ADGM · FSRA-regulated firms

IT and cyber security for firms in Abu Dhabi Global Market.

Managed IT, Microsoft 365 governance and cyber security for FSRA-regulated firms, built around the Cyber Risk Management Rules that took effect on 31 January 2026.
Built for ADGM

New cyber rules, and a regulator that will ask for evidence

The FSRA’s Cyber Risk Management Rules bring cyber risk into every authorised firm’s risk framework, set clear expectations for how you oversee IT providers, and require material cyber incidents to reach the FSRA within 24 hours.
Cre8 IT runs the technical controls you own, supplies the information you need to assess us as a provider, and keeps the evidence organised so a request from the FSRA, an auditor or a client takes minutes to answer.

What ADGM firms ask us for

What the regulator expects

How we support the FSRA Cyber Risk Management Rules

These rules apply to authorised persons and recognised bodies in proportion to the size and complexity of the business. Here is what we do for each area.

Cyber risk in your risk framework

The FSRA expects cyber risk to be part of your overall risk management. We supply the technical risk inputs and evidence that the controls work.

ICT provider oversight

Due diligence before you appoint, clear contract terms and ongoing supervision. We expect to be assessed and provide our certificate, scope and control information.

Contract terms

Security obligations, review and audit rights, incident notification, subcontractor controls and data return. We will work through these terms with you.

Protective controls

Multi-factor authentication, Conditional Access, device management, patching, encryption, backup and training, reported monthly.

Incident readiness

A material cyber incident must reach the FSRA immediately, and within 24 hours at the latest. We help you agree who decides, rehearse the process and keep the logs you will need.

Evidence

A standing evidence pack, so a review request takes minutes rather than days.
Summary for orientation, checked against the regulators’ published text on 19 September 2026. Confirm the current wording in the Rulebooks. This is not legal advice.

Where we help on data protection

Data protection

ADGM Data Protection Regulations 2021

ADGM’s Data Protection Regulations 2021 are overseen by the Commissioner of Data Protection. A controller must notify a personal data breach to the Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. If notification is later than 72 hours, it must explain the delay.
We build the technical measures that make that possible: access control, encryption, logging and a fast way to establish what happened. Decisions about lawful basis, notices and whether a breach must be notified belong with your data protection lead or legal adviser.
How we work with you

From first assessment to steady state

1. Assess

A cyber health audit and gap assessment against the FSRA’s cyber rules, with a prioritised plan.

2. Secure

A secure baseline: multi-factor authentication, Conditional Access, managed devices, endpoint protection, backup and recovery.

3. Evidence

Registers, reports and records collected into an evidence pack your compliance officer can use.

4. Operate

Helpdesk, monitoring and regular reviews, with reports written for your governing body.
Why Cre8 IT

Certified, experienced and open to scrutiny

We support an ADGM-based strategic advisory and investment firm, and helped it start small and grow fast, including a cross-country Microsoft 365 migration to the UAE that took regulatory requirements into account. Our own information security management system is certified to ISO 27001:2022.
Our UAE office is in Dubai, and we support ADGM firms remotely and on site.

Our credentials

ISO 27001:2022

Information security management

ISO 9001

Quality management

Microsoft Partner

Certified partner
Guides

Guides for ADGM firms

Sourced to the regulator’s own text, dated and written by a named specialist.
Vendor management

IT vendor and outsourcing management for DFSA and FSRA firms

How to manage IT providers when you are regulated in DIFC or ADGM: a register, tiering, due diligence, contract terms and ongoing oversight.
4 min read · Reviewed 19 September 2026
DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026
FAQ

ADGM and FSRA questions

What changed for ADGM firms on 31 January 2026?

The FSRA’s Cyber Risk Management Rules took effect for authorised persons and recognised bodies. They integrate cyber risk into the firm’s risk framework, set expectations for oversight of ICT providers and require material cyber incidents to be notified to the FSRA.

How fast must an ADGM firm notify the FSRA of a material cyber incident?

Immediately, and in any event no later than 24 hours after becoming aware, or having information that reasonably suggests, that a material cyber incident has occurred. The FSRA provides a prescribed form.

What should an ADGM firm’s contract with an IT provider include?

The FSRA’s expectations cover clear security obligations, the right to verify the provider’s compliance (by your own audit, a review of its controls or independent reports), notification of material cyber incidents, controls on subcontractors and return or deletion of data at the end. See our vendor management guide.

Do you have an office in Abu Dhabi?

Our UAE office is in Dubai, in Jumeirah Lake Towers. We support ADGM firms remotely and with on-site visits, and we already support an ADGM-based advisory and investment firm.

Talk to a specialist about the FSRA’s cyber rules

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.