If the DFSA authorises your firm, you must maintain a written cyber risk management framework approved by your governing body, oversee any IT provider you rely on, and report material cyber incidents to the DFSA within 72 hours at the latest. The rules are proportionate and outcome-based, so the test is whether you can show your controls fit your business and actually work. Outsourcing IT does not outsource responsibility.
There is no single IT rulebook. For a firm authorised by the Dubai Financial Services Authority (DFSA), the technology and cyber expectations sit in a few places in the General (GEN) module of the DFSA Rulebook, and in DIFC data protection law.
The DFSA applies these proportionately. A ten-person advisory firm and a bank are not expected to look the same, but each must be able to show that its approach fits its size, complexity and risk.
The table summarises the main areas and the evidence that tends to satisfy a reviewer. It is a guide for orientation; the Rulebook text is the authority.
| Area | What the DFSA expects | Evidence worth keeping |
|---|---|---|
| Framework and governance | A written cyber risk management framework, approved by your governing body, proportionate to your business and reviewed at least annually. Senior management is accountable for oversight of cyber risk. | The approved framework, minutes showing your governing body reviewed it, named owners, a statement of risk tolerance. |
| Know your assets and risks | A current inventory of ICT assets, classified by sensitivity and criticality, and regular cyber risk assessments. | Asset register; risk register with owners and treatment decisions. |
| Protect | Controls such as anti-malware, network security, least-privilege access with regular reviews, strong authentication (including multi-factor authentication for internet-facing systems and privileged access), change management, timely patching, encryption proportionate to sensitivity, and staff awareness training. | MFA coverage report, patch compliance reports, access review records, configuration baselines, training completion records. |
| Test | Regular resilience testing, with annual testing expected for internet-facing systems, and a process to fix what it finds. | Penetration test report; remediation tracker with dates and sign-off. |
| Detect and respond | Monitoring for actual and potential cyber incidents, a written incident response plan that is tested and reviewed, and a process to investigate, contain and recover. | Monitoring alerts and reviews, the incident response plan, exercise or test records. |
| Report | Material cyber incidents reported to the DFSA as soon as reasonably practicable, and in any event within 72 hours of becoming aware, using the form on its electronic portal (GEN 5.5.19). | Incident log, materiality decision record, copy of the report submitted. |
The exact wording, and any change since this guide was reviewed, is in GEN 5.5 in the DFSA Rulebook.
GEN 5.3.21 says that a firm that outsources functions or activities directly related to financial services to a service provider, including one in its own group, is not relieved of its regulatory obligations. It must do due diligence in choosing a suitable provider, supervise the outsourced activity effectively, and deal effectively with any failure by the provider that leads, or might lead, to a breach of DIFC legislation. The guidance describes an arrangement as material where weakness or failure of the service would cast serious doubt on the firm’s continuing ability to remain fit and proper or to comply with DFSA-administered laws and rules.
GEN 5.5 adds specific expectations for third-party ICT service providers: due diligence before you appoint, contract terms covering incident notification and remediation, and effective supervision afterwards. In practice that means a register of your IT and cloud providers, proportionate checks before you sign, and evidence that you review them. Our guide to vendor and outsourcing management covers how to do that.
GEN 5.5.19 requires a firm to report a material cyber incident to the DFSA as soon as reasonably practicable, and in any event within 72 hours after becoming aware of it or having information that reasonably suggests it has occurred, using the form on the DFSA electronic portal. The Rulebook guidance lists factors for judging materiality, including risk to customer information, data leakage, business disruption, financial loss and the effect on stakeholders. Other reporting may also apply. A personal data breach, for example, may need to be notified to the DIFC Commissioner of Data Protection as soon as practicable.
Decide these things before an incident, not during one:
These are patterns that commonly appear when regulated firms test their own controls:
Most are cheap to fix once you can see them. Our audit readiness checklist shows how to build the evidence pack that exposes them early.
The Financial Services Regulatory Authority (FSRA) in Abu Dhabi Global Market has its own Cyber Risk Management Rules, in force since 31 January 2026. They share the same goals but differ in detail, including a 24-hour deadline for notifying material incidents. See our page for ADGM firms and the comparison on our regulated industries page.
Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
