADGM firms.

How do incident reporting deadlines differ between DIFC and ADGM?

The DFSA expects a material cyber incident to be reported as soon as reasonably practicable and within 72 hours at the latest. The FSRA expects notification immediately and within 24 hours at the latest. Personal data breaches follow separate data protection rules: as soon as practicable in DIFC, and within 72 hours where feasible in ADGM.

Are these pages legal advice?

No. They summarise what regulators publish and how firms can meet it. Confirm the current rules and take advice from your compliance officer or legal adviser about your own obligations.
Microsoft 365 and security basics

Plain answers to common security questions

What is Microsoft 365 governance?

It is the set of decisions, settings and records that control who can reach your data, from which devices, how long it is kept and how you would prove it. It covers identity, devices, sharing, retention and logging. See the full guide.

What is multi-factor authentication and why do regulators expect it?

Multi-factor authentication (MFA) asks for a second proof of identity, such as an authenticator app, as well as a password. Stolen passwords are a common way in, and MFA stops most of those attacks. The DFSA’s cyber rules expect MFA for internet-facing systems and privileged access.

What is the difference between ISO 27001 and Cyber Essentials?

ISO 27001 certifies a full information security management system covering governance, risk, people, suppliers and technology. Cyber Essentials is a UK scheme that verifies five technical controls. Cyber Essentials is a quicker, cheaper baseline; ISO 27001 is broader. See our guides to ISO 27001 and Cyber Essentials.

What does “audit ready” mean for IT?

It means you can produce, on request, evidence that your controls exist, operate and are reviewed: registers, dated reports and records with named owners. Our audit readiness checklist shows how to build it.

What is SOC as a Service?

SOC as a Service is round-the-clock threat monitoring by a dedicated security operations centre, delivered as a managed service, so you get 24/7 detection without building your own team.
Working with Cre8 IT

About our service

Where is Cre8 IT based and who do you support?

Our head office is in Jumeirah Lake Towers, Dubai, with offices in the United Kingdom and Riyadh. We have supported businesses since 2012 across hospitality, retail, finance and education, including regulated financial firms.

Which certifications does Cre8 IT hold?

We are certified to ISO 27001:2022 for information security and ISO 9001 for quality management, and we are a certified Microsoft Partner.

What does managed IT support include?

A helpdesk phone line and ticketing system, proactive monitoring of networks and devices, virus detection and removal, scheduled backups with tested recovery, on-site visits as often as you need, and 24/7 emergency support.

How is managed IT support priced?

A fixed monthly rate shaped around your requirements, your budget and how often you want us on site. Ask for a free estimate.

Do you offer 24/7 support?

Yes. We provide 24/7 emergency IT support, on site or remote.

Can start-ups and non-profits get a free consultation?

Yes. New start-ups and non-profits can book a complimentary 30-minute consultation.

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.