DIFC · DFSA-regulated firms

IT support that stands up to a DFSA review.

Managed IT, Microsoft 365 governance and cyber security for firms authorised by the Dubai Financial Services Authority, run by an ISO 27001:2022 certified team that supports DFSA-regulated firms today.
Built for the DIFC

A DIFC firm’s IT is more than uptime

The DFSA expects a written cyber risk management framework, tested controls, oversight of your providers and evidence you can produce quickly. Your compliance officer should not have to chase screenshots.
Cre8 IT runs the technical controls you own and produces the records that show they work: monthly reports on multi-factor authentication, patching and backups, access reviews and incident readiness. You keep governance and accountability. We make the evidence easy to find.

What DIFC firms ask us for

What the regulator expects

How we support DFSA GEN 5.5 and outsourcing rules

The DFSA’s cyber risk management rules are proportionate and outcome-based. These are the areas a reviewer is likely to test and what we do for each.

Framework and governance

Your governing body owns the cyber risk management framework. We document the technical controls it relies on and keep them current.

Assets and risk

A live asset register and inputs from our monitoring, so your risk assessments rest on real data.

Protective controls

Multi-factor authentication, Conditional Access, device management, patching, encryption and endpoint protection, reported monthly.

Testing

Cyber health audits and penetration testing, with a tracked remediation plan.

Detection and response

Optional 24/7 monitoring through SOC as a Service, an incident plan we help you write and exercise, and a clear route to the 72-hour DFSA report.

Providers and outsourcing

Under GEN 5.3.21 you stay responsible for outsourced services. We expect to be assessed like any material provider and supply what you need to do it.
Summary for orientation, checked against the regulators’ published text on 19 September 2026. Confirm the current wording in the Rulebooks. This is not legal advice.

Where we help on data protection

Data protection

DIFC Data Protection Law, split into IT jobs and legal jobs

The DIFC Data Protection Law (Law No. 5 of 2020) is enforced by the Commissioner of Data Protection. It expects appropriate technical and organisational measures to protect personal data, and notification of a qualifying breach to the Commissioner as soon as practicable.
Access control, encryption, logging and retention are IT jobs, and we implement them. What personal data you hold, your lawful basis and your notices are legal jobs for your data protection officer or legal adviser.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against GEN 5.5, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance officer can use.

4. Operate

Helpdesk, monitoring and regular reviews, with reports written for your governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

We have been supporting businesses since 2012 and support DFSA-regulated firms today. Our own information security management system is certified to ISO 27001:2022, and we can share our certificate and scope as part of your due diligence.
We also support an ADGM-based advisory and investment firm that started small and grew fast.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for DIFC firms

Sourced to the regulator’s own text, dated and written by a named specialist.
DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in a DFSA- or FSRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026
FAQ

DIFC and DFSA questions

What does IT support for a DFSA-regulated firm include?

Beyond a helpdesk, it includes secure configuration of identity, devices and Microsoft 365, patching and backup, monitoring, incident readiness and the regular reports that become your evidence. We also help you map these to GEN 5.5.

Can you write our DFSA cyber risk management framework?

We can help draft and maintain the technical parts and supporting procedures. The framework itself must be approved by your governing body and owned by senior management, so we work alongside your compliance officer rather than in place of them.

Does a DIFC firm’s IT provider have to be based in the DIFC?

No. Cre8 IT’s Dubai office is in Jumeirah Lake Towers, and our engineers work on site or remotely depending on the arrangement.

Who is responsible if our IT provider has an incident?

You are. Under GEN 5.3.21, outsourcing does not relieve an authorised firm of its regulatory responsibility. That is why contracts should require prompt incident notification, and why you should supervise the provider.

How long does onboarding a DIFC firm take?

It depends on your size, your current set-up and how much needs fixing. After an initial assessment we agree a plan and dates with you and start with the controls that reduce the most risk.

Talk to a specialist about your DFSA obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.